Effective September 8, 2026
Bennu keeps your records on your device. Nothing leaves it until you create an account and turn on sync. This page says what goes where, and when.
Bennu is run by an independent developer, lapidix. Contact lapidix@gmail.com.
| Account | Signing in with Google or Apple gives us your email and name to create an account. Signing in is only needed for sync and subscription. The app works fully without it. |
|---|---|
| Records | Todos, routines, categories, notes, places. Stored in the database on your device. Only subscribed accounts with sync on get a copy on the server, and that copy is used only to keep your devices in step. |
| Device calendar | If you allow it, we read your device's calendar events to draw them on the calendar. Read only. Events never leave the device. |
| Google Calendar | If you connect it, we read your calendar list and events, read only. The access token stays in your device's keychain and events stay in an on-device cache. The server never receives this data. You can disconnect in Settings at any time, which deletes the token and the cache. |
| Place search | When a subscribed account searches for a place, the server forwards the query to the NAVER search API. Queries are not stored, only counted. |
| Usage analytics | How often the app is opened, the device's country setting, and how many todos and routines were recorded, sent to PostHog. The contents of your todos are never sent. You can turn this off in Settings. |
| Error reports | If the app crashes or hits an error, technical details go to Sentry. Record contents are scrubbed. The same switch as analytics turns this off. |
We do not collect your age, GPS location, contacts, or advertising identifiers.
| Supabase | Sign-in and the server database |
|---|---|
| Vercel | The server and this website |
| PostHog | Usage analytics |
| Sentry | Error reports |
| NAVER Cloud | Place search |
| Sign-in, Google Calendar API |
Each receives only what its job needs. We never sell or share your data for advertising or marketing.
From Settings you can withdraw your account, turn off analytics, and disconnect Google Calendar. To get a copy of your server data or have it deleted, email the address above.
Bennu's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to show your events on the calendar and is never used for any other purpose or transferred to anyone else.
Changes are posted here with a new effective date. If we start collecting something new, the app will tell you too.