Bento Wish — Privacy Policy
Version: 1.5 · Status: published · Last updated: 2026-08-17 · Effective date: 2026-08-17 Publishes to:
https://bentowish.com/legal/privacy
This Privacy Policy explains what personal data we collect, why, and what your rights are when you use Bento Wish — our mobile apps for iOS and Android, the website bentowish.com, and the shared wishlist pages guests open in a browser (together, the "Service").
Bento Wish is operated by DROVA APPS AND GAMES SERVICES FZCO ("Bento Wish", "we", "us"), registered at Unit No: UT-12-CO-200, DMCC Business Centre, Level No 12, Uptown Tower, Dubai, United Arab Emirates, 00000. For anything in this policy, contact us at help@drova.services.
The short version: we collect what we need to run a wishlist and gifting service — your account, your wishes, and basic technical data. We run our own infrastructure and we do not sell your personal data. The mobile app includes one third-party product-analytics component (§3a) that receives usage facts — never the content of your wishes. In the EEA, UK, and Switzerland it runs only with your consent, and everyone can switch it off in the app's Settings at any time. We use no advertising or tracking SDKs.
1. Data we collect
1.1 Account data
When you create an account with Sign in with Apple or Google Sign-In, we receive your name (if provided), your email address (or Apple's private relay address if you choose to hide your email), and an account identifier. Profile details you add in the app — such as your birthday and appearance settings — are stored with your account. We run our own authentication — your credentials are not managed by a third-party identity vendor.
1.2 Content you provide
Wishes and wish lists you create: titles, descriptions, notes, images, prices, product links, occasions, event dates, and list settings. We also store your social connections on the Service: people or lists you follow, and groups you create or join. Greeting cards you create: the occasion and style choices, your message, and any personal details you add; if you add a photo of the recipient, we process it as described in §3 and store only a short AI-derived description of it — never the photo itself. If you paste a link, we fetch that page server-side to fill in the wish card (see §3).
1.3 Guest data (no account required)
People you share a list with can open it in a browser without an account. For guests we store a random guest token (kept on their device) so their gift reservations persist, plus the reservation itself and any name a guest chooses to show other guests. By design, the list owner never sees who reserved what.
1.4 Purchase data
Subscriptions and wish-coin purchases are processed by Apple (App Store) or Google (Google Play). We never see your card or bank details. We receive transaction identifiers and receipts from Apple/Google to activate and verify what you bought.
1.5 Technical data
IP address, device type and OS version, app version, language, timestamps, and server logs (used for security and debugging). If you enable notifications, we store your device push token. The mobile app also collects product-analytics events as described in §3a. We use no advertising or tracking SDKs, and the guest web pages load no third-party scripts at all.
2. Why we use your data
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the Service: accounts, lists, sharing, reservations | account, content, guest data | contract |
| Fill in wish cards from pasted links, incl. AI analysis (§3) | the link and fetched page/video content | contract |
| Create the greeting card you ask for: text, artwork, and song (§3) | the card's details and message, and any photo you add | contract |
| Process purchases, subscriptions, wish-coins | purchase data | contract |
| Reminders and event countdown notifications (optional) | push token, event dates | consent |
| Security, abuse prevention, debugging | technical data | legitimate interest |
| Product analytics: which features are used, where the app fails (§3a) | usage events, app telemetry | EEA/UK/Switzerland: consent; elsewhere: legitimate interest, with an in-app opt-out everywhere |
| Internal service statistics: counting installs, active users, wishes created, and funnel completion to steer the product (§3a) | data we already store to run the Service — no new collection | further processing for statistical purposes, compatible with the purposes above (Art. 5(1)(b) GDPR); outputs are aggregate only |
| Legal obligations (tax, accounting, lawful requests) | purchase, account data | legal obligation |
We do not use your data for third-party advertising and we do not sell it.
3. AI features: link parsing and greeting cards
Link parsing. When you paste a product or video link, our servers fetch the public page behind it and extract the product details (photo, title, price, store). For video links (e.g. Instagram, TikTok, YouTube), the video's audio and frames may be processed by our AI service providers (currently Anthropic for content extraction and Groq for audio transcription) to identify the product.
Greeting cards. When you create a greeting card, our AI service providers generate its parts at your request: Anthropic (the greeting-text suggestions), OpenAI (the card artwork), and ElevenLabs (the card song). What we send is what that card needs: the occasion and style you chose, the recipient's first name, your personal message, and any personal details you add (your message and personal details are used for the text and artwork only). If you add a photo of the recipient, the photo is sent to OpenAI to create the artwork and to Anthropic to derive a short factual description of what is visible (for example, "a child at a birthday table") so the greeting text fits the person. We never store the photo itself — only that short description, which is kept with the card and deleted with it. For the song we send only the occasion, the musical mood, the language, and the recipient's first name — never your message and never the photo.
What we send to AI providers is the content needed for that one request — the link and the fetched page or media, or the card details above. Our providers process it solely to provide the feature; Anthropic, OpenAI, and Groq are contractually restricted from using it for their own purposes, including training their models, and what ElevenLabs receives carries no message or photo content. AI results can be wrong; you can always edit, regenerate, or delete what the analysis or generation produced.
3a. Product analytics
To understand which features are used and where the app fails, the mobile app uses AppMetrica, an analytics service operated by YANDEX LLC (Moscow, Russia). What it receives is deliberately narrow:
- Usage events made of fixed codes, numbers, and yes/no flags — for example "a list was shared" or "a sign-in succeeded, method: Apple". The event format technically cannot carry the content of your wishes, lists, notes, images, or messages.
- Standard app telemetry: installs, sessions, crashes, device model, OS and app version, language, and approximate region.
- An internal account identifier, so usage can be understood per account — never your name or email.
Analytics data is stored on the provider's servers in the European Union and the Russian Federation. For users in the EEA, the United Kingdom, and Switzerland, our contracting processor is Air Smart Advertising Solutions FZ-LLC (Dubai, UAE) under the EU Standard Contractual Clauses, and analytics runs only if you consent — the app asks first, and if you decline, no analytics data leaves your device.
You can turn analytics off at any time in the app's Settings; the switch stops analytics data from leaving your device. The app does not use advertising identifiers and does not show a tracking permission prompt.
The guest web pages load no analytics scripts. We count page visits on our own servers using a short-lived, session-scoped technical identifier that stores nothing on your device (no cookies or similar storage) and is not used to recognize you across visits.
Internal service statistics. Separately from the analytics service above, we compute statistics inside our own infrastructure from data we already store to run the Service — for example, how many users were active on a day, how many wishes or lists were created, and how many shared links were opened. This adds no collection, touches nothing on your device, and involves no third party. The results are aggregate numbers with small groups suppressed; they are never published, never exported as individual records, and never used to make decisions about you as an individual. Because it uses only data we already hold, this applies to all users and is independent of the analytics consent and opt-out above.
4. Who we share data with
We share personal data only with:
- Service providers (processors): our hosting provider Render (servers, database, storage), the AI providers named in §3, Apple/Google push notification services (APNs/FCM) for delivering notifications, and AppMetrica/Yandex for product analytics as described in §3a. They process data on our instructions.
- Apple and Google as independent payment processors for in-app purchases, under their own privacy policies.
- People you share with: anyone who has a link to a list you shared can see that list's content. Share links thoughtfully — a list link works for whoever holds it.
- Authorities, where a law we are subject to requires it, or to protect the Service and its users from fraud or abuse.
- A successor entity, if we go through a merger, acquisition, or asset sale — this policy would continue to apply to your data.
Affiliate links: when you open a wish's store link, it may carry an affiliate tag, so the retailer or its affiliate network knows the visit came from Bento Wish and may pay us a commission. This never changes the price you pay, and we do not send them your personal data — they only see the click.
5. International transfers
Our servers are located in the European Union and/or the United States. Where data moves across borders (including to AI providers in the US), we rely on recognized safeguards such as the EU Standard Contractual Clauses or an adequacy decision (e.g. the EU–US Data Privacy Framework, where the provider is certified). Analytics data (§3a) is stored by the provider in the European Union and the Russian Federation; for EEA, UK, and Swiss users — who are asked for consent first — transfers to our analytics processor are safeguarded by the EU Standard Contractual Clauses.
6. Retention
- Account and content data — kept while your account exists; deleted when you delete your account (§7), except records we must keep by law (e.g. purchase records for tax purposes).
- Guest reservations and tokens — kept while the related list exists.
- Server logs — kept for a short rolling window for security and debugging, then deleted or anonymized.
- AI processing inputs — not retained by us beyond fulfilling the request; provider-side handling is governed by the restrictions in §3.
- Greeting-card photos — a photo you add to a card is processed for that card's requests and never stored on our servers; the short AI-derived description of it (§3) is stored with the card and deleted with the card or your account (§7).
- Analytics events (§3a) — kept only as long as needed for the purposes above, then aggregated or deleted; turning analytics off stops new collection immediately.
- Internal statistics (§3a) — per-user analytical tables are kept for up to 13 months (one seasonal cycle), then deleted; long-term statistics are retained only in aggregate form that identifies no one.
7. Deleting your account
You can delete your account at any time:
- In the app: Settings → Account → Delete account.
- On the web:
https://bentowish.com/legal/delete-account.
Deletion removes your account, lists, wishes, images, and greeting cards (including any AI-derived photo descriptions) from our production systems, and shared links to your lists stop working. Purchase records held by Apple/Google are governed by their policies. Unused wish-coins are forfeited on deletion (see the Terms of Use).
8. Your rights
Depending on where you live, you have the right to access, correct, delete, and receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent (e.g. turn off notifications) at any time.
- EEA/UK: you also have the right to lodge a complaint with your data protection authority.
- California: we do not "sell" or "share" personal information as defined by the CCPA/CPRA, and we do not use sensitive personal information beyond what is necessary to provide the Service. You may exercise your access, deletion, and correction rights without discrimination.
To exercise any right, email help@drova.services. We may need to verify that you control the account. We respond within the timelines set by applicable law.
9. Children
The Service is not directed to children under 13 (or the higher minimum age your country sets for consenting to data processing). We do not knowingly collect personal data from children below that age; if you believe a child has created an account, contact us and we will delete it.
10. Security
We use encryption in transit, access controls, and least-privilege infrastructure to protect your data. No online service can guarantee absolute security — if we learn of a breach that affects your data, we will notify you and the competent authorities as required by law.
11. Changes to this policy
We will update this policy as the Service evolves (a version history is kept in our public repository). If a change is material, we will notify you in the app or by email before it takes effect. The "Effective date" above always tells you which version applies.
12. Contact
DROVA APPS AND GAMES SERVICES FZCO, Unit No: UT-12-CO-200, DMCC Business Centre, Level No 12, Uptown Tower, Dubai, United Arab Emirates, 00000 Email: help@drova.services · Web: https://bentowish.com