privacy
Privacy Policy
Last updated: August 19, 2026
The short version. Blanc keeps browsing data on your device unless you enable end-to-end-encrypted Profile Sync for eligible data. A fresh install asks before search suggestions or the pseudonymous launch ping can send anything; both choices are presented on and can be turned off before continuing. The blocker ships with the app instead of downloading filter code at first launch. This website runs Google Analytics in restricted, cookieless Consent Mode by default and enables full measurement only if you allow it.
Who is responsible
This policy covers the Blanc desktop browser for macOS, Windows, and Linux and blancbrowser.com. The data controller is Bananify, an independent software studio in Rochester, New York, United States. Contact [email protected] for privacy questions or requests.
A mobile version is in development and is not covered until it is released.
What stays on your device
Blanc stores these records locally and does not send them to Bananify unless an optional feature below explicitly says otherwise:
- browsing history, capped to limit growth;
- the regular downloads list;
- favorites and settings;
- cookies and site data created by websites;
- per-site permission decisions; and
- the regular session used to restore tabs after restart.
Private tabs share a separate, non-persistent session for the current app run. They are excluded from Blanc history, session restore, reopen-closed-tab, and Profile Sync. Metadata for a download started in a private tab remains only in memory and disappears when Blanc quits; the file you explicitly downloaded remains wherever you saved it. Clearing Blanc's download list does not delete downloaded files.
Local stores use owner-only file permissions and atomic replacement. Cookies use the operating system's protected cookie encryption where Electron supports it. A Profile Sync key retained for future sync is wrapped with the operating system credential service; on Linux, Blanc refuses to retain it if only an insecure plaintext fallback is available. These controls reduce offline profile-copy risk but do not protect against malware already running with your full user privileges.
Optional app requests
Usage ping
Blanc asks before the first usage ping. On a fresh profile, “Help improve Blanc” is presented on; you can turn it off before continuing or later in Settings. Existing profiles retain their saved setting. When the saved setting is on, a packaged build sends one pseudonymous event at launch containing:
- a random installation UUID;
- a random per-launch session ID;
- the Blanc version;
- the operating-system family and coarse major version; and
- the processor architecture.
It contains no URL, history, search, page content, account, name, email address, or precise location. The collector immediately replaces the installation UUID with a secret-keyed hash. The raw UUID is not retained or forwarded. Short-lived per-IP keys, expiring after about two minutes, enforce abuse limits; Cloudflare may also process ordinary edge logs to deliver and protect the Worker.
The keyed hash deduplicates daily, weekly, and monthly active-install counts. Daily markers expire after about 90 days and weekly/monthly markers after about 13 months; aggregate counts are retained for product trends. If the collector's optional Google Analytics mirror is configured, Google receives the keyed hash as a client ID plus the same version, platform, architecture, coarse OS, and session fields. Development builds do not send pings.
The random ID lives in install.json, does not enter Profile Sync, and can be reset in Settings. Turning the ping off stops future events; resetting the ID makes any future enabled event appear as a new installation.
Search suggestions (optional)
On a fresh profile, search suggestions are presented on; you can turn them off before continuing or later in Settings. When enabled, Blanc sends an eligible prefix typed in the Island to the selected provider—DuckDuckGo, Google, Bing, or Brave Search—and shows that provider's suggestions. Requests are main-process-only, cookie-free, bounded, and never made from private tabs. Pasted text, slash commands, URLs and URL-like values, local paths, payment-card-like numbers, and recognized credential or token prefixes are excluded. Pressing Enter for a search still sends the completed query to the selected search provider, as expected.
Profile Sync (off by default)
If enabled, Profile Sync can synchronize favorites and eligible settings. Each device has a separate off-by-default choice to publish a bounded, read-only snapshot of its open HTTP(S) tabs. History, downloads, permissions, cookies, site data, private tabs, Patron and supporter status, app-icon choice, search-suggestion choice, and usage-ping choice are never synced.
Sync content is encrypted on the device with a key derived from the sync name and passphrase. The current v1 server stores ciphertext under an opaque account locator; it cannot read, index, or merge the content. The passphrase is discarded after derivation and never sent or stored. The retained derived key is protected by the operating system credential service as described above. Losing the passphrase and every configured device means Bananify cannot recover the data.
When open-tab sharing is enabled, an optional encrypted icon sidecar can include bounded, source-rasterized PNG favicons. The receiving device therefore does not contact a remote tab's website just to draw its row.
Blanc Patron activation (optional)
Blanc Patron is handled by Polar, the merchant of record. Polar processes payment and contact details under its privacy policy. Activation sends the license key, Blanc's public organization ID, and the generic label “Blanc” to Polar, and Blanc stores the activation locally. For a recurring subscription, Blanc also revalidates about once a day — sending only the license key, activation ID, and organization ID, never any browsing data — so a cancelled or lapsed subscription can quietly step down. A founding or one-time license does not revalidate; it is trusted offline after activation. Bananify does not receive full payment-card details.
Browsing the web with Blanc
Blanc connects directly to sites you choose to visit. Those sites, embedded resources, search providers, your network, and your internet provider can observe requests as they can in other browsers. Blanc does not proxy or anonymize traffic, and Bananify does not receive a browsing log.
- Blocking. Reviewed, hash-pinned EasyList and EasyPrivacy snapshots ship inside each Blanc release. The desktop blocker does not download changing filter resources at startup. Network rules, cosmetic CSS, and bundled blocker scriptlets update only with a new signed Blanc release; scriptlet declarations are isolated from one another before injection. Blocking reduces known ads and trackers but cannot guarantee that every tracker is stopped.
- Favicons. Sites may deliver icons as part of normal page loading. When Blanc needs to retain an icon for chrome, a favorite, or optional tab sync, its main process may fetch the site-provided icon separately without cookies or a referrer. It refuses redirects and private/local network destinations, limits the response, and rasterizes the result to a fixed PNG. Only that PNG—not the source URL—is persisted or synced. The icon host still sees the network request and source IP.
- Updates. An installed build checks GitHub for app updates and downloads an update only from that channel.
- Secure DNS. If you choose a named or custom secure-DNS provider, DNS queries go to that provider under its policy. “Automatic” and “Off” use the platform/browser resolver behavior described in Settings.
- Downloads. A website serving a download observes that request. Blanc does not upload the resulting file or download record to Bananify.
This website
- Analytics consent. Non-legal pages load Google Analytics in Consent Mode with
analytics_storagedenied. In this restricted state, no analytics cookie or persistent site identifier is stored, but cookieless pings let Google model aggregate traffic. If you click Allow, full measurement is enabled and Google may set an analytics cookie. The choice is stored locally in your browser. Legal pages do not show the banner or load analytics code. - Downloads. Pages with download controls ask GitHub's public API for the latest release, and GitHub serves the selected artifact. GitHub receives ordinary request data such as IP address and user agent under its policy.
- Hosting. Cloudflare Pages serves the site and processes ordinary request and security logs, including IP addresses, to deliver and protect it.
- Fonts. Fonts are bundled and served by blancbrowser.com; no font provider is contacted.
Newsletter (optional, double opt-in)
Submitting the footer form does not immediately subscribe an address. The newsletter Worker temporarily stores the address, request time, and opaque confirmation/unsubscribe material for up to 24 hours and asks Resend to deliver a confirmation email. Resend therefore processes the address for that delivery under its privacy policy. The Worker uses short-lived per-IP rate-limit keys, expiring after about two minutes, but does not attach an IP address to the subscriber record.
Only following the confirmation link creates a subscriber record containing the email address, confirmation time, and opaque unsubscribe token. Every message must include the generated one-click unsubscribe link; using it deletes the record. You can also request deletion at [email protected]. A valid address caught by the hidden honeypot is held in a separate 30-day quarantine for manual review of possible browser-autofill false positives. It is never subscribed or sent to Resend unless someone submits it again without the honeypot and then follows the confirmation link.
Why we process information
Where a legal basis is required, usage measurement follows the saved in-app choice, full website analytics and newsletter enrollment rely on consent, and restricted cookieless site measurement is used to understand aggregate traffic. Choices can be withdrawn for future processing. Patron and supporter purchases and activation are necessary to provide the requested transaction. Security logs, rate limits, signed-update delivery, and service reliability rely on our legitimate interests in operating and protecting Blanc without overriding user rights. Legal obligations may require limited processing or preservation in exceptional cases.
Service providers and international transfers
Cloudflare hosts the site and Blanc-owned Workers; GitHub hosts source code and releases; Resend delivers confirmation and newsletter messages; Polar handles Patron and supporter purchases; and Google receives restricted site analytics by default, full site analytics after Allow, and app analytics only when the saved usage-ping setting is enabled and that mirror is configured. These providers process data under their own terms and may process it in the United States or other countries using their applicable transfer safeguards.
Retention and deletion
- Local records remain until you clear them, the applicable cap removes older entries, or you remove the profile.
- Private browsing state and private download metadata disappear when Blanc quits; downloaded files remain until you delete them.
- Usage markers and aggregate counts follow the periods described under Usage ping.
- Encrypted sync blobs remain until a configured client erases the server copy. The sync server is not a backup; keep a device containing the source data.
- Unconfirmed newsletter requests expire after 24 hours. Honeypot quarantine records expire after 30 days. Confirmed records remain until unsubscribe or deletion.
- Provider security and delivery logs follow the provider's configured retention.
Your choices and rights
You can turn search suggestions and the usage ping off before completing first run or later in Settings, reset the installation ID, leave Profile Sync off or erase its server copy, clear local browsing records, decline full site analytics, and unsubscribe from email. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, and appeal or complain to a data-protection authority. Blanc does not sell personal information or share it for cross-context behavioral advertising.
Email [email protected] to exercise a right. We may need enough information to verify that a request concerns your record; for server-blind ciphertext or an unlinked pseudonymous event, we may be unable to identify a record from your identity alone.
Children
Blanc is not directed to children under 13, and Bananify does not knowingly collect their personal information. A parent or guardian can contact us to request deletion.
Security and changes
Blanc uses sandboxing, least-privilege bridges, signed releases, protected local keys, encryption in transit, and end-to-end encryption where described. No product or service can promise perfect security. Please report vulnerabilities through the security policy. Material policy changes will update the date above and, when appropriate, be called out in the product or site.
Contact
Bananify · Rochester, New York, United States · [email protected]