TRUST & SECURITY
AI Policy
EFFECTIVE: AUGUST 19, 2026 · REVIEWED AT LEAST ANNUALLY · OWNER: SECURITY & LEGAL
1. Purpose & scope
This policy explains how Bannersnack approaches artificial intelligence: what we do today, the rules any future AI feature must meet before it ships, and how our own team is allowed to use AI tools internally. It applies to all Bannersnack products, employees, and contractors.
2. Where we stand today
Bannersnack does not currently use AI to generate designs or process customer content in the product.
The platform provides workflow and production tools designed to improve efficiency, but does not make automated creative decisions on behalf of users. Customer designs, assets, personal data, and other customer-provided content are not used to train machine-learning or AI models, whether developed by us or by third parties.
We do use well-established automated services that are not generative AI, such as Google Safe Browsing (to scan published embeds for malware and phishing) and standard fraud and abuse prevention in our payment and authentication flows.
3. Principles for future AI features
AI capabilities are on our horizon. Any AI feature we introduce will follow these commitments, in place before launch:
Transparency. If a feature uses AI, we will say so — in the product, in our documentation, and on this page. No silent AI.
No training on your content without explicit consent. Customer designs, assets, and personal data will not be used to train AI models unless you explicitly opt in. Opting out will never degrade the core product.
Customer control. AI-assisted features will be optional. Workspace administrators will be able to disable AI features for their team.
Data minimization & isolation. AI processing will use the minimum data necessary, preserve our logical separation between customer workspaces, and follow the same encryption standards as the rest of the platform (TLS in transit, AES-256 at rest).
Vetted providers only. Any third-party AI provider becomes a subprocessor: due-diligence review, a data processing agreement, no retention of customer data for provider-side training, and listing on our subprocessors page before go-live.
Human accountability. AI output will support, never replace, human decisions in security-relevant or account-affecting operations (billing, moderation, account actions).
Compliance by design. AI features will be assessed against GDPR, CCPA/CPRA, and the EU AI Act’s risk framework as applicable, with records of the assessment retained.
4. Internal use of AI by our team
Our engineers and staff may use AI assistants (for example, coding and productivity tools) under these rules:
Approved tools only, reviewed by the security team before use.
No customer personal data, customer content, secrets, or credentials may be pasted into AI tools that are not under an approved agreement covering confidentiality and non-training.
AI-generated code follows the same path as all code: peer review, automated linting and validation gates, and controlled deployment. AI never ships code to production on its own.
Suspected leaks of sensitive data into an AI tool are treated as security incidents under our incident response process.
5. Reporting & contact
Questions or concerns about AI at Bannersnack — including suspected misuse — go to our security team via the contact published on our Security page (see Responsible disclosure). Data protection questions go to our Data Protection Officer (see the Privacy section of the Security page).
6. Changes to this policy
We review this policy at least annually and whenever we introduce or materially change an AI capability. The current version always lives at this address; material changes to how customer data interacts with AI will be announced before they take effect.