privacy
Privacy Policy
Last updated October 5, 2026
The short version. Blanc keeps browsing data on your device unless you enable end-to-end-encrypted Sync for eligible data or explicitly create a one-time tab handoff. A fresh install asks before search suggestions or pseudonymous usage measurement can send anything; both choices are presented on and can be turned off before continuing. Usage measurement counts launches and a small allowlist of local feature actions, never browsing activity, and excludes private tabs from feature-use events. The blocker ships with the app instead of downloading filter code at first launch. This website counts page views with Cloudflare's cookieless Web Analytics. Optional Google analytics and ad-conversion measurement stay off until you explicitly allow them through footer Privacy choices, or an existing saved grant applies.
Who is responsible
This policy covers the Blanc desktop browser for macOS, Windows, and Linux and blancbrowser.com. The data controller is Bananify, an independent software studio in Rochester, New York, United States. Contact support@blancbrowser.com for privacy questions or requests.
A mobile version is in development and is not covered until it is released.
What stays on your device
Blanc stores these records locally and does not send them to Bananify unless an optional feature below explicitly says otherwise:
- browsing history, capped to limit growth;
- the regular downloads list;
- favorites and settings;
- cookies and site data created by websites;
- per-site permission decisions; and
- the regular session used to restore tabs after restart.
The Billboard start page derives its frequent-site row on the device from that local history. It can reuse a bounded cache of sanitized favicon pixels that Blanc already captured during normal visits; drawing the row makes no new request to the site or a favicon service, and clearing history clears that artwork. Hiding a tile stores only the dismissed hostname in the local blanc://newtab page storage. The row is never synced or reported as telemetry, and private tabs receive no history-derived row.
Private tabs share a separate, non-persistent session for the current app run. They are excluded from Blanc history, session restore, reopen-closed-tab, and Sync. Metadata for a download started in a private tab remains only in memory and disappears when Blanc quits; the file you explicitly downloaded remains wherever you saved it. Clearing Blanc's download list does not delete downloaded files.
Local stores use owner-only file permissions and atomic replacement. Cookies use the operating system's protected cookie encryption where Electron supports it. A Sync key retained for future sync is wrapped with the operating system credential service; on Linux, Blanc refuses to retain it if only an insecure plaintext fallback is available. These controls reduce offline profile-copy risk but do not protect against malware already running with your full user privileges.
Optional app requests
Usage measurement
Blanc asks before the first usage event. On a fresh profile, “Help improve Blanc” is presented on; you can turn it off before continuing or later in Settings. Existing profiles retain their saved setting. When the saved setting is on, a packaged build sends one pseudonymous event at launch containing:
- a random installation UUID;
- a random per-launch session ID;
- the Blanc version;
- the operating-system family and coarse major version; and
- the processor architecture.
During the same app run, Blanc may also send each of these bounded feature-use events once: mahjong_play after the first real move in Mahjong, and newtab_layout when each start-page layout actually renders. A layout event carries only one fixed value: ledger, billboard, shelf, or tally. These feature-use events are never sent from private tabs.
No usage event contains a URL, history, search, page content, account, name, email address, precise location, tile choice, game state, or custom text. The collector immediately replaces the installation UUID with a secret-keyed hash. The raw UUID is not retained or forwarded. Short-lived per-IP keys, expiring after about two minutes, enforce abuse limits; Cloudflare may also process ordinary edge logs to deliver and protect the Worker.
The keyed hash deduplicates daily, weekly, and monthly active-install counts for launches and each fixed feature metric. Daily markers expire after about 90 days and weekly/monthly markers after about 13 months; aggregate counts are retained for product trends. If the collector's optional Google Analytics mirror is configured, Google receives the keyed hash as a client ID plus the same version, platform, architecture, coarse OS, session, fixed event name, and fixed layout value when applicable. Development builds do not send usage events.
The random ID lives in install.json, does not enter Sync, and can be reset in Settings. Turning the ping off stops future events; resetting the ID makes any future enabled event appear as a new installation.
Search suggestions (optional)
On a fresh profile, search suggestions are presented on; you can turn them off before continuing or later in Settings. When enabled, Blanc sends an eligible prefix typed in the island to the selected provider—DuckDuckGo, Google, Bing, or Brave Search—and shows that provider's suggestions. Requests are main-process-only, cookie-free, bounded, and never made from private tabs. Pasted text, slash commands, URLs and URL-like values, local paths, payment-card-like numbers, and recognized credential or token prefixes are excluded. Pressing Enter for a search still sends the completed query to the selected search provider, as expected.
