privacy

Privacy Policy

Who is responsible

This policy covers the Blanc desktop browser for macOS, Windows, and Linux and blancbrowser.com. The data controller is Bananify, an independent software studio in Rochester, New York, United States. Contact support@blancbrowser.com for privacy questions or requests.

A mobile version is in development and is not covered until it is released.

What stays on your device

Blanc stores these records locally and does not send them to Bananify unless an optional feature below explicitly says otherwise:

Private tabs share a separate, non-persistent session for the current app run. They are excluded from Blanc history, session restore, reopen-closed-tab, and Profile Sync. Metadata for a download started in a private tab remains only in memory and disappears when Blanc quits; the file you explicitly downloaded remains wherever you saved it. Clearing Blanc's download list does not delete downloaded files.

Local stores use owner-only file permissions and atomic replacement. Cookies use the operating system's protected cookie encryption where Electron supports it. A Profile Sync key retained for future sync is wrapped with the operating system credential service; on Linux, Blanc refuses to retain it if only an insecure plaintext fallback is available. These controls reduce offline profile-copy risk but do not protect against malware already running with your full user privileges.

Optional app requests

Usage measurement

Blanc asks before the first usage event. On a fresh profile, “Help improve Blanc” is presented on; you can turn it off before continuing or later in Settings. Existing profiles retain their saved setting. When the saved setting is on, a packaged build sends one pseudonymous event at launch containing:

During the same app run, Blanc may also send each of these bounded feature-use events once: mahjong_play after the first real move in Mahjong, and newtab_layout when each start-page layout actually renders. A layout event carries only one fixed value: ledger, billboard, shelf, tally, or mahjong. These feature-use events are never sent from private tabs.

No usage event contains a URL, history, search, page content, account, name, email address, precise location, tile choice, game state, or custom text. The collector immediately replaces the installation UUID with a secret-keyed hash. The raw UUID is not retained or forwarded. Short-lived per-IP keys, expiring after about two minutes, enforce abuse limits; Cloudflare may also process ordinary edge logs to deliver and protect the Worker.

The keyed hash deduplicates daily, weekly, and monthly active-install counts for launches and each fixed feature metric. Daily markers expire after about 90 days and weekly/monthly markers after about 13 months; aggregate counts are retained for product trends. If the collector's optional Google Analytics mirror is configured, Google receives the keyed hash as a client ID plus the same version, platform, architecture, coarse OS, session, fixed event name, and fixed layout value when applicable. Development builds do not send usage events.

The random ID lives in install.json, does not enter Profile Sync, and can be reset in Settings. Turning the ping off stops future events; resetting the ID makes any future enabled event appear as a new installation.

Search suggestions (optional)

On a fresh profile, search suggestions are presented on; you can turn them off before continuing or later in Settings. When enabled, Blanc sends an eligible prefix typed in the island to the selected provider—DuckDuckGo, Google, Bing, or Brave Search—and shows that provider's suggestions. Requests are main-process-only, cookie-free, bounded, and never made from private tabs. Pasted text, slash commands, URLs and URL-like values, local paths, payment-card-like numbers, and recognized credential or token prefixes are excluded. Pressing Enter for a search still sends the completed query to the selected search provider, as expected.

1Password login fill on macOS (off by default)

On macOS, if you enable this device-local integration and enter the email address used to sign in to 1Password or an account ID, Blanc can connect to your installed 1Password desktop app through 1Password's SDK when you choose Verify in Settings or explicitly invoke Fill on a login form. The 1Password app asks you to authorize Blanc and applies 1Password's own session and audit rules. SDK authorization can cover the approved account; Blanc limits its behavior to verifying access, listing vault and Login-item overview metadata for local website matching and a chooser of at most ten items, then reading only the built-in username and/or password the detected fields require from the one selected Login item.

While the integration is enabled and configured, Blanc may run a bounded check in an isolated world on the active page to decide whether to show its 1Password key hint. The check asks only whether the page declares a visible autocomplete="current-password" field without a contradictory new-password token. It reads form structure only—never field values, page text, or content—returns only yes or no, does not contact the 1Password SDK or credential broker, and is not persisted or synced. Choosing the hint starts the same explicit Fill flow; Blanc never fills automatically.

Blanc first identifies a safe login target without contacting the SDK. Returned credentials exist only transiently in an isolated helper and the main process while the exact page and fields are revalidated and filled. Blanc does not save, log, sync, or send those credentials to Bananify. The sign-in email or account ID is stored only in local settings and is excluded from Profile Sync. Turning the integration off ends Blanc's cached SDK session. 1Password processes the authorized account interaction under its privacy policy.

