Benmore Technologies ("Benmore", "we") runs benmore.ai: the dashboard, the benmore command-line tool, the MCP server that AI assistants connect to, the hosted apps people build on the platform, and the client portal Benmore's agency clients use. This policy describes what we collect and how we handle it in each of those.
If you build an app on the platform, you decide what your app collects from its own users, and you are the controller of that data. We store and process it on your behalf, as described in section 4.
With your email and password followed by a 6-digit code we email you, or with Google. The CLI signs in through your browser and keeps its token in a file on your computer that only you can read. AI assistants such as Claude, ChatGPT or Cursor connect through an OAuth consent screen; what you send them is governed by your own terms with them.
Sign-in codes, email verification, password reset, email-change confirmations, collaborator invitations, ownership transfers, custom-domain status, notices when an app's email sending is paused, waitlist confirmations, and (for portal clients) unread-message reminders. If you subscribe to updates we send a confirmation email first, and every message has a one-click unsubscribe. We keep an address on a suppression list if mail to it bounces or is marked as spam.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-benmore_session | Keeps you signed in (HttpOnly, Secure, SameSite=Lax) | 30 days |
_benmore_otp_uid, _benmore_mfa_uid, _oauth_state, _oauth_pkce, _oauth_nonce | Carry a sign-in in progress between steps | 5 to 10 minutes |
bm_cookie_consent | Remembers whether you accepted or declined first-party analytics | 1 year |
_bm_vid | First-party analytics visitor ID, set only after you click Accept | 1 year |
Google Analytics (_ga and related) | Google Analytics 4, set by Google only after you click Accept | Set by Google; removed if you decline |
Both kinds of analytics start only after you click Accept on the cookie banner; nothing is recorded if you decline or ignore it. Our own analytics records page views, referrer, device, browser, operating system and country, and, when you are signed in, your account ID; it stores no IP address. Google Analytics, on benmore.ai pages including the dashboard and client portal, sends Google your IP address, browser details and the pages you visit. You can change your choice at any time from "Cookie settings" in the footer; declining stops Google Analytics and removes its cookies. Fonts are served from our own server, not from Google.
Once a day, in an interactive terminal, the CLI asks GitHub whether a newer release exists (turn off with BENMORE_NO_UPDATE_CHECK=1). The CLI also reports agent usage by default. It reads your local Claude Code and Codex session logs and uploads, for each run, the app, provider, model, outcome, timestamps, duration and token counts. It never uploads prompts, code, transcripts or file paths. We keep per-run detail for 30 days, then only monthly totals. Turn it off with benmore telemetry off or BENMORE_TELEMETRY=0.
Benmore's agency clients use the portal to follow their projects. It holds project details and contract values, chat messages (including messages mirrored from the project's Slack channel), files, tickets and comments, deliverables and questions, meeting records with full transcripts, invoices, recorded voice briefs and their transcripts, reactions and read receipts, and API keys a client chooses to share with us. Those keys are encrypted and visible only to Benmore administrators, and each read is logged.
Each app has its own database on our server, plus its uploaded files and source history. We access an app's data only to run, back up and show it to its owner, when the owner asks for support, when legally required, or to investigate abuse or a security incident. By default the platform also keeps, inside each app:
Email an app sends through the platform goes through Amazon SES, and SMS through AWS End User Messaging. We keep the recipient and subject of each email, and the recipient of each SMS, for 30 days, and keep bounced or complaining addresses on a suppression list. Uploaded files are stored in Amazon S3 and served through Amazon CloudFront. Real-time audio and video are relayed by Cloudflare, and visitors' browsers also contact Google's STUN servers to set up the connection. If an app uses platform-provided Google sign-in, the sign-in passes through Benmore's Google account and the visitor's email and name are handed to the app. If an app owner connects Stripe, payments run under the owner's own Stripe account. Pastes are stored in our database and served at edge-<name>.benmoreusercontent.com, publicly or behind a password, with a view count.
