Privacy Policy

Last updated: September 25, 2026. We do not sell your data, we do not share it with advertisers, and we do not use it to train AI models.

1. Who we are and what this covers

Benmore Technologies ("Benmore", "we") runs benmore.ai: the dashboard, the benmore command-line tool, the MCP server that AI assistants connect to, the hosted apps people build on the platform, and the client portal Benmore's agency clients use. This policy describes what we collect and how we handle it in each of those.

If you build an app on the platform, you decide what your app collects from its own users, and you are the controller of that data. We store and process it on your behalf, as described in section 4.

2. Your benmore.ai account

a. What we store

  • Profile: email address, first and last name, company (if you add it), plan, signup date and last sign-in.
  • Credentials: a bcrypt hash of your password (none if you only use Google sign-in). CLI tokens, MCP connection tokens, API tokens, session tokens and password-reset links are stored as hashes, never in readable form. Emailed sign-in codes are stored for 10 minutes. If you sign in with Google we receive your email and name, and store the access tokens Google returns.
  • Sessions: each signed-in session records the IP address and browser user agent it started from. You can see your own sessions in your account. Sessions last 30 days.
  • Sign-in protection: failed sign-ins are counted by email and by IP address for one hour, to lock out password guessing.
  • Connected tools: the AI assistants and other clients you have allowed to use your account over MCP, until you revoke them.
  • GitHub: if you link GitHub to mirror an app's source, your GitHub username and an encrypted access token.
  • Usage: active build time per app, which documentation topics you have read through the MCP tools, and, if you use the CLI, agent usage figures (section 2e).
  • Billing: if you upgrade, Stripe handles the payment. We store your Stripe customer and subscription IDs, subscription status and renewal date. We never see or store your card number, expiry or CVC.

b. How you sign in

With your email and password followed by a 6-digit code we email you, or with Google. The CLI signs in through your browser and keeps its token in a file on your computer that only you can read. AI assistants such as Claude, ChatGPT or Cursor connect through an OAuth consent screen; what you send them is governed by your own terms with them.

c. Email we send

Sign-in codes, email verification, password reset, email-change confirmations, collaborator invitations, ownership transfers, custom-domain status, notices when an app's email sending is paused, waitlist confirmations, and (for portal clients) unread-message reminders. If you subscribe to updates we send a confirmation email first, and every message has a one-click unsubscribe. We keep an address on a suppression list if mail to it bounces or is marked as spam.

d. Cookies and analytics on benmore.ai

CookiePurposeLifetime
__Host-benmore_sessionKeeps you signed in (HttpOnly, Secure, SameSite=Lax)30 days
_benmore_otp_uid, _benmore_mfa_uid, _oauth_state, _oauth_pkce, _oauth_nonceCarry a sign-in in progress between steps5 to 10 minutes
bm_cookie_consentRemembers whether you accepted or declined first-party analytics1 year
_bm_vidFirst-party analytics visitor ID, set only after you click Accept1 year
Google Analytics (_ga and related)Google Analytics 4, set by Google only after you click AcceptSet by Google; removed if you decline

Both kinds of analytics start only after you click Accept on the cookie banner; nothing is recorded if you decline or ignore it. Our own analytics records page views, referrer, device, browser, operating system and country, and, when you are signed in, your account ID; it stores no IP address. Google Analytics, on benmore.ai pages including the dashboard and client portal, sends Google your IP address, browser details and the pages you visit. You can change your choice at any time from "Cookie settings" in the footer; declining stops Google Analytics and removes its cookies. Fonts are served from our own server, not from Google.

e. The CLI

Once a day, in an interactive terminal, the CLI asks GitHub whether a newer release exists (turn off with BENMORE_NO_UPDATE_CHECK=1). The CLI also reports agent usage by default. It reads your local Claude Code and Codex session logs and uploads, for each run, the app, provider, model, outcome, timestamps, duration and token counts. It never uploads prompts, code, transcripts or file paths. We keep per-run detail for 30 days, then only monthly totals. Turn it off with benmore telemetry off or BENMORE_TELEMETRY=0.

3. The client portal

Benmore's agency clients use the portal to follow their projects. It holds project details and contract values, chat messages (including messages mirrored from the project's Slack channel), files, tickets and comments, deliverables and questions, meeting records with full transcripts, invoices, recorded voice briefs and their transcripts, reactions and read receipts, and API keys a client chooses to share with us. Those keys are encrypted and visible only to Benmore administrators, and each read is logged.

  • Where it comes from: what you and our team enter in the portal; the project's Slack channel, through Slack's API; and meeting records and invoices from our project system at client.benmore.tech, whose transcripts are recorded by our meeting notetaker, Fireflies.ai.
  • AI processing: every 6 hours we send each project's new meeting transcripts, Slack messages, agreement text, existing ticket and deliverable text, and a summary of contract and invoice amounts to Anthropic's Claude, using Benmore's own Anthropic account. It extracts action items, decisions and questions, and updates the project board. Credentials and API keys are removed from meeting and Slack text before it is sent. Names, email addresses and other content are not. Items drawn from meetings and Slack are held for 4 hours so our team can remove them before clients see them. Voice briefs are transcribed on our own server and are not sent to a third party.
  • Who can see it: the client accounts on the project and Benmore staff on it. Staff also work with portal content through AI coding assistants (Anthropic's Claude), using tools that require an explicit instruction for each operation.
  • How long: portal content is kept for the life of the project; nothing deletes it on a schedule. Ask us to delete it (section 8).

4. Apps built on the platform

Each app has its own database on our server, plus its uploaded files and source history. We access an app's data only to run, back up and show it to its owner, when the owner asks for support, when legally required, or to investigate abuse or a security incident. By default the platform also keeps, inside each app:

  • Request log: the last 5,000 requests, with method, path, status, IP address, user agent and the signed-in user's email.
  • Error reports from the app's pages, with IP address and user agent, until the app is deleted.
  • Sessions with IP address and user agent, sign-in attempts for one hour, and an audit log of every change made through the app's API, kept until the app is deleted.
  • Analytics: the same first-party analytics as benmore.ai, only after a visitor accepts the app's cookie banner, keeping the last 50,000 events.
  • Visitor feedback (name, email, page, message, screenshot) when the app turns it on.

Email an app sends through the platform goes through Amazon SES, and SMS through AWS End User Messaging. We keep the recipient and subject of each email, and the recipient of each SMS, for 30 days, and keep bounced or complaining addresses on a suppression list. Uploaded files are stored in Amazon S3 and served through Amazon CloudFront. Real-time audio and video are relayed by Cloudflare, and visitors' browsers also contact Google's STUN servers to set up the connection. If an app uses platform-provided Google sign-in, the sign-in passes through Benmore's Google account and the visitor's email and name are handed to the app. If an app owner connects Stripe, payments run under the owner's own Stripe account. Pastes are stored in our database and served at edge-<name>.benmoreusercontent.com, publicly or behind a password, with a view count.

When our automated browser checks test an app, we keep a recording of the browser session: the 200 most recent, plus any a user has shared, until deleted.

5. Who else processes data

ProviderWhat they handleWhy
Amazon Web Services (us-east-1)The server everything runs on (EC2), backups and uploaded files (S3), file delivery (CloudFront), email (SES), SMS (End User Messaging), DNS for domains you have us manage (Route 53), server monitoringHosting and delivery
CloudflareAll traffic to benmore.ai, hosted apps and pastes (including IP addresses and request contents), DNS, TLS for custom domains, real-time audio and video relay, and (when enabled) bot checks on the waitlist formNetwork, security and real-time media
GoogleGoogle Analytics on benmore.ai pages (after you accept cookies), Google sign-in (for benmore.ai and for apps using platform sign-in), and STUN for real-time callsAnalytics and sign-in
StripePayment details, billing email and subscription for benmore.ai plans; payments in apps whose owners connect StripePayments
AnthropicClient portal content for AI processing (section 3), and portal content our staff work with through ClaudeProject automation
SlackMessages in client projects' Slack channels, and portal messages posted back to themClient portal
Fireflies.aiRecordings and transcripts of client project meetingsClient portal
GitHubApp source and history, when you link a repository; the CLI's daily update checkSource mirroring
Let's EncryptCustom domain names, when a certificate is issued on our server rather than by CloudflareCertificates
AI assistants you connect (Claude, ChatGPT, Cursor and others)Whatever you ask them to read or change through MCPYour choice, under your terms with them
Services an app calls with its own keysWhatever the app sends themThe app owner's choice, under their terms

6. Where data lives

Your account, apps, databases, uploaded files and backups are on a single server and in storage in AWS us-east-1 (Northern Virginia, USA). Cloudflare, Google, Stripe, Slack, Anthropic, Fireflies.ai and GitHub process data in their own locations, mostly in the United States. If you are outside the United States, using the Service means your data is transferred to and processed in the U.S.

7. How long we keep it

DataKept
Account, apps and portal contentUntil you ask us to delete them
Sessions; MCP connection tokens30 days
Sign-in codes; reset and verification links; failed sign-in counts10 minutes; 1 hour; 1 hour
Server logs7 days
App request logs; app analyticsLast 5,000 requests; last 50,000 events per app
App error reports and audit logsUntil the app is deleted
Email and SMS send records30 days; suppression list indefinitely
CLI agent usage30 days per run, then monthly totals
Database backupsProduction apps only, hourly. All from the last 24 hours, one a day for 7 days, one a week for 30 days; pre-deploy copies 7 days. Deleted backups stay recoverable in versioned storage for 90 more days. Copies taken during platform releases stay on the server until we clear them.
Point-in-time recovery data (apps that enable it)7 days, plus the latest copy
Billing recordsAs long as tax and audit law requires (typically 7 years)

Deleting an app stops it and removes its database, files on the server and source history at once. Its backups expire on the schedule above. Its uploaded media, pastes and saved environment variables are not removed automatically; ask us and we will delete them.

Legacy hosted-builder records

Before July 23, 2026, Benmore offered a hosted builder that stored chat messages, model-usage measurements, credit-ledger entries, and attachment metadata and private attachment objects. That builder is retired and no active interface shows these records. Its chat messages are deleted when the associated app is deleted. Attachment files expire from storage after 7 days, and unattached uploads are cleaned up after 24 hours. Usage and credit-ledger records are kept for billing, security and audit purposes.

8. Your rights and requests

  • Access and export: the dashboard shows your apps and their data. An app's editors can download its latest production backup. benmore pull downloads an app's source. Each app's GET /api/_my-data exports the signed-in user's own records in that app. For a copy of your account records, email us.
  • Deletion: there is no self-serve account deletion yet. Email [email protected] (the dashboard's Delete account button points to [email protected], which also works). We confirm within 3 business days and delete your account, apps, portal content and linked records within 30 days, except what law requires us to keep. Backups expire on the schedule in section 7.
  • Correction: edit your name and company in your profile. To change your email address, contact us.
  • Opt-outs: decline the cookie banner or change your choice under "Cookie settings" (our analytics and Google Analytics), turn off CLI telemetry (section 2e), unsubscribe from updates, and revoke connected tools in your account.
  • GDPR, UK GDPR, CCPA: if you are in the EEA, the UK or California, you can also object to processing, ask for a portable export, and complain to your data protection authority. We are the controller for account and portal data; app owners are the controllers for their apps' end-user data.

9. Security

Traffic is encrypted in transit (HSTS). Pages use a content security policy, and cookies are HttpOnly and Secure. Passwords are hashed with bcrypt, and tokens and session IDs are stored as hashes. Environment variables are encrypted in our database with AES-256-GCM and written to a file on the server that only the app's process and the platform can read. Each app runs under its own operating-system user. Fields an app declares as encrypted are encrypted with AES-GCM; the rest of an app's database is a plain SQLite file on the server. Backups in S3 are encrypted. Stripe webhooks are signature-checked. The platform has been reviewed internally but not audited by an independent third party. No system is perfectly secure. Report vulnerabilities to [email protected]; we respond within 72 hours.

10. Children

The Service is not for anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact [email protected] and we will delete it.

11. Changes to this policy

If we make material changes to this policy we will email the address on your account and post a banner on the dashboard at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

12. Contact

Privacy questions or requests: [email protected]. Security disclosures: [email protected].