Banny
arrow_backBack to Home

Privacy Policy

Last Updated: May 16, 2026

🔒 OUR PRIVACY PROMISE

Banny App is built privacy-first. Your sensitive recovery information — your assessment answers, your name, your journal and setback notes, your private session logs, and the saved record of your AI coach conversations — is stored only on your device, not in our database. The one important exception is the AI coach: to generate a reply, the message you send and a snapshot of your recovery context are transmitted over the internet and processed by a third-party AI provider (Google Gemini) — see Section 2.3 below. Aside from that, we process only a limited amount of de-identified analytical and usage data on our remote infrastructure, tied to a random anonymous identifier rather than to your real identity. We do not sell your data. Ever.

1. Who We Are & Scope

This Privacy Policy explains how Banny App ("Banny", "we", "us", or "our") collects, uses, stores, and protects information when you use the Banny mobile application (the "App") and the website at banny.app (the "Site", together with the App, the "Service").

Banny is a health and wellness recovery companion. It is an educational and motivational tool and is not a medical device or a provider of medical care. Please also read our Terms of Use, which govern your use of the Service.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.

2. Our Privacy-First Architecture

The most important thing to understand about Banny is where your data lives. The Service is intentionally designed so that the personal, sensitive, and identifying content you generate never leaves your phone.

2.1 Data Stored Only On Your Device

The following information is stored locally on your device — in an encrypted secure storage area and a local on-device database — and is never transmitted to Banny servers:

  • Your assessment answers. All responses to the onboarding and recovery assessment (including questions about symptoms, habits, relationships, mood, self-esteem, and lifestyle) are processed on-device to generate your personalized plan.
  • Your profile details. Information such as the name you choose to enter, your recovery day count, your symptom duration, and your assessment-derived profile, stored in encrypted on-device secure storage.
  • Your AI coach conversation history. The persistent record of your chat with the in-app coach is stored only in a local database on your device (with a rolling limit on the number of stored messages) and is not saved in our database. Important: this concerns storage only — when you send a message to the AI coach, its content is transmitted in real time to generate a reply, as described in Section 2.3.
  • Your journals, reflections, and setback entries. Free-form notes, triggers, and reflections you log stay on-device.
  • Your private session and check-in logs. Detailed session outcomes, weekly check-ins, milestone history, and the detailed content of your progress tracking remain on-device.
  • Your app preferences. Settings such as notification times, language selection, and onboarding completion status.

Because this data lives only on your device, it is removed when you delete the App or clear its data, and it is not recoverable by us.

2.2 Data We Process On Our Remote Servers (Supabase)

We use Supabase as our backend infrastructure. The only data we send to and store on Supabase is a limited set of de-identified analytical and usage data, associated with a randomly generated anonymous identifier (see Section 4 on anonymous accounts), not with your name, email, phone number, or any direct identifier. This includes:

  • An anonymous account record containing your random anonymous identifier, a coarse severity tier, a numeric recovery-plan length, timestamps, and basic device metadata (such as platform, operating system version, device model, and app version).
  • Anonymous activity/audit eventssuch as completing a quest, unlocking an achievement, opening the App, and completing a daily "pulse" — recorded as numeric scores and categorical metadata (for example, mood, urge, sensitivity, and morning indicators expressed as scaled numbers) rather than as free-form personal content.

This Supabase server-side data is used to operate the Service, understand aggregate engagement, measure recovery-program effectiveness, detect abuse, and improve the product. It does not include your name, your chat conversations, your journal text, your individual assessment answers, or any directly identifying information. (The AI coach uses a separate third-party processing path, described in Section 2.3.)

2.3 The AI Coach & Third-Party AI Processing (Google Gemini)

The in-app AI coach is the one feature that transmits your information off your device. When you send a message to the coach, the following is sent over the internet to our backend service and then processed by a third-party large language model, Google Gemini, which generates the response:

  • The text of the message you type to the coach;
  • Recent conversation turns (up to the last several messages) for context; and
  • A contextual snapshot of your recovery profile assembled to personalize the reply. This may include the name you entered, your age, your condition severity and recovery metrics, your current program day and streak, and the free-form notes, trigger tags, and reflections from recent setbacks you logged.

This information is processed by Google as part of the Gemini service. Your inputs are handled under Google's applicable terms and privacy policy, and Banny does not control how Google processes data submitted to its AI models. We use this path solely to generate coaching responses; the conversation transcript itself is stored only on your device (Section 2.1) and is not retained in our database. See the Google Privacy Policy and Google Terms of Service.

