How we collect, use, and protect your data. We believe in transparency and keeping things simple.
The GalleryID website and Service are operated by GalleryID, LLC. The GalleryID iOS and Android mobile applications are developed by SmartLink Basics, LLC for GalleryID, LLC and distributed under SmartLink Basics, LLC’s Apple App Store and Google Play developer accounts. For photos, biometric data, and roster information uploaded by clients, the client is the data controller and GalleryID, LLC is a data processor acting on the client’s behalf. GalleryID, LLC acts as a controller only with respect to its own account-holder data necessary to operate the Service.
Effective Date: February 1, 2026
Last Updated: May 16, 2026
We do not sell your personal data. Period. All data we collect is used for the specific purpose of providing the GalleryID service to you, whether through our website or iOS app. We use Google Analytics for website analytics. Your photos remain your property.
We collect only the data necessary to provide and improve the GalleryID service. Here’s exactly what we collect and why:
| Data Type | What We Collect | Why |
|---|---|---|
| Account Information | Email address, display name, password (managed securely by our authentication provider) | To create and manage your account, authenticate you, and communicate about service updates |
| Organization Details | Organization name, billing email, contact information | To manage your organization's account, process billing, and provide support |
| Photos | Photos you upload, including embedded EXIF/XMP metadata | To provide the core service: gallery hosting, AI identification, and metadata management |
| Roster Data | Athlete names, jersey numbers, positions, team affiliations, headshot photos | To enable AI-assisted athlete identification in your photos |
| Facial Recognition Data | Facial feature vectors derived from uploaded headshots and photos | To match athletes across your galleries — these are mathematical representations, not images |
| Usage Data | Actions performed (uploads, downloads, approvals), IP address, browser type, timestamps | To operate the service, maintain security, and provide activity logs to account administrators |
| Billing Information | Payment method details (processed by Stripe — we do not store card numbers), billing address | To process subscription payments and credit purchases |
| Mobile Device Data | Push notification token (APNs token on iOS, Firebase Cloud Messaging token on Android), device platform (iOS or Android), app version | To deliver push notifications about gallery processing status and service updates via our iOS or Android companion app |
| Camera & Photo Library | Photos and images you select or capture within the iOS or Android app | To upload photos to galleries and capture headshots for roster indexing — accessed only when you initiate an upload or headshot capture (via the Apple Photos picker on iOS or the Android Photo Picker / system camera on Android) |
| Biometric Authentication (Optional) | Local biometric template used by Face ID / Touch ID / Optic ID (iOS) or Android BiometricPrompt (fingerprint, face) — only when you opt in to biometric login. The biometric template never leaves your device; only a yes/no match result is returned to the app. | To unlock your saved email + password for faster sign-in |
All data collected is used for the specific purpose of providing the GalleryID service to you. We do not use your data for any unrelated purpose. Specifically, we use your data to:
We do not sell your personal data to any third party, for any reason, ever.
We do not sell your photos or use them for any purpose beyond providing the Service.
We do not use your photos to train AI models. Your uploaded photos are processed through our identification pipeline and then stored — they are not used as training data for machine learning.
We do not share your data with advertisers.
We do not send marketing emails unless you explicitly opt in.
We use Google Analytics to understand how visitors interact with our website. Google Analytics collects information such as:
This data is used solely to improve the GalleryID website and user experience. Google Analytics uses cookies to collect this information. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
For more information, see Google’s Privacy Policy.
We use a limited number of third-party services to operate GalleryID. These providers process your data only as necessary to provide their services to us:
We do not share your data with any third parties beyond what is described here.
GalleryID offers companion apps for iOS (Apple App Store) and Android (Google Play). Both apps connect to the same account you use on the web at galleryid.ai. The mobile apps do not create separate accounts or collect data independently from the web service. All data accessed through the mobile apps is the same data described throughout this policy.
Push Notifications. When you enable push notifications, your device’s push token (Apple Push Notification service token on iOS, Firebase Cloud Messaging token on Android) is stored on our servers and associated with your user account. This token is used solely to deliver notifications about your galleries (such as when face recognition processing completes). You can disable push notifications at any time through your device’s Settings app. When you sign out of the app, your device token is automatically deleted from our servers.
Camera and Photo Library. The mobile apps request access to your camera for capturing athlete headshots and to your photo library for selecting photos to upload. On iOS this uses the Apple Photos picker and camera APIs; on Android this uses the Android Photo Picker (or, on older Android versions, the system file picker) and the standard camera intent. These permissions are requested only when you initiate a headshot capture or photo upload. Photos and images are transmitted to our servers using the same encrypted channels as the web application. The apps do not access your camera or photo library in the background or for any purpose other than what you explicitly initiate.
Biometric Login (Optional). If you opt in to biometric login (Face ID, Touch ID, or Optic ID on iOS; fingerprint or face unlock on Android), your biometric template is processed entirely by your device’s operating system and never leaves the device. The GalleryID app only receives a yes/no match result, which is used to unlock your saved email + password. Your biometric data is never transmitted to GalleryID or any third party. You can disable biometric login at any time from inside the app.
No Background Data Collection. The mobile apps do not collect location data, access your contacts, track your activity across other apps, or perform any data collection in the background. The apps communicate with our servers only when you are actively using them, with the exception of receiving push notifications.
Apple App Store and Google Play disclosures. Our App Store and Google Play data-disclosure forms (App Privacy on iOS, Data Safety on Android) reflect the data practices described in this policy. Where the store listing surfaces a summary, this policy is the authoritative source of detail.
When you upload a headshot for roster indexing, our system generates a mathematical representation (a “face embedding”) of the facial features. This is a numerical vector, not an image. These embeddings are used solely to match faces in your uploaded photos against your roster.
Face embeddings are stored securely and are associated with your organization’s account. They are not shared across organizations, not used for surveillance, and not accessible to other users.
Collection and purpose. We collect facial recognition data — specifically, face embedding vectors derived from headshot photos you upload — for the sole purpose of identifying athletes in sports photographs within your organization’s account. We do not collect facial recognition data from any other source, and we do not use it for any purpose other than providing the identification features of the Service.
Retention and destruction schedule. Face embeddings are retained for as long as your organization’s account is active and the associated person record exists. Face embeddings are permanently destroyed in the following circumstances:
We do not sell, lease, trade, or profit from facial recognition data.
Your consent responsibilities. By enabling facial recognition features and uploading headshots, you confirm that you have obtained any consent required by applicable law from the individuals whose biometric data you are submitting for processing. Several U.S. states — including Illinois (BIPA), Texas, and Washington — require written consent prior to collecting biometric identifiers. GalleryID does not provide legal advice; you are solely responsible for your compliance obligations in your jurisdiction.
You may delete any person’s facial data at any time by removing them from your roster, which also permanently deletes the associated face embedding.
We take the security of your data seriously and implement industry-standard measures including:
While we implement reasonable security measures, no system is 100% secure. We cannot guarantee absolute security of your data.
We retain your data for as long as your account is active. You can delete your account at any time directly from inside the iOS or Android app (User tab → Delete Account) or by emailing support@galleryid.ai. Full step-by-step instructions, including what gets deleted and what we retain, are documented at galleryid.ai/account-deletion.
When you delete your account:
For plans with ephemeral storage, photos are automatically deleted after the specified retention period (e.g., 14 days).
You have the right to:
To exercise any of these rights, use the relevant features in your account settings or contact us.
GalleryID is operated from the United States and is primarily intended for users in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States.
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with data protection laws (such as the GDPR or UK GDPR), you may have additional rights including:
To exercise any of these rights, contact us. We will respond to requests within 30 days.
By using the Service from outside the United States, you consent to the transfer of your personal data to the United States for processing as described in this policy.
GalleryID processes facial recognition data, which may be classified as biometric data under certain laws. Several U.S. states — including Illinois, Texas, and Washington — have enacted biometric privacy laws with specific requirements regarding notice, consent, and data handling.
You are responsible for ensuring your use of GalleryID’s facial recognition features complies with all applicable laws in your jurisdiction. This may include obtaining written consent from individuals whose photos you upload for facial recognition processing. GalleryID does not provide legal advice regarding your compliance obligations.
GalleryID is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. Note that photos of minor athletes may be uploaded by authorized photographers and organizations — the responsibility for appropriate use and distribution of those photos rests with the uploading organization.
We use a minimal number of cookies:
We do not use advertising cookies, tracking pixels from ad networks, or any third-party marketing cookies.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice within the Service. The “Last Updated” date at the top of this page reflects the most recent revision.
Questions about this Privacy Policy or your data? Contact us.
We collect what we need to run GalleryID and nothing more, whether you use the website, the iOS app, or the Android app. Your photos are yours. We don’t sell your data to anyone. We use Google Analytics to see how people use the website. Stripe handles payments — we never see your card number. The mobile apps only access your camera and photo library when you initiate an action, biometric login is processed entirely on-device, and your push notification token is deleted when you sign out. You can delete your data anytime — see galleryid.ai/account-deletion. You’re responsible for following biometric privacy laws in your area. If you have questions, email us.