Privacy Policy

bento is a tool for turning a single static HTML file into a shareable, sandboxed link — an incubation under draftzero.xyz. This policy explains what we collect, why, who processes it, how long we keep it, and your controls. It applies whether you use bento via the website, the HTTP API, the CLI, or a connected AI client (e.g. ChatGPT or Claude over MCP).

What we collect

We do not require an account, name, or email to use bento, and we do not collect passwords, payment-card data, health data, or government identifiers. Publishing pages that contain login/password fields is blocked.

How content is rendered

Your HTML renders inside a sandboxed iframe on a separate, cookieless per-paste origin, isolating it from the app and from other pastes. Public pastes are reachable by anyone who has the link; private pastes additionally require the PIN.

Who processes your data (subprocessors)

We don't sell your data, and there are no third-party advertising or analytics trackers.

Retention

Pastes auto-expire 30 days after their last update, after which the HTML body and its metadata are deleted. Deleting a paste removes it immediately. Reported content that crosses a threshold is disabled pending review. Hashed tokens persist until they expire or are revoked.

Your controls

Connected AI clients (MCP)

When you connect bento to an AI client, authorizing the connection mints a bento token tied to that connection (no account or email is created). The client can then create, update, and delete the pastes it makes. Only the HTML documents you ask it to publish are sent to bento.

Children

bento is not directed to children under 13 and we do not knowingly collect their data.

Changes & contact

We may update this policy as bento evolves; material changes will be reflected here. Questions, data requests, or privacy concerns: hi@bento.draftzero.xyz (abuse reports: abuse@draftzero.xyz).

© Draft Zero Archive · v0.1 — handle with care · unfinished material