Last updated March 12, 2026

Privacy Policy

How Bento collects, uses, and protects your information when you use our calm, private desktop app.



1. Introduction and Scope

This Privacy Policy explains how Bento(“we,” “our,” or “us”) collects, uses, stores, and protects your information when you use our desktop application and website at iamazeyou.me and all associated services.

Bento is a calm, private desktop app with seventeen built-in mini-apps — dashboard, notes, journal, tasks, voice memos, focus, habits, mood, goals, clipboard, sleep, health, nutrition, budget, passwords, countdowns, and settings. This policy covers every interaction you have with Bento, whether you are browsing the website, using the free version, or subscribed to a paid plan.

By accessing or using Bento, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your information as described. If you do not agree, you should not use the app.

This policy is governed by the laws of the jurisdiction in which Bento operates. We encourage you to read this document carefully and contact us at privacy@iamazeyou.me if you have any questions.

2. Information We Collect

Information You Provide Directly

When you create an account, interact with the app, or contact us, you provide information directly. This includes:

  • Account registration data: your email address, chosen display name, and password (stored in hashed form only)
  • Content you create: entries, notes, tasks, habits, and any data you log within Bento’s mini-apps
  • Payment information: billing details provided during subscription. Bento does not store raw credit card numbers. Payment is processed securely by our payment provider, Paystack, under their own terms
  • Profile information: avatar, bio, and any optional details you add to your profile
  • Communications: messages you send to our support team, feedback you submit, and any correspondence with us

Information Collected Automatically

Bento is designed with a local-first, privacy-first architecture. The desktop app does not collect any usage analytics, telemetry, or tracking data.

The only automatic data collection happens on our marketing website (iamazeyou.me):

  • Vercel Analytics: anonymised, cookie-free page view data to understand which pages are visited. No personal data is collected
  • Vercel Speed Insights: anonymised website performance metrics (load times, Core Web Vitals) to ensure the site is fast. No personal data is collected
  • Cookies and local storage: session management tokens, authentication state, and theme preferences stored in your browser

The desktop app itself sends no telemetry, usage statistics, or performance data. Crash reports are opt-in only and disabled by default.

Information From Third Parties

  • Authentication providers: if you sign in through a third-party provider, we receive your email address and basic profile information as permitted by that provider
  • Payment processor: Paystack provides us with transaction status, subscription state, and billing cycle information. We do not receive your full card details
  • AI model providers: when you use the AI chat feature, prompts are processed by third-party AI providers. These providers may process data under their own privacy policies. We describe this further in Section 5

3. How We Use Your Information

To Provide the Service

We use your information to create and maintain your account, process your subscription, and deliver the features you use. Cloud sync (coming soon) will allow you to sync data across devices if you choose to enable it.

To Improve Bento

We review anonymised website analytics from Vercel to understand how visitors interact with our marketing site. The desktop app itself sends no usage data. Feature improvements are guided by user feedback and direct support requests.

To Communicate With You

We send transactional emails including account confirmation, subscription receipts, and billing updates. If you opt in, we may send product updates and feature announcements. We respond to support requests you initiate.

To Process Payments

We use billing information to manage your subscription, process monthly or annual charges, handle upgrades and downgrades between tiers, and process refunds when applicable.

To Ensure Safety

We use information to detect and prevent abuse of the platform, enforce our terms, protect the integrity of the service, and safeguard our users.

4. Content You Create

You own what you create. Your entries, notes, tasks, habits, and any data you log in Bento belong to you. Bento does not claim ownership of your user-generated content.

To deliver the service, you grant Bento a limited, non-exclusive, royalty-free licence to process, store, display, and transmit your content when you enable cloud sync. This licence exists solely for the purpose of operating the service and expires when you delete your content or close your account.

Bento is designed to be private first. Your data stays on your computer by default. When cloud sync launches, your data will be encrypted in transit and at rest.

5. AI and Third-Party Model Processing

Bento’s AI chat feature uses third-party AI model providers to power its conversations. When you send a message to the AI, your prompt is sent to these providers to generate a response.

Bento uses a Bring Your Own Key (BYOK) model for AI providers. You provide your own API keys (OpenAI, Anthropic, Grok, Gemini, or OpenRouter), and AI requests are sent directly from your machine to the provider you choose. Bento never has access to your API keys or the content of your AI conversations.

