← Back

Privacy Policy

Last updated: July 7, 2026

What we collect

When you sign in with Google, Bento List receives your name and email address from Google OAuth. We store only what is necessary to identify your account. Bento List also stores the projects, items, search sessions, and price snapshots you create while using the app.

When automatic price tracking is active, Bento List periodically fetches the product pages of URLs you have saved in order to record current prices. A shared price-check record is maintained per URL so that multiple users saving the same product do not trigger redundant fetches. We also store price-drop notification records tied to your account to power the in-app notification feed and to track which email alerts have been sent.

How we use it

Your data is used solely to power Bento List's features: authenticating you, persisting your research projects across sessions, and surfacing relevant history. Search queries are sent to third-party APIs (SerpAPI, AI providers) to retrieve results and generate summaries. We do not use your data for advertising or analytics beyond error logging.

Your email address is also used to send transactional price-drop alert emails via Resend when Bento List detects a significant price decrease on an item you are tracking. These emails are operational — not marketing — and are sent only when a qualifying price change occurs.

Error monitoring

Bento List uses Sentry to detect and diagnose unexpected errors. When something breaks, technical diagnostics are sent to Sentry: the error message and stack trace, browser and device information, and the page address. We configure this deliberately to exclude personal information — invitation and sharing links are redacted before anything is sent, and no email addresses, cookies, form contents, or chat messages are included. This applies to visitors viewing a shared registry as well as signed-in users. Error data is used only to keep Bento List working and is retained by Sentry for a limited period under its own privacy policy.

What we do not do

We do not sell, rent, or share your personal information with third parties for marketing or commercial purposes. We do not display advertising. We do not use tracking pixels or analytics that profile you — the only diagnostics we collect are the error reports described above.

Third-party services

Bento List uses Google OAuth (for sign-in), SerpAPI (for shopping results), Anthropic Claude (for AI research features), Resend (for transactional email), and Sentry (for error monitoring, as described above). Queries and result data are transmitted to these services as part of normal operation. Your email address is shared with Resend solely to deliver price-drop alert emails. Each service operates under its own privacy policy.

Data retention and deletion

Your data is retained for as long as you have an account. To request deletion of your account and all associated data, contact the operator directly. Data will be removed within 30 days of a confirmed deletion request.

Cookies and sessions

Bento List uses a single HTTP-only JWT cookie to maintain your signed-in session. No third-party tracking cookies are set. The session cookie expires when you sign out or after the configured session window.

Changes to this policy

This policy may be updated as Bento List's features evolve. The “last updated” date at the top reflects the most recent revision. Continued use of Bento List constitutes acceptance of any updated policy.

Questions? privacy@bentolist.com · Terms of Service