Bento
Get Bento
Privacy Policy

Privacy Policy for Bento

Effective Date: 11 July 2026 Last Updated: 11 July 2026

This Privacy Policy explains how Bento (“the App”, “we”, “us”, or “our”) handles information in connection with your use of the Bento mobile application. It is designed to comply with the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), Australia’s Privacy Act 1988 (including the Australian Privacy Principles), and the developer data-disclosure requirements of the Apple App Store and Google Play Store.

Please read this Privacy Policy carefully. By downloading, installing, or using the App, you acknowledge that you have read and understood this Privacy Policy.

On this page

  1. 1. Who We Are (Data Controller)
  2. 2. Summary: The Short Version
  3. 3. Information We Collect
  4. 4. Legal Bases for Processing (GDPR)
  5. 5. Third-Party Services
  6. 6. Local Backups and Data Export
  7. 7. How We Use Information
  8. 8. Data Sharing and Disclosure
  9. 9. Data Retention and Deletion
  10. 10. Your Privacy Rights
  11. 11. Children’s Privacy
  12. 12. Data Security
  13. 13. International Data Transfers
  14. 14. Changes to This Privacy Policy
  15. 15. Platform-Specific Disclosures
  16. 16. Contact Us

1. Who We Are (Data Controller)

The App is developed and published by:

Halcyon Code
Contact: support@trybento.app

For the purposes of the GDPR and equivalent laws, the developer identified above is the data controller for any personal data processed in connection with the App, to the limited extent described in this Policy.

2. Summary: The Short Version

Bento is a local-first, offline-capable personal budgeting app. In plain terms:

  • We do not operate a server or backend for the App. There is no user account, no login, and no cloud database of your financial information.
  • All of the financial and personal information you enter (your name, income, pay schedule, recurring bills, one-time expenses, and savings goals) is stored only on your own device, in storage that is private to the App.
  • We (the developer) never receive, see, collect, or have access to your financial data. It never leaves your device unless you choose to export it (see Section 6) or share it yourself.
  • The only outbound network requests the App makes are anonymous calls to a public currency exchange rate service to display up-to-date conversion rates (see Section 5). These requests do not contain any of your personal or financial information.
  • We do not use analytics, advertising SDKs, tracking pixels, or any third-party data-broker integrations. The App contains no advertising.
  • The App offers a single in-app purchase (a one-time fee to unlock full functionality after a free trial period), processed entirely through Google Play Billing. We never receive or store your payment card, bank, or billing details (see Section 5.2).
  • A small, non-identifying marker recording only the date your free trial began is stored separately from your financial data, solely to enforce the trial period (see Section 3.4).

The rest of this Policy provides the full legal detail behind that summary.

3. Information We Collect

3.1 Information You Provide (stored locally only)

When you use the App, you may enter the following categories of information directly into the App’s interface:

  • Profile information: a display name, preferred currency, and pay-cycle preferences.
  • Financial information: income/pay entries, recurring bill details (name, amount, currency, category, due date, frequency, and historical price/schedule changes), one-time expense records, and savings-goal details (target amounts, currencies, and contribution history).
  • App preferences: theme (light/dark/system), language selection, notification preferences, and automatic-backup preferences.

All of the above is stored exclusively in local, app-private storage on your device. It is not transmitted to us, to any server we operate, or to any third party, except as a direct, explicit result of an action you personally initiate (exporting a backup file, or sharing exported data via your device’s native share sheet).

3.2 Information We Do NOT Collect

We do not collect, and the App does not contain the technical capability to collect:

  • Your name, email address, or contact details (unless you choose to type them into the App’s own “profile name” field, which, as above, stays on your device).
  • Precise or approximate location data.
  • Device identifiers used for cross-app tracking or advertising (e.g., advertising ID, IDFA).
  • Contacts, photos, camera, microphone, or SMS data.
  • Usage analytics, crash telemetry, session recordings, or behavioral tracking of any kind.
  • Payment card numbers, bank account numbers, or other financial account credentials: the App is a manual budget tracker; it does not connect to, or read data from, any bank, card network, or financial institution.

3.3 Local Notifications

The App can send you local device notifications (e.g., bill reminders, payday reminders, overspending alerts, savings-goal milestones). These notifications are scheduled and delivered entirely on-device using the Android notification system (@capacitor/local-notifications). No notification content or scheduling data is transmitted to us or to any third party.

