Skip to main content
Back to BenAgent

Privacy Policy

Privacy Policy

BenAgent keeps Clipboard History in an opt-in local store. Submitted chats, native clients you authorize, and website analytics are separate data paths described below.

Updated August 8, 2026
Privacy stance

Documented local and outbound paths.

Clipboard recording is opt-in. The site uses Vercel Analytics separately; BenAgent does not route Clipboard History or macOS app content into website analytics.

Clipboard History recording
Opt-in
native Clipboard API grant
Separate
website analytics provider
Vercel
No BenAgent server collecting prompts.
Website analytics stay separate from app content.

Clipboard storage is opt-in

Clipboard History uses a dedicated local, unencrypted store only after you review the disclosure and enable recording.

Website analytics are separate

The landing page uses Vercel Analytics for website measurement and named outbound-link events, not for Clipboard History or macOS app content.

Secrets stay local

Model-provider credentials stay with your runtime, and BenAgent administrative secrets stay in the macOS Keychain. No BenAgent cloud account is needed to hold them.

Overview

This Privacy Policy explains the distinct data paths used by the BenAgent macOS app and the BenAgent landing page. The app stores its local state on your Mac and sends submitted agent requests to endpoints you configure.

The landing page uses Vercel Analytics as described below. BenAgent does not connect that website integration to Clipboard History or other content stored by the macOS app.

What stays on your Mac

BenAgent settings, selected agent configuration, runtime status, local conversation records, and app preferences are designed to live on your Mac.

Model-provider credentials should remain in the selected runtime. BenAgent-owned administrative secrets use macOS Keychain and are not copied into a BenAgent-hosted account.

  • No BenAgent account is required to hold your settings.
  • No BenAgent message archive is created on our server.
  • Landing-page analytics are not connected to Clipboard History or other macOS app storage.

Clipboard History storage and recognition

Clipboard History is off until you review its disclosure and opt in. When you enable recording, BenAgent stores supported clipboard representations—such as text and formatting, links, file references, colors, images, and PDFs—in a dedicated local SwiftData store. This Clipboard History store is not encrypted.

A saved entry can include the original supported clipboard content, a preview and search index, the source application name and bundle identifier when macOS attribution is available, capture and last-used timestamps, and file paths contained in copied file references. Source-application attribution is best effort.

When a copied file reference points to an image that BenAgent can read, BenAgent stores the image bytes and a thumbnail in the Clipboard History record in addition to the file reference. If you enable image recognition, OCR and QR-code recognition run on the Mac; recognized text and QR-code values are stored in the local search index.

Clipboard retention and deletion controls

You choose a retention period and storage limit, or quota, in Clipboard Settings. Automatic cleanup removes eligible older unpinned entries. Pinned entries are exempt from automatic retention and storage-limit cleanup, so pinned data can remain beyond the selected period and the selected storage limit is not a hard cap on pinned data.

Pausing recording stops new capture but keeps existing history. When you revoke Clipboard History consent, recording stops; you can either keep the existing local history or permanently delete it. Clear Clipboard Storage permanently deletes all local Clipboard History entries, including pinned entries, without changing the recording or storage preferences you selected.

Local Clipboard Feature API

Clipboard History routes use BenAgent's loopback-only Feature API without a separate Clipboard access permission or Settings toggle. Native software on the same Mac can use these routes to read, edit, and permanently delete saved clipboard content, pause or resume already-consented recording, and change Clipboard preferences. The API cannot grant Clipboard History recording consent.

Browser-origin requests are rejected, but BenAgent does not identify or authenticate individual native callers. Any native process on the Mac that can reach the loopback listener can use Clipboard routes while verified Full Unlock and the operation's domain rules permit. Run only native clients you trust.

A native client, including a configured agent runtime, may process or transmit clipboard data according to that client's or provider's behavior. BenAgent cannot control retention, deletion, or onward use by that client or provider.

What can leave your device

BenAgent does not send recorded Clipboard History content to an agent automatically. Add to Chat prepares the selected clipboard content in the local Chat composer for your review; it is sent to your configured agent endpoint only after you submit the chat. At that point, submitted text, file-path text, or an attached image can leave the Mac as part of the request.

If you configure an agent endpoint and submit a message, BenAgent sends the request directly to that endpoint rather than through a BenAgent prompt server. The provider or endpoint may process and retain submitted content under its own configuration, privacy terms, and deletion controls. BenAgent cannot control or delete data retained by a provider or endpoint you configure.

Landing-page analytics

The landing page loads Vercel Analytics for website measurement. The site sends the custom event app_store_click, with location and placement properties, to measure outbound App Store call-to-action clicks. It sends feedback_typeform_opened, with a source property, to measure clicks that open the external feedback form.

These are website events. BenAgent does not route Clipboard History, conversations, prompts, transcripts, documents, API keys, provider responses, or other content stored by the macOS app into Vercel Analytics.

Permissions

BenAgent may ask macOS for permissions such as microphone or speech access when you enable voice features. These permissions are controlled by macOS and can be changed in System Settings.

BenAgent does not forward raw microphone data to a BenAgent server. Voice features should be treated as local app features plus any system services or configured endpoints you choose to use.

Retention and deletion

Controls for data retained on your Mac include clearing local conversations, using Clipboard History's revoke and clear options, deleting local app data, removing BenAgent administrative credentials from Keychain, or uninstalling the app. Clipboard History's retention and storage settings apply only to eligible unpinned clipboard entries in its dedicated local store.

BenAgent cannot delete data from an endpoint you configured yourself. Use that provider's own controls for any data sent directly to it.

Changes

If this policy changes, the updated version should be posted with a new updated date. Material changes should keep the same plain-language privacy stance visible.