Two Layers of Protection
Her Galaxy uses a two-layer model: we verify you're a real woman, then we keep your real details completely hidden from everyone else.
Who We Are
Her Galaxy Universe is a free, women-focused community platform operated from the United Kingdom. This Privacy Policy explains how we handle any personal information when you visit, browse, or use our platform.
Data Controller: Her Galaxy Universe
Country of operation: United Kingdom
Contact: support@hergalaxyuniverse.co.uk
Regulator: Information Commissioner's Office (ICO) โ ico.org.uk
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
What We Collect
Her Galaxy uses a two-layer security model. Here's exactly what we collect at each layer:
- Email address: Used for account access, password recovery, and security notifications. Never shown to other members.
- UK mobile number: Used at signup to verify you're a real person and not a bot. Stored encrypted. Never shown to other members.
- Encrypted password hash: We never see or store your real password โ only an irreversible cryptographic hash.
- Account metadata: Sign-up date, last login (for security purposes only).
- Galaxy Name: The display name you choose at signup. This is the only thing other members see.
- Posts and activity: Anything you share in circles, the celebration wall, or peer chats โ attributed to your Galaxy Name only.
- Optional preferences: Any non-identifying preferences you choose to set.
- Conversation messages during your session โ used only to generate a response.
- Conversations are not stored by Her Galaxy after your session ends.
- Conversations are processed by our AI provider (Anthropic) under their commercial data terms, which prohibit training on your conversations.
- Your full real name (unless you choose to share it)
- Your date of birth (only that you confirmed an age range)
- Your home address
- Your contacts, photos, microphone, or camera
- Your location beyond standard server logs
- Any data from third-party advertisers or trackers
Why We Collect It (Lawful Basis)
Under UK GDPR, we must have a lawful reason for processing any personal data. Here are ours:
- Consent (Article 6.1.a): When you sign up, you give consent for us to hold your email and phone for verification. You can withdraw consent at any time by deleting your account.
- Contract performance (Article 6.1.b): We need your verification details to provide the secure, women-only service you've signed up for.
- Legitimate interest (Article 6.1.f): Phone verification is essential to keep men, bots, and fraudulent accounts off the platform โ protecting all members. Brief security logs are kept only to detect attempted fraud or abuse.
We will never process your data for marketing, profiling, or behavioural advertising.
Your Rights Under UK GDPR
You have full control over any data we hold. These rights are guaranteed by law and we will always respect them quickly and free of charge.
- Right to access: Ask us for a copy of any personal data we hold about you. We'll respond within one month.
- Right to rectification: Ask us to correct anything inaccurate.
- Right to erasure ("right to be forgotten"): Ask us to delete your account and any associated data permanently. We'll do this within 30 days.
- Right to restrict processing: Ask us to pause processing your data while a query is being resolved.
- Right to data portability: Ask us for your data in a portable format you can take elsewhere.
- Right to object: Object to any processing based on legitimate interests.
- Right to withdraw consent: Withdraw any previously given consent at any time.
- Right to complain: Lodge a complaint with the ICO if you believe we've handled your data incorrectly.
To exercise any of these rights, email support@hergalaxyuniverse.co.uk. You don't need to give a reason, and we won't ask for one.
How Long We Keep Data
We hold data only as long as needed for the purpose it was collected.
- Verified account data (email, phone): Held while your account is active. Deleted within 30 days of account deletion.
- Posts & community content: Held while your account is active. You can delete individual items any time.
- AI conversations: Not stored after the session ends.
- Server logs (security only): Held for up to 30 days, then automatically deleted.
- Banned account records: If an account is permanently banned for abuse, we keep the email and phone hash for up to 5 years to prevent re-registration.
- Backups: Encrypted backups may persist for up to 90 days for disaster recovery, then permanently deleted.
Cookies & Similar Tech
We use as few cookies as possible. We do not use any tracking cookies, advertising cookies, or third-party analytics cookies.
Strictly necessary cookies and storage we use:
- Session cookie: Keeps you signed in during your visit. Expires when you close your browser (or sign out).
- Local storage: Saves your Galaxy Name, universe choice, pledge completion, and personal preferences โ only on your device.
Because we use only strictly necessary cookies, we don't show a cookie consent banner โ UK GDPR does not require one for these. If we ever add anything beyond essentials, we'll ask first.
Safety Disclosures
Her Galaxy is committed to user safety. In rare circumstances, we may need to share specific information with relevant authorities โ only if there is a credible risk to life. This is consistent with UK law and ICO guidance.
This means:
- If a moderator sees content suggesting imminent risk to a user (e.g. active suicide planning), we may notify emergency services.
- If a court order legally compels disclosure, we will comply only with what the order requires โ no more.
- If we are alerted to child sexual abuse material, we will report it to the appropriate UK authorities.
In all other cases, your data stays with you.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Last updated" date at the top.
- For significant changes, we will notify registered users by email.
- The previous version will remain accessible for at least 12 months on request.
Continued use of the platform after a change means you accept the updated terms.
Email us anytime. For complaints we cannot resolve, you have the right to escalate to the UK Information Commissioner's Office.