GPT Image 2 价格狂欢 价格狂欢:套餐首月免费!创作自由就现在!

-- : -- : -- : --
立享优惠

Privacy Policy

Last updated: May 8, 2026

Learn how Nano Banana Canvas, operated by Digital Bang Intelligence (DBI), collects, uses, and protects your personal information. This privacy policy explains your rights and our practices in accordance with applicable data protection laws.

**Effective Date:** May 8, 2026

1. ABOUT

This Privacy Policy was last updated on May 8, 2026.

Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.

Capitalized terms not defined in this Privacy Policy have the meanings set forth in our Terms of Service.

Data Controller Information

Nano Banana Canvas is operated by Digital Bang Intelligence (DBI). Digital Bang Intelligence (DBI) is the data controller responsible for your personal information.

Our business address is 30 N Gould St Ste R, Sheridan, WY 82801, United States. For any questions or concerns regarding how we handle your personal data, you can contact us at faceswap@126.com, or visit our Contact page.

As the data controller, we determine the purposes and means of processing your personal information in accordance with this Privacy Policy and applicable data protection laws.

Information We Collect

This Privacy Policy applies to personal information processed by us, including on our websites (e.g., nanobananacanvas.com and any other websites that we own or operate), our mobile applications, our application program interfaces, our AI-powered visual workflow platform and tools, and our related online and offline offerings (collectively, the "Services").

This Privacy Policy does not apply to any third-party websites, services or applications, even if they are accessible through our Services. In addition, a separate privacy notice, available upon request if it applies to you, governs processing relating to our current employees and contractors.

2. PERSONAL INFORMATION WE COLLECT

The personal information we collect depends on how you interact with our Services.

Information You Provide to Us

Account Information

When you create a Nano Banana Canvas account, we collect the personal information you provide to us, such as your name, email address, profile picture, and website. If you enable two-factor authentication, we collect a phone number.

Payment Information

Where we sell products and services through the Services, we use third-party applications, such as Stripe, to process your payments. These third-party applications will collect information from you to process a payment on behalf of Digital Bang Intelligence (DBI), including your name, email address, mailing address, payment card information, and other billing information. Digital Bang Intelligence (DBI) does not receive or store your payment card information, but it may receive and store information associated with your payment information (e.g., the fact that you have paid, the last four digits of your credit card information, and your country of origin).

Communication Information

We collect personal information from you such as email address, phone number, mailing address, and marketing preferences when you request information about the Services, register for our newsletter, or otherwise communicate with us.

Customer Content

We collect the creative works, materials, and workflow configurations that are developed by you on the Services or uploaded to the Services by you or by third parties acting on your behalf. Customer Content may include personal information such as any names, images, videos, audio recordings, prompts, node structures, execution histories, and other data you incorporate into your workflows or projects.

Interaction with the Agent

When you communicate with our conversational Agent feature, we collect the messages, prompts, feedback, and proposals you exchange with the Agent. This information is used to operate the Agent and improve its responses. The Agent operates on a proposal-and-review basis; you retain full control over whether its suggestions are applied to your canvas.

Profile and Community Information

If you choose to publish content to the public Explore area, your username and the published content (e.g., workflows, generated images, videos) will be publicly visible. You control what is published. Additionally, we collect information about your interactions with other users' content, such as likes, clones, and comments.

Surveys, Contests, and Events Information

In connection with surveys, contests, conferences, and other events hosted, run or sponsored by us, you may provide information to us, or we may receive information about you, such as name, email address, mailing address, demographic data, and any information specific to the event.

Information Collected Automatically

Automatic Data Collection

We collect certain information automatically when you use the Services. This information may include your Internet protocol (IP) address, user settings, MAC address, cookie identifiers, mobile advertising and other unique identifiers, details about your browser, operating system or device, location information (inferred from your IP address), internet service provider, pages that you visit, information about the links you click, and information about how you interact with and use the Services.

Bot and Abuse Detection (Cloudflare Turnstile)

To protect account registration, social sign-in flows, one-time passcode resend requests, and other security-sensitive interactions from spam, fraud, and automated abuse, we use Cloudflare Turnstile, including its invisible mode. When Turnstile runs, Cloudflare may receive and evaluate technical and connection information such as your IP address, user agent, browser and device characteristics, TLS fingerprint, sitekey, origin, and related request metadata.

We use this processing only to distinguish human visitors from bots, prevent abuse, and help keep the Services safe and available. For more information about how Cloudflare processes Turnstile data, please review Cloudflare's Turnstile Privacy Addendum and Privacy Policy.

Cookies, Pixel Tags/Web Beacons, and Analytics Information

We, as well as third parties that may provide content, advertising, or other functionality on or in connection with the Services, may use cookies, pixel tags, local storage, and other technologies ("Technologies") to automatically collect information through the Services.

