How the product works

Data & security

A practical guide to payment processing, AI data flows, asset sharing and API key handling at LocalBanana.

Updated September 8, 2026

Trust starts with knowing where your information goes. Here are the practical details to check before paying, uploading a reference or connecting your own API key.

Payments through Stripe

Online purchases use Stripe-hosted checkout. Enter payment details on the checkout page, then use your LocalBanana account to check the purchase and GP status. Our billing integration uses payment references and account identifiers to deliver your purchase.

Support does not need your full card number, security code, password or API key. Share an order reference and account email when asking about a payment. Payment methods and the final amount are shown at checkout.

Accounts and infrastructure

Supabase provides authentication, database and storage services. Vercel hosts the website and supplies usage and performance measurements. Your account connects your saved work, access and GP balance.

Use a sign-in method you control, protect the linked email account, and sign out on shared devices. If you believe someone else can access your account, contact support from your account email.

What happens when you generate

Prompts, reference files and relevant settings are sent to the AI services that fulfill the request. Depending on the selected model and feature, this may involve a direct provider connection or a routing service such as APIMart. The model's name alone does not identify every service that processes the request.

Provider retention, training use and processing locations can depend on the route and applicable terms. Before sending confidential client material or data with specific handling requirements, ask us to confirm whether the selected feature is suitable.

Sharing and asset access

Public gallery content is visible to other people. Some stored assets, including slide and wardrobe images, can also be accessed through their asset URLs. An item not appearing in the gallery is not a guarantee that its direct link is access-restricted.

Review sharing controls before uploading. Avoid placing credentials, confidential documents or unnecessary personal information in creative inputs. If a file or link needs to be removed, send support the affected URL and account details so its scope can be checked.

Your own API key

Supported Google BYOK keys are saved in your browser's local storage and sent through our server for validation and generation requests. They are not confined to the browser during use. Remove saved keys from API key settings when you no longer need them on a device.

Use provider-side restrictions where suitable and monitor usage in your provider account. Rotate a key with its provider if you suspect exposure. Never send it in a support email or a public report.

Security questions and reports

Send security concerns to support@localbanana.io with the affected URL or feature, what you observed, and minimal steps to reproduce it. Redact credentials and personal information. Avoid testing other people's accounts or data.

If a purchase requires a particular certification, data location, retention rule or contractual safeguard, contact us to confirm its availability before proceeding. This page describes product behavior; it is not a certification or a security assessment of every connected provider.