Conversation privacy
A plain-English record of what the agent stores, why it is stored and what remains under your control.
What is collected
When you use text or voice, Benaiah.ai records the conversation, selected model and creation mode, timestamps, approximate request metadata, latency, token usage, errors and any tool or artifact events generated by the service.
If you create a Benaiah profile, the service stores a random profile identifier, the public half of your passkey, plan and billing identifiers, usage records and the conversation history you choose to sync. Your biometric data and device PIN never leave your device. Email is collected by Stripe during checkout and may then be associated with your Benaiah profile for receipts, billing support and account display.
Why it is collected
Operational records are used to provide the conversation, investigate failures, protect the service, monitor cost and quality, and review whether the agent responded appropriately.
Website analytics
Public Benaiah pages record page visits, approximate location derived from the network address, device and viewport information, referring page, named buttons and links selected, sections viewed, scroll milestones and time spent. This is used to understand where visitors engage or leave and to improve the product. The tracker does not record text entered into chats or forms, filenames, payment details or credentials.
Signed-in product operations
For signed-in profiles, Benaiah also keeps a private operational record of account creation, login, subscription and allowance state, conversation channel, success, failure and latency, and whether core features such as chat, voice, files, connections and tasks succeeded or failed. For Tasks, the console also shows the task title, status, cadence, permission mode and next run so allowance, scheduling and support issues can be managed. These records are linked through a pseudonymous internal profile identifier.
This operational layer does not copy message text, voice transcripts, filenames, file contents, email or calendar contents, connector credentials, or payment-card details into the people directory. Detailed product events are automatically removed after 90 days. Access is restricted to an explicit operator allowlist and sensitive record views are audited.
Optional improvement use
Help improve Benaiah is off by default. A signed-in user can enable it under Settings → Personalisation. From that point, future text, voice and website-building conversations may be automatically redacted and placed in a separate, operator-only Research Library for human review, evaluations, prompt improvement or possible future model training. No candidate is automatically used for training merely because it entered the library.
The service records when consent was granted and which notice was shown. Turning the setting off stops future Research Library capture and removes that profile’s pending candidates. A person may also request removal of reviewed candidates; where a candidate has already been incorporated into an evaluation or model-development process, Benaiah will assess and explain what can technically and legally be removed.
Contributor models
Auto High, the default in-app Auto level, may use Meta's Muse Spark 1.3 Contributor through OpenRouter. Contributor is also a separately labelled manual model. Requests sent to Meta can include your prompt, conversation context and any content included for the model to process. Meta may use prompts and outputs to improve its products. This is a condition of the Contributor tier, separate from Benaiah's own optional Research Library and improvement programme.
The Help improve Benaiah setting does not control Meta's use of Contributor requests. To avoid sending new requests to Contributor, select another Auto level or a non-Contributor manual model. This does not undo data already sent. Existing standard Muse Spark selections are not automatically changed to Contributor. Native Codex Responses uses a separate compatible route, and Auto High may use another provider for native private-file search or connected tools, or if OpenRouter funding is unavailable.
Do not use Contributor for secrets, confidential client material or sensitive personal information. Review OpenRouter's model disclosure and the provider's applicable terms before choosing it.
Storage and sharing
Conversation and profile records are stored privately using Vercel-deployed infrastructure. Requests are sent to the model provider selected in the interface through OpenRouter. Operational copies are sent to the owner through Telegram for quality review. Stripe processes subscription and payment details. Providers process data under their own applicable terms and controls.
Benaiah Connect channel credentials, provider API keys and other private application secrets remain on the device where Connect is installed; they are not included in the cloud conversation sync.
Retention
Operational conversation records are retained for up to 90 days unless they are needed to investigate abuse, resolve a dispute or meet a legal obligation. Conversation history deliberately synced to a signed-in profile is retained so it can be restored across devices, until you delete it in the product or request profile deletion. Pending Research Library candidates are removed when the user withdraws consent. Reviewed and approved candidates are retained only while useful for the disclosed improvement purpose or until a valid deletion request applies.
Your choices
- Leave Help improve Benaiah off and still use the service normally.
- Turn it off at any time under Settings → Personalisation to stop future research capture and remove pending candidates.
- Do not enter secrets, passwords, payment-card data or highly sensitive personal information.
- Request access, correction or deletion by emailing [email protected].
Controller
Benaiah AI Ltd (company number 17403584) is the controller of personal data processed through Benaiah.ai. The registered office is 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom. This notice is version 2026-09-04.v7 and will be updated before conversation, profile or website analytics data is used for any materially different purpose.