`Cookies`: Cookies are small text files placed in device browsers to store their preferences. For more information about how to control cookies, see the "Your Choices" section below.

`Pixel Tags/Web Beacons`: A pixel tag (also known as a web beacon) is a piece of code embedded in the Services that collects information about engagement on the Services. The use of a pixel tag allows us to record that a user has visited a particular web page or clicked on a particular advertisement.

`Analytics`: We use service providers including PostHog, Vercel Analytics, Vercel Speed Insights, Ahrefs Web Analytics, and Google Tag Manager to collect and process analytics information on our Services when you allow analytics cookies.

Information from Other Sources

Organizations and Collaborators

If you use our Services on behalf of, or in collaboration with, an organization (e.g., your employer), that organization may provide us with information about you so that we can provision your account.

Third Party Services and Organizations

We may obtain information about you from other sources, including from third party services and organizations. For example, if you access our Services through a third-party service, we may collect information about you from that third-party service that you have made available via your privacy settings.

3. HOW WE USE YOUR INFORMATION AND OUR LEGAL BASIS FOR PROCESSING

We use your personal information for a variety of business purposes. When we process your information based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on such consent before it is withdrawn.

We use your information to:

  • Provide, manage, and personalize the Services, including creating and maintaining your account, executing workflows, processing AI-generated content, and enabling community features.
  • Process payments and manage billing, credits, and subscriptions.
  • Communicate with you regarding your account, support inquiries, service updates, and marketing materials (where permitted by law).
  • Improve, develop, and analyze the performance of the Services and our AI models, including using Customer Content in an aggregated or anonymized form to enhance workflow efficiencies.
  • Detect and prevent fraud, abuse, and violations of our Terms of Service.
  • Comply with legal obligations and enforce our rights.

Data Retention Periods

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal, accounting, or reporting requirements. Specific retention periods include:

After the retention period expires, we will securely delete or anonymize your personal information. However, we may retain your personal information for longer periods if required by law or for archiving purposes in the public interest, scientific, or historical research purposes.

  • `Account Information`: Retained for the duration of your account plus 30 days after account deletion, unless longer retention is required by law.
  • `Transaction Records`: Retained for 7 years to comply with tax and financial regulations.
  • `AI-Generated Content and Workflow Data`: Retained for as long as you maintain your account, or as needed for service improvement and abuse prevention.
  • `Communication Records`: Retained for up to 3 years for customer service and legal purposes.
  • `Analytics Data`: Typically retained in aggregated, anonymized form for up to 2 years.

Automated Decision Making and AI Processing

Our Services use artificial intelligence and automated systems to:

We do not use automated decision-making for decisions that produce legal effects concerning you or similarly significantly affect you, except where such processing is necessary for entering into or performing a contract with you, is authorized by applicable law, or is based on your explicit consent.

You have the right to request human review of any automated decision that significantly affects you, to express your point of view, and to contest such decisions. Please contact us using the details provided below to exercise these rights.

  • Generate content based on your inputs and prompts.
  • Recommend workflow structures and tools that may be relevant to you.
  • Detect and prevent abuse, fraud, and violations of our Terms of Service.
  • Optimize and improve our AI models and Services.

Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and where feasible, within 72 hours of becoming aware of the breach.

Our notification will include:

We maintain appropriate technical and organizational measures to prevent data breaches and to detect and respond to security incidents promptly.

  • The nature of the personal data breach.
  • The likely consequences of the breach.
  • The measures taken or proposed to address the breach and mitigate its potential adverse effects.
  • Contact information for further inquiries.

Children's Privacy

Our Services are not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18 years of age. If you are a parent or guardian and you believe that your child has provided us with personal information, please contact us immediately.

If we become aware that we have collected personal information from children under 18 without verification of parental consent, we will take steps to remove that information from our servers promptly.

We take children's privacy seriously and are committed to protecting children online. Our AI content generation tools include safety measures to prevent the creation of inappropriate content involving minors.

Disclosure of Personal Information to Third Parties

We may disclose personal information to:

  • a parent, subsidiary, or affiliate of our company;
  • third-party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, analytics, error loggers, debt collectors, maintenance or problem-solving providers, professional advisors, and payment systems operators;
  • our employees, contractors, and/or related entities;
  • our existing or potential agents or business partners;
  • credit reporting agencies, courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you;
  • courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights;
  • third parties, including agents or sub-contractors, who assist us in providing information, products, services, or direct marketing to you;
  • third parties to collect and process data; and
  • an entity that buys, or to which we transfer all or substantially all of our assets and business.

Third-Party Subprocessors

The following table identifies third-party subprocessors authorized to process customer or personal data on behalf of Nano Banana Canvas to provide our Services. We carefully select our subprocessors and require them to comply with applicable data protection laws.

