Legal
Privacy, without the fog.
This policy explains what bento.surf collects, why we use it, and the controls available to creators, customers, and visitors.
Last updated August 26, 2026
Information we collect
We collect the account information you provide, such as your email address, profile details, page content, uploaded files, products, and preferences.
When you connect a third-party service, we receive the account identifiers, permissions, and access tokens needed to provide the integration. Tokens are encrypted and are not shown to other users.
We collect product-usage, device, referral, and approximate location information to operate the service, prevent abuse, and provide analytics. Payment providers process payment credentials; bento.surf does not store full card or bank details.
Instagram automation data
If a creator enables Instagram Auto-DM, Meta sends comment or message events to bento.surf so the creator's chosen rule can be evaluated and a reply can be sent.
The automation service does not retain the raw comment or direct-message text. It stores limited delivery metadata, such as the Instagram account, event type, media identifier, delivery status, timestamps, and a keyed hash of the sender identifier, to prevent duplicate replies and show activity history.
Creators control their own rules and can pause them, delete them, or disconnect Instagram at any time. Meta's own terms and privacy policy also apply to Instagram activity.
Free tools and AI processing
Exact utilities such as counters, formatters, campaign-link builders, and image tools run in your browser. The text or image you enter into those tools is not uploaded to bento.surf unless the tool clearly says it uses AI.
When you press Generate on an AI writing tool, the details you entered are sent through bento.surf to a configured model provider, currently Cloudflare Workers AI or Groq, only to produce the requested result. bento.surf does not store that prompt or result as tool content or send it to PostHog product analytics.
When you submit a public YouTube, Instagram, TikTok, or X media URL, bento.surf sends that URL and your requested operation to its media-processing infrastructure and providers only after you confirm that you own the media, have permission to use it, or have a suitable license. These tools do not sign in to a social account or bypass private or restricted content.
Media files are streamed through temporary provider links that expire shortly. bento.surf does not save downloaded media or URL-generated transcripts as account content. Infrastructure and providers may process limited request, security, performance, and abuse-prevention metadata under their own data terms.
We record limited operational metadata such as the tool used, provider, input character count, output count, latency, and success or failure. Model providers process submitted text under their own data terms; where provider controls are available, prompt logging and response caching are disabled.
X automation data
If a creator enables X Auto-DM, X sends inbound direct-message, mention, like, or repost events to bento.surf so the creator's chosen rule can be evaluated and a reply can be sent.
The automation service does not retain the raw direct-message or mention text. It stores limited delivery metadata, such as the X account, event type, delivery status, timestamps, and a keyed hash of the sender identifier, to prevent duplicate replies and show activity history.
Creators control their own rules and can pause them, delete them, or disconnect X at any time. X's own terms and privacy policy also apply to X activity.
Reddit data
If a creator connects Reddit, we store the encrypted OAuth tokens needed to publish on their behalf, their Reddit username and display name, communities they choose when composing a post, and the post identifiers, URLs, and delivery status for posts they authored in the scheduler.
We do not store Reddit comment trees, vote graphs, or other users' content. We do not sell, license, or share Reddit data, and we do not use Reddit content to train machine-learning or AI models. Transient API responses are used only to complete the request and are discarded; unused Reddit API payloads are not retained beyond 48 hours.
Disconnecting Reddit or deleting a bento.surf account removes the tokens and Reddit connection records. Creators can also revoke bento.surf from Reddit's authorized-application settings. Reddit's own terms and privacy policy also apply.
Facebook automation data
If a creator enables Facebook Auto-DM, Meta sends Page comment or Messenger events to bento.surf so the creator's chosen rule can be evaluated and a reply can be sent.
The automation service does not retain the raw comment or Messenger text. It stores limited delivery metadata, such as the Facebook Page, event type, media identifier, delivery status, timestamps, and a keyed hash of the sender identifier, to prevent duplicate replies and show activity history.
Creators control their own rules and can pause them, delete them, or disconnect Facebook at any time. Meta's own terms and privacy policy also apply to Facebook activity.
How we use information
We use information to provide and secure bento.surf, publish creator pages, deliver purchased content, run integrations and automations, communicate about the service, support users, analyze performance, and comply with legal obligations.
We do not sell personal information. We do not use connected social-account data for unrelated advertising.
Service providers and sharing
We share only what is necessary with infrastructure, database, storage, email, analytics, fraud-prevention, AI, social-network, and payment providers that help us operate the service. These currently include Cloudflare, Supabase, Resend, PostHog, Groq when its AI fallback is configured, and the services a user chooses to connect.
We may disclose information when required by law, to protect users or the service, or as part of a business transaction with appropriate safeguards.
Retention, security, and your choices
We retain information only as long as it is needed for the service, security, accounting, dispute resolution, or legal requirements. We use access controls, encryption, signed webhooks, and other safeguards, but no online service can guarantee absolute security.
You can update your profile and preferences, disconnect integrations, or delete your account from bento.surf settings. You may also contact us to request access, correction, export, or deletion, subject to applicable law.
International use and children
bento.surf and its service providers may process information in countries other than your own. We use appropriate safeguards where required.
The service is not directed to children under 13, and users must meet the minimum age required in their country to use the service and enter binding agreements.
Changes and contact
We may update this policy as the product or legal requirements change. We will post the revised date here and provide additional notice when required.
Questions or privacy requests can be sent to bizibeast@gmail.com.