Because you control what you type, we strongly recommend that you do not include sensitive personal information— such as real addresses, financial details, or medical information — in your AI chat messages.

We review our AI provider relationships regularly and will update this policy if we add or change providers in a way that materially affects how your data is processed.

6. Data Sharing and Disclosure

Bento does not sell your personal data. Period. We have never sold user data and have no plans or business model that involves selling it.

We share data only in the following limited circumstances:

  • Service providers: we share data with providers that help us operate Bento, including hosting infrastructure, payment processing (Paystack), email delivery services, and AI model providers. These providers operate under data processing agreements that restrict how they may use your information
  • Legal requirements: we may disclose information if required by law, court order, subpoena, or government request, or if we believe in good faith that disclosure is necessary to protect the rights, safety, or property of Bento, our users, or the public
  • Business transfers: in the event of a merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity. We will provide notice to affected users before any such transfer and give you the opportunity to delete your account beforehand

7. Data Retention

We retain your information for as long as necessary to provide the service, comply with legal obligations, and resolve disputes. Specific retention periods:

  • Account data: retained while your account is active, plus 90 days after deletion to allow for recovery if requested
  • Created content: retained per your account status. When you delete content, it is removed from active systems within 30 days. Backup copies are purged within 90 days
  • Website analytics: anonymised page view data collected by Vercel Analytics is retained by Vercel per their data retention policy. This data cannot be linked back to individual users. The desktop app retains no usage analytics
  • Payment records: retained as required by applicable financial regulations, typically 7 years

To request deletion of your data, contact us at privacy@iamazeyou.me or use the account deletion option in your settings.

8. Children's Privacy

Bento is designed for general audiences and is not directed at children under 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent.

If you are a parent or guardian and believe your child has provided personal information to Bento without your consent, please contact us immediately at privacy@iamazeyou.me. We will take prompt steps to delete such information.

9. Your Rights and Choices

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you
  • Correction: request that we correct inaccurate or incomplete data
  • Deletion: request that we delete your account and associated personal data
  • Export: export your created content in standard formats before closing your account
  • Opt out: unsubscribe from non-essential communications at any time via email preferences or account settings
  • Object: object to certain types of processing where we rely on legitimate interests as the legal basis

To exercise any of these rights, use the relevant options in your account settings or contact us at privacy@iamazeyou.me. We will respond to verified requests within 30 days.

10. Cookies and Tracking

Bento uses a limited set of cookies and browser storage to operate the website and app. Here is what we use and why:

  • Essential cookies: session management and authentication tokens that keep you logged in. These cannot be disabled without breaking the service
  • Preference storage: your selected theme and display settings stored in local storage. You can clear these through your browser settings
  • Website analytics: we use Vercel Analytics on our marketing website (iamazeyou.me) to collect anonymised page view data. This is cookie-free and does not track individual users. You can opt out via browser extensions

Bento does not use advertising cookies, third-party tracking pixels, or cross-site trackers. We do not participate in ad networks or sell data to advertisers.

11. Security

We implement technical and organisational measures to protect your data:

  • Encryption in transit: all data transmitted between your device and our servers is encrypted using TLS
  • Encryption at rest: sensitive data is encrypted in our database infrastructure
  • Local-first design: your data stays on your computer by default. Only cloud-synced data is transmitted to our servers
  • Access controls: role-based access restrictions, with staff access limited to what is necessary for their function

No system is perfectly secure. In the event of a data breach that affects your personal information, we will notify affected users and relevant authorities within the timeframes required by applicable law.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, legal requirements, or the app itself. When we make material changes, we will notify you by email and via an in-app notice at least 14 days before the changes take effect.

Continued use of Bento after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree with the revised policy, you may close your account before the changes take effect.

Previous versions of this policy are available upon request by emailing legal@iamazeyou.me.

13. Contact and Questions

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us:

We are committed to resolving privacy concerns promptly and will respond to all verified requests within 30 days.

Questions?

If you have questions about this document or your data, reach out to us at legal@iamazeyou.me. We aim to respond within 5 business days.