Privacy Policy
Bentar is a mindful-pause app: it briefly appears before apps you choose to guard, so you can decide whether opening them is really what you want. This policy explains exactly what data exists, where it lives, and what leaves your device. The short version: your app data lives on your device, sign-in is optional, and there are no ads.
1. Data that stays on your device
- Your intention questions and the reason you wrote during setup
- The list of apps you chose to guard
- Your wins, streaks, "minutes won" history, and bypass counters
- Settings, content theme, and language preference
Stored locally (Room database / DataStore). We cannot see it because it never leaves your phone.
2. Data that leaves your device
- Opportunity feed & AI drafting — the goal text you optionally write is sent to the Bentar backend so it can match opportunities to your goal and help draft your intention question. No account identifier is attached beyond what is technically required.
- Purchases (Bentar Pro) — handled by Google Play Billing and RevenueCat. They process your purchase history and an anonymous app-user ID to manage your subscription. We never see your payment details.
- Push notifications — OneSignal receives a device push token to deliver optional reminders and opportunity notifications.
- Firebase (Google) — the app bundles Firebase SDKs used for messaging and basic diagnostics; Google may process device identifiers and standard diagnostic events under its own policies.
- Google sign-in (optional) — if you choose to sign in, Firebase Authentication stores your Google account identity (user ID, display name, email) so purchases can be restored across devices. You can delete it anytime — see section 6.
3. Accessibility Service — what it does and does not do
Bentar's core feature uses Android's AccessibilityService API with your explicit, manual permission. The service observes window/app-launch events only to know when an app you chose to guard is opening, so Bentar can show its pause overlay first.
- It does not read screen content, typed text, or passwords.
- It does not monitor keystrokes or gestures.
- No data obtained through the Accessibility API is collected, stored off-device, or transmitted — detection happens entirely locally.
- The overlay always shows the Bentar wordmark so it is clearly attributable.
- You can revoke it anytime in Android Settings → Accessibility; Bentar keeps working in a limited mode (reminders, feed, stats) without it.
4. Installed apps list
To let you pick which apps to guard, Bentar reads the list of installed launchable apps on your device. This list is rendered locally for the picker only — it is never uploaded, shared, or stored remotely.
5. Optional sign-in, no ads, no sale
Bentar works without an account. Optional Google sign-in exists only to link purchases to you for restore across devices — it is never required and never used for tracking. Bentar shows no ads and does not sell or share your data for advertising or marketing purposes.
6. Data & account deletion
Local app data is on your device — uninstalling Bentar deletes it completely. If you signed in, you can delete your account permanently in Settings → Delete account, or request deletion at our account deletion page / by emailing support@ajfbyte.com. Deletion removes your sign-in identity and unlinks your billing identity; for the optional goal text sent to our backend or billing-record erasure, email us and we will delete it.
7. Children
Bentar is not directed at children under 13 and does not knowingly collect their data.
8. Changes
If this policy changes, the updated version will be posted at this URL with a new effective date.
9. Contact
Questions or deletion requests: support@ajfbyte.com
Ringkasan (Bahasa Indonesia)
Data aplikasi (niat, aplikasi yang dijaga, kemenangan, pengaturan) tersimpan di HP kamu dan tidak pernah dikirim. Yang keluar dari HP hanya: teks tujuan opsional ke backend Bentar, data pembelian via Google Play/RevenueCat, token notifikasi OneSignal, dan — kalau kamu memilih login — identitas Google di Firebase Authentication. AccessibilityService hanya mendeteksi aplikasi yang kamu pilih untuk dijaga — tidak membaca isi layar, tidak mengirim data apa pun. Login opsional, tidak ada iklan. Hapus data lokal = uninstall; hapus akun = Setelan → Hapus akun di aplikasi atau lewat halaman penghapusan akun / email support@ajfbyte.com.