1Password login fill on macOS (off by default)
On macOS, if you enable this device-local integration and enter the email address used to sign in to 1Password or an account ID, Blanc can connect to your installed 1Password desktop app through 1Password's SDK when you choose Verify in Settings or explicitly invoke Fill on a login form. The 1Password app asks you to authorize Blanc and applies 1Password's own session and audit rules. SDK authorization can cover the approved account; Blanc limits its behavior to verifying access, listing vault and Login-item overview metadata for local website matching and a chooser of at most ten items, then reading only the built-in username and/or password the detected fields require from the one selected Login item.
While the integration is enabled and configured, Blanc may run a bounded check in an isolated world on the active page to decide whether to show its 1Password key hint. The check asks only whether the page declares a visible autocomplete="current-password" field without a contradictory new-password token. It reads form structure only—never field values, page text, or content—returns only yes or no, does not contact the 1Password SDK or credential broker, and is not persisted or synced. Choosing the hint starts the same explicit Fill flow; Blanc never fills automatically.
Blanc first identifies a safe login target without contacting the SDK. Returned credentials exist only transiently in an isolated helper and the main process while the exact page and fields are revalidated and filled. Blanc does not save, log, sync, or send those credentials to Bananify. The sign-in email or account ID is stored only in local settings and is excluded from Sync. Turning the integration off ends Blanc's cached SDK session. 1Password processes the authorized account interaction under its privacy policy.
Sync (off by default)
If enabled, Sync can synchronize favorites and eligible settings. Each device has a separate off-by-default choice to publish a bounded, read-only snapshot of its open HTTP(S) tabs. History, downloads, permissions, cookies, site data, private tabs, Patron and supporter status, app-icon choice, search-suggestion choice, and usage-ping choice are never synced.
Sync content is encrypted on the device with a key derived from the sync name and passphrase. The current v1 server stores ciphertext under an opaque account locator; it cannot read, index, or merge the content. The passphrase is discarded after derivation and never sent or stored. The retained derived key is protected by the operating system credential service as described above. Losing the passphrase and every configured device means Bananify cannot recover the data. If no Blanc device uses a sync account for about 12 months, the server deletes it automatically; see Retention and deletion.
When open-tab sharing is enabled, an optional encrypted icon sidecar can include bounded, source-rasterized PNG favicons. The receiving device therefore does not contact a remote tab's website just to draw its row.
One-time tab handoff (only when requested)
This relay-based handoff is separate from Blanc's in-app Bring Your Tabs migration, which reads a user-selected Chromium profile's saved session on the device. Bring Your Tabs does not send that saved session to the handoff relay.
The open-tab handoff copies only the selected tabs' URL, title, order, and active-tab status into a new Blanc window. It excludes private or incognito tabs, browser-internal pages, cookies, logins, page contents, form state, browsing history, back stacks, groups, pins, and favicons. Source tabs remain untouched.
On the ChatGPT path, ChatGPT and its connected browser process the selected metadata under OpenAI's terms. The Blanc MCP endpoint necessarily receives that metadata, validates it, encrypts it immediately, and does not intentionally log request bodies. On the Firefox and Safari paths, the source-browser extension encrypts the metadata locally before upload, so the relay receives only ciphertext.
In either path, the Blanc storage relay holds an AES-256-GCM encrypted envelope and its authenticated expiry for at most ten minutes. It does not receive the decryption key; on the ChatGPT path, the separate MCP handler generates the key transiently before staging ciphertext. A random handoff ID and key travel in the landing-page fragment, which is not sent in an HTTP request, and the page clears that fragment before offering the opaque values to Blanc through its dedicated protocol. The landing page loads no analytics or measurement code. Claiming atomically deletes the ciphertext and leaves only an opaque used-ID marker and the original expiry until that expiry, preventing reuse without keeping a permanent used-ID log. An expired, replayed, or already claimed handoff returns the same generic claim error. Cloudflare still processes ordinary edge request data and short-lived hashed rate-limit keys to deliver and protect the service.
Blanc decrypts and validates the claimed handoff in its main process and shows the source browser, target local profile, count, titles, and domains before opening anything. Accepting creates the new window; canceling discards the claimed handoff from memory. Because claiming is one-time, a canceled or failed post-claim import must be recreated in the source browser.
Blanc Patron activation (optional)
Blanc Patron is handled by Polar, the merchant of record. Polar processes payment and contact details under its privacy policy. Activation sends the license key, Blanc's public organization ID, and the generic label “Blanc” to Polar, and Blanc stores the activation locally. For a recurring subscription, Blanc also revalidates about once a day — sending only the license key, activation ID, and organization ID, never any browsing data — so a cancelled or lapsed subscription can quietly step down. A founding or one-time license does not revalidate; it is trusted offline after activation. Bananify does not receive full payment-card details.
Browsing the web with Blanc
Blanc connects directly to sites you choose to visit. Those sites, embedded resources, search providers, your network, and your internet provider can observe requests as they can in other browsers. Blanc does not proxy or anonymize traffic, and Bananify does not receive a browsing log.
- Blocking. Reviewed, hash-pinned EasyList and EasyPrivacy snapshots ship inside each Blanc release. The desktop blocker does not download changing filter resources at startup. Network rules, cosmetic CSS, and bundled blocker scriptlets update only with a new signed Blanc release; scriptlet declarations are isolated from one another before injection. Blocking reduces known ads and trackers but cannot guarantee that every tracker is stopped.
- Favicons. Sites may deliver icons as part of normal page loading. When Blanc needs to retain an icon for chrome, a favorite, or optional tab sharing, its main process may fetch the site-provided icon separately without cookies or a referrer. It refuses redirects and private/local network destinations, limits the response, and rasterizes the result to a fixed PNG. Only that PNG—not the source URL—is persisted or synced. The icon host still sees the network request and source IP.
- Updates. An installed build checks GitHub for app updates and downloads an update only from that channel.
- Secure DNS. If you choose a named or custom secure-DNS provider, DNS queries go to that provider under its policy. “Automatic” and “Off” use the platform/browser resolver behavior described in Settings.
- Downloads. A website serving a download observes that request. Blanc does not upload the resulting file or download record to Bananify.
This website
- Measurement consent. Non-legal pages load no Google Analytics script and send no Google measurement events until you explicitly choose Allow in footer Privacy choices, or an existing saved grant applies. There is no automatic consent prompt. After Allow, Google Analytics loads and may set analytics cookies. The same choice permits ad-conversion measurement: when a ChatGPT ad supplies an opaque
opprefreference, Blanc keeps it only for that browser tab's session and includes it in a download redirect. The server then sends OpenAI the reference, event time, download platform, and Blanc download URL. Blanc does not include a name, email, account, visitor IP address, user agent, or user profile, and sets OpenAI's event opt-out flag. No thanks stops event dispatch, clears pending and stored ad references and cleans download links, saves the denied choice, and reloads the page to unload any previously loaded Google measurement library. Requests already sent cannot be recalled. Missing or inaccessible consent storage disables optional measurement. Downloads remain ordinary links throughout. The choice is stored locally in your browser. Legal pages load no measurement code. - Page-view counting. Non-legal pages also load Cloudflare Web Analytics, a beacon that reports the page URL, referrer, and coarse browser and device information to Cloudflare. It sets no cookie and stores no persistent identifier, so it is not affected by the Allow choice; it is used only to understand aggregate traffic, and blockers that filter
cloudflareinsights.comstop it entirely. - Downloads. Pages with download controls ask GitHub's public API which artifacts exist. Choosing an artifact then requests Blanc's Cloudflare download Worker, which increments one aggregate counter for that UTC day and platform target and redirects to the matching GitHub release file. Blanc stores no download cookie, IP address, user agent, or per-user identifier in that counter. When the consented ChatGPT-ad reference described above is present, the same Worker also sends the limited conversion event to OpenAI. Cloudflare and GitHub still receive ordinary request data such as IP address and user agent under their own policies.
- Hosting. Cloudflare Pages serves the site and processes ordinary request and security logs, including IP addresses, to deliver and protect it.
- Fonts. Fonts are bundled and served by blancbrowser.com; no font provider is contacted.
- Tab-handoff landing page. The
/import-tabsutility page is excluded from the sitemap and loads no Google Analytics, Cloudflare Web Analytics beacon, conversion measurement, or consent script. Cloudflare still processes ordinary hosting and security logs.
Newsletter (optional, double opt-in)
Submitting the footer form does not immediately subscribe an address. The newsletter Worker temporarily stores the address, request time, and opaque confirmation/unsubscribe material for up to 24 hours and asks Resend to deliver a confirmation email. Resend therefore processes the address for that delivery under its privacy policy. The Worker uses short-lived per-IP rate-limit keys, expiring after about two minutes, but does not attach an IP address to the subscriber record.
Only following the confirmation link creates a subscriber record containing the email address, confirmation time, and opaque unsubscribe token. Every message must include the generated one-click unsubscribe link; using it deletes the record. You can also request deletion at support@blancbrowser.com. A valid address caught by the hidden honeypot is held in a separate 30-day quarantine for manual review of possible browser-autofill false positives. It is never subscribed or sent to Resend unless someone submits it again without the honeypot and then follows the confirmation link.