3.4 Trial and Purchase Information

To operate the App’s free-trial-then-one-time-purchase model, the App stores and processes the following additional, minimal information:

  • Trial start marker: a single timestamp recording the date you first launched the App, stored in a location kept separate and isolated from the financial and profile data described in Section 3.1. This marker contains no name, financial information, or other personally identifying content.
  • Purchase/entitlement status: whether you have completed the one-time unlock purchase, as reported to the App by Google Play Billing. We do not receive, and the App does not store, your payment card number, bank details, billing address, or other payment-instrument information: that information is collected and processed entirely by Google as part of its own payment-processing service, subject to Google’s own privacy policy.

Neither the trial-start marker nor your purchase/entitlement status is transmitted to us or to any server we operate. The trial-start marker’s device-backup behavior is described further in Section 6.2, and Google Play Billing is described further in Section 5.2.

3.5 App Lock (Optional Security Feature)

The App includes an optional lock screen you may enable in Settings to require a PIN, passphrase, or biometric unlock before the App’s content is shown. If you choose to enable this feature:

  • PIN or passphrase: the App never stores your PIN or passphrase itself. It stores only a salted cryptographic hash, a one-way, irreversible representation that cannot be used to recover your original PIN or passphrase, even by us. This hash is stored locally on your device only and is never transmitted anywhere.
  • Biometric unlock (fingerprint or face): if you choose to enable this option, authentication is performed entirely by your device’s own operating system using its own biometric hardware and software. The App itself never receives, processes, or stores your fingerprint, face, or any other biometric data. The App only receives a simple success or failure result from your device’s operating system, telling it whether to unlock.
  • This feature is a screen-lock convenience layer only. It does not encrypt your budgeting data itself, and does not change anything else described in this Policy about how your financial and profile information is stored or handled.
  • If you use the “Delete All Data” feature described in Section 9, your App Lock PIN/passphrase hash and lock settings are deleted along with your other data.

4. Legal Bases for Processing (GDPR)

Because virtually all processing of your personal data occurs locally on your own device under your direct control, in most cases the App does not “process” personal data in the sense regulated by the GDPR (the developer never receives it). To the limited extent any processing by the developer occurs (e.g., responding to a support request you send us), our legal bases are:

  • Consent (Art. 6(1)(a)): where you voluntarily contact us or provide information.
  • Legitimate interests (Art. 6(1)(f)): for maintaining, securing, and improving the App, where such interests are not overridden by your rights.

We do not rely on your data to fulfill a contract requiring processing beyond what happens locally on your device, since use of the App does not require creating an account with us.

5. Third-Party Services

5.1 Currency Exchange Rate Data

To display live currency-conversion rates, the App queries a public, third-party currency exchange rate service that publishes official European Central Bank reference rates. This request:

  • Contains no personal data, device identifiers, or account information. It is a simple, anonymous request for current exchange rates.
  • Is made directly from your device to the third-party service provider over the internet (this is the sole reason the App requests internet/network access).
  • May be logged by the third-party service operator in accordance with their own privacy practices, which are outside our control. We encourage you to review that service’s own terms if you have concerns.
  • Falls back to a locally bundled, static estimate table if the network request fails or if you are offline, meaning currency conversion works even without internet access, using approximate figures.

5.2 Google Play Billing (In-App Purchase)

If you choose to complete the one-time unlock purchase described in our Terms and Conditions, that transaction is processed by Google Play Billing, a payment-processing service operated by Google. In connection with a purchase:

  • Google collects and processes your payment information (card details, billing address, etc.) directly; this information is never received, seen, or stored by us.
  • Google provides the App with a confirmation of your purchase/entitlement status (i.e., whether you have unlocked the App), which the App uses locally to determine whether to display trial/read-only functionality or full functionality.
  • Google’s own handling of your payment and account information is governed by Google’s own Privacy Policy and Google Play’s Terms of Service, which are independent of this Privacy Policy and outside our control.

5.3 No Other Third Parties

Other than the exchange-rate lookup described in Section 5.1 and Google Play Billing described in Section 5.2, the App does not integrate with, transmit data to, or embed any other third-party service, SDK, or library, including no analytics providers, no advertising networks, no crash-reporting services, and no cloud storage providers.