This list may be updated from time to time as we add or remove service providers. We will notify you of any material changes to our subprocessor list that may affect your data.

Name of SubprocessorDescription of ProcessingLocation of ProcessingCorporate Location
OpenAIAI model inference for text and image generationGlobalUSA
AnthropicAI language model inferenceGlobalUSA
VercelWeb hosting, Vercel Analytics, and Vercel Speed InsightsGlobalUSA
CloudflareBot detection, abuse prevention, and security challenges through TurnstileGlobalUSA
PostHogProduct analytics and event measurementGlobalUSA/EU
Google Tag ManagerTag management for analytics or marketing scripts after consentGlobalUSA
AhrefsWebsite analyticsGlobalUSA
StripePayment processingGlobalUSA
SupabaseAuthentication and database servicesGlobalUSA
ClerkUser authentication and identity managementGlobalUSA

International Transfers of Personal Information

Where we transfer your personal information to countries and territories outside of the European Economic Area ("EEA"), Switzerland and the UK which have been formally recognized as providing an adequate level of protection for personal information, we rely on the relevant "adequacy decisions" and "adequacy regulations" from the European Commission, Swiss and UK authorities.

Where the transfer is not subject to an adequacy decision or derogation under the applicable law, we take appropriate safeguards to ensure that your personal information will remain protected in accordance with this Privacy Policy and applicable laws. These safeguards include implementing the European Commission's Standard Contractual Clauses for transfers originating in the EEA, Switzerland and the UK.

4. YOUR RIGHTS AND CONTROLLING YOUR PERSONAL INFORMATION

`Your choice`: By providing personal information to us, you understand we will collect, hold, use, and disclose your personal information in accordance with this privacy policy. You do not have to provide personal information to us, however, if you do not, it may affect your use of our website or the products and/or services offered on or through it.

`Information from third parties`: If we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person's consent to provide the personal information to us.

`Marketing permission`: If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below.

`Access`: You may request details of the personal information that we hold about you.

`Correction`: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, please contact us using the details provided in this privacy policy. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading, or out of date.

`Non-discrimination`: We will not discriminate against you for exercising any of your rights over your personal information.

Unless your personal information is required to provide you with a particular service or offer (for example processing transaction data),

we will not deny you goods or services and/or charge you different prices or rates for goods or services,

including through granting discounts or other benefits, or imposing penalties,

or provide you with a different level or quality of goods or services.

`Notification of data breaches`: We will comply with laws applicable to us in respect of any data breach.

`Complaints`: If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.

`Unsubscribe`: To unsubscribe from our email database or opt-out of communications (including marketing communications), please contact us using the details provided in this privacy policy, or opt-out using the opt-out facilities provided in the communication. We may need to request specific information from you to help us confirm your identity.

Business Transfers

If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may, to the extent permitted by applicable law, continue to use your personal information according to this policy, which they will be required to assume as it is the basis for any ownership or use rights we have over such information.

Limits of Our Policy

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.

Changes to This Policy

At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.

If the changes are significant, or if required by applicable law, we will contact you (based on your selected preferences for communications from us) and all our registered users with the new details and links to the updated or changed policy.

If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information.

Additional Disclosures for General Data Protection Regulation (GDPR) Compliance (EU)

Data Controller / Data Processor

The GDPR distinguishes between organisations that process personal information for their own purposes (known as “data controllers”) and organizations that process personal information on behalf of other organizations (known as “data processors”). We, Digital Bang Intelligence (DBI), located at the address provided in our Contact Us section, are a Data Controller with respect to the personal information you provide to us.

Legal Bases for Processing Your Personal Information

We will only collect and use your personal information when we have a legal right to do so. In which case, we will collect and use your personal information lawfully, fairly, and in a transparent manner. If we seek your consent to process your personal information, and you are under 16 years of age, we will seek your parent or legal guardian’s consent to process your personal information for that specific purpose.

Our lawful bases depend on the services you use and how you use them. This means we only collect and use your information on the following grounds:

Consent From You

Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however this will not affect any use of your information that has already taken place. When you contact us, you may consent to your name and email address being used so we can respond to your enquiry. While you may request that we delete your contact details at any time, we cannot recall any email we have already sent. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the details provided in the Contact Us section of this privacy policy.

Performance of a Contract or Transaction

Where you have entered into a contract or transaction with us, or in order to take preparatory steps prior to our entering into a contract or transaction with you. For example, if you purchase a product, service, or subscription from us, we may need to use your personal and payment information in order to process and deliver your order.

Our Legitimate Interests

Where we assess it is necessary for our legitimate interests, such as for us to provide, operate, improve and communicate our services. We consider our legitimate interests to include research and development, understanding our audience, marketing and promoting our services, measures taken to operate our services efficiently, marketing analysis, and measures taken to protect our legal rights and interests.

