Galley
How it worksPrivacy
Get the app

Privacy Policy

Last updated: [to be finalized] · Draft

⚠Draft for review. This is a structural first draft. The sections below reflect how Galley actually works, but the legal language must be reviewed and finalized before launch.

1. Who we are

Galley is an anonymous community for the aviation community (pilots, cabin crew, students, instructors, and others in aviation). This policy explains what information we collect, why, and what choices you have. [Legal entity, contact address, and Data Controller details to be finalized.]

2. The information we collect

  • Account data. An email address used to create and sign in to your account, and an anonymous handle.
  • Verification data. To verify crew status you submit a work email. We do not store the address itself. We record only a salted, one-way fingerprint (hash) of it — used to issue your one-time code and to limit abuse — together with the domain it resolves to, which maps to your company. The fingerprint is held in a restricted, service-only store, is never linked to your public handle, and is marked used once you verify, then removed shortly after by a routine cleanup. The address is sent to a third-party email delivery provider solely to deliver your code; the address cannot be recovered from the stored fingerprint. What we retain is your verified affiliation (role + company).
  • Content you create. Posts, comments, votes, tags, and direct messages.
  • Technical data. Standard device/usage data needed to operate and secure the service. [Analytics/logging specifics to be finalized.]

3. What we show publicly

Your anonymous handle is shown on your activity. If you are verified, your posts also show a coarse role @ company Verified company affiliation. We never display your real name or your email address. Nothing more granular than coarse role + company is shown.

4. How we use your information

  • To operate the community (show your posts under your handle).
  • To verify crew affiliation and gate company channels.
  • To keep the service safe (moderation of reported content).
  • To send service email (e.g. verification). [Email provider disclosure to be finalized.]

5. Moderation

Reported content may be reviewed by moderators and hidden or removed, and accounts may be suspended for violations. Moderation acts on content and accounts — it does not deanonymize you to other users.

6. Data sharing

We use service providers to host and operate Galley (e.g. cloud infrastructure and email delivery). We do not sell your personal data. [Full sub-processor list and legal bases to be finalized.]

7. Account deletion

You can delete your account at any time from within the app. Deletion happens in two stages:

  • Immediately. Your account and public identity are removed: your handle is replaced with [deleted], your role and verified affiliation are cleared, and you are signed out on all devices. Your posts and comments remain on the platform, but they are no longer linked to you — they show as authored by [deleted].
  • After 30 days. Your account is permanently purged: your email address and sign-in credentials are erased from our servers, and your direct messages and votes are deleted. Your posts and comments are retained (still shown as [deleted]) so the surrounding conversations stay intact. This final step cannot be undone.

In short: deletion removes your identity, not the discussions you took part in. This disclosure exists to satisfy App Store account-deletion requirements. [Confirm the 30-day window and exact retention behavior with counsel before launch.]

8. Your rights

Depending on your location, you may have rights to access, correct, or delete your data. [GDPR/CCPA rights and how to exercise them to be finalized.]

9. Children

Galley is intended for adults in the aviation community and is not directed to children. [Minimum-age statement to be finalized.]

10. Contact

Questions about this policy: [contact email to be finalized].

Galley
How it worksGet the appPrivacyTerms

© 2026 Galley · by crew, for crew