Privacy Policy
Last updated: April 19, 2026
1. What We Collect
When you use Galley, we collect and process:
- Document text — the text you submit for fact-checking (full document or selected portion)
- Account information — your Google account email and display name, used for authentication and attribution
- Run history — the results of each fact-checking run, including claims, verdicts, sources, and cost estimates
- Feedback — any feedback you provide on claim verdicts (correct/wrong)
2. How We Use Your Data
- Document text is sent to AI models (Anthropic Claude) for claim extraction and synthesis, and to web search APIs (Brave Search, Google ClaimReview) for evidence gathering
- Run results are stored in your organization's workspace for team visibility and historical reference
- Verified claims are cached to speed up future checks of similar content
- Feedback is used to evaluate and improve fact-checking accuracy
- Aggregate usage statistics (run counts, timing) are used to estimate processing times
3. Data Isolation
Each organization has an isolated workspace. Your document text, run history, rules, and feedback are only visible to members of your organization and system administrators. Members of other organizations cannot access your data.
4. Third-Party Services
Galley uses the following third-party services to process your data:
- Anthropic (Claude) — AI models for claim extraction, filtering, and verdict synthesis
- Brave Search API — web search for evidence gathering
- Google ClaimReview API — structured fact-check data from published fact-checkers
- Voyage AI — text embeddings for claim similarity and caching
- Google Firebase — authentication, data storage, and hosting
Document text is sent to these services for processing and is subject to their respective privacy policies. We do not sell your data to any third party.
5. Data Retention
Run history and claim data are retained indefinitely for your organization's reference. Cached claims have a configurable TTL (time-to-live) after which they are re-verified. You may request deletion of your organization's data by contacting us.
6. Google API Services
Galley's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google Docs content only when you explicitly initiate a fact-check, and we do not use this data for advertising or any purpose unrelated to providing the fact-checking service.
7. Security
Data is transmitted over HTTPS and stored in Google Firebase with role-based access controls. Authentication is handled through Google OAuth and Firebase Authentication. Only authorized members of your organization can access your workspace data.
8. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. Your team lead or system administrator can remove your membership, which revokes your access to the organization's workspace.
9. Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected by updating the "Last updated" date above.
10. Contact
For questions about this policy, contact john_randolph@alumni.brown.edu.