6. Local Backups and Data Export

6.1 Manual and Automatic Backups

The App includes an optional backup/export feature that lets you save a copy of your data (profile, bills, expenses, goals, and pay history) as a file:

  • Manual export and optional automatic backups (if you enable this feature in Settings) are written to your device’s shared Documents folder, not to any server.
  • These backup files are encrypted using a key generated and stored on your device. This protects against casual access by other apps or tools on your device, but is not a substitute for keeping your device itself secure (see Section 12). As described in Section 6.2, this key may also be included in your device’s own backup feature if you have that enabled. You may optionally add a separate passphrase to a backup for extra protection when moving it to a different device or account, as described in the App’s Settings; a passphrase-protected backup does not depend on this device-stored key at all.
  • You are solely responsible for the security of any backup file you create, including deciding whether to share it, where to store it, and whether to delete it when no longer needed.
  • The App never uploads backup files anywhere automatically; transmission only occurs if you personally choose to share, email, or upload the file yourself using your device’s own sharing tools.

6.2 Trial Marker and Backup Key Device Backup

Unlike the financial and profile data described in Section 3.1, which is never backed up off your device by the App, two small, non-identifying technical items may be included in Android’s built-in device backup feature (“Auto Backup for Apps”), if enabled on your device: the trial-start marker described in Section 3.4, and the backup-encryption key described in Section 6.1. Where enabled, this causes only those two items (never your financial or profile data, and never your App Lock PIN/passphrase hash described in Section 3.5) to be stored in your own private Google Drive account associated with your device. This data is accessible only to you through your own Google account and is not accessible to us. This mechanism exists to preserve the integrity of the free trial period, and to let your encrypted backups remain readable, if you reinstall the App on the same device and Google account. It does not involve any transmission of your financial or personal data to us, to Google, or to any other party.

7. How We Use Information

Because information you enter stays on your device, the App uses it exclusively to provide its core functionality to you: calculating budgets, tracking bills and expenses, projecting savings goals, generating local reminders, and (if you choose) producing an export/backup file. We do not use your information for advertising, profiling, analytics, resale, or any purpose other than operating the App’s features on your own device, on your own behalf.

8. Data Sharing and Disclosure

We do not sell, rent, trade, or otherwise disclose your personal or financial information to any third party, because we do not receive or hold it in the first place. We may disclose information only in the following limited, hypothetical circumstances, none of which apply to data that never reaches us:

  • To comply with a valid legal obligation, subpoena, or court order, to the extent we hold any such information (e.g., limited technical support correspondence you initiate with us).
  • To protect the rights, property, or safety of the developer, users, or the public, where permitted by law.

We have never sold personal information as defined by the CCPA/CPRA, and we do not have “actual knowledge” of any sale or sharing of personal information for cross-context behavioral advertising, because no personal information is transmitted to us to sell or share.

9. Data Retention and Deletion

  • Data you enter remains stored locally on your device for as long as you keep the App installed, or until you delete it yourself.
  • The App provides a “Delete All Data” option (Settings → Danger Zone) that permanently removes your financial and profile information from the App’s local storage. This action is irreversible.
  • The trial-start marker described in Section 3.4 is intentionally NOT deleted by “Delete All Data.” It is unrelated to your financial records and exists solely to track your free-trial entitlement, independent of your budgeting data.
  • The backup-encryption key described in Section 6.1 is also intentionally NOT deleted by “Delete All Data.” This preserves your ability to restore a backup made before you deleted your data, if you choose to.
  • Uninstalling the App removes the App’s private on-device storage. It does not automatically delete any backup files you previously exported to your device’s shared Documents folder. You must delete those separately if you no longer want them.
  • Because we never receive or retain your data on any server, there is no “developer-side” copy for us to delete upon a deletion or account-closure request. Deletion is entirely in your control, on your device.

10. Your Privacy Rights

10.1 GDPR / UK GDPR (EEA, UK, and other applicable jurisdictions)

Because your personal data (where any exists) is processed exclusively on your own device and not by us, most GDPR data-subject rights (access, rectification, erasure, restriction, and portability) are already fully exercisable by you directly within the App, at any time, without needing to contact us:

  • Right of access / portability: use the App’s Export feature to obtain a complete copy of your data at any time.
  • Right to rectification: edit any entry directly within the App.
  • Right to erasure: use the “Delete All Data” feature, or uninstall the App.
  • Right to restrict/object to processing: since no server-side processing of your personal data occurs, this right is inherently satisfied; you may also decline to enter data or disable optional features (e.g., notifications, auto-backup).

