Privacy Policy
Last updated: September 29, 2026
The short version
BentoSort collects no data about you. It has no account, no analytics, no advertising and no tracking. The files you sort never pass through us: the app moves and copies them on your Mac, straight to the places you chose. Your workflows (your grids of boxes and their settings) sync between your Macs only through your own private iCloud database, which we cannot read.
Responsible party
The controller under Art. 4(7) of the General Data Protection Regulation (GDPR) is:
Keitgen GmbHJoseph Keitgen, CEO
Goldguldenweg 11
53489 Sinzig
Germany
support at keitgen dot de
Our legal notice required by German law: Impressum.
The app
What we collect
Nothing. The app contains no analytics, crash-reporting or advertising code. We never see which files you sort, where they go, or how you use the app. The app talks to no server of ours. It uses the network only for the iCloud sync described below, which runs through Apple’s CloudKit service directly to your own iCloud account, and to reach places you chose yourself, such as a folder on a network drive (NAS).
Your files
BentoSort runs in Apple’s app sandbox. It can reach only the files you drop on it and the folders you choose for your boxes. When you drop something on a box, the app moves, copies, tags, trashes or opens exactly those items, as that box is set up to do. File contents are read only to copy them, to check that each copy is complete, and to show a small picture of the first dropped file in the drop animation, which macOS Quick Look makes on your Mac.
Items dragged from other apps that are not files yet (for example a Mail attachment or an image from Safari) are first saved to a temporary folder inside the app’s sandbox, then placed like any other file. The temporary folder is removed once they are placed.
What stays on your Mac
So that the app can do its job, it stores the following locally, inside its own sandbox folder on your Mac. None of it is synced or sent anywhere:
- The permission to use each folder you chose for a box (a macOS “security-scoped bookmark”). It works only on this Mac.
- The drop log: for each drop the time, the box, what was done, the names of the dropped items and the result. It keeps the last 1,000 drops per workflow.
- Window positions and your settings, such as the default mode for new boxes and whether a sound plays after a drop.
You can delete a workflow, and with it its log, inside the app at any time. To remove everything from this Mac, