OpenBanana operates at openbanana.si. This policy was updated October 10, 2026. For privacy requests, contact wolongxiansheng82@gmail.com.
We store your account email, password hash or connected login identity, prompts, generation settings, task status, credit transactions and order records to provide the service. Session cookies keep you signed in. Verification and password recovery emails use your account email. Generation history is available to the signed-in account owner.
Cloudflare hosts the website and database. Resend delivers account emails. If you choose Google sign-in, Google supplies your basic profile and email; we do not request access to your Gmail messages or Drive files.
Your prompt and optional reference image are sent to APIMart for content checks and image generation. Generated images are checked before delivery through APIMart's moderation service. APIMart may route requests to its model suppliers. These suppliers process data under their own terms and privacy policies, and processing may occur outside your country.
Reference files are not published in a public gallery or retained as uploads in our database. We keep the prompt, settings and task record. Completed images are served through temporary provider links; download the images you want to keep. Supplier retention and deletion follow the supplier's policies, independently of the account records stored by OpenBanana.
The current tab keeps your draft prompt, settings and optional reference in browser storage for up to two hours so you can continue after signing in or viewing plans. Clear draft removes it. Signing out clears the current draft. Expired reference storage is removed when the studio is next opened.
First-party usage records include random browser and visit identifiers, event name, public page path, broad campaign source, campaign label, site version, timestamp and account ID when signed in. A signed first-party browser cookie lasts up to 30 days and connects visits with sign-in on the same browser. We use this information to understand which visits lead to registration, image creation, downloads, return visits and payment. They contain no prompts or reference images. We use a rolling 30-day report; older records are removed when the next usage event is recorded. A rotating hashed network identifier limits event requests and is removed on the next usage event after one day. We do not send these events to third-party marketing analytics.
Stripe hosts checkout and processes payment details. OpenBanana stores order, subscription, payment status and credit records. We do not store full card numbers. Stripe processes payment and fraud-prevention data under its Privacy Policy.
Account, task and credit records are retained while needed to operate your account, handle support or resolve a transaction. Billing and security records may be retained where needed for legal obligations or fraud prevention. Temporary image links can expire independently of these records.
To request access, correction or deletion, email us from your account address. We may verify account ownership before handling the request. Explain whether you want your account closed or specific records removed. Account deletion does not automatically cancel a Stripe subscription; cancel renewal in Settings → Billing or contact us for help first.
We use service data to operate, protect and improve OpenBanana. We do not sell your prompts or reference images. This policy will be updated when our data practices change.