Privacy policy
Last updated: 3 October 2026
BenOS is an app for macOS, made by Ben Galbraith ("we"). It copies your own data from the services you choose into a library on your Mac, so that an AI agent you choose can answer questions from it. This policy explains what BenOS does with that data. The short version: your data stays on your Mac, and we never receive it.
We don't collect your data
BenOS has no servers that hold your data, no user accounts and no analytics. It has no telemetry or crash reporting, and nothing in it reports your activity to us. We never receive, see or store your email, messages, calendar, notes, contacts or files.
Where your data is stored
Everything BenOS copies is stored on your Mac, in a folder named benos in
your home folder. Sign-in tokens for the services you add are stored in that folder,
readable only by your macOS user account. BenOS also keeps a few small settings files in
your Mac's application support folder.
What leaves your Mac, and when
BenOS only uses the network in these cases:
- The services you add. When you add a source, BenOS signs in to it and fetches your data from it: for example Google (Gmail, Google Calendar, Google Drive), WhatsApp, Todoist, Granola, Peloton or Withings. It also sends changes to them when you or your agent ask for one (see "Google user data" below). Each service sees these requests under its own privacy policy, as it does when you use the service directly.
- The agent you connect. BenOS lets an AI agent on your Mac (for example the Claude app) read your library. You choose which agents can do this. When the agent reads your data to answer you, it sends what it read to its provider (for example Anthropic) under your account with that provider and that provider's privacy policy. BenOS doesn't send your data to any AI provider by itself.
-
Optional features you set up. Some advanced features, off unless you
turn them on, use other services:
- Features that use an AI model through your own API key (for example an Anthropic API key you add) send the records they work on to that provider.
- Search can use a model on another computer you choose, instead of the default one on your Mac.
- You can pair your Macs so they keep copies of the library in sync with each other.
- iCloud files. If you add files kept in iCloud Drive, macOS may download them from iCloud so that BenOS can read them.
-
Updates. BenOS checks
benos.octo.dadfor new versions and downloads them from there. These requests carry no personal data beyond what any web request does (your IP address and the app version).
Google user data
If you add a Google account, BenOS asks Google for the permissions below. It uses them only to provide BenOS's features to you, on your Mac.
| Permission | Why BenOS asks for it |
|---|---|
Read, compose and send email, and manage labels in Gmail (gmail.modify) |
To copy your email into your library. Also to archive, label, mark as read or unread and move to trash when you or your agent ask for it. BenOS doesn't use this permission to send email. Every change is recorded, and BenOS asks for your approval before any change that can't be undone. |
See your calendars (calendar.readonly) |
To copy your calendars and events into your library. |
View and edit events (calendar.events) |
To make the event changes you or your agent ask for. Creating, deleting or replying to an event, or inviting someone, always asks for your approval first. |
See your Google Drive files (drive.readonly) |
To copy the Drive files you choose into your library. BenOS never changes Drive. |
Your email address (openid, email) |
To tell which Google account a source belongs to. |
Google data stays on your Mac. We never receive it, sell it, or use it for advertising. Neither we nor BenOS use it to train AI models. People never read it, except you. The only transfer is to the agent you connect, when you ask it to use your data. BenOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
BenOS connects to WhatsApp as a linked device on your account, like WhatsApp on the web or a desktop computer. It uses an independent client, not one made by WhatsApp. BenOS receives your messages and their media to copy them into your library. It doesn't send messages. You can see BenOS in WhatsApp under Linked devices and remove it there at any time.
Your control
- Remove a source in BenOS, and it stops fetching from that service.
- Take back BenOS's access to Google at myaccount.google.com/permissions, and to WhatsApp under Linked devices.
-
Delete everything by deleting the BenOS app and the
benosfolder in your home folder. We hold no copy, so there's nothing for us to delete.
This website
This site has no cookies and no analytics. It is hosted by Vercel, which records standard request information such as IP addresses to run and protect the service.
Children
BenOS isn't meant for children under 16.
Changes
If BenOS starts handling data differently, we'll update this page and the date at the top before the change ships.
Contact
Questions about privacy: benos@octo.dad.