⚠️ Because this content leaves your device and is processed by a third party, please do not enter information into the AI coach that you do not want transmitted to or processed by a third-party AI service — including precise details that identify you or other people, financial information, or anything you consider too sensitive to share. The AI coach is a motivational tool, not a confidential medical, psychological, or counseling service.

3. Third-Party Analytics & Crash Reporting

In the production version of the App only, we use the following third-party services to understand usage and improve stability. These services are configured to receive product analytics, screen and event data, user properties, and a random anonymous identifier — not your sensitive recovery content. Each operates under its own privacy policy:

These analytics and crash-reporting tools are disabled in non-production builds of the App. We do not deliberately transmit your assessment answers, chat content, journal entries, or other sensitive recovery content to these services.

4. Anonymous Accounts & Authentication

Banny does not require you to create an account with an email address, phone number, password, or social login. We do not ask for and do not collect such credentials.

Instead, the App signs you in anonymously and assigns a randomly generated identifier so the Service can function (for example, to associate anonymous usage events and your subscription entitlement with the same installation). This identifier is not linked to your real-world identity by us. If you delete your account or reinstall the App, a new anonymous identifier may be generated.

5. Payments & Subscriptions

Banny offers optional paid subscriptions. Payments are not processed by Banny and your payment card details never pass through or get stored by us.

  • All purchases are processed through the Apple App Store or Google Play Store using their respective in-app purchase systems. Your payment information is handled by Apple or Google under their own privacy policies.
  • We use RevenueCat to manage subscription entitlements and validate purchase status. RevenueCat receives the random anonymous identifier and subscription/transaction metadata from the app store — not your payment card number. See the RevenueCat Privacy Policy, Apple Privacy Policy, and Google Privacy Policy.

6. How We Use Information

We use the limited information described above to:

  • Provide, operate, maintain, and secure the Service;
  • Generate and adjust your personalized recovery plan (performed on-device);
  • Understand aggregate, de-identified usage and measure the effectiveness of the recovery program;
  • Generate AI coach responses, which involves third-party AI processing as described in Section 2.3;
  • Diagnose crashes, debug, and improve reliability;
  • Manage subscription entitlements; and
  • Detect, prevent, and address fraud, abuse, or security issues.

We do not sell your personal information, and we do not use your sensitive recovery content for advertising or share it with advertisers.

7. Legal Bases for Processing

Where the EU/UK General Data Protection Regulation (GDPR) applies, we rely on the following legal bases: (a) performance of a contract, to provide the Service you request; (b) our legitimate interests in operating, securing, and improving the Service in a privacy- protective, de-identified manner; (c) compliance with legal obligations; and (d) your consent, where required (for example, for certain analytics), which you may withdraw at any time.

8. Data Sharing & Disclosure

We share information only in these limited circumstances:

  • Service providers / processors: our backend service, our third-party AI provider (Google Gemini, which processes AI coach inputs to generate responses — see Section 2.3), and the infrastructure, analytics, crash-reporting, and subscription-management providers described above, who process data on our behalf or under their own terms.
  • Legal and safety: where required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of users or the public.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy.

We do not sell or rent personal information to third parties.

9. Data Retention

On-device data is retained on your device until you delete it, clear the App's data, or uninstall the App. You can clear your AI coach chat history from within the App at any time.

De-identified analytical and usage data stored on our servers is retained for as long as necessary for the purposes described in this Policy and is deleted or further anonymized thereafter. Analytics and crash-reporting providers retain data according to their own retention policies.

10. Your Privacy Rights

Depending on where you live, you may have rights under laws such as the GDPR and the California Consumer Privacy Act (CCPA/CPRA), including the right to access, correct, delete, or restrict processing of your personal data, to data portability, to object to processing, and to not be discriminated against for exercising these rights.

Because most of your sensitive data is stored only on your device, you are in direct control of it. You can exercise core rights yourself by:

  • Deleting your account from within the App, which triggers deletion of your server-side anonymous account record;
  • Clearing your chat history within the App;
  • Uninstalling the App or clearing its data, which removes all on-device information.

To make any other privacy request, contact us at privacy@banny.app. We will respond consistent with applicable law. Note that, by design, we cannot access, retrieve, or export the data that resides solely on your device.

11. Children's Privacy

The Service is intended for adults and is not directed to children. It is not intended for use by anyone under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact privacy@banny.app and we will take appropriate steps to address it.

12. International Data Transfers

Our service providers may process the limited de-identified data described above in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.

13. Data Security

We implement technical and organizational measures designed to protect information, including on-device encrypted storage for sensitive profile data, encrypted data transmission, and access controls and row-level security on our backend so that anonymous records are restricted to their associated installation. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after changes become effective constitutes acceptance of the updated Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: privacy@banny.app