Your data

Privacy policy

What LocalBanana processes, which services help deliver it, and how to request help with your data.

Updated September 8, 2026

Creating with AI involves sending information to the services that run the product. This page explains the different paths for your account, payments, creative work and browser settings.

Account and payment information

When you sign in, we process account information such as your email address, account ID and the profile information you provide. We use it to authenticate you and connect your saved work, access and GP balance to your account.

Stripe handles online payments. We send Stripe your account email and an account identifier to associate a purchase with you. We retain payment references, purchase and subscription status, and related billing records to deliver your purchase and handle billing questions. Payment details entered on Stripe checkout are processed by Stripe.

Prompts, reference files and generated work

To carry out a generation or editing request, we process the prompt, reference files and settings you submit. Saved work and assets may be stored to support history, editing, sharing and downloads, depending on the feature.

Generation diagnostics can include prompt excerpts, model and settings, success or failure, processing time, IP address and browser information. Account, visitor and session identifiers may connect these records to usage and billing. Avoid including secrets or unnecessary personal information in prompts and files.

Services involved in processing

We use Supabase for account, database and storage services, and Vercel for website hosting, analytics and performance measurements. Storage and content-delivery services help serve uploaded and generated assets. Stripe supports payment processing and billing.

AI requests are sent to the model or routing services configured for the selected feature. These include direct model-provider connections and routing services such as APIMart; a model name does not always mean a direct connection to its developer. Processing, retention and any training use depend on the provider, route and applicable terms. Contact us before sending material that requires a particular processing location or data-use restriction.

We do not sell your personal data. Sharing data with the services described above is part of providing the product. These services may process information in countries other than your own.

Visibility and shared links

A public gallery entry and a stored asset are different things. Publishing or sharing work can make it available to others. Some assets, including slide and wardrobe images, use URLs that can be opened by anyone who has the link; absence from the public gallery does not mean an asset URL requires a login.

Check the feature and its sharing controls before uploading sensitive material. Do not treat LocalBanana as confidential storage unless the required access and processing conditions have been confirmed for your use case. Copies downloaded or shared by other people are outside your account controls.

Cookies, browser storage and analytics

Cookies and browser storage support sign-in, preferences and product features. We also use first-party analytics to understand page visits and feature use. These records can include visited paths, referring domains, campaign parameters and visitor or session identifiers stored in your browser.

Vercel Analytics and Speed Insights provide additional usage and performance measurements. You can clear cookies and site storage through your browser settings; this may sign you out or remove saved preferences. Clearing browser storage does not delete records already held by the service.

When you use your own API key

For supported BYOK features, your Google API key is saved in this browser's local storage. The key also passes through LocalBanana's server to validate it and make the supported provider request. Browser storage does not mean the request stays entirely on your device.

Remove a saved key in API key settings or clear this site's browser storage when you no longer need it, especially on a shared device. Revoke or rotate the key with its provider if it may have been exposed. Never email an API key to support.

Access, deletion and retention requests

Contact support@localbanana.io from your account email to request access, correction, export or deletion of account-related data. Describe the account, project or asset concerned, without sending passwords or payment-card details. We may need to verify account ownership before acting on a request.

Account data, saved work, operational logs and transaction records serve different purposes and do not necessarily share one retention period. Deleting an item or signing out does not by itself confirm deletion of every copy, backup, provider record or billing record. Some records may need to remain for legal, accounting, fraud-prevention or dispute-handling reasons. Support can clarify the scope, status and any retention limits for your request.

Depending on the laws that apply to you, additional rights concerning your personal information may be available. Contact us to raise a privacy concern or exercise a right. We update this page when our published information changes; its revision date appears above.