Legal
Privacy Policy
How BentoMind handles your data. In short, it runs on your phone, and your chats and personal data stay there.
- Effective
- 5 October 2026
- Last updated
- 5 October 2026
This Privacy Policy explains how the BentoMind app for Android (“BentoMind”, “the app”, “we”, “us”) handles information. BentoMind is built so that your conversations and personal data are processed on your own phone. We do not run a server that receives your chats, and we do not collect analytics.
The short version: BentoMind runs AI models on your device. Your chats, memories, voice and phone data stay on your phone. Information leaves your phone only when you use a feature that needs the internet, such as downloading a model, web search, nearby places, or a remote model you set up yourself. We have no accounts, no ads and no trackers, and we never sell data.
1. Who we are
BentoMind is developed by Shivang Gupta, an individual developer based in India, who is the data controller for the purposes of this policy.
Contact: shivanggupta9696@gmail.com
2. Our principle: on-device processing
BentoMind runs open-weight language models (for example Qwen, MiniCPM, Gemma, LFM, Llama and others) directly on your phone using the open-source llama.cpp engine. When you chat with a model downloaded to your phone, your messages are processed by your phone’s processor. They are not sent to us or to any AI provider.
Because we do not operate a backend for the app, we, the developer, do not receive your chats, your personal data, or information about how you use the app.
3. Information that stays on your device
The following is created, stored and processed only on your phone, in the app’s private storage. It is never uploaded by BentoMind:
- Chats and history: your messages, the model’s replies, conversation titles and per-message statistics.
- Memories: short notes you ask BentoMind to remember, which you can view, edit and delete.
- Model files: the language and voice models you download.
- Voice audio: when you use voice input with a local model (Moonshine or Whisper), your audio is transcribed on the device and is not saved to a file.
- Settings and benchmark results, including any benchmark exports you choose to save or share yourself.
- Device data accessed by tools. If you switch on a capability, BentoMind can read the related data to answer your request:
- contacts (and, with your confirmation, add, edit or delete them);
- calendar events (and, with your confirmation, add events);
- notifications (see below);
- your location (only while answering a request).
This device data is processed locally, only to answer the request you made, and is never uploaded by BentoMind. One exception is under your control: if you choose to chat with a remote model (section 4), the conversation, including any results a tool added to it, is sent to the server you configured.
Notifications. If you turn on the Notifications capability and grant notification access, BentoMind keeps the app name, title and text of notifications from the last 7 days (up to 500, skipping ongoing notifications) on your phone so it can answer questions such as “who messaged me?”. Turning the capability off stops collection and deletes the stored notifications.
Shared content. When you share text to BentoMind from another app (for example with Android’s Share menu or by selecting text and choosing BentoMind), that text is added to a chat on your phone so the model can work with it. It is stored like any other chat and is never uploaded by BentoMind, unless you send it to a remote model you set up.
BentoMind does not request access to your SMS inbox or call history.
Backups. BentoMind opts out of Android cloud backup, so its data is not copied to your Google account backup.
4. Information that leaves your device, and when
BentoMind connects to the internet only for the features below, and only when you use them. These connections go directly from your phone to the third-party service, not through us. Like any internet request, each service can see your IP address and basic technical information (such as the app’s user agent), and handles it under its own privacy policy.
| Feature | What is sent | Sent to | When |
|---|---|---|---|
| Downloading models | A standard file request (no personal data) | Hugging Face (language models), GitHub (voice models) | When you tap Download |
| Web search | The search query text | DuckDuckGo; Wikipedia as a fallback | When web search is switched on, you are online, and your question needs current information (or you turn on Search in the composer) |
| Reading web pages | A standard page request | The websites in the search results | When the assistant opens a result to read it |
| Nearby places / “where am I” | An area derived from your location, rounded to about 100 m | OpenStreetMap services (Nominatim and Overpass API servers) | When you ask about places or your location with Location switched on |
| Remote models (optional) | Your conversation messages, including any tool results in them, and your API key | The OpenAI-compatible server you add (for example your own computer, or a hosted provider) | Only after you add an endpoint and choose a remote model; chats using it are labelled in the app |
| Google voice recognition (optional) | Your speech, handled by Google’s on-device speech recognizer | Google’s speech service on your phone, under Google’s policies | Only if you choose the Google recognizer for voice input |
Web search is switched on by default and can be switched off at any time in Settings → Permissions. Location, remote models and the other phone-data capabilities are off until you turn them on.
Some actions hand off to other apps instead of BentoMind acting itself. For example, drafting an SMS opens your messaging app, calling opens your dialer, and reminders can open your calendar app. You complete the action there.
5. What we don’t do
- No accounts. You never sign up or log in.
- No ads, and no advertising identifiers.
- No analytics, crash-reporting or tracking SDKs.
- No selling or sharing of personal data. We never receive it in the first place.
- No training on your data. Your chats are not used to train any model.
6. Android permissions
BentoMind asks for each permission only when you switch on the feature that needs it, and works for chat with no special permissions at all.
| Permission | Why BentoMind uses it |
|---|---|
| Internet, network state | Model downloads, optional web search, nearby places and remote models; showing whether you are online |
| Contacts (read, write) | Find contacts, spot duplicates, and add, edit or delete contacts after you confirm |
| Calendar (read, write) | Show upcoming events and add events after you confirm |
| Location (approximate or precise, while in use) | “Where am I?” and nearby places. No background location |
| Microphone | Voice input, transcribed on your phone |
| Notification access | The optional Notifications capability described in section 3 |
| Show notifications | Download progress, “reply in progress” and “reply ready” notices |
| Foreground service, wake lock, run at startup | Finishing a model download or a reply you asked for when you switch apps |
BentoMind does not use the camera, background location, accessibility services or access to all files.
Default digital assistant
You can choose BentoMind as your phone’s default digital assistant (for example, by long-pressing the home button). This lets you open BentoMind quickly from anywhere. It is optional and does not give BentoMind access to any extra data. You can change your default assistant at any time in your phone’s settings. While BentoMind is your default assistant, some phones may also route system voice-input requests to it.
7. Confirmation before actions
BentoMind always asks for your confirmation (OK or Cancel) before it changes anything on your phone, such as editing or deleting a contact or adding a calendar event.
8. Data retention and deletion
Because your data is stored on your phone, you control it:
- Delete chats from the conversation history.
- View, edit and delete memories in Settings.
- Delete downloaded models from the Models screen.
- Remove remote endpoints, and the API keys saved with them, in the app.
- Turn off a capability to stop BentoMind using that data (turning off Notifications also deletes stored notifications).
- Uninstalling BentoMind removes all of its data from your phone.
We cannot delete or recover your data for you, because we never have a copy of it.
9. Children
BentoMind is not directed to children under 13, and we do not knowingly process children’s personal information. AI responses can be inaccurate or unsuitable, so we recommend parental supervision for younger users.
10. Security
Your data stays in BentoMind’s private app storage, which other apps cannot read. API keys for remote models are encrypted with a key held in the Android Keystore. Connections to online services use HTTPS where the service supports it. A remote endpoint you add on your local network may use plain HTTP; only do this on networks you trust. No system is perfectly secure, so please keep your phone protected with a screen lock.
11. International users
BentoMind processes data on your device wherever you are. When you use an online feature, your request goes directly to that third-party service, which may process it in other countries under its own policies. If you live somewhere with data-protection rights (such as the EU/UK GDPR or India’s Digital Personal Data Protection Act, 2023), you can contact us with any request. In practice, the data the app handles is on your device and under your control.
12. Changes to this policy
We may update this policy as BentoMind changes. We will update the “Last updated” date above and, for significant changes, tell you in the app or on this website.
13. Contact
Questions or requests about privacy? Email shivanggupta9696@gmail.com.
Questions? Email shivanggupta9696@gmail.com.