Privacy
Last updated: 26 August 2026. This is a working draft, not legal advice.
We use GitHub OAuth (read:user, user:email) to identify GitHub accounts. Company accounts register with an email and a password hash we store. We do not store the password in plain text. If you drop a peel, repository access is a GitHub App you install on the repos you choose. We store your GitHub user id and login when you connect GitHub. Installation tokens are minted as needed to scan and freeze a vault copy; we do not keep a standing repo OAuth token.
Listing metadata (title, stack, commit counts, summaries) is shown publicly. We do not sell personal data. Server logs may include IP addresses for security.
We record first-party product analytics so staff can see visits, unique visitors, time on pages, clicks, and referrers. That uses two cookies (bb_vid visitor id and bb_sid session id), the page path, click labels, browser user-agent, and whether you were signed in. We do not store IP addresses in analytics. Staff can export this data. Admin pages are not tracked.
Public helper cards (pitch, roles, stack) and Side Peels intros (note, which bunch, GitHub logins) are stored so founders and helpers can find each other. Intro notes are visible to the two parties in the cabinet.
Peel Trade offers (which peels, optional cash, the note) are stored so both parties can accept or decline in the cabinet. They are not public except as the two listings already shown on seller profiles.
When you accept the Seller IP Assignment Deed or the Buyer Pre-Access NDA, we store the document version, acceptance time, IP address, and browser user-agent with that listing or deal.
Payment data will be handled by Stripe when payments launch; BoredBanana will not store full card numbers.
Questions: info@boredbanana.io. Product help, ideas, and bug reports: support@boredbanana.io or the form on /support. That form stores your email, the note, optional page URL, and request IP.