Skip to content

Legal

Privacy Policy

How BentoMind handles your data. In short, it runs on your phone, and your chats and personal data stay there.

Effective
5 October 2026
Last updated
5 October 2026

This Privacy Policy explains how the BentoMind app for Android (“BentoMind”, “the app”, “we”, “us”) handles information. BentoMind is built so that your conversations and personal data are processed on your own phone. We do not run a server that receives your chats, and we do not collect analytics.

The short version: BentoMind runs AI models on your device. Your chats, memories, voice and phone data stay on your phone. Information leaves your phone only when you use a feature that needs the internet, such as downloading a model, web search, nearby places, or a remote model you set up yourself. We have no accounts, no ads and no trackers, and we never sell data.

1. Who we are

BentoMind is developed by Shivang Gupta, an individual developer based in India, who is the data controller for the purposes of this policy.

Contact: shivanggupta9696@gmail.com

2. Our principle: on-device processing

BentoMind runs open-weight language models (for example Qwen, MiniCPM, Gemma, LFM, Llama and others) directly on your phone using the open-source llama.cpp engine. When you chat with a model downloaded to your phone, your messages are processed by your phone’s processor. They are not sent to us or to any AI provider.

Because we do not operate a backend for the app, we, the developer, do not receive your chats, your personal data, or information about how you use the app.

3. Information that stays on your device

The following is created, stored and processed only on your phone, in the app’s private storage. It is never uploaded by BentoMind:

  • Chats and history: your messages, the model’s replies, conversation titles and per-message statistics.
  • Memories: short notes you ask BentoMind to remember, which you can view, edit and delete.
  • Model files: the language and voice models you download.
  • Voice audio: when you use voice input with a local model (Moonshine or Whisper), your audio is transcribed on the device and is not saved to a file.
  • Settings and benchmark results, including any benchmark exports you choose to save or share yourself.
  • Device data accessed by tools. If you switch on a capability, BentoMind can read the related data to answer your request:
    • contacts (and, with your confirmation, add, edit or delete them);
    • calendar events (and, with your confirmation, add events);
    • notifications (see below);
    • your location (only while answering a request).

This device data is processed locally, only to answer the request you made, and is never uploaded by BentoMind. One exception is under your control: if you choose to chat with a remote model (section 4), the conversation, including any results a tool added to it, is sent to the server you configured.

Notifications. If you turn on the Notifications capability and grant notification access, BentoMind keeps the app name, title and text of notifications from the last 7 days (up to 500, skipping ongoing notifications) on your phone so it can answer questions such as “who messaged me?”. Turning the capability off stops collection and deletes the stored notifications.

Shared content. When you share text to BentoMind from another app (for example with Android’s Share menu or by selecting text and choosing BentoMind), that text is added to a chat on your phone so the model can work with it. It is stored like any other chat and is never uploaded by BentoMind, unless you send it to a remote model you set up.

BentoMind does not request access to your SMS inbox or call history.

Backups. BentoMind opts out of Android cloud backup, so its data is not copied to your Google account backup.

4. Information that leaves your device, and when

BentoMind connects to the internet only for the features below, and only when you use them. These connections go directly from your phone to the third-party service, not through us. Like any internet request, each service can see your IP address and basic technical information (such as the app’s user agent), and handles it under its own privacy policy.

FeatureWhat is sentSent toWhen
Downloading modelsA standard file request (no personal data)Hugging Face (language models), GitHub (voice models)When you tap Download
Web searchThe search query textDuckDuckGo; Wikipedia as a fallbackWhen web search is switched on, you are online, and your question needs current information (or you turn on Search in the composer)
Reading web pagesA standard page requestThe websites in the search resultsWhen the assistant opens a result to read it
Nearby places / “where am I”An area derived from your location, rounded to about 100 mOpenStreetMap services (Nominatim and Overpass API servers)When you ask about places or your location with Location switched on
Remote models (optional)Your conversation messages, including any tool results in them, and your API keyThe OpenAI-compatible server you add (for example your own computer, or a hosted provider)Only after you add an endpoint and choose a remote model; chats using it are labelled in the app
Google voice recognition (optional)Your speech, handled by Google’s on-device speech recognizerGoogle’s speech service on your phone, under Google’s policiesOnly if you choose the Google recognizer for voice input

Web search is switched on by default and can be switched off at any time in Settings → Permissions. Location, remote models and the other phone-data capabilities are off until you turn them on.

Some actions hand off to other apps instead of BentoMind acting itself. For example, drafting an SMS opens your messaging app, calling opens your dialer, and reminders can open your calendar app. You complete the action there.

5. What we don’t do

  • No accounts. You never sign up or log in.
  • No ads, and no advertising identifiers.
  • No analytics, crash-reporting or tracking SDKs.
  • No selling or sharing of personal data. We never receive it in the first place.
  • No training on your data. Your chats are not used to train any model.

6. Android permissions

BentoMind asks for each permission only when you switch on the feature that needs it, and works for chat with no special permissions at all.

PermissionWhy BentoMind uses it
Internet, network stateModel downloads, optional web search, nearby places and remote models; showing whether you are online
Contacts (read, write)Find contacts, spot duplicates, and add, edit or delete contacts after you confirm
Calendar (read, write)Show upcoming events and add events after you confirm
Location (approximate or precise, while in use)“Where am I?” and nearby places. No background location
MicrophoneVoice input, transcribed on your phone
Notification accessThe optional Notifications capability described in section 3
Show notificationsDownload progress, “reply in progress” and “reply ready” notices
Foreground service, wake lock, run at startupFinishing a model download or a reply you asked for when you switch apps

BentoMind does not use the camera, background location, accessibility services or access to all files.

Default digital assistant

You can choose BentoMind as your phone’s default digital assistant (for example, by long-pressing the home button). This lets you open BentoMind quickly from anywhere. It is optional and does not give BentoMind access to any extra data. You can change your default assistant at any time in your phone’s settings. While BentoMind is your default assistant, some phones may also route system voice-input requests to it.

7. Confirmation before actions

BentoMind always asks for your confirmation (OK or Cancel) before it changes anything on your phone, such as editing or deleting a contact or adding a calendar event.

8. Data retention and deletion

Because your data is stored on your phone, you control it:

  • Delete chats from the conversation history.
  • View, edit and delete memories in Settings.
  • Delete downloaded models from the Models screen.
  • Remove remote endpoints, and the API keys saved with them, in the app.
  • Turn off a capability to stop BentoMind using that data (turning off Notifications also deletes stored notifications).
  • Uninstalling BentoMind removes all of its data from your phone.

We cannot delete or recover your data for you, because we never have a copy of it.

9. Children

BentoMind is not directed to children under 13, and we do not knowingly process children’s personal information. AI responses can be inaccurate or unsuitable, so we recommend parental supervision for younger users.

10. Security

Your data stays in BentoMind’s private app storage, which other apps cannot read. API keys for remote models are encrypted with a key held in the Android Keystore. Connections to online services use HTTPS where the service supports it. A remote endpoint you add on your local network may use plain HTTP; only do this on networks you trust. No system is perfectly secure, so please keep your phone protected with a screen lock.

11. International users

BentoMind processes data on your device wherever you are. When you use an online feature, your request goes directly to that third-party service, which may process it in other countries under its own policies. If you live somewhere with data-protection rights (such as the EU/UK GDPR or India’s Digital Personal Data Protection Act, 2023), you can contact us with any request. In practice, the data the app handles is on your device and under your control.

12. Changes to this policy

We may update this policy as BentoMind changes. We will update the “Last updated” date above and, for significant changes, tell you in the app or on this website.

13. Contact

Questions or requests about privacy? Email shivanggupta9696@gmail.com.

Questions? Email shivanggupta9696@gmail.com.