1. Information We Collect
We collect information to provide and improve our services:
Account Information:
- Email address and name (at registration)
- Password (stored securely using bcrypt hashing)
- Profile preferences and settings
Payment Information:
- Payment details are collected and processed by Stripe, our payment processor
- We do not store your full credit card number on our servers
- We retain transaction records (amounts, dates, credit purchases)
Usage Data:
- Image generation history (prompts used, timestamps, credit consumption)
- Template browsing and purchase history
- Device information, browser type, and IP address
- Pages visited and features used
Content Data:
- Images you upload as references for generation
- AI-generated images created through our platform
- Prompt templates uploaded by creators
2. How We Use Information
We use your information for:
Service Delivery:
- Processing account registration and authentication
- Generating AI images based on your prompts
- Managing credits, purchases, and transactions
- Facilitating the creator marketplace and revenue sharing
Platform Improvement:
- Analyzing usage patterns to improve features
- Monitoring service performance and reliability
- Debugging and resolving technical issues
Communication:
- Sending transactional emails (verification, password reset, purchase receipts)
- Marketing communications (only with your consent, opt-out available)
- Email campaigns about new features or promotions (unsubscribe link in every email)
- Service announcements and policy updates
We do not sell your personal information to third parties.
3. Data Sharing
We share your data only with the following service providers, as necessary to operate our platform:
Stripe β Payment processing. When you purchase credits, your payment information is handled directly by Stripe under their privacy policy.
Google Cloud Platform β Infrastructure hosting. Your data is stored on Google Cloud servers (region: Asia Southeast 1). Google processes data per their data processing terms.
Resend β Email delivery. We use Resend to send transactional and marketing emails. Your email address is shared for delivery purposes only.
AI Service Providers β Image and video generation. Your prompts and reference images are sent to AI providers (Google Gemini, Luma, Kling) for generation. These providers may process your content per their terms.
We may also share information:
- When required by law or legal process
- To protect the rights and safety of our users and platform
- In connection with a merger, acquisition, or sale of assets (with notice to users)
4. Data Retention
We retain your data as follows:
- Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Generated images: Retained for the duration of your account. You may delete individual generations from your dashboard.
- Transaction records: Retained for 7 years for financial compliance and auditing purposes.
- Server logs: Retained for up to 90 days for debugging and security monitoring.
- Email engagement data: Retained for up to 24 months for marketing optimization.
5. Your Rights
You have the following rights regarding your personal data:
Access: You can view your personal information through your account settings at any time.
Correction: You can update your name, email, and profile information in your account settings.
Deletion: You can request deletion of your account and associated data through account settings or by contacting us. We will process deletion requests within 30 days.
Export: You can request a copy of your personal data by contacting us at hello@nanobanana.wayjet.io. We will provide your data in a standard machine-readable format.
Opt-out: You can unsubscribe from marketing emails at any time using the link in each email, or through your email preferences page.
Restriction: You may request that we limit processing of your data in certain circumstances.
To exercise any of these rights, contact us at hello@nanobanana.wayjet.io.
7. Children's Privacy
Nano Banana is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you are between 13 and 18, you must have parental or guardian consent to use our service.
If we discover that we have inadvertently collected information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us at hello@nanobanana.wayjet.io.
8. International Data Transfers
Our services are hosted on Google Cloud Platform with primary servers in Asia Southeast 1 (Singapore). Your data may be transferred to and processed in regions outside your country of residence.
We ensure appropriate safeguards are in place for international transfers, including:
- Standard contractual clauses with service providers
- Reliance on adequacy decisions where applicable
- Technical security measures (encryption in transit and at rest)
9. Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: All data in transit is encrypted via TLS/HTTPS. Sensitive data (API keys) is encrypted at rest using AES-256-GCM.
- Password Security: Passwords are hashed using bcrypt and never stored in plaintext.
- Access Control: Administrative access is restricted and audited.
- Infrastructure: Hosted on Google Cloud Platform with enterprise-grade security controls.
- Payment Security: All payment processing is handled by Stripe, a PCI-DSS Level 1 certified provider.
While we take security seriously, no system is perfectly secure. We encourage you to use strong, unique passwords and report any security concerns to us immediately.
10. GDPR & CCPA Compliance
For EU/EEA residents (GDPR):
- Legal basis for processing: contract performance, legitimate interests, and consent
- You have the right to access, rectify, erase, restrict, port, and object to processing
- You may lodge a complaint with your local data protection authority
- Data Protection contact: hello@nanobanana.wayjet.io
For California residents (CCPA):
- You have the right to know what personal information we collect and how we use it
- You have the right to request deletion of your personal information
- You have the right to opt out of the sale of personal information (we do not sell your data)
- We will not discriminate against you for exercising your privacy rights
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will notify registered users via email
- We will post the updated policy on this page with a new effective date
- Continued use of the platform after changes constitutes acceptance
We encourage you to review this policy periodically.
12. Contact Us
For privacy-related questions or to exercise your data rights, contact us at:
WayJet LLC
Email: hello@nanobanana.wayjet.io
We aim to respond to all privacy inquiries within 30 days.