Compliance with Law

In some cases, we may have a legal obligation to use or keep your personal information. Such cases may include (but are not limited to) court orders, criminal investigations, government requests, and regulatory obligations. If you have any further enquiries about how we retain personal information in order to comply with the law, please feel free to enquire using the details provided in the Contact Us section of this privacy policy.

International Transfers Outside of the European Economic Area (EEA)

We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.

Your Rights Under GDPR

Restrict: You have the right to request that we restrict the processing of your personal information if (i) you are concerned about the accuracy of your personal information; (ii) you believe your personal information has been unlawfully processed; (iii) you need us to maintain the personal information solely for the purpose of a legal claim; or (iv) we are in the process of considering your objection in relation to processing on the basis of legitimate interests.

Objecting to processing: You have the right to object to processing of your personal information that is based on our legitimate interests or public interest. If this is done, we must provide compelling legitimate grounds for the processing which overrides your interests, rights, and freedoms, in order to proceed with the processing of your personal information.

Data portability: You may have the right to request a copy of the personal information we hold about you. Where possible, we will provide this information in CSV format or other easily readable machine format. You may also have the right to request that we transfer this personal information to a third party.

Deletion: You may have a right to request that we delete the personal information we hold about you at any time, and we will take reasonable steps to delete your personal information from our current records. If you ask us to delete your personal information, we will let you know how the deletion affects your use of our website or products and services. There may be exceptions to this right for specific legal reasons which, if applicable, we will set out for you in response to your request. If you terminate or delete your account, we will delete your personal information within 30 days of the deletion of your account. Please be aware that search engines and similar third parties may still retain copies of your personal information that has been made public at least once, like certain profile information and public comments, even after you have deleted the information from our services or deactivated your account.

Additional Disclosures for California Compliance (US)

Under California Civil Code Section 1798.83, if you live in California and your business relationship with us is mainly for personal, family, or household purposes, you may ask us about the information we release to other organizations for their marketing purposes.

To make such a request, please contact us using the details provided in this privacy policy with “Request for California privacy information” in the subject line. You may make this type of request once every calendar year. We will email you a list of categories of personal information we revealed to other organisations for their marketing purposes in the last calendar year, along with their names and addresses. Not all personal information shared in this way is covered by Section 1798.83 of the California Civil Code.

Do Not Track

Some browsers have a “Do Not Track” feature that lets you tell websites that you do not want to have your online activities tracked. At this time, we do not respond to browser “Do Not Track” signals.

We adhere to the standards outlined in this privacy policy, ensuring we collect and process personal information lawfully, fairly, transparently, and with legitimate, legal reasons for doing so.

CCPA-permitted financial incentives

In accordance with your right to non-discrimination, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels for the goods or services we provide.

Any CCPA-permitted financial incentive we offer will reasonably relate to the value of your personal information, and we will provide written terms that describe clearly the nature of such an offer. Participation in a financial incentive program requires your prior opt-in consent, which you may revoke at any time.

California Notice of Collection

In the past 12 months, we have collected the following categories of personal information enumerated in the California Consumer Privacy Act:

Identifiers, such as name, email address, phone number account name, IP address, and an ID or number assigned to your account.

Customer records, such as billing and shipping address, and credit or debit card data.

For more information on information we collect, including the sources we receive information from, review the “Information We Collect” section. We collect and use these categories of personal information for the business purposes described in the “Collection and Use of Information” section, including to provide and manage our Service.

Right to Know and Delete

If you are a California resident, you have rights to delete your personal information we collected and know certain information about our data practices in the preceding 12 months. In particular, you have the right to request the following from us:

The categories of personal information we have collected about you;

The categories of sources from which the personal information was collected;

The categories of personal information about you we disclosed for a business purpose or sold;

The categories of third parties to whom the personal information was disclosed for a business purpose or sold;

The business or commercial purpose for collecting or selling the personal information; and

The specific pieces of personal information we have collected about you.

To exercise any of these rights, please contact us using the details provided in this privacy policy.

Shine the Light

If you are a California resident, in addition to the rights discussed above, you have the right to request information from us regarding the manner in which we share certain personal information as defined by California’s “Shine the Light” with third parties and affiliates for their own direct marketing purposes.

To receive this information, send us a request using the contact details provided in this privacy policy. Requests must include “California Privacy Rights Request” in the first line of the description and include your name, street address, city, state, and ZIP code.

Contact Us

Nano Banana Canvas is operated by Digital Bang Intelligence (DBI). For any questions or concerns regarding your privacy, you may contact us at faceswap@126.com, visit our Contact page, or write to 30 N Gould St Ste R, Sheridan, WY 82801, United States.