Privacy
Benji is a personal AI companion you text. This page says what Benji keeps, where it is kept, who else handles it, and what you can do about it. Benji is operated by Skynet Ventures (“we”). Benji is in beta, by invitation, and some of what is described here is not switched on for everyone yet.
The short version
- Each person gets a private Benji of their own: a separate, isolated computer (your “node”) that holds your conversations and memory. Nobody else’s Benji can see into yours.
- The services every Benji shares (the gateway that carries messages, the control service that holds accounts, and the relay) keep no message content at rest.
- We do not sell your data, we do not show ads, and we do not use your content to train AI models.
- You can ask what Benji knows about you, have things forgotten, and delete your account. Deletion comes with a receipt.
What is kept, and where
Your node runs at Fly.io in the United States, on an encrypted volume. It holds:
- Your conversations with Benji. Older conversations are deleted after a period you can set: three months unless you change it.
- Memories: things you told Benji in your own words that help it help you. Benji keeps no memories from content you did not write, such as a page or an email it read. Before saving one it checks for things that look like passwords, PINs, card numbers and codes and leaves those out, but a check like that can miss a secret, so it is better not to send Benji one.
- Your profile (what to call you, your city and time zone, the standing preferences you gave), your approvals, a record of the actions Benji took for you, and your reminders and tasks.
- The access tokens for accounts you connect, such as Google. They are stored on your node and in its encrypted backups. Our sign-in service handles them for a moment when you connect, seals them to your node and keeps no copy.
Backups of your node are encrypted on the node, with a key only your node holds, before they are stored at Tigris. Deleting your account destroys that key.
The shared services hold an account record: the phone number or handle you text from, your invitation, which node is yours, its public keys, and usage counts and limits. Messages pass through the gateway in transit and are encrypted to your node before they are queued; the gateway keeps no message text. For seven days it keeps a record that a message was sent and whether that worked, without the text. Our logs hold measurements such as timings and error codes, never message content.
Who else is involved
- Messages. iMessage reaches Benji through Sendblue, on a line shared by all Benji users. Apple and Sendblue handle your messages to deliver them, and Sendblue keeps a message history under its own terms; it offers no zero-retention option. If a message falls back to SMS, your carrier carries it unencrypted. In private mode you talk to Benji on Signal, which is encrypted as far as our gateway.
- AI models. On the standard tier, requests go through OpenRouter to the provider running the model. Every request is sent with data collection denied, so a provider that collects or trains on prompts is never used. A zero-retention route is used where the model has one, unless our testing shows another route is clearly better; some models have none. Private mode is opt-in and on Signal only: it uses Venice’s private models only, and keeps its conversations and memory in a separate encrypted store on your node. If you point Benji at a model endpoint of your own instead, that endpoint receives what Benji sends it, under its own terms.
- Browsing. When Benji uses a browser for you, the session runs at Browserbase with session recording and logging turned off. Browserbase handles the pages visited and the values typed, and may hold an encrypted browser profile so that a site keeps you signed in; that profile is deleted with your account. A decision model run by TypeSafe is shown each page’s text and controls, including values already entered, to choose the next step. TypeSafe does not train on this and may keep requests for a time under its own terms.
- Email. Your Benji’s own address is at benjipost.com. Mail sent to it is received by our mail service for that domain and passed to your node.
- Phone calls, if you approve one, are placed through Bland with audio recording turned off. Bland still processes the call’s audio and its transcript, and does not document how long it keeps transcripts. The script you approved passes through our service on its way to Bland and is not logged.
- Hosting. Fly.io runs your node, and when your node is paused Fly.io holds a snapshot of its memory, which contains unencrypted data. Tigris stores the encrypted backups, and Cloudflare serves this website.
- Us. We could reach a node by deploying code to it or opening a shell on it. We build no tooling to do so, any such access is logged and disclosed to you, and we do not claim that we are unable to.
Your Google account
Connecting Google is optional. If you connect it, Benji asks for the following access, and uses it only to do what you ask:
- Calendar: read the events on your calendars, and create, change or delete events on calendars you own. Creating, changing or deleting an event waits for your approval, unless a standing approval you gave already covers it.
- Gmail: read your mail. Benji does not send mail from your Gmail account.
- Contacts: read your contacts, to find the person you name.
What Benji reads from Google is kept on your node and in its encrypted backups. Benji sends what your request needs to the model endpoint described above, shares calendar details with another person’s Benji when you have approved that, and can pass on what another action you approve needs. We do not sell Google data, we do not use it for advertising, and we do not use it to develop, improve or train generalized AI or machine-learning models. No person at Skynet Ventures reads it unless you ask us to for support, or security or the law requires it.
Benji’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google at any time by telling Benji, or from your Google account’s permissions.
What we do not do
We do not sell or rent your data. We show no advertising and build no advertising profile. We do not train models on your content, and the model providers we choose work under terms that forbid it. This website sets no cookies, runs no analytics and loads nothing from any other site.
Your controls
- Ask “what do you know about me?” and Benji lists what it remembers, each item with where it came from.
- Ask Benji on iMessage to forget something it remembers, and that memory is removed. The messages it came from stay in your conversation history until that conversation is deleted, and a reply already on its way may still mention it. “Forget this conversation” deletes the current conversation.
- Change how long conversations are kept.
- Delete your account. That destroys your node, its storage and its keys, deletes its backups, removes your account and routing records, empties the gateway’s and the relay’s queues, deletes your browser profile at Browserbase and asks Bland to delete your call data. The gateway keeps a minimal record that the account was deleted, so that a late message cannot bring it back. You get a receipt that lists each step, its result and anything still outstanding.
Deleting your account cannot remove what is already in your own Messages app, or the copies Apple, Sendblue or your carrier keep under their own terms.
Age, changes and contact
Benji is for adults: you must be 18 or older. When this page changes in a way that matters, Benji tells you in your conversation before the change applies. Questions and requests about your data go to Skynet Ventures at privacy@benji.bot.