If you contact us directly (e.g., by email), any personal data you provide in that correspondence will be handled in accordance with your instructions and applicable law, and you may request access to, correction of, or deletion of that correspondence at any time by contacting us at the address in Section 1.

10.2 California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information is collected, to request deletion, to correct inaccurate information, to opt out of the sale/sharing of personal information, and to non-discrimination for exercising these rights. As described above, we do not collect, sell, or share personal information as part of the App’s core functionality. To exercise any right that may still be applicable (e.g., relating to direct correspondence with us), contact us at the address in Section 1.

10.3 Other Jurisdictions

Residents of other jurisdictions with comprehensive privacy laws (e.g., Canada/PIPEDA, Australia/Privacy Act, Brazil/LGPD, and various U.S. state privacy laws) have similarly-scoped rights of access, correction, and deletion, which (for the reasons above) are directly self-serviceable within the App. Contact us at the address in Section 1 with any additional questions specific to your jurisdiction.

11. Children’s Privacy

The App is not directed at, marketed to, or intended for use by children under the age of 13 (or the applicable minimum age in your jurisdiction, e.g., 16 in certain EEA member states). We do not knowingly collect personal information from children. Because the App does not collect personal information on any server in the first place, no server-side children’s data exists to be removed; however, if you believe a child has provided information through correspondence with us directly, contact us at the address in Section 1 and we will address it promptly.

12. Data Security

While all of your data remains on your own device rather than on servers we control (which eliminates many server-side data-breach risks), we recommend the following to protect your information:

  • Keep your device protected with a passcode, PIN, biometric lock, or equivalent.
  • Keep your device’s operating system and the App up to date.
  • Consider enabling the App’s own optional lock screen (a PIN, passphrase, or biometric unlock) in Settings for an additional layer of protection against casual access to the App itself.
  • Treat any exported/backup file as sensitive (see Section 6), and consider using the App’s optional passphrase-protection feature when exporting; store backup files securely and delete copies you no longer need.
  • Be cautious about which other apps you grant storage access to on your device, since such apps could potentially access backup files sitting in shared storage.

No method of electronic storage is 100% secure; we cannot guarantee absolute security of information stored on your device, which is outside our control.

13. International Data Transfers

Because we do not operate servers that store your personal data, there is no transfer of your personal data by us across international borders. The sole outbound network request the App itself makes (the anonymous currency-rate lookup described in Section 5.1) may be routed to servers operated by the third-party API provider, which may be located outside your country of residence; that transfer does not include any personal data. If Android’s device-backup feature is enabled on your device, the trial-start marker and backup-encryption key described in Section 6.2 may be stored on Google Drive servers, which may be located outside your country of residence as part of Google’s own infrastructure; this transfer is governed by Google’s own privacy practices and does not involve any of your financial or personal data. If you complete a purchase, your payment information is transferred to and processed by Google as described in Section 5.2, subject to Google’s own privacy practices.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the App’s functionality or in applicable law. Any changes will be reflected by an updated “Last Updated” date at the top of this document, and (for material changes) we will provide additional notice within the App where reasonably practicable. Your continued use of the App after a change becomes effective constitutes acceptance of the revised Policy.

15. Platform-Specific Disclosures

15.1 Google Play Data Safety

Consistent with Google Play’s Data Safety requirements, we disclose: the App does not collect or share any user data with third parties, other than (a) the anonymous, non-personal exchange-rate API request described in Section 5.1, which contains no personal information, and (b) purchase/payment data processed directly by Google Play Billing as described in Section 5.2, which we never receive or store. All financial and profile data described in Section 3.1 is processed on-device only and is not collected by the developer. A minimal, non-identifying trial-start date and backup-encryption key may be included in Android’s device backup feature, as described in Section 6.2. The App also requests permission to use your device’s biometric hardware solely to let you optionally unlock the App itself, as described in Section 3.5; no biometric data is ever collected, transmitted, or stored by the App or the developer.

15.2 Apple App Store Privacy Nutrition Label

Consistent with Apple’s App Privacy requirements, we disclose: no data is collected from this app by the developer.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:

support@trybento.app

Bento
About Contact Privacy Policy Terms & Conditions