Ambassador applications
If you apply to the Blanc Ambassador Pilot, the form sends your name, email address, creator-profile link, and short introduction through a Blanc-owned Cloudflare Worker. Resend delivers that information to Bananify's support inbox so we can review and reply. An application does not subscribe you to the newsletter or another marketing list, and the Worker does not store it in its database. Short-lived per-IP keys limit abuse but are not attached to the application.
Bananify keeps an application in the receiving mailbox only as long as reasonably needed to evaluate it, respond, maintain necessary business records, or meet legal obligations. You can request deletion at support@blancbrowser.com.
Why we process information
Where a legal basis is required, usage measurement follows the saved in-app choice; optional website Google analytics, ad-conversion measurement, and newsletter enrollment rely on consent; and Cloudflare’s cookieless site counts are used to understand aggregate traffic. A tab handoff and an ambassador application are processed only to perform and respond to the user's explicit request. Choices can be withdrawn for future processing. Patron and supporter purchases and activation are necessary to provide the requested transaction. Security logs, rate limits, signed-update delivery, and service reliability rely on our legitimate interests in operating and protecting Blanc without overriding user rights. Legal obligations may require limited processing or preservation in exceptional cases.
Service providers and international transfers
Cloudflare hosts the site and Blanc-owned Workers, including the encrypted tab-handoff relay, and receives cookieless page-view counts where described; GitHub hosts source code and releases; Resend delivers confirmation, newsletter, and ambassador-application messages; Polar handles Patron and supporter purchases; 1Password handles an account interaction only when its optional login-fill integration is enabled and invoked; OpenAI receives the limited ChatGPT-ad conversion event described above only after Allow and separately processes selected tab metadata on the user-invoked ChatGPT handoff path; and Google receives optional site analytics only after Allow or an existing saved grant, and app analytics only when the saved usage-ping setting is enabled and that mirror is configured. Google also receives searches and eligible suggestion prefixes when selected as the app’s search provider. These providers process data under their own terms and may process it in the United States or other countries using their applicable transfer safeguards.
Retention and deletion
- Local records remain until you clear them, the applicable cap removes older entries, or you remove the profile.
- Private browsing state and private download metadata disappear when Blanc quits; downloaded files remain until you delete them.
- Usage markers and aggregate counts follow the periods described under Usage measurement.
- Encrypted sync blobs remain until a configured client erases the server copy, or until no Blanc device has used the sync account for about 12 months, when the server deletes them automatically. Alongside each account the server keeps an activity marker recording only when the account was last used, refreshed at most monthly; it is erased with the account. A count of new sync accounts per UTC day is kept for two days to limit server load. The sync server is not a backup; keep a device containing the source data.
- An unclaimed tab-handoff ciphertext expires after at most ten minutes. A successful claim deletes it immediately and retains an opaque used-ID marker only until the original expiry; canceling clears the decrypted copy from Blanc's memory.
- Unconfirmed newsletter requests expire after 24 hours. Honeypot quarantine records expire after 30 days. Confirmed records remain until unsubscribe or deletion.
- Ambassador applications remain in the receiving mailbox only as long as described above; the application Worker does not retain a database copy.
- Provider security and delivery logs follow the provider's configured retention.
Your choices and rights
You can turn search suggestions and usage measurement off before completing first run or later in Settings, leave 1Password login fill off or disable it to end Blanc's cached SDK session, reset the installation ID, leave Sync off or erase its server copy, avoid creating a tab handoff or cancel it at Blanc's review sheet, clear local browsing records, decline full site analytics and ad-conversion measurement, and unsubscribe from email. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, and appeal or complain to a data-protection authority. Blanc does not sell personal information or share it for cross-context behavioral advertising.
Email support@blancbrowser.com to exercise a right. We may need enough information to verify that a request concerns your record; for server-blind ciphertext or an unlinked pseudonymous event, we may be unable to identify a record from your identity alone.
Children
Blanc is not directed to children under 13, and Bananify does not knowingly collect their personal information. A parent or guardian can contact us to request deletion.
Security and changes
Blanc uses sandboxing, least-privilege bridges, signed releases, protected local keys, encryption in transit, and end-to-end encryption where described. No product or service can promise perfect security. Please report vulnerabilities through the security policy. Material policy changes will update the date above and, when appropriate, be called out in the product or site.
Contact
Bananify · Rochester, New York, United States · support@blancbrowser.com