Back to app

Privacy Policy

Last updated: May 13, 2026

1. Who We Are

galleybook is a private recipe management app for families and households. It is operated as a personal project. If you have any questions about this policy or your data, please contact us at contact@galleybook.com.

2. Data We Collect

We collect only what is necessary to run the app:

  • Account information — your name and email address. If you sign in with Google we also receive your profile photo. If you sign in with Apple and choose to hide your email, we only receive an Apple-relayed address (e.g. xyz@privaterelay.appleid.com) that forwards to your real inbox.
  • Subscription information — if you purchase a galleybook premium subscription on iOS, Apple processes the payment and shares only a signed transaction receipt with us (product, purchase date, expiry, renewal status). We never see your card or App Store account details.
  • Recipes and content — recipe names, descriptions, ingredients, preparation steps, and photos you add or import.
  • Saved sources — website URLs, Instagram handles, and YouTube channels you save to generate recipe recommendations.
  • Usage data — standard server access logs (IP address, timestamps) retained by our infrastructure provider.
  • Session cookie — a single authentication cookie that keeps you signed in. No tracking cookies are used.

3. Third-Party Services We Use

To operate, galleybook shares data with the following processors. Each processes only the data described below and is bound by their own privacy policy.

Supabase Database, authentication, and file storage

All app data (recipes, accounts, photos) is stored on Supabase servers.

Region: EU / US · Privacy policy

Google Sign-in (OAuth) and AI recipe extraction (Gemini)

We receive your name, email, and profile photo when you sign in with Google. When you import a recipe via URL or photo, or translate a recipe, the page content or image is sent to Google Gemini for parsing. Google has stated that data submitted via the Gemini API is not used to train models.

Region: US / EU · Privacy policy

Apple Sign in with Apple and App Store subscription billing

If you sign in with Apple, Apple shares your name and email (or an Apple-relayed email) with us. If you purchase a galleybook premium subscription, Apple processes the payment and sends us only a signed transaction receipt. Card details and Apple ID never reach our servers.

Region: US / Ireland · Privacy policy

Perplexity AI Web search for recipe content and recommendations

When you import a recipe from certain URLs (e.g. Instagram, YouTube) or use the Discover feature, your recipe collection metadata and saved sources are sent to Perplexity to retrieve content and generate personalised recommendations.

Region: US · Privacy policy

Vercel Hosting

Our web servers and edge functions run on Vercel. Vercel processes standard HTTP request data (IP address, user agent, request path) to deliver the service. We do not use Vercel Analytics or any other behavioural tracking.

Region: Global edge / US · Privacy policy

Bring! Labs Shopping list integration

When you click “Add to Shopping List”, a public share link for the recipe is sent to Bring!’s servers so they can parse the ingredient list.

Region: Switzerland · Privacy policy

4. How We Use Your Data

  • To operate and display your recipe library.
  • To allow you to invite family members to your Galley.
  • To power AI-assisted recipe import and personalised recommendations.
  • We do not sell your data, use it for advertising, or share it with anyone beyond the processors listed above.

5. Your Rights

Under the GDPR and similar laws, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Deletion (right to erasure) — delete your account and all associated data at any time via Settings → Delete Account.
  • Portability — request a machine-readable export of your recipes by emailing us.
  • Correction — update your name or username directly in Settings.

To exercise any right, contact contact@galleybook.com.

6. Data Retention

Your data is retained for as long as your account is active. When you delete your account:

  • Your personal data (name, email, recipes, photos) is deleted immediately.
  • Recipes you created in galleys owned by other members are anonymised (the creator attribution is removed) rather than deleted, so the galley is not disrupted.
  • Supabase infrastructure backups are purged within 30 days.

7. Cookies, Local Storage & Analytics

On the web, we use a single session cookie to keep you signed in. This cookie is essential for the app to function. In the iOS app, the equivalent session token is stored securely in the device Keychain.

We do not use any advertising, analytics, behavioural-tracking, or third-party crash-reporting SDKs in the web or iOS app.

8. Children

galleybook is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us to have it removed.

9. Changes to This Policy

We may update this policy from time to time. We will update the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance.

Also see our Terms of Service.