Overview
This Privacy Policy explains the distinct data paths used by the BenAgent macOS app and the BenAgent landing page. The app stores its local state on your Mac and sends submitted agent requests to endpoints you configure.
The landing page uses Vercel Analytics as described below. BenAgent does not connect that website integration to Clipboard History or other content stored by the macOS app.
What stays on your Mac
BenAgent settings, selected agent configuration, runtime status, local conversation records, and app preferences are designed to live on your Mac.
Model-provider credentials should remain in the selected runtime. BenAgent-owned administrative secrets use macOS Keychain and are not copied into a BenAgent-hosted account.
- No BenAgent account is required to hold your settings.
- No BenAgent message archive is created on our server.
- Landing-page analytics are not connected to Clipboard History or other macOS app storage.
Clipboard History storage and recognition
Clipboard History is off until you review its disclosure and opt in. When you enable recording, BenAgent stores supported clipboard representations—such as text and formatting, links, file references, colors, images, and PDFs—in a dedicated local SwiftData store. This Clipboard History store is not encrypted.
A saved entry can include the original supported clipboard content, a preview and search index, the source application name and bundle identifier when macOS attribution is available, capture and last-used timestamps, and file paths contained in copied file references. Source-application attribution is best effort.
When a copied file reference points to an image that BenAgent can read, BenAgent stores the image bytes and a thumbnail in the Clipboard History record in addition to the file reference. If you enable image recognition, OCR and QR-code recognition run on the Mac; recognized text and QR-code values are stored in the local search index.
Clipboard retention and deletion controls
You choose a retention period and storage limit, or quota, in Clipboard Settings. Automatic cleanup removes eligible older unpinned entries. Pinned entries are exempt from automatic retention and storage-limit cleanup, so pinned data can remain beyond the selected period and the selected storage limit is not a hard cap on pinned data.
Pausing recording stops new capture but keeps existing history. When you revoke Clipboard History consent, recording stops; you can either keep the existing local history or permanently delete it. Clear Clipboard Storage permanently deletes all local Clipboard History entries, including pinned entries, without changing the recording or storage preferences you selected.
Local Clipboard Feature API
Clipboard History routes use BenAgent's loopback-only Feature API without a separate Clipboard access permission or Settings toggle. Native software on the same Mac can use these routes to read, edit, and permanently delete saved clipboard content, pause or resume already-consented recording, and change Clipboard preferences. The API cannot grant Clipboard History recording consent.
Browser-origin requests are rejected, but BenAgent does not identify or authenticate individual native callers. Any native process on the Mac that can reach the loopback listener can use Clipboard routes while verified Full Unlock and the operation's domain rules permit. Run only native clients you trust.
A native client, including a configured agent runtime, may process or transmit clipboard data according to that client's or provider's behavior. BenAgent cannot control retention, deletion, or onward use by that client or provider.
What can leave your device
BenAgent does not send recorded Clipboard History content to an agent automatically. Add to Chat prepares the selected clipboard content in the local Chat composer for your review; it is sent to your configured agent endpoint only after you submit the chat. At that point, submitted text, file-path text, or an attached image can leave the Mac as part of the request.
If you configure an agent endpoint and submit a message, BenAgent sends the request directly to that endpoint rather than through a BenAgent prompt server. The provider or endpoint may process and retain submitted content under its own configuration, privacy terms, and deletion controls. BenAgent cannot control or delete data retained by a provider or endpoint you configure.
Landing-page analytics
The landing page loads Vercel Analytics for website measurement. The site sends the custom event app_store_click, with location and placement properties, to measure outbound App Store call-to-action clicks. It sends feedback_typeform_opened, with a source property, to measure clicks that open the external feedback form.
These are website events. BenAgent does not route Clipboard History, conversations, prompts, transcripts, documents, API keys, provider responses, or other content stored by the macOS app into Vercel Analytics.
Permissions
BenAgent may ask macOS for permissions such as microphone or speech access when you enable voice features. These permissions are controlled by macOS and can be changed in System Settings.
BenAgent does not forward raw microphone data to a BenAgent server. Voice features should be treated as local app features plus any system services or configured endpoints you choose to use.
Retention and deletion
Controls for data retained on your Mac include clearing local conversations, using Clipboard History's revoke and clear options, deleting local app data, removing BenAgent administrative credentials from Keychain, or uninstalling the app. Clipboard History's retention and storage settings apply only to eligible unpinned clipboard entries in its dedicated local store.
BenAgent cannot delete data from an endpoint you configured yourself. Use that provider's own controls for any data sent directly to it.
Changes
If this policy changes, the updated version should be posted with a new updated date. Material changes should keep the same plain-language privacy stance visible.