Privacy Policy

Effective date: January 1, 2026

Last updated: August 20, 2026

This policy describes how The Preservation Network LLC collects, uses, and protects your information when you use TheGalaxyDB.

1. Introduction

The Preservation Network LLC ("we," "us," or "our") operates TheGalaxyDB at thegalaxydb.org. This Privacy Policy describes what personal information we collect, how we use it, when we share it, and the choices you have regarding your data.

We are committed to protecting your privacy and handling your data responsibly. This policy applies to all users of TheGalaxyDB, including visitors who browse without an account, registered free users, and paid subscribers.

GDPR: If you are a resident of the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent local laws. We process your data on the legal bases of contractual necessity (to provide the Service you signed up for), legitimate interests (to improve and secure the Service), and, in limited cases, your consent (for optional communications).

CCPA: If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). We do not sell personal information. See Section 7 for how to exercise your rights.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

2. Information We Collect

We collect information in several categories depending on how you interact with the Service:

Account Information

When you register, we collect your name, email address, and a password (stored as a one-way hash we never store your plaintext password). If you upgrade to a paid plan, we also store your subscription tier and the date of your most recent upgrade or renewal.

Usage Data

As you use the Service, we collect information about your activity, including: galaxies you have viewed, bookmarked, or explored in the GLEN renderer; search queries you have entered; session duration; and features you have used. This data helps us improve the catalog and personalize your experience.

API Usage Logs

For API subscribers, we log endpoint calls, timestamps, HTTP response codes, and request counts against your API key. We do not log the content of query parameters that contain personal information. Logs are retained for 90 days and are used for rate-limit enforcement, abuse detection, and billing verification.

Galaxy Registry Data

If you register a galaxy name or purchase a galaxy gift, we store the galaxy identifier, your chosen name, any personal dedication message, and for gifts the recipient's name and email address. This data becomes part of the permanent galaxy registry and is treated as described in Section 6.

Payment Information

All payment processing is handled by Stripe. We do not store your credit or debit card number, CVV, or bank account details on our servers at any time. We store only your Stripe customer ID, subscription status, current plan, and billing cycle dates. For questions about how Stripe handles payment data, see stripe.com/privacy.

Technical and Server Log Data

Our servers automatically collect standard log data whenever you access the Service, including your IP address, browser type and version, operating system, referring URL, pages visited, and timestamps. This data is used for security monitoring, performance analysis, and abuse detection. It is not used for behavioral advertising.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service: Processing your searches, rendering GLEN visualizations, maintaining your bookmarks and galaxy registry, and serving catalog data through the API.
  • Account management: Creating and maintaining your account, verifying your identity, and communicating with you about your subscription.
  • Payment processing: Verifying subscription status, processing renewals, issuing invoices, and managing refunds in coordination with Stripe.
  • Transactional communications: Sending receipts, API key alerts (when usage approaches your limit), subscription renewal reminders, galaxy anniversary emails (if you have gifted or named a galaxy), and system status notifications. You cannot opt out of transactional emails while you have an active account, as they are necessary for account management.
  • Service improvement: Analyzing aggregate usage patterns to improve catalog accuracy, expand the GLEN shader library, optimize search relevance, and prioritize new features. We analyze this data in aggregate and do not use it to build individual behavioral profiles for advertising purposes.
  • Rate limit enforcement and abuse detection: Monitoring API usage against your tier's limits and detecting patterns consistent with scraping, credential stuffing, or other forms of abuse.
  • Legal compliance: Complying with applicable law, responding to lawful government requests, and enforcing our Terms of Service.

We do not sell your personal information. We do not share your data with advertising networks, data brokers, or any third party for marketing purposes. We do not serve behavioral advertising.

4. Cookies and Local Storage

Authentication: When you sign in, your authentication token is stored in your browser's localStorage. This is not a cookie and is not transmitted to third parties. The token expires after 30 days of inactivity or when you sign out.

Preferences: We may store your preferred view settings (such as galaxy field preferences or GLEN display options) in localStorage as well. This data never leaves your browser and is not transmitted to our servers.

No advertising cookies: We do not use advertising cookies, retargeting pixels, or third-party tracking scripts on TheGalaxyDB. We do not participate in any ad network or use tools like Google Analytics that track your activity across other websites.

Cloudflare: As our CDN and DDoS protection provider, Cloudflare may set cookies (such as __cf_bm) on your browser for bot mitigation and performance purposes. These cookies are set by Cloudflare's infrastructure and are covered by Cloudflare's privacy policy. They do not track your activity across other sites and are not used for advertising.

5. Third-Party Services

We use a small number of trusted third-party services to operate TheGalaxyDB. Each processes your data only as necessary to provide their specific service:

  • Stripe: Payment processing. Stripe processes your payment card details directly and is PCI DSS compliant. We receive only a customer ID and subscription status from Stripe. See stripe.com/privacy.
  • Cloudflare: CDN, DDoS protection, and DNS. All traffic to thegalaxydb.org passes through Cloudflare's network for performance and security. Cloudflare may process IP addresses and request headers as part of this service. See cloudflare.com/privacypolicy.
  • Hetzner Online GmbH: Server hosting. Our database and application servers are hosted in Hetzner's data centers in the European Union (Finland and Germany). Data processed on these servers is subject to EU data protection standards. See hetzner.com/legal/privacy-policy.

We do not share your personal information with any other third parties for processing purposes. We do not use analytics platforms, customer data platforms, or marketing automation tools that receive identifiable user data.

6. Data Retention

We retain your data for different periods depending on its type and purpose:

  • Account data (name, email, hashed password, subscription status): Retained for the lifetime of your account and for 90 days after you submit an account deletion request. The 90-day window allows us to address any outstanding billing disputes or legal holds before permanent deletion.
  • Usage data (browsing history, bookmarks, search queries): Retained for the lifetime of your account. Deleted when your account is permanently deleted.
  • API usage logs: Retained on a rolling 90-day basis. Older logs are permanently deleted on a daily schedule.
  • Galaxy registry entries (galaxy names, dedications, gift records): Retained permanently as part of the catalog. If you delete your account, your galaxy names and dedications remain in the registry but may be disassociated from your email address and personal profile at your request.
  • Payment records: Retained for 7 years from the date of each transaction to satisfy tax and accounting compliance requirements. This retention period applies even after account deletion.
  • Server logs: Retained for 30 days on a rolling basis, then permanently deleted.

7. Your Rights

You have the following rights with respect to your personal information:

  • Access: You may request a copy of the personal information we hold about you.
  • Correction: You may update or correct your account information at any time from your profile settings. For corrections to galaxy registry records, contact us directly.
  • Deletion (right to be forgotten): You may request deletion of your account and associated personal data from your profile settings or by contacting us. Certain data may be retained for the periods described in Section 6 (retention compliance) even after deletion.
  • Data portability: You may request an export of your data, including your galaxy registry entries, bookmarks, and account information, in a machine-readable format. Submit a portability request to privacy@thepreservationnetwork.org.
  • Restriction of processing: You may request that we restrict processing of your data in certain circumstances for example, while a dispute is being resolved.
  • Objection: You may object to processing based on our legitimate interests where your particular situation warrants it.

GDPR rights for EU residents: All of the rights above apply to you under GDPR. To exercise any right, contact privacy@thepreservationnetwork.org. We will respond within 30 days. If you believe we have not responded appropriately, you have the right to lodge a complaint with your local supervisory authority.

CCPA rights for California residents: You have the right to know what personal information we have collected, to request deletion of your personal information, and to opt out of the sale of personal information (we do not sell personal information). To exercise CCPA rights, contact privacy@thepreservationnetwork.org or use the account deletion option in your profile settings. We will not discriminate against you for exercising any CCPA rights.

8. Children's Privacy

TheGalaxyDB is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you are under 13, you may not create an account or use the Service.

If you are a parent or guardian and believe that your child under 13 has provided us with personal information without your consent, please contact us at privacy@thepreservationnetwork.org. We will promptly investigate and, if confirmed, delete the information and any associated account.

For users between the ages of 13 and 18, we recommend parental review of this Privacy Policy and our Terms of Service before the minor uses the Service.

9. Security

We implement a range of technical and organizational measures to protect your personal information:

  • Passwords: All account passwords are hashed using bcrypt with a suitable work factor before storage. We never store plaintext passwords and cannot retrieve your password if it is lost.
  • API keys: API keys are stored as SHA-256 hashes in our database. The plaintext key is displayed once upon creation and is not stored in a recoverable form.
  • Transport security: HTTPS (TLS 1.2 or higher) is enforced for all connections to thegalaxydb.org. HTTP requests are redirected to HTTPS automatically.
  • Access controls: Database access is restricted to application servers by network firewall rules. We use separate database users with minimal privileges for different product areas.
  • Infrastructure: Our servers are hosted in Hetzner's ISO/IEC 27001-certified data centers in the EU.

While we take reasonable precautions to protect your information, no security system is impenetrable. We cannot guarantee that your information will never be accessed, disclosed, altered, or destroyed in the event of a breach beyond our reasonable control. If a security incident occurs that is likely to affect your rights, we will notify you as required by applicable law.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make changes, we will update the "Last updated" date at the top of this page.

For material changes those that significantly affect how we collect, use, or share your data we will provide at least 14 days' advance notice by sending an email to the address associated with your account and displaying a prominent notice on the Service. Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the revised policy.

If you have questions about changes to this policy or wish to review a prior version, contact us at privacy@thepreservationnetwork.org.

11. Contact

If you have questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us:

We aim to respond to all privacy-related inquiries within 5 business days and will fulfill verifiable rights requests within 30 days as required by applicable law.