Privacy Policy

Last updated: August 19, 2026. This policy describes how Banana Peel (operated by [Banana Peel legal entity]) handles data for the site, console, and API at bananapeel.com. It is written against the shipped product — the technical claims below match the retention, encryption, and custody documentation. Bracketed items are pending legal review and will be replaced before this policy is final.

What we collect

  • Account data — your email address and authentication records, managed by Google Identity Platform (email + password or Google sign-in). Agent-created accounts hold a claim token until a human claims them.
  • Billing data — handled by Stripe. We store your Stripe customer id, email, credit balance, and a ledger of charges per run. Card numbers live with Stripe, not with us.
  • Task data — the task text and URLs you submit, run status and results (output, distilled answer, steps), screenshots and downloaded artifacts the runner produced, and session replay links from the executing provider.
  • Credentials you choose to store — vault entries (username, password, optional TOTP seed) are encrypted before write with per-secret envelope encryption (AES-256-GCM data keys wrapped by Cloud KMS, automatic 90-day rotation). Secrets are write-only: no API or console surface ever returns them, and custody policies control which runners may receive them at run time.
  • Routing telemetry — redacted decision traces (domain, task type, ranked runners, outcome status/cost/latency; passwords, tokens, and card-like strings are stripped before persist) and aggregate per-runner statistics that power smart routing and the public benchmarks. Aggregates contain no page content.
  • Site analytics — Google Analytics 4 runs on the marketing site, docs, and console (not on the admin surface). Standard GA cookies and usage events apply.

How long we keep it

  • Run documents we copied — screenshots, artifacts, result payloads — are kept 7 days by default, after which payloads are stripped and blobs deleted. Enterprise workspaces can set 24h / 7d / 30d self-serve; zero retention is a contract term. Outcome metadata (id, status, runner, cost, latency) is kept for billing and history.
  • Vault credentials are kept until you delete them.
  • Redacted routing traces and aggregate statistics are retained.
  • DELETE /api/v1/responses/:idpurges a run's copied blobs immediately and retires the id. The full storage contract, row by row, is in Data handling & retention.

Subprocessors and where data flows

Banana Peel is a routing layer: executing your task can require sending the task content to the runner that executes it. Data leaves our infrastructure only in the ways listed here.

  • Cloud infrastructure — Google Cloud Platform: Cloud Run (compute), Firestore (data), Cloud Storage (artifact bytes), Cloud KMS (key management), Secret Manager, and Identity Platform (auth), in us-central1 (United States).
  • Payments — Stripe.
  • Analytics — Google Analytics 4.
  • LLM providers — task parsing, extraction, output normalization, and result grading can send task text and retrieved page content to Google Vertex AI (Gemini), OpenAI, and Anthropic via their APIs.
  • Runner vendors — when routing dispatches your task to a vendor-hosted runner, the task input (and, for credentialed runs, secrets permitted by your custody policy) flows to that vendor. Live vendor-hosted runners currently comprise Browserbase, Steel, Anchor Browser, Skyvern, Browser Use, Hyperbrowser, Kernel, Airtop, Browserless, Lightpanda, Cloudflare, Manus, TinyFish, Asteroid, Deck, and the extraction APIs (Firecrawl, Jina AI, Exa, Tavily, SerpAPI, Serper, Diffbot, AgentQL, Notte, Apify, ScrapingBee, ScraperAPI, Scrapfly, Decodo, ZenRows, Parallel Web Systems), plus model-native agents from OpenAI, Anthropic, and Google. The authoritative, current list is the runner catalog (live runners marked); open-source frameworks run on Banana Peel compute, not at a vendor. You can restrict or pin the eligible set per credential via custody policies and per request via routing.

We do not sell your data. Banana Peel does not train models on your task content; routing learns from outcome aggregates (success, cost, latency) and redacted decision traces. Session replays hosted by a runner vendor live on that vendor's infrastructure under their retention.

Data location

Banana Peel stores data in Google Cloud region us-central1 (United States). Runner vendors and LLM providers process data wherever they operate. Region pinning and contractual residency commitments are available on Enterprise — see Regional execution.

Your controls and deletion

  • Delete a run and its copied artifacts immediately: DELETE /api/v1/responses/:id.
  • Delete vault credentials at any time (API or console); deletion is immediate.
  • Enterprise workspaces control the retention window self-serve (PATCH /api/v1/workspace).
  • Account deletion is not self-serve yet — contact [privacy contact email] and we will delete the account and associated data, subject to records we must keep (e.g. billing ledgers).
  • Depending on your location, you may have statutory rights to access, correct, delete, or port your personal data — requests go to [privacy contact email].

Data processing terms

For customers that need one, a Data Processing Addendum is [NEEDS OWNER INPUT: DPA availability to be confirmed]. Enterprise agreements can add regional processing and zero-retention commitments.

Changes and contact

We will update this page when practices change and revise the date above. Questions and privacy requests: [privacy contact email]. Governing law: [governing law / jurisdiction].

Command Palette

Search for a command to run...