Privacy Policy
Bento 1.0.0+1 (com.benopdf.scan) · Last updated: September 30, 2026
On-device only. No analytics.
As the in-app Privacy notice says: all PDF processing and scanning happens on-device — no file is ever uploaded. The release build declares no internet permission, so Bento physically cannot transmit your data.
- No uploads
- No accounts
- No analytics
- No ads or tracking
1. Overview
This policy describes how Bento — the offline-first PDF toolkit and document scanner (package com.benopdf.scan, version 1.0.0+1, Android 7.0+ and iOS 13+) — handles your information. In short: it doesn’t handle it at all. Your documents are processed locally on your phone or tablet, and Bento has no servers, no accounts and no analytics to send anything to.
2. How your documents are processed
All nine tools — Merge PDFs, Organize Pages, Extract Pages, Compress PDF, Image → PDF, PDF → Image, Protect PDF, Unlock PDF and Sign PDF — run locally through a native Rust engine over FFI, off the main thread. There is no WebView and no browser-based processing step.
Scanning uses Google ML Kit on Android and the in-app camera with native edge detection (Apple Vision on iOS, OpenCV on Android) with perspective correction and the Original / Grayscale / B&W filters. Multi-page review, reorder, rename and PDF export all happen on-device. Audio capture is disabled in the capture screen, and the camera never runs in the background.
3. What we collect — and what we don’t
Bento collects nothing by default. There is no sign-in, no analytics SDK, no advertising SDK and no usage telemetry of any kind. The single exception is optional crash reporting (Sentry): it is off by default and sends fatal-error reports only if you turn on Settings → Privacy → “Send crash reports”. The app does not read your contacts, messages, location or call history.
Your preferences — theme choice and save-folder choice — are stored in the app’s private on-device settings and are never synced anywhere. If you email us, we receive only what you choose to include in that message, and we use it solely to reply.
4. Permissions the app requests
| Permission | When it’s asked for | Why |
|---|---|---|
| Camera (Android & iOS) | Only when you open the Scan tab | Capturing pages. iOS prompt: “Camera access is required to scan documents.” Never used in the background; audio capture is off. |
| Photos / media library (iOS) | When you pick images for Image → PDF | Reading only the images you choose. iOS prompt: “Photo library access is required to pick images for Image to PDF.” |
| Files & storage (Android) | When you pick files or save results | Opening documents you select and writing results to Documents/Bento (or your chosen folder). Android 11+ uses all-files access for this; photo, video, audio and music library permissions are stripped from the release build. |
| Network | Crash reports only, and only if you opt in | Release builds declare INTERNET solely for Sentry crash reporting, which is off by default and sends only when you enable “Send crash reports” in Settings → Privacy — no documents, file names or contents are ever sent. Reports are queued offline and uploaded when connectivity returns; switching it off stops all sending. Audio-recording permission is removed. |
5. Where your files live
Results are written to Documents/Bento by default, or to any folder you pick in Settings. The Files tab is a local browser over those folders: opening, sharing, sending to another tool, viewing details or deleting a file all act on the copy stored on your device. Deleting a file in Bento deletes that local copy.
6. What can leave your device (only by your hand)
The only way a document leaves your device is through an action you explicitly take: the system Share sheet, “Open with…” another app, or handing a scanned PDF to another on-device tool such as Compress or Sign. These are operating-system handoffs you trigger — Bento itself initiates no transfer.
7. Passwords and encryption
Protect PDF secures documents with AES-256 encryption. A password you type for Protect or Unlock exists only in the app’s memory for the duration of that operation: it is never saved by the app and never sent anywhere (crash reports contain no document data). Because there is no server and no backdoor, a forgotten password cannot be recovered by us — keep it somewhere safe.
8. Third-party components
Bento runs entirely on-device using trusted built-in components. No document data is shared with third parties.
| Component | Role in the app |
|---|---|
| PDF engine | Native Rust PDF engine (merge, split, organize, compress, encrypt, render) |
| Document scanner | Native document scanner (Android) |
| Scan pipeline | Scan capture, perspective crop and Original / Grayscale / B&W filters |
9. Children’s privacy
Bento collects no personal information from anyone, including children. The app contains no ads, no purchases, no chat and no social features.
10. Changes to this policy
When features change — for example, new tools or permission needs — this page will be updated with a new date, and material changes will be noted in the app’s release notes.
11. Contact
Questions about this policy or about privacy in Bento? Email [email protected].