{"schemaVersion":"1.0.0","verifiedAt":"2026-08-07","canonicalPage":"https://benagent.app/trust","product":"BenAgent","records":[{"dataClass":"Notes and Prompt Inventory","localOwner":"BenAgent on the user's Mac","localStorage":"SwiftData","leavesMacWhen":"The user selects relevant content, prepares a request and submits it.","destination":"The configured Hermes or OpenClaw endpoint","localRetention":"Retained as local records until the user deletes the individual note or prompt, or removes local app data.","deletionBoundary":"BenAgent can delete its local record; it cannot delete a copy already processed by a configured endpoint."},{"dataClass":"Clipboard History","localOwner":"BenAgent on the user's Mac","localStorage":"Dedicated unencrypted SwiftData store in Application Support when the opt-in feature is enabled","leavesMacWhen":"The user chooses Send to Agent, reviews the prepared composer content and submits it.","destination":"The configured Hermes or OpenClaw endpoint","localRetention":"Controlled by the selected retention and storage limit; pinned entries are exempt from automatic cleanup.","deletionBoundary":"BenAgent supports per-entry, recent-window and full-history deletion, including pinned entries for a full clear."},{"dataClass":"Completed conversation text","localOwner":"BenAgent on the user's Mac","localStorage":"SwiftData conversation records","leavesMacWhen":"A new request is submitted with bounded completed history: at most 200 messages and 120,000 text characters.","destination":"The configured Hermes or OpenClaw endpoint","localRetention":"Retained for local continuity until the relevant local conversation data or app data is removed.","deletionBoundary":"Removing a local record does not erase data retained independently by a configured runtime or model provider."},{"dataClass":"Current-turn image attachment","localOwner":"BenAgent on the user's Mac","localStorage":"Sanitized image bytes persisted with the local conversation after submission","leavesMacWhen":"The user attaches the image to the current request and submits it.","destination":"The configured Hermes or OpenClaw endpoint","localRetention":"Retained with the local conversation. Historical images are represented by metadata/placeholders and are not retransmitted as bytes on later turns.","deletionBoundary":"Cancelling before send discards the composer attachment; provider-side deletion follows that provider's controls."},{"dataClass":"Provider gateway token","localOwner":"BenAgent on the user's Mac","localStorage":"macOS Keychain, scoped separately to Hermes or OpenClaw","leavesMacWhen":"BenAgent sends an outbound request to that selected provider and the user configured a token.","destination":"Authorization header for the selected configured endpoint only","localRetention":"Retained in Keychain until the user clears the field or removes the Keychain item.","deletionBoundary":"Clearing a saved token removes the local Keychain item; BenAgent never exposes it through prompts, request bodies or the local Feature API."},{"dataClass":"Voice audio and transcript","localOwner":"macOS voice permission and BenAgent's active capture session","localStorage":"No BenAgent-hosted audio archive","leavesMacWhen":"A recognized transcript becomes a user request and the user or configured voice flow submits it.","destination":"The configured runtime receives the submitted text; Apple speech-service processing depends on the active macOS speech path and system terms.","localRetention":"Completed submitted text can become part of the local conversation; raw microphone audio is not uploaded to a BenAgent server.","deletionBoundary":"The user can stop capture and revoke microphone or speech permissions in macOS System Settings."},{"dataClass":"Supported background event payload","localOwner":"BenAgent on the user's Mac after loopback delivery","localStorage":"Pending event data in local preferences, bounded to 50 events and retained for up to seven days","leavesMacWhen":"The configured runtime or plugin sends the event to BenAgent's loopback-only listener; BenAgent does not relay it to a BenAgent cloud service.","destination":"Native BenAgent event/result surfaces","localRetention":"Dismissed events are removed from the pending queue; stale pending events are removed after the retention window.","deletionBoundary":"Runtime-side cron history and plugin retry queues remain under the configured runtime's controls."}]}