Privacy policy — Bento Records
Effective 27 July 2026 · Last updated 27 July 2026
Bento Records collects no data. It has no user accounts, no analytics, no advertising, no third-party services, and no server. Everything you enter stays on your Mac.
What data the app handles
Bento Records is a record-keeping tool for independent practitioners. You use it to store the information you choose to record about the people you see — typically names, contact details, dates, and your own clinical notes — together with any files you attach yourself.
You decide what fields exist. Bento Records ships no fixed set of fields: you build the record layout when you first import your data, and you can rename, hide, add or delete fields at any time.
Where that data is stored
Exclusively on your Mac, inside the app's own sandbox container:
~/Library/Containers/com.quenet.bento/Data/Library/Application Support/Bento/
That folder holds your database (Bento.store), your form layout
and value lists (Settings.json), automatic local backups (the 30
most recent), and any files you have attached to a consultation.
Nothing is copied anywhere else. There is no cloud storage, no synchronisation service and no remote backup.
What the app sends over the internet
Nothing, and it cannot.
Bento Records runs in Apple's App Sandbox and is deliberately built
without the network entitlements
(com.apple.security.network.client and
.network.server). On macOS, an app without those entitlements is
prevented by the operating system from making network connections. This is not a
policy choice that could be quietly reversed in an update — it is a property of
the signed application, and anyone can inspect it:
codesign -d --entitlements - /Applications/Bento.app
There is therefore no telemetry, no crash reporting, no analytics, no licence check and no update check.
What the developer can see
Nothing. No data reaches the developer, because no data leaves your Mac. The developer cannot read, recover or delete your records, and cannot tell whether you use the app at all.
Files you open and save
When you import records or export a PDF, macOS shows you a standard open or save panel. The app can read or write only the file you select there. It has no access to the rest of your disk.
Data protection responsibilities
Because your records never leave your Mac, the developer is neither a controller nor a processor of them. Under the GDPR and comparable regimes, you — the practitioner — remain the data controller for the information you record about the people you see, exactly as you would with a paper file or a local spreadsheet. Your professional obligations regarding consent, retention, confidentiality and subject access requests are unchanged by using this app.
Practical consequences worth knowing:
- Backups are your responsibility. The app keeps 30 local backups beside its database, which protects against its own mistakes — not against a lost, stolen, failed or wiped Mac. Use an encrypted backup such as Time Machine, and enable FileVault.
- Deleting the app deletes the data. Removing Bento Records removes its container, and with it your records and their local backups. Export first if you want to keep them.
- Export produces an unencrypted file. The
.bentoarchiveand PDF files the app writes are ordinary readable files. Treat them with the same care as the records themselves.
Children
Bento Records is a professional tool, not directed at children and not intended for their use. Practitioners may of course record information about patients who are minors; that information is handled exactly like any other, stays on the practitioner's Mac, and remains the practitioner's responsibility as controller.
What this app is not
Bento Records keeps records. It provides no diagnosis, no treatment recommendation and no clinical decision support of any kind, and it must not be relied on for those purposes.
Changes to this policy
If a future version of Bento Records changes how data is handled — in particular, if it ever gains network access — this policy will be updated before that version is released, and the effective date above will change.