Privacy Policy
Last updated: August 24, 2026 (notice published August 10, 2026)
1. What we collect
Account data. Your email address and a salted bcrypt hash of your password (we never store the password itself). If you sign in with Google or Apple we store the provider's stable account id and your verified email — never your social password or tokens beyond the sign-in exchange. We also record the date you accepted these terms and which version, the acceptance method, and your confirmations that you are at least 18 and a United States resident. We do not collect your birth date or identity document for this.
Optional gallery passwords. If you password-protect a published gallery, we store a salted bcrypt hash rather than the gallery password itself. After a viewer enters the correct password, we set a signed, httpOnly gallery-access cookie that expires after seven days. Changing the gallery password invalidates access granted with the earlier one.
Your photos and videos. The files you upload, thumbnails and video poster frames we generate from them, and technical metadata (dimensions, file size, duration, a content checksum used to detect duplicates), plus anything you write: captions, private notes, and tags.
Camera metadata inside your files (EXIF). When you upload a photo we read the metadata your camera or phone embedded in it — camera and lens model, exposure settings, and capture date — and use it to date and arrange your galleries and show you camera details.
We deliberately do not read or store location. Phones commonly write the GPS coordinates of where a photo was taken into the file. We do not extract them, so they are never stored in our database, never appear in backups, and are not in your data export. Furthermore, photos served from a published gallery have their embedded metadata removed as they are sent, so a person you share a gallery link with cannot read the coordinates out of the image file either. The image itself is not altered or recompressed — only the metadata attached to it is dropped.
The file we keep in storage is still the exact file you uploaded, so if it contained location data, that copy still does. It is only ever served back to you, when you view or download your own photo or export your data — which is why your export gives you your true originals. Deleting the photo deletes that file.
Billing. Subscriptions are processed by Stripe. We store your Stripe customer and subscription identifiers and the subscription status — never card numbers. We also keep the exact plan, price, term, allowance, automatic-renewal choice, disclosure version and acceptance time shown at checkout; later renewal changes; and when required billing notices were sent. Card details go directly to Stripe and are never seen by our servers.
Session data. A signed, httpOnly account-session cookie so you stay logged in, stored server-side as a hash with an expiry, plus the gallery-access cookie described above when a viewer unlocks a protected gallery. Short-lived signed cookies protect Google or Apple sign-in (including Apple's identity-token nonce) and a Google Photos import you start. We keep standard server logs (IP address, request path, timestamp) briefly for security and debugging.
Support correspondence. If you send us a customer question or support email, we collect the email address you used and the contents of your message so we can respond or route it to the right person.
Cookieless browser traffic data. Starting August 23, 2026, when someone opens the public 3D viewer or uses the Gallmo management application we may record a pageview, its fixed surface class (such as home, sample gallery, published gallery, dashboard, organizer, or admin), and coarse technical facts such as browser, operating system, device type, screen size and language. We do not send the gallery access token, gallery or account id, email, gallery title, captions, media, form input, full URL, referring URL, precise location, or advertising identifiers. PostHog does not store an analytics cookie or create a person profile for this measurement.
1a. Why we use each of these
- Providing the Service — storing your photos, serving your galleries, and signing you in. Without this data there is no product.
- Taking payment and keeping the billing records we are obliged to keep for tax and accounting.
- Security, abuse prevention and debugging — rate limiting and server logs, so the Service stays available and other people's photos stay safe.
- Cookieless audience measurement — understanding total visits and which public or management surface was opened, so we can operate and improve the Service without building an identifiable browsing history.
- Service email you cannot opt out of while you hold an account: password resets and billing notices.
- Customer support — answering general product questions and routing requests that need a person.
That is the whole list. We do not run advertising or profile you. Our audience measurement is cookieless and does not identify account holders or gallery viewers. If we ever add identifiable analytics, advertising, or marketing email, we will ask first.
2. Camera & gestures
The 3D viewer can optionally use your camera for hand-gesture and head-tracking control. All of that processing happens entirely on your device in your browser — camera frames are never uploaded, stored, or seen by our servers. The camera activates only when you enable it and stops when you turn it off.
3. How we use data
To operate the Service: authenticate you, store and serve your galleries, bill per-gallery subscriptions, prevent abuse, and communicate about your account. We do not sell your data, show ads, or use your photos to train machine-learning models.
