Privacy Policy
Last updated: 9 October 2026
BeNexo is a personal assistant for nurturing your relationships. For it to work across your devices and offer useful suggestions, we handle your data with the greatest possible care. This page explains what data we process, why, with whom, and what control you have over it.
1. Data controller
The controller of your data is the BeNexo team. You can request the controller's full identity by writing to us. For any privacy question or to exercise your rights, contact us at privacy@benexo.app.
2. What data we process
- Account data: your phone number (to identify you and sign you in) and, optionally, your name.
- Content you create: the contacts you add and the information you record about them (notes, moments, next steps, dates, links, attachments such as photos or documents). Some of this information may relate to third parties (see point 4).
- Location (optional): if you choose to attach a place to a moment or step, we store the coordinates you select. We only access your location while you use that feature and with your permission; you can use the app without granting it.
- Contacts from your address book (optional): if you turn on contact discovery, your phone sends our server fingerprints (hashes) of the numbers in your address book to find out which ones are already on BeNexo; we do not send names or plain numbers and we do not keep those lookups. We only store the fingerprint of a number in cases such as sharing something with (or adding to a group) someone who does not use BeNexo yet: it stays pending until they join or you cancel it. A fingerprint is not a plain number, but it is not anonymous data either. Anyone who has your number and uses BeNexo with discovery turned on can see that you are on BeNexo.
- Board contributions without an account: if someone contributes to a board through a link without creating an account, we store the name they type, their text and their photo or video so that the person organising the board can review them. If a contribution is rejected, the photo or video is deleted immediately and the name and text within 30 days at most.
- Technical and usage data: device identifiers needed for syncing, minimal security records (e.g. the account-deletion date in our audit log) and, only if you turn it on in the app ("Help me improve BeNexo"), aggregated usage data and error reports to improve it. On the server and the web panel we also log technical errors, without your content (on the web, with an opaque internal identifier).
3. Why we process your data and legal basis
- To provide the service (storing your information, syncing it across your devices and the web version, generating reminders and suggestions): legal basis is the performance of our contract with you.
- Artificial-intelligence features (suggestions generated with cloud AI): only activate when you use them, based on your consent. See point 7.
- Security and abuse prevention: legal basis is our legitimate interest in protecting the service.
- Product improvement and error detection: in the app, only with your consent ("Help me improve BeNexo" option, off by default); technical errors from the server and the web: our legitimate interest in keeping the service running.
- Communications you request (e.g. joining the waitlist from the website): legal basis is your consent.
4. Third-party data (your contacts)
When you store information about other people, you act as the controller of that data within your personal activity. BeNexo processes it on your behalf, solely to provide you the service, and never uses it for its own marketing purposes nor makes it available to third parties beyond the processors listed below. You are responsible for handling your contacts' information respectfully and in accordance with applicable law.
We do not profile users or cross-link information between different accounts: what you record in your account is not used to enrich anyone else's, except for the content you explicitly choose to share.
5. Who we share data with
We do not sell your data. To run the service we rely on a small number of providers acting as processors, bound by confidentiality and security obligations:
- Railway: hosting and infrastructure provider; stores the service database.
- Supabase: sending the SMS verification code and storing attachment files.
- Google (Gemini): only if you enable cloud AI features, the text needed to generate the suggestion is sent to Google. See point 7.
- PostHog: product analytics (hosted in the European Union) to understand, in aggregate, how the app is used and improve it. In the app it only turns on if you give your consent. It does not receive the content of your contacts or notes.
- Sentry: error reports (data centre in the European Union) to fix bugs. In the app they are only sent if you give your consent; on the server and the web, only technical errors. It does not receive the content of your contacts or notes.
- Expo: delivery of app updates (when opened, the app checks its version, platform and channel) and relay of push notifications. For notifications, Expo receives your device's notification identifier and the notification text (e.g. "Sara shared a memory with you"), never the content of the memory.
- Google (Firebase Cloud Messaging): delivery of push notifications on Android.
- Google Drive (optional): if you connect your account, the backup is uploaded to a folder in your Drive with the minimum permission (only the files BeNexo creates). The file goes straight from your phone to Google; it does not pass through our servers.
- Hugging Face (optional): if you download an AI model to use on your device, your phone downloads it from Hugging Face. They only see the download (as on any website), not your content.
- Websites of the links you add: to show a link's title and image, your phone visits that website (the site sees your IP address, as if you opened it yourself). On the BeNexo web app, our server does it.
- FormBold: on the website only, to manage the waitlist (your email address).
This list of providers may change; we will publish any updates on this page.
In addition, if you choose to share certain content with other people inside the app (shared contexts), that content will be visible to the people you choose, for as long as you keep sharing active.
6. International transfers
Some of the providers above may process data outside the European Economic Area. In those cases, transfers are covered by the safeguards provided for by law (e.g. the European Commission's standard contractual clauses).
7. Artificial intelligence
AI features are optional. When you use cloud AI, the necessary text (for example, the notes about the contact you're asking about) is sent to Google to generate the response; that content is not used to train general models. The app also offers the option to run AI on the device itself, so the content never leaves it.
8. Retention
We keep your data for as long as your account is active. If you delete your account, we erase your information from our systems (deletion cascades to associated content). Unreferenced files and technical records are purged periodically.
9. Security
We apply reasonable technical and organizational measures to protect your information, including encryption in transit (TLS) and encryption at rest of storage. No measure is infallible, but we work to minimize the risks.
Our infrastructure is hosted with providers holding recognized security certifications: Railway (SOC 2 Type II) and Supabase (SOC 2 Type II and ISO 27001).
So that the service can work (syncing, reminders and suggestions), we do not use end-to-end encryption: encryption at rest protects against theft of the physical media, but anyone who gained access to the running database could read the data. We work to make sure that never happens.
If a security breach affecting your personal data were to occur, we will notify you in accordance with applicable law.
10. Your rights
You can exercise your rights of access, rectification, erasure, portability, restriction and objection at any time:
- Access and portability: from the app you can export all your data in a file.
- Erasure: from the app you can delete your account and all your data.
- For any other right, write to us at privacy@benexo.app.
If you reside in the EU, you also have the right to lodge a complaint with your supervisory authority (in Spain, the Spanish Data Protection Agency).
11. Minors
BeNexo is not directed to children under 14, and we do not knowingly collect their data. If you believe a minor has provided us with information, write to us at privacy@benexo.app and we will delete it.
12. Cookies
This website (benexo.app) does not use cookies, neither our own nor third-party, neither advertising nor tracking, which is why we do not ask you to accept them. To count visits in aggregate we use PostHog (hosted in the European Union) without cookies: it stores no identifier in your browser, does not follow you across pages, does not record your session, does not receive URL parameters and honours your browser's «Do Not Track» signal. The web panel (web.benexo.app) keeps in your browser's local storage only what is essential to maintain your session and preferences; it is not used for advertising and is not shared.
13. Changes to this policy
We may update this policy to reflect changes in the service or in the law. We will publish the current version on this page with its update date.
14. Contact
For any matter related to your data: privacy@benexo.app.