Profile Sync (off by default)

If enabled, Profile Sync can synchronize favorites and eligible settings. Each device has a separate off-by-default choice to publish a bounded, read-only snapshot of its open HTTP(S) tabs. History, downloads, permissions, cookies, site data, private tabs, Patron and supporter status, app-icon choice, search-suggestion choice, and usage-ping choice are never synced.

Sync content is encrypted on the device with a key derived from the sync name and passphrase. The current v1 server stores ciphertext under an opaque account locator; it cannot read, index, or merge the content. The passphrase is discarded after derivation and never sent or stored. The retained derived key is protected by the operating system credential service as described above. Losing the passphrase and every configured device means Bananify cannot recover the data.

When open-tab sharing is enabled, an optional encrypted icon sidecar can include bounded, source-rasterized PNG favicons. The receiving device therefore does not contact a remote tab's website just to draw its row.

Blanc Patron activation (optional)

Blanc Patron is handled by Polar, the merchant of record. Polar processes payment and contact details under its privacy policy. Activation sends the license key, Blanc's public organization ID, and the generic label “Blanc” to Polar, and Blanc stores the activation locally. For a recurring subscription, Blanc also revalidates about once a day — sending only the license key, activation ID, and organization ID, never any browsing data — so a cancelled or lapsed subscription can quietly step down. A founding or one-time license does not revalidate; it is trusted offline after activation. Bananify does not receive full payment-card details.

Browsing the web with Blanc

Blanc connects directly to sites you choose to visit. Those sites, embedded resources, search providers, your network, and your internet provider can observe requests as they can in other browsers. Blanc does not proxy or anonymize traffic, and Bananify does not receive a browsing log.

This website

Newsletter (optional, double opt-in)

Submitting the footer form does not immediately subscribe an address. The newsletter Worker temporarily stores the address, request time, and opaque confirmation/unsubscribe material for up to 24 hours and asks Resend to deliver a confirmation email. Resend therefore processes the address for that delivery under its privacy policy. The Worker uses short-lived per-IP rate-limit keys, expiring after about two minutes, but does not attach an IP address to the subscriber record.

Only following the confirmation link creates a subscriber record containing the email address, confirmation time, and opaque unsubscribe token. Every message must include the generated one-click unsubscribe link; using it deletes the record. You can also request deletion at support@blancbrowser.com. A valid address caught by the hidden honeypot is held in a separate 30-day quarantine for manual review of possible browser-autofill false positives. It is never subscribed or sent to Resend unless someone submits it again without the honeypot and then follows the confirmation link.

Why we process information

Where a legal basis is required, usage measurement follows the saved in-app choice; full website analytics, ad-conversion measurement, and newsletter enrollment rely on consent; and restricted cookieless site measurement is used to understand aggregate traffic. Choices can be withdrawn for future processing. Patron and supporter purchases and activation are necessary to provide the requested transaction. Security logs, rate limits, signed-update delivery, and service reliability rely on our legitimate interests in operating and protecting Blanc without overriding user rights. Legal obligations may require limited processing or preservation in exceptional cases.

Service providers and international transfers

Cloudflare hosts the site and Blanc-owned Workers; GitHub hosts source code and releases; Resend delivers confirmation and newsletter messages; Polar handles Patron and supporter purchases; 1Password handles an account interaction only when its optional login-fill integration is enabled and invoked; OpenAI receives the limited ChatGPT-ad conversion event described above only after Allow; and Google receives restricted site analytics by default, full site analytics after Allow, and app analytics only when the saved usage-ping setting is enabled and that mirror is configured. These providers process data under their own terms and may process it in the United States or other countries using their applicable transfer safeguards.

Retention and deletion

Your choices and rights

You can turn search suggestions and usage measurement off before completing first run or later in Settings, leave 1Password login fill off or disable it to end Blanc's cached SDK session, reset the installation ID, leave Profile Sync off or erase its server copy, clear local browsing records, decline full site analytics and ad-conversion measurement, and unsubscribe from email. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, and appeal or complain to a data-protection authority. Blanc does not sell personal information or share it for cross-context behavioral advertising.

Email support@blancbrowser.com to exercise a right. We may need enough information to verify that a request concerns your record; for server-blind ciphertext or an unlinked pseudonymous event, we may be unable to identify a record from your identity alone.

Children

Blanc is not directed to children under 13, and Bananify does not knowingly collect their personal information. A parent or guardian can contact us to request deletion.

Security and changes

Blanc uses sandboxing, least-privilege bridges, signed releases, protected local keys, encryption in transit, and end-to-end encryption where described. No product or service can promise perfect security. Please report vulnerabilities through the security policy. Material policy changes will update the date above and, when appropriate, be called out in the product or site.

Contact

Bananify · Rochester, New York, United States · support@blancbrowser.com