Privacy notice
Last updated 28 September 2026.
Galleris is made by Hoo Socials Limited. This notice says what we collect, who holds it, how long it stays and how to get rid of it. It is written to be read once, by a person, rather than filed.
Three different people use Galleris, and what is collected is different for each. Find yourself in this list:
- You scanned a code beside an object, or opened a museum's link. Almost nothing. Which museum you opened, and a random number your browser made up for itself. No name, no email, no account. Nothing is recorded about how you moved around the guide unless you sign in to an archive.
- You signed in to a museum's archive. Your email address and the name you typed. Those belong to the museum, not to us — see Whose data it is.
- You are building a museum, or you wrote to us. What you typed into the studio stays in your own browser until you publish. What you typed into the contact form comes to us.
Index
1. Personal information we collect 2. Tracking and other technologies 3. How we use your personal information 4. Retention 5. How we share your personal information 6. Your choices 7. Who is responsible for what, and other sites 8. Security 9. International data transfer 10. Children 11. Changes 12. How to contact us 13. Your rights, and notice to European users
Personal information we collect
If you only opened a museum
| What | Why |
|---|---|
| The museum's short name | so the curator can see that somebody opened it |
| A random number your browser made up | so two visits from the same phone in one hour count as one |
That random number is not a person. It is not derived from your device, your network or anything about you, it is never joined to a name or an address, and it is never shared with another museum. For a museum on a fourteen-day trial it sits in trial_visits on our database and is deleted when the museum ends. For every other published museum we keep only a one-way scramble of it, for two hours, so that a refresh is not counted as a second visitor.
What the curator sees is a total per day — the museum's short name, the date and a number — kept in museum_days. Nothing in it says who you are.
The guide itself keeps a count of which objects you opened and how far through each recording you got. That stays on your own phone. It is never sent anywhere, and it is what fills in the curator's numbers only on their own device, not yours. Clearing your browser clears it.
If you asked for a sign-in code
| What | Where | How long |
|---|---|---|
| A one-way scramble of your email address | sign_in_codes | ten minutes, then swept within the hour |
| A one-way scramble of the code we sent | sign_in_codes | the same |
| Your real email address | in the sending request, and then in the museum's list | see the next table |
A one-way scramble (a SHA-256 hash) cannot be turned back into your address. We store it that way on purpose: a copy of that table is not a mailing list and not a set of working codes. Your address itself exists for the length of one request while the email is sent.
If you signed in to a museum's archive
| What | Why |
|---|---|
| Your email address | it is how the museum recognises you and how it can write to you |
| The name you typed | so the museum can address you |
| Whether you ticked the box asking for museum news | see Two questions, not one |
| When you joined, and when you last signed in | so a list that nobody uses can be cleared |
| A random unsubscribe token | so one press of a link in an email takes you off |
If you said you are coming to a show
| What | Why |
|---|---|
| The name and email address you typed, and how many of you are coming | so the gallery or museum has a door list for its private view |
| Which show, and when you said yes | so saying yes twice changes your answer rather than counting you twice |
Only the gallery or museum that runs the show can read this list. Nothing is paid, no place is held, and nobody checks you in.
If you wrote to us
The contact form asks for your name, your organisation, your email, what you look after, roughly what budget you are working with, and your message. It goes to our enquiry inbox through Formspree. There is a hidden field on the form that a person never sees, used to catch automated spam; if you are a person you will never fill it in.
If you opened the studio
To open the studio we ask for your email address. It goes to our enquiry inbox through Formspree, with the page you were on and, if you came from a viewing room's "Built with Galleris" link, that viewing room's link name. If it cannot be sent straight away, your browser keeps it and sends it the next time you open a Galleris page, for up to a month, and then forgets it. We use it to write to you about the studio, and for nothing else.
When you publish, we are sent one note with that address, your viewing room's name, its link, what kind of collection it is and how many works it holds, so that we know who to help. A few days later the studio asks one question, "What's missing?". If you answer, your answer comes to the same inbox with the same address. If you do not, nothing is sent.
The studio also tells Mixpanel how far you have got — opened, first work added, spreadsheet brought in, published, link shared — with the kind of collection and a count, and no name, email address or link.
If you published a museum
The museum's own document and its photographs go to our storage so that a stranger's phone can reach them. We also keep the museum's short name, its size, how many times it has been sent up, and a one-way scramble of the key your browser made to prove the museum is yours. We do not keep the key itself, which is why there is no way for us to give it back to you if you clear your browser. There are no accounts and no passwords.
A draft is never uploaded. Everything you build in the studio stays in your own browser, in its own storage, until you press Publish. We cannot see it.
Tracking and other technologies
Galleris sets no cookies of its own. Google Analytics and Mixpanel set theirs on the marketing site and in the studio, to tell one visit from another. The visitor guide sets none.
What the product does use is your browser's own storage, which is not a cookie and is not sent to anybody: the random number described above, a note of which archives you have signed in to on this device, your own count of what you opened, and — in the studio — the museum you are building and any note to us still waiting to be sent. Clearing your browser's site data clears all of it.
How we use your personal information
Three parts of the product, and they are treated differently on purpose.
| Where | What runs |
|---|---|
The marketing site (galleris.app) | pages counted, clicks counted, and the screen recorded |
| The studio | pages and clicks counted. No screen recording, because a curator's unpublished material is on it |
| The visitor guide | nothing, by default. No pages counted, no clicks, no recording |
The visitor guide is the one that matters most. Somebody who pointed a phone at a square on a wall agreed to nothing, may be a child on a school trip, and cannot opt out of something they were never told about. So it measures itself on the device and sends nothing.
Where recording does run, every field and every piece of text is masked before anything is stored, so what somebody typed is never in the recording. Your network address is shortened by Google Analytics before it is stored. If your browser sends a "Do Not Track" signal, Mixpanel is switched off.
What we do not measure at all: how long you looked at anything. There is no timer anywhere in the product, and nothing we say about the product will claim one.
Retention
| What | How long |
|---|---|
| A one-way scramble of an address, and of a sign-in code | ten minutes, then swept within the hour |
| The counter that stops one address being sent hundreds of codes | one day |
| A trial visit: museum name and random number | until the museum ends, then deleted |
| A one-way scramble of the random number, for any other published museum | two hours |
| A museum's total visits per day | kept; it holds no device number and no address |
| A trial museum's own record | until it ends, then deleted |
| A record that a museum ended: its name, when it opened, when it ended, why, and how many visits it had | kept, and it holds no addresses and no device numbers |
| An archive member's row | until the museum stops existing, or three years after that person last signed in — whichever comes first |
| Somebody's yes to a show: name, email, how many | 180 days, then swept automatically |
| A row saying somebody left a list | kept, because deleting it is how the next import puts them back |
| A published museum's document and photographs | while it is published |
| Anything in your own browser | until you clear it |
| An enquiry you sent us | until we delete it by hand. Nothing clears our own inbox on a timer, and we are not going to claim otherwise. Ask and we will delete it |
How we share your personal information
We use other companies to run this. None of them is sold your data, and none of them may use it for their own purposes.
| Company | What they do with it | Where |
|---|---|---|
| Supabase | the database, the functions and the file storage | Ireland (eu-west-1) |
| Vercel | serves the website | global network |
| Resend | sends the sign-in codes and the "your museum is live" email | United States |
| Formspree | receives what you type into the contact form, the email you give to open the studio, the note sent when you publish, and your answer to "What's missing?" | United States |
| Google Analytics | counts pages on the marketing site and the studio | United States |
| Mixpanel | counts pages, clicks, and records screens on the marketing site only | United States |
| Google Fonts | serves the two typefaces the site is set in | global network |
Google Fonts is worth naming plainly. The site asks Google's servers for its typefaces, which means your browser tells Google your network address when a page loads. That is true of a great many websites and it is still true here. We list it rather than leave it out.
Your choices
Giving an address to open a door is not the same as agreeing to be written to. They are asked separately.
The tick box asking to hear from the museum is not ticked for you, it is asked once when you join and never again, and the answer is stored as its own yes-or-no beside your row. If you say no, you get a working archive and no email. If you say yes and later change your mind, one press of the link at the bottom of any of their emails takes you off — and signing in again afterwards cannot put you back on.
Under the Nigeria Data Protection Act 2023 and under the UK and EU GDPR, that separation is the difference between a list a museum may lawfully write to and one it may not.
Who is responsible for what, and other sites
This matters more than it sounds, because it decides who you complain to.
For a museum's archive list, the museum is responsible and we are not. The museum decides to have an archive, decides what is behind it, and holds the list of who signed in. We store it for them and hand it back to whoever holds that museum's key. In the words the law uses, the museum is the data controller and Hoo Socials Limited is the data processor. If you want off a museum's list, the museum is who that is between — and there is a one-press way to do it at the bottom of every email they send.
For everything else, we are responsible. The contact form, the marketing site, the studio, and the measurements described below.
Security
- The tables holding real addresses have their row-level security switched on with no policy at all, which is the strictest setting the database has. Nothing reaches them but one function holding a key that never leaves the server.
- A sign-in code is eight digits from a cryptographic random source, is good for ten minutes, and stops working after five wrong guesses.
- A museum's list is only ever read one museum at a time, with that museum's own key. A wrong key and a museum that does not exist give the same answer, so the product cannot be used to find out which museums exist.
- Every page is served over HTTPS with a content security policy that names every outside service it may talk to.
- Nothing about sign-in is trusted from the browser: the code is checked on the server, and the count of wrong guesses is kept there too.
We do not claim this is unbreakable. Nobody honest does.
International data transfer
Our database sits in Ireland and several of the companies above are in the United States. That is a cross-border transfer under section 41 of the Nigeria Data Protection Act 2023, and under Chapter V of the GDPR.
The legal footing is:
- Ireland is inside the European Economic Area, which the Nigeria Data Protection Commission treats as offering adequate protection.
- The United States companies above are used under the standard contractual clauses in their own data processing terms, which is what section 41(1)(a) of the Act asks for.
If a transfer is not something you want, the only part of the product that requires one is signing in to an archive. Everything a visitor does in the guide itself works without it.
Children
Galleris is not aimed at children, and the visitor guide asks nobody for anything, which is deliberate — a class of eleven-year-olds can use a museum's guide from start to finish without typing a word. Signing in to an archive is meant for adults. If you believe a child has given us an address, write to the contact above and we will remove it.
Changes
When this changes we update the date at the top and post the new version here. If a change means we start collecting something new, we will say so on the screen where it happens rather than only here.
How to contact us
- Hoo Socials Limited, registered in Nigeria.
- RC number: 1974588
- Registered address: 10 Oyelowo Close, Surulere, Lagos
- Email: hello@hoosocials.com
- WhatsApp: +234 905 937 1877
Governed by the laws of the Federal Republic of Nigeria, and disputes belong to the courts of Lagos State.
Your rights, and notice to European users
Under the Nigeria Data Protection Act 2023 (sections 34 to 37) and under the GDPR, you may ask to:
- See what is held about you.
- Correct it if it is wrong.
- Delete it.
- Take it with you, in a form another service can read.
- Stop it being used for marketing, at any time, with no reason given.
- Object to it being used at all, where we are relying on our own legitimate interest.
You may also complain to the Nigeria Data Protection Commission (ndpc.gov.ng), or, if you are in the UK or EU, to your own supervisory authority.
How to ask. Write to Emeka Ugochukwu at hello@hoosocials.com. We answer within 30 days, which is what section 38(2) of the Act asks for.
Two honest limits.
If you are asking about a museum's archive list, we will pass the request to that museum, because it is theirs. We will do it and tell you we have.
If what you want deleted is only in your own browser, we cannot reach it — and neither can anybody else. Clearing your site data is the whole of it.