GBGallery
Privacy

Privacy Policy

Last updated: September 13, 2026

This policy explains what GBGallery collects, what stays local on your device, what is uploaded for ROM generation, recovery, and cartridge fulfillment, and how account, credit, payment, and order records are handled.

What stays on your device

Photo import, crop, and preview conversion happen in your browser. When you choose Generate ROM, converted image data, photo titles, album title, and platform are sent to our server for authorized generation and private storage. Original working photos are not saved to your account.

The browser can temporarily store your album and editing data to return from sign-in or credit checkout. This handoff expires after 24 hours and is removed when next checked; it is not general draft autosave. A local pointer may identify your latest completed ROM, with ownership rechecked on restoration.

Completed ROM recovery

Successfully generated ROMs contain viewable photos. We store them privately for their signed-in owner to download across devices for 72 hours after successful generation. Unchanged downloads are free and do not extend that deadline. Access stops at the deadline; physical deletion follows on the next successful cleanup sweep, with failed cleanup retried.

Files you deliberately download and keep on your own devices do not expire. Editable original photos and projects are not an account library. Order files have a separate retention period from recovery files.

Account and Google sign-in data

GBGallery uses Google OAuth for sign-in. We request only the account information needed to identify your account, such as your verified email address and provider account identifier.

We use that information to create your account, enforce daily generation limits, apply credits, attach signed-in cartridge orders, prevent repeated signup bonuses, and help with account support.

We do not use Google sign-in to read your Gmail, Google Drive, contacts, calendar, photos, or other Google account content.

Usage and credit records

We count first-preview completions by day to understand whether the editor works for visitors. That counter does not receive photos, titles or account identifiers. Abuse counters use keyed hashes and expire after their enforcement window plus cleanup delay.

We store credit balances, credit purchases, free daily generation usage, signup bonus usage, generation attempts, and related account history so the service can enforce limits and keep billing records accurate.

For abuse prevention, reset prevention, payment records, and legal or accounting obligations, GBGallery keeps a minimal HMAC-based usage ledger even after an account is deleted. This ledger is designed to avoid storing the raw email address while still preventing the same identity from repeatedly claiming new-account benefits.

Cartridge checkout data

If you choose to order a physical cartridge, GBGallery uploads and stores only the files and order details needed to produce and fulfill that order: the finished ROM, the cartridge label image, cartridge shell choice, order notes, inventory or backorder status, Stripe identifiers, fulfillment status, and related order metadata.

If you are signed in when you order, the order may be linked to your account so it can appear in your account order history. Guest checkout remains available, but guest orders may only be trackable through checkout, receipt, and shipping emails.

Pending checkout uploads that do not become paid orders are temporary and are cleaned up after about 24 hours. Paid order ROM and label files are retained through fulfillment and for 60 days after shipment or cancellation, then removed from storage. Order and payment records may be retained longer where needed for customer support, tax, accounting, fraud prevention, or legal obligations.

Payments and shipping

Payments are processed by Stripe. GBGallery does not receive or store full card numbers, card security codes, or bank credentials.

Stripe may collect payment details, customer email, receipts, shipping address, tax information, and other checkout details needed to complete the transaction. Pirate Ship or another shipping provider may receive shipping information needed to create labels and send tracking updates.

Service providers

GBGallery may use service providers including Netlify for hosting, Neon for database storage, Cloudflare R2 for private generated-ROM and order-file storage, Google for OAuth sign-in, Stripe for payments, and Pirate Ship or shipping carriers for fulfillment.

We use these providers to operate the service, process orders, prevent abuse, secure files, and provide customer support. We do not sell personal information and do not use third-party advertising trackers in the gallery editor.

Security

GBGallery is designed to minimize what is uploaded, keep paid order files private, use server-generated storage paths, and provide admin downloads through signed links rather than public bucket URLs.

No online service can guarantee perfect security. If you believe there is a security issue, contact GBGallery support before sharing details publicly.

Your choices

You can use the editor before signing in, but ROM generation requires an account because credits and abuse prevention depend on account identity.

You can delete your account from the account page. Account deletion removes the active sign-in account and hides the email from normal account use, but does not remove records that GBGallery must retain for paid orders, fraud prevention, payment records, accounting, legal obligations, or the HMAC usage ledger described above.

You can clear browser-stored project data by clearing this site's browser data on your device. For billing, deletion, privacy, or order support, email austin.good.business@gmail.com.

Children

GBGallery is not directed to children under 13. Do not use the service if you are not old enough to create an account or make purchases under the laws that apply to you.