Your data

Privacy policy

What LocalBanana processes, which services help deliver it, and how to request help with your data.

Updated September 18, 2026

Creating with AI involves sending information to the services that run the product. This page explains the different paths for your account, payments, creative work and browser settings.

Account and payment information

When you sign in, we process account information such as your email address, account ID and the profile information you provide. We use it to authenticate you and connect your saved work, access and GP balance to your account.

Stripe handles online payments. We send Stripe your account email and an account identifier to associate a purchase with you. We retain payment references, purchase and subscription status, and related billing records to deliver your purchase and handle billing questions. Payment details entered on Stripe checkout are processed by Stripe.

Prompts, reference files and generated work

To carry out a generation or editing request, we process the prompt, reference files and settings you submit. Saved work and assets may be stored to support history, editing, sharing and downloads, depending on the feature.

Generation diagnostics can include prompt excerpts, model and settings, success or failure, processing time, IP address and browser information. Account, visitor and session identifiers may connect these records to usage and billing. Avoid including secrets or unnecessary personal information in prompts and files.

Services involved in processing

We use Supabase for account, database and storage services, and Vercel for website hosting, analytics and performance measurements. Storage and content-delivery services help serve uploaded and generated assets. Stripe supports payment processing and billing.

AI requests are sent to the model or routing services configured for the selected feature. These include direct model-provider connections and routing services such as APIMart; a model name does not always mean a direct connection to its developer. Processing, retention and any training use depend on the provider, route and applicable terms. Contact us before sending material that requires a particular processing location or data-use restriction.

We do not sell your personal data. Sharing data with the services described above is part of providing the product. These services may process information in countries other than your own.

Visibility and shared links

A public gallery entry and a stored asset are different things. Publishing or sharing work can make it available to others. Some assets, including slide and wardrobe images, use URLs that can be opened by anyone who has the link; absence from the public gallery does not mean an asset URL requires a login.

Check the feature and its sharing controls before uploading sensitive material. Do not treat LocalBanana as confidential storage unless the required access and processing conditions have been confirmed for your use case. Copies downloaded or shared by other people are outside your account controls.

Cookies, browser storage and analytics

Cookies and browser storage support sign-in, preferences and product features. We also use first-party analytics to understand page visits and feature use. These records can include visited paths, referring domains, campaign parameters and visitor or session identifiers stored in your browser.

Vercel Analytics and Speed Insights provide additional usage and performance measurements. You can clear cookies and site storage through your browser settings; this may sign you out or remove saved preferences. Clearing browser storage does not delete records already held by the service.

Previously saved API keys

BYOK has been discontinued, and LocalBanana no longer accepts personal API keys. Previously, Google API keys were saved in browser local storage and passed through our server for validation and provider requests; those requests were not confined to your device.

The updated website clears previously saved keys from the current browser when it loads. You can also clear this site's browser storage yourself. This does not remove keys from other browsers or devices or revoke them with the provider. Revoke or rotate a key with its provider if it may have been exposed. Never email an API key to support.

Access, deletion and retention requests

Contact support@localbanana.io from your account email to request access, correction, export or deletion of account-related data. Describe the account, project or asset concerned, without sending passwords or payment-card details. We may need to verify account ownership before acting on a request.

Account data, saved work, operational logs and transaction records serve different purposes and do not necessarily share one retention period. Deleting an item or signing out does not by itself confirm deletion of every copy, backup, provider record or billing record. Some records may need to remain for legal, accounting, fraud-prevention or dispute-handling reasons. Support can clarify the scope, status and any retention limits for your request.

Depending on the laws that apply to you, additional rights concerning your personal information may be available. Contact us to raise a privacy concern or exercise a right. We update this page when our published information changes; its revision date appears above.