Privacy Policy

Last updated: September 2, 2026

1. Who We Are

BananaBanana is operated by BananaBanana LLC, 157 Revaz Uridia St., Tbilisi 0101, Georgia. We are the data controller for the personal data described in this policy. For any privacy question or request, write to [email protected].

This policy covers the website bananabanana.pro, the generation studio, our public MCP server at /api/mcp, the pay-per-call x402 endpoint and the Telegram Mini App.

2. Information We Collect

Data you give us:

  • Account. An email address and a password (stored only as a bcrypt hash), or a Google account id if you sign in with Google, or a Telegram user id, username and language code if you use the Telegram Mini App. We do not ask for your real name, phone number or postal address.
  • Content. Text prompts, negative prompts, reference images, uploaded videos and the images, videos and audio the models return for you.
  • Payments. Crypto top-ups are handled by our payment provider; we store the deposit address assigned to you, the memo/tag where the network requires one, the transaction hash, amount and currency. Telegram payments (Stars, TON, USDT-TON) store the Telegram transaction id and the credited amount. We never receive or store card numbers or bank details.
  • Integrations. MCP API keys (kept as a SHA-256 hash — the key itself is shown once and cannot be recovered), OAuth applications you connect and the tokens issued to them, and a per-call log of tool name, model, cost and a prompt preview of up to 200 characters.
  • Correspondence. Email you send to our support addresses, including the message body, so we can answer it.

Data we collect automatically:

  • IP address (used for country lookup, rate limiting and fraud prevention), browser and device type, and the language your browser sends.
  • Product analytics: pages visited, time on page, scroll depth, the language version of the site you used, the referring site and UTM parameters, and a first-party session id and visitor id (see Section 8).
  • Generation history and balance activity, so the studio, billing and refunds work.
  • Signals used to detect abuse of the free welcome balance and of the referral program: registration IP, shared visit identifiers and deposit addresses.

We do not run advertising networks, third-party ad pixels or cross-site trackers, and we do not sell personal data.

3. How We Use Your Information

  • Run the service: generate media, deliver files, keep your balance and history.
  • Process top-ups, apply promo codes and referral commissions, issue refunds.
  • Send transactional messages: verification codes, billing and support replies, and — if you use the Telegram Mini App — a notification when a generation finishes.
  • Keep the service reliable and fair: rate limits, quotas, abuse and fraud prevention.
  • Understand how the product is used in aggregate so we can improve it.
  • Comply with legal obligations and enforce our Terms and content policy.

We do not use your prompts or generated content to train any model, our own or anyone else's. Access to account content by our staff is limited to what a specific support request, billing investigation or abuse report requires.

4. How Generation Requests Are Processed

Every generation runs on Google's models — the Gemini image and speech models, Veo 3.1 and Gemini Omni Flash. We reach those models through several access channels, including our own Google Cloud Vertex AI projects; which channel serves a given request depends on the model, the resolution and channel availability at that moment, and the choice is ours, not yours.

What travels to the model is the generation request itself: your prompt, any reference images or source video, and the generation parameters. Your email address, account id and any other account identifier stay with us — the request is not linked to your identity on the way out. Results come back to your account, and neither the prompt nor the output is used to train any model.

Once a request leaves our servers it is handled under the model provider's own terms and retention rules, which we do not control. Take that into account before uploading material you are contractually required to keep confidential — client source files, unreleased products, personal documents or anything covered by an NDA. If a specific job needs a guarantee about where it is processed, contact us before submitting it.

5. Service Providers

Besides the generation channels described above, we rely on:

  • Hetzner Online GmbH (Falkenstein, Germany) — the servers that run the application and store your files and database records.
  • 0xProcessing — cryptocurrency top-ups. It receives the transaction data needed to credit your balance.
  • Telegram — the Mini App, Stars/TON payments and generation notifications, if you use them.
  • Google — sign-in with Google, if you choose it.
  • Resend — delivery of transactional email and receipt of mail sent to our support addresses.
  • Cloudflare — DNS and protection of the site against attacks; requests to bananabanana.pro pass through its network.

Country lookup from an IP address is done locally on our own servers with an offline database — your IP is not sent to a geolocation service.

6. Where Your Data Is Stored and Transferred

Your account, balance, generation history and generated files are stored on our servers in Germany (European Union). Generation requests, and only those, leave that infrastructure as described in Section 4; the model access channels we use operate outside the European Economic Area, and payment, email and messaging providers process data in their own jurisdictions. By using the service you understand that generation requests are processed internationally.

7. How Long We Keep Things

  • Generated images, videos and audio: 30 days from generation, then deleted automatically together with their database record. Download anything you want to keep before that.
  • Deleted generations: a deleted generation goes to trash and is recoverable for 30 days, then permanently removed.
  • Uploaded reference videos: deleted once the generation finishes, and in any case within 24 hours.
  • Multi-turn editing context(the model's own reasoning data used to continue editing an image): 7 days.
  • Failed generations: kept as billing evidence for the automatic refund, without the generated file.
  • Raw analytics events: 180 days. Daily aggregates without per-event detail, and the record of when a visitor id was first seen, are kept indefinitely.
  • Payments and refunds: kept for as long as required for accounting and dispute resolution.
  • Account data: kept while your account exists. Delete your account and we remove it along with its remaining content, except records we must retain for legal or anti-fraud reasons.

8. Cookies and Local Storage

We use first-party cookies only:

  • Session cookie — keeps you signed in. Strictly necessary.
  • bb_sid — a random visit id, valid for the browser session, used to group page views into one visit.
  • bb_vid — a random visitor id stored for one year, used to tell new visitors from returning ones and to attribute a signup to the visit that produced it. It carries no personal data and is not shared with anyone.

Your browser's local storage also holds studio preferences (selected model, prompt draft, panel layout). That never leaves your device. You can clear cookies and local storage at any time in your browser; analytics identifiers are then simply regenerated.

9. Your Rights

You have the right to:

  • Access and receive a copy of your personal data
  • Rectify inaccurate personal data
  • Request deletion of your personal data
  • Object to or restrict processing of your data
  • Data portability
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your local data protection authority

Write to [email protected] from the address on your account and we will answer within 30 days. You can also delete individual generations, revoke API keys and disconnect OAuth applications yourself in your profile at any time.

10. Security

Passwords are stored as bcrypt hashes and API keys as SHA-256 hashes — neither can be read back by us. Traffic is served over HTTPS, session cookies are HttpOnly, and file links handed to external agents are signed and expire. No system is perfectly secure, so we cannot guarantee absolute security; if a breach affects your data we will notify you without undue delay.

11. Children's Privacy

Our service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy. Material changes — a new category of data, a new processor, a shorter or longer retention period — will be reflected here with a new "Last updated" date, and we will notify account holders by email when the change affects how your content is processed.

13. Contact Us

BananaBanana LLC, 157 Revaz Uridia St., Tbilisi 0101, Georgia — [email protected].