Galley

Privacy Policy

Last updated: April 19, 2026

1. What We Collect

When you use Galley, we collect and process:

2. How We Use Your Data

3. Data Isolation

Each organization has an isolated workspace. Your document text, run history, rules, and feedback are only visible to members of your organization and system administrators. Members of other organizations cannot access your data.

4. Third-Party Services

Galley uses the following third-party services to process your data:

Document text is sent to these services for processing and is subject to their respective privacy policies. We do not sell your data to any third party.

5. Data Retention

Run history and claim data are retained indefinitely for your organization's reference. Cached claims have a configurable TTL (time-to-live) after which they are re-verified. You may request deletion of your organization's data by contacting us.

6. Google API Services

Galley's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google Docs content only when you explicitly initiate a fact-check, and we do not use this data for advertising or any purpose unrelated to providing the fact-checking service.

7. Security

Data is transmitted over HTTPS and stored in Google Firebase with role-based access controls. Authentication is handled through Google OAuth and Firebase Authentication. Only authorized members of your organization can access your workspace data.

8. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. Your team lead or system administrator can remove your membership, which revokes your access to the organization's workspace.

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be reflected by updating the "Last updated" date above.

10. Contact

For questions about this policy, contact john_randolph@alumni.brown.edu.