4. Sharing & who processes your data
People you share with. Photos in a published gallery are visible to anyone who has its unguessable link or, when you enable password protection, anyone who has both the link and gallery password. Recipients can forward either. You control this: change the password to revoke earlier browser access, remove it to return to link-only access, or unpublish at any time to stop public access.
Our service providers. We use a small number of providers to run the Service. They process data as described below to provide their services:
| Provider | What it does | Data involved | Where |
|---|---|---|---|
| Hosting infrastructure provider | Hosting — the server, database and file storage | Everything you store with us | United States |
| Cloudflare | Delivers published galleries — caches images at locations near your viewers, filters malicious traffic, and screens served images against known child-sexual-abuse-material hash lists (see Section 4b) | Photos and videos in published galleries, and the IP address and request details of people who open a gallery link | Global edge network |
| Stripe | Subscription payments | Email, billing details you give Stripe, subscription status | EU / US |
| Email delivery provider | Sending password-reset email, purchase confirmations, and renewal reminders | Your email address and the message | EU / US |
| Third-party AI service provider (only when automated support is enabled) | Text processing for the automated support agent | The subject and text of a customer question or support email; the sender's email address, photo/video files, and email attachments are not sent | People's Republic of China (current provider) |
| Social sign-in, only if you choose it | Your account id and verified email | US | |
| Apple | Social sign-in, only if you choose it; and hosting the iCloud+ mailbox used for support correspondence | For sign-in, your account id and verified email (which may be an Apple private relay address). If you email support, your sender address and message as ordinary email. | US / global |
| PostHog (only when telemetry is enabled) | Anonymous reliability telemetry and cookieless browser traffic measurement | For server operations: a fixed service identifier, controlled reliability fields, and fixed error category. For browser traffic: an anonymous cookieless pageview, fixed surface class, and coarse browser/device facts. No media, file names, account identifiers, emails, gallery identifiers or access tokens, form inputs, full or referring URLs, advertising identifiers, cookies, or precise location. | US or EU, depending on our configured PostHog region |
| Centralized logging provider (only when centralized logging is enabled) | Stores short-lived server and application logs for security, reliability monitoring and debugging | Timestamp, service name, request path and IP address, plus controlled application errors. We do not intentionally log or send media contents, passwords, session cookies or payment-card data. | US or EU, depending on our configured logging region |
The companies currently filling these provider roles are listed in our Current Service Providers register. We keep that register separate so it can stay accurate when an infrastructure provider changes without obscuring what data is processed, why it is processed, or where it may be processed.
Some of these providers operate internationally, so your data may be processed outside the country you live in. We assess providers' privacy and security practices before using them. We do not sell your data or share it with advertisers. We will disclose data to authorities only where the law genuinely requires it.
Cookieless browser analytics. Starting August 23, 2026, the 3D viewer and management application may send the limited pageview described in Section 1 to PostHog. The analytics library is part of our own browser bundles: it does not enable session replay, heatmaps, automatic click or form capture, surveys, feature flags, advertising, person profiles, or tracking cookies. We remove query strings, titles, referrers and all form input before an event is sent, and request that PostHog discard geolocation data. Neither opening a gallery link nor using an account is reported to an advertiser or data broker. Published galleries are also delivered through Cloudflare, so Cloudflare sees the request as our delivery provider, not to profile you.
Anonymous operational telemetry. Starting August 23, 2026, we may use PostHog to confirm that core server operations, including automated upload screening, are working. This is server-to-server telemetry with one fixed service identity, not a profile of you. It contains only controlled technical fields such as the moderation provider, media type, outcome, failure category, and elapsed time. We do not send your media, file names, account or gallery identifiers, email, IP address, cookies, browser activity, or precise location to PostHog. This operational data uses the same processor but remains separate from the limited cookieless pageviews above. We do not use PostHog session replay, advertising, feature flags, surveys, or marketing.
Centralized operational logs. Starting August 23, 2026, we may copy the standard server logs described in Section 1 to a centralized logging provider so we can inspect failures even when the production server is unavailable. These logs can contain an IP address, request path, timestamp, service name and controlled application error. They are used only for security, reliability and debugging; they are not browser analytics, advertising or profiling, and we do not intentionally include media contents, passwords, session cookies or payment-card data.
4a. Cookies
We use only strictly necessary first-party cookies, never tracking or advertising cookies: the account-session cookie; short-lived social-sign-in state and Apple nonce cookies; and a short-lived Google Photos import-session cookie when you start an import. Because these cookies provide authentication, security, or a feature you requested, they do not require an advertising-cookie consent banner. We set no analytics cookies.
4b. Delivery, caching & screening of published galleries
Published galleries are served through Cloudflare's content-delivery network. Three consequences worth stating plainly:
Copies are cached near your viewers. When someone opens a published gallery, its images may be stored temporarily on Cloudflare servers around the world so the next viewer loads them quickly. These copies are short-lived — our instruction to Cloudflare is to keep them for about five minutes. If you unpublish a gallery, delete a photo, or its photos are deleted at the end of the retention period described in Section 5, a cached copy can still be served for up to a few minutes afterwards before it expires.
Only published galleries are involved. Anything you have not published, and everything you view while signed in to your own account, is served directly by us and is never cached by Cloudflare.
Screening for illegal images. Cloudflare compares images served from published galleries against known hash lists of child sexual abuse material, and notifies us of any match so we can block the content and meet our legal reporting obligations. This particular check only compares served images against lists of already-known illegal files. It is separate from the upload screening described next.
4c. Automated screening of uploads, and when a person sees your photos
Every upload is screened before it is stored. When you add a photo or video — by uploading it or importing it from Google Photos — it is passed through an automated system that scores it for nudity, sexually explicit content, other adult ("NSFW") content, and graphic violence. If a score exceeds our threshold the file is rejected and never stored. Files that pass are stored normally and the scores are not kept against your account.
To perform this screening, we send a resized analysis copy of each photo, or sampled frames from each video, over HTTPS to the moderation provider named in our Service Providers register, or process it in our private moderation service. We do not place uploads in general-purpose cloud storage for this check, and we do not retain safety ratings against your account. We do not use your uploads to train a model or create a profile of you or your family, and no Gallmo employee sees media as part of the automated screening step. If the screening system is unavailable we refuse uploads rather than store them unchecked, so uploading can occasionally be temporarily unavailable.
Automated screening is imperfect. It can reject an innocent photo — swimwear, breastfeeding, art and medical images are all known to trip these models. This is an automated filter on a single upload, not a decision about you or your account, and you can always contact privacy@gallmo.app if a legitimate photo is refused.
When a person may look at your content. We do not browse customer galleries. A member of our team may view specific media in only two situations: when that content has been reported to us, or when we are acting on a legal notice or a suspected breach of the Terms. In those cases we may also suspend an account. Every such action — viewing a reported item, removing content, suspending an account — is written to an internal audit log recording who did it and when.
We also keep aggregate daily request counts in our own database and the limited cookieless PostHog pageviews described above to operate, understand traffic, and capacity-plan. Neither includes an account, gallery, or media identifier, and neither is a per-person browsing history.
Operations automation. Our internal operations assistant, Hermes, may handle routine account and order workflows using account and workflow metadata. Hermes is not given image or video bytes, thumbnails, or private gallery media, and does not receive content from your galleries.
4d. Importing from Google Photos
If you choose to import from Google Photos, we use Google's Photos Picker. That means you select the specific items in Google's own interface, and we can only ever read the items you picked — we cannot browse, search, or list the rest of your Google Photos library.
Google gives us a short-lived access token to fetch just those items. We store that token encrypted, use it only to download what you selected, and the import session — token included — expires within about fifteen minutes and is then discarded. We do not keep a long-lived connection to your Google account, and we never request a refresh token. Once imported, the copies are ordinary photos in your gallery and are screened like any other upload (Section 4c). You can revoke our access at any time from your Google account's third-party access settings.
4e. Automated customer support
Customer questions and support emails may be processed by an automated support agent to help provide responses. The agent can answer general product questions or route a request for human follow-up. It cannot access your gallery media or private notes, make account changes, authenticate you, issue a refund, process a payment, or make a legal, privacy, security, or content-enforcement decision. Those requests are routed for human review.
When this feature is enabled, we send the subject and text of the support message — but not the sender's email address — to a third-party AI service provider to generate or assist with a response. We do not send email attachments, photo or video files, passwords, payment-card information, or government ID information to the agent. Do not include those details in a support email. The provider may process the message in a country other than your own, as described by the international processing disclosure in Section 4.
We retain support correspondence, automated-response records, and escalation records for no more than 90 days, unless a longer period is necessary to resolve a request, comply with law, or establish, exercise, or defend a legal claim.
5. Retention & deletion
Your content is retained while your account and its subscriptions are active. Deleting a photo or gallery yourself removes it and its files immediately; deleting your account permanently removes your galleries, photos, identities, and sessions immediately, unless particular material is subject to a legal preservation hold.
After a gallery's subscription is canceled — by you, or because a failed payment was never resolved — its photos and videos are kept for 14 days so that resubscribing restores it with nothing lost. If it is not resubscribed within that window, its photos and videos are permanently deleted from our servers; the gallery record itself (name, description, settings) is not deleted. See the Terms of Service, Section 3, for the corresponding payment grace period.
Backups. We keep backups of the database and media storage for disaster recovery, retained on a rolling window that may be as long as the retention period above. This means a backup can, for a limited additional time, still contain a photo that has already been deleted from the live service — including one removed by the automatic process described above. Backups are used only to restore service after data loss, are never used to serve or share your photos, and age out automatically; we do not retain them indefinitely. Server logs expire on a separate, shorter rolling schedule.
Cookieless analytics. We configure PostHog to retain browser pageview events for no longer than 12 months. Our own aggregate daily request totals do not identify a visitor and may be retained longer for historical capacity planning.
Billing and consent evidence. We retain subscription authorizations, renewal changes, and billing-notice records for up to seven years for accounting, charge disputes, and legal compliance. If you delete your account, these limited records are detached from the deleted account and gallery; they do not contain your password, card number, or media.
6. Control over your data
You should not have to ask us — or wait for us — to get at your own data. These are built into the product and work immediately, at any hour:
| What you want to do | How |
|---|---|
| Get a copy of everything | Account → Download my data. Produces a ZIP of every original photo and video plus all your captions, notes, tags, camera metadata and account details as machine-readable JSON. |
| Correct something | Edit captions, notes, tags and capture dates in the organizer; change your password in Account settings, or contact us about an account-email correction. |
| Delete it | Account → Delete account. Immediately and permanently deletes your galleries, photos, videos, linked sign-ins and sessions. Individual photos and galleries can be deleted at any time in the organizer. |
| Stop sharing a gallery | Unpublish it. The public link stops working right away. |
For anything the app cannot do for you, email privacy@gallmo.app and we will deal with it. We may need to verify your identity first — normally by asking you to send the request from the email address on the account. There is no charge for any of this.
Depending on where you live, local law may give you further rights over your personal data, and may give you the right to complain to a data-protection regulator. Nothing here limits those rights, and we would appreciate the chance to sort out any problem with you directly first.
6a. Automated decisions
Nothing in the Service profiles you or makes automated decisions about you as a person. The one automated judgement we make is on an individual file at upload time, described in Section 4c, and it decides only whether that file may be stored.
6b. Data breaches
If personal data is exposed in a way that could put you at risk, we will tell you directly, and inform the relevant authorities where we are required to, without undue delay.
7. Security
Passwords are hashed with bcrypt; sessions are signed, httpOnly, SameSite cookies stored hashed server-side; social sign-in uses the OAuth authorization-code flow with CSRF protection; uploads are validated as real images and deduplicated by checksum; and the API enforces per-account authorization on every request. No system is perfectly secure — use a strong, unique password.
8. Children
Gallmo accounts are for United States residents who are at least 18. The Service is not directed to children, and we do not knowingly permit a child to create an account. If you believe a child has provided account data, contact us and we will investigate and delete it when we are legally permitted to do so.
Photos of other people. Family photos usually contain other people, including children. When you upload them you are the one deciding to do so, and you are responsible for having a proper basis to share them — see Terms of Service, Section 5. We process those images only as your service provider, to store and serve what you upload.
9. Changes & contact
We may update this policy. Material changes will be announced in the app or by email at least 14 days before taking effect, and the "last updated" date above will change. The version you agreed to is shown in your Account settings.
Privacy questions or requests: privacy@gallmo.app.
© 2026 Gallmo · Terms of Service · Service Providers · Home