Legal
Privacy, without the fog.
This policy explains what bento.surf collects, why we use it, and the controls available to creators, customers, and visitors.
Last updated August 14, 2026
Information we collect
We collect the account information you provide, such as your email address, profile details, page content, uploaded files, products, and preferences.
When you connect a third-party service, we receive the account identifiers, permissions, and access tokens needed to provide the integration. Tokens are encrypted and are not shown to other users.
We collect product-usage, device, referral, and approximate location information to operate the service, prevent abuse, and provide analytics. Payment providers process payment credentials; bento.surf does not store full card or bank details.
Instagram automation data
If a creator enables Instagram Auto-DM, Meta sends comment or message events to bento.surf so the creator's chosen rule can be evaluated and a reply can be sent.
The automation service does not retain the raw comment or direct-message text. It stores limited delivery metadata, such as the Instagram account, event type, media identifier, delivery status, timestamps, and a keyed hash of the sender identifier, to prevent duplicate replies and show activity history.
Creators control their own rules and can pause them, delete them, or disconnect Instagram at any time. Meta's own terms and privacy policy also apply to Instagram activity.
X automation data
If a creator enables X Auto-DM, X sends inbound direct-message, mention, like, or repost events to bento.surf so the creator's chosen rule can be evaluated and a reply can be sent.
The automation service does not retain the raw direct-message or mention text. It stores limited delivery metadata, such as the X account, event type, delivery status, timestamps, and a keyed hash of the sender identifier, to prevent duplicate replies and show activity history.
Creators control their own rules and can pause them, delete them, or disconnect X at any time. X's own terms and privacy policy also apply to X activity.
Reddit data
If a creator connects Reddit, we store the encrypted OAuth tokens needed to publish on their behalf, their Reddit username and display name, communities they choose when composing a post, and the post identifiers, URLs, and delivery status for posts they authored in the scheduler.
We do not store Reddit comment trees, vote graphs, or other users' content. We do not sell, license, or share Reddit data, and we do not use Reddit content to train machine-learning or AI models. Transient API responses are used only to complete the request and are discarded; unused Reddit API payloads are not retained beyond 48 hours.
Disconnecting Reddit or deleting a bento.surf account removes the tokens and Reddit connection records. Creators can also revoke bento.surf from Reddit's authorized-application settings. Reddit's own terms and privacy policy also apply.
Facebook automation data
If a creator enables Facebook Auto-DM, Meta sends Page comment or Messenger events to bento.surf so the creator's chosen rule can be evaluated and a reply can be sent.
The automation service does not retain the raw comment or Messenger text. It stores limited delivery metadata, such as the Facebook Page, event type, media identifier, delivery status, timestamps, and a keyed hash of the sender identifier, to prevent duplicate replies and show activity history.
Creators control their own rules and can pause them, delete them, or disconnect Facebook at any time. Meta's own terms and privacy policy also apply to Facebook activity.
How we use information
We use information to provide and secure bento.surf, publish creator pages, deliver purchased content, run integrations and automations, communicate about the service, support users, analyze performance, and comply with legal obligations.
We do not sell personal information. We do not use connected social-account data for unrelated advertising.
Service providers and sharing
We share only what is necessary with infrastructure, database, storage, email, analytics, fraud-prevention, social-network, and payment providers that help us operate the service. These currently include Cloudflare, Supabase, Resend, PostHog, and the services a user chooses to connect.
We may disclose information when required by law, to protect users or the service, or as part of a business transaction with appropriate safeguards.
Retention, security, and your choices
We retain information only as long as it is needed for the service, security, accounting, dispute resolution, or legal requirements. We use access controls, encryption, signed webhooks, and other safeguards, but no online service can guarantee absolute security.
You can update your profile and preferences, disconnect integrations, or delete your account from bento.surf settings. You may also contact us to request access, correction, export, or deletion, subject to applicable law.
International use and children
bento.surf and its service providers may process information in countries other than your own. We use appropriate safeguards where required.
The service is not directed to children under 13, and users must meet the minimum age required in their country to use the service and enter binding agreements.
Changes and contact
We may update this policy as the product or legal requirements change. We will post the revised date here and provide additional notice when required.
Questions or privacy requests can be sent to bizibeast@gmail.com.