Legal
Privacy
Short, because we collect little. Last updated 16 September 2026.
Who we are
Galley Render is operated by Matt Mueller, a sole proprietor in Fernandina Beach, Florida, United States, and he is the data controller. Write to legal@galleyrender.com about anything on this page. A postal address is on every invoice and is provided on request.
What we collect
- Your email address
- Given when you create an account, and verified before a key is issued. It is how we identify the account, send you a receipt and warn you about a limit. Nothing else.
- Your templates
- The HTML, the JSON Schema and the example payload you publish, plus every earlier version. Kept until you delete the template.
- The payloads you render
-
The JSON you send to
/v1/renderis stored with the render record. It has to be: it is what makes a render reproducible and what the cache key is built from. It can contain whatever you put in it, so send only what the document prints. - The documents we render
- The PDF, PNG or JPG itself, in object storage, behind an expiring signed URL.
- Usage records
- One row per render: the template and version, the format, the page count, the billable units, the byte size and the timestamps. This is what your invoice is built from.
- Request logs
- Method, path, status, duration, request id and account id. Not payload contents, not document contents, and no API key — keys are stored only as a hash.
- Payment details
- Handled entirely by Stripe. We never see or store a card number; we hold a Stripe customer id and the invoice history.
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not use your templates, payloads or rendered documents to train models — ours or anyone else's.
- We do not read your documents except when you ask us to look at one for support.
- We set no advertising or cross-site tracking cookies on this site.
Sub-processors
These are the only third parties that touch your data, and only to run the service.
| Processor | What it handles | Where |
|---|---|---|
| Render | Application hosting, the database that holds accounts, templates and usage, and request logs | United States (Oregon) |
| Cloudflare | Object storage for rendered documents (R2), DNS, and the email we send and receive | United States |
| Stripe | Payments, invoices and metered billing. Card details never reach us | United States |
If this list changes we will update this page and email account holders before the new processor handles anything.
How long we keep things
- Rendered documents
- 30 days on Free, Pay as you go and Starter; 90 days on Growth and Scale. Then deleted.
- Render records and the payloads in them
- The same retention window as the document they produced.
- Templates
- Until you delete them. Deleting is a soft delete so existing renders keep working.
- Request logs
- 30 days.
- Account records, invoices and usage totals
- While the account exists, and afterwards for as long as tax and accounting law requires.
Deleting your data
Email legal@galleyrender.com from the address on the account and ask. We will delete the account, its templates, its renders and the stored documents within 30 days, and confirm when it is done. Invoices and the totals behind them are kept, because we are required to keep them.
You can also ask for a copy of what we hold, ask us to correct it, or object to how we use it. Wherever you live, we will answer; if you are in the EEA or the UK, we treat those as your rights under the GDPR, and our basis for processing is performing the contract you entered into and our legitimate interest in keeping the service running and unabused.
Keys and security
API keys are stored as a hash and shown to you once. A key is a bearer credential: anything done with it is treated as done by you. Tell us at support@galleyrender.com if one leaks and we will revoke it. Signed URLs are also bearer credentials, for one file, for about an hour. More detail is in the security page.
Children
This is a developer API. It is not directed at children and we do not knowingly collect anything from anyone under 16.
Changes
If this page changes materially we will email account holders at least 30 days before it takes effect. The date at the top always says when it last moved. The terms of service cover the rest of the arrangement, including what you may render and how refunds work.