When our automated browser checks test an app, we keep a recording of the browser session: the 200 most recent, plus any a user has shared, until deleted.
| Provider | What they handle | Why |
|---|---|---|
| Amazon Web Services (us-east-1) | The server everything runs on (EC2), backups and uploaded files (S3), file delivery (CloudFront), email (SES), SMS (End User Messaging), DNS for domains you have us manage (Route 53), server monitoring | Hosting and delivery |
| Cloudflare | All traffic to benmore.ai, hosted apps and pastes (including IP addresses and request contents), DNS, TLS for custom domains, real-time audio and video relay, and (when enabled) bot checks on the waitlist form | Network, security and real-time media |
| Google Analytics on benmore.ai pages (after you accept cookies), Google sign-in (for benmore.ai and for apps using platform sign-in), and STUN for real-time calls | Analytics and sign-in | |
| Stripe | Payment details, billing email and subscription for benmore.ai plans; payments in apps whose owners connect Stripe | Payments |
| Anthropic | Client portal content for AI processing (section 3), and portal content our staff work with through Claude | Project automation |
| Slack | Messages in client projects' Slack channels, and portal messages posted back to them | Client portal |
| Fireflies.ai | Recordings and transcripts of client project meetings | Client portal |
| GitHub | App source and history, when you link a repository; the CLI's daily update check | Source mirroring |
| Let's Encrypt | Custom domain names, when a certificate is issued on our server rather than by Cloudflare | Certificates |
| AI assistants you connect (Claude, ChatGPT, Cursor and others) | Whatever you ask them to read or change through MCP | Your choice, under your terms with them |
| Services an app calls with its own keys | Whatever the app sends them | The app owner's choice, under their terms |
Your account, apps, databases, uploaded files and backups are on a single server and in storage in AWS us-east-1 (Northern Virginia, USA). Cloudflare, Google, Stripe, Slack, Anthropic, Fireflies.ai and GitHub process data in their own locations, mostly in the United States. If you are outside the United States, using the Service means your data is transferred to and processed in the U.S.
| Data | Kept |
|---|---|
| Account, apps and portal content | Until you ask us to delete them |
| Sessions; MCP connection tokens | 30 days |
| Sign-in codes; reset and verification links; failed sign-in counts | 10 minutes; 1 hour; 1 hour |
| Server logs | 7 days |
| App request logs; app analytics | Last 5,000 requests; last 50,000 events per app |
| App error reports and audit logs | Until the app is deleted |
| Email and SMS send records | 30 days; suppression list indefinitely |
| CLI agent usage | 30 days per run, then monthly totals |
| Database backups | Production apps only, hourly. All from the last 24 hours, one a day for 7 days, one a week for 30 days; pre-deploy copies 7 days. Deleted backups stay recoverable in versioned storage for 90 more days. Copies taken during platform releases stay on the server until we clear them. |
| Point-in-time recovery data (apps that enable it) | 7 days, plus the latest copy |
| Billing records | As long as tax and audit law requires (typically 7 years) |
Deleting an app stops it and removes its database, files on the server and source history at once. Its backups expire on the schedule above. Its uploaded media, pastes and saved environment variables are not removed automatically; ask us and we will delete them.
Before July 23, 2026, Benmore offered a hosted builder that stored chat messages, model-usage measurements, credit-ledger entries, and attachment metadata and private attachment objects. That builder is retired and no active interface shows these records. Its chat messages are deleted when the associated app is deleted. Attachment files expire from storage after 7 days, and unattached uploads are cleaned up after 24 hours. Usage and credit-ledger records are kept for billing, security and audit purposes.
benmore pull downloads an app's source. Each app's GET /api/_my-data exports the signed-in user's own records in that app. For a copy of your account records, email us.Traffic is encrypted in transit (HSTS). Pages use a content security policy, and cookies are HttpOnly and Secure. Passwords are hashed with bcrypt, and tokens and session IDs are stored as hashes. Environment variables are encrypted in our database with AES-256-GCM and written to a file on the server that only the app's process and the platform can read. Each app runs under its own operating-system user. Fields an app declares as encrypted are encrypted with AES-GCM; the rest of an app's database is a plain SQLite file on the server. Backups in S3 are encrypted. Stripe webhooks are signature-checked. The platform has been reviewed internally but not audited by an independent third party. No system is perfectly secure. Report vulnerabilities to [email protected]; we respond within 72 hours.
The Service is not for anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact [email protected] and we will delete it.
If we make material changes to this policy we will email the address on your account and post a banner on the dashboard at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
Privacy questions or requests: [email protected]. Security disclosures: [email protected].