Privacy Policy
Last updated 2026-05-31
What we collect
- Account. Your email address and the public half of your passkey. Top Banana uses WebAuthn passkeys, so we never see or store a password — there isn’t one to store.
- Sites. The HTML, CSS, and JavaScript the build agent writes for you, plus any images you upload and any form data your published site collects from its visitors.
- Prompts. The text you submit to the build agent, plus any markdown or HTML reference files you attach to a build.
- Edit history. Snapshots we take before each build so you can restore previous versions.
- Logs. Standard request metadata — method, URL, status code, response time, host header — for debugging and abuse prevention.
Where it goes
- Site files live in our S3-compatible object store, scoped to your account.
- Prompts are sent to the configured LLM provider so the agent can respond. If we ever change which provider that is, we’ll update this page.
- Authentication happens entirely through WebAuthn. The private key for your passkey stays on your device — we never see it.
- HTTPS certificates for custom domains are issued through Let’s Encrypt, which means the certificate authority sees the domain name you’re binding.
Who we share it with
Nobody, beyond what’s strictly required to deliver the service:
- The LLM provider sees your prompt and reference files so it can generate a response.
- Let’s Encrypt sees the domain names we issue certificates for.
- Your hosting and database providers (object store, etc.) hold the bytes your sites are made of.
That’s the whole list. No advertisers, no analytics resellers, no data brokers, no model-training partners.
Sites are public by default
When you publish a site at {slug}.topbanana.dev or your own custom domain, anyone who knows the URL can view it. That’s the product. You can flip a site to private from its Manage page if you’d rather it require a session to view.
Your controls
- Export. Download any site as a
.tar.zstarchive from/export/{slug}at any time. The archive is a complete copy you can keep, import elsewhere, or re-import here. - Delete a site. The Manage page has a delete button. Snapshots for that site go away with it.
- Delete your account. Email hello@topbanana.dev and we’ll purge your sites, snapshots, and account metadata.
Data retention
Active sites stick around as long as your account does. Edit-history snapshots are kept so you can restore previous versions; they’re deleted when the site is. Request logs are kept short-term for debugging and abuse prevention.
Cookies
One session cookie after passkey login. No third-party tracking, no analytics pixels, no ad networks.
Children
Top Banana is not directed at children under 13. If you believe a child has signed up, contact us and we’ll remove the account.
Changes
If we make a material change to this policy, we’ll surface it before it takes effect. The “last updated” date above always reflects the most recent revision.
Contact
Privacy questions, deletion requests, or anything else: hello@topbanana.dev.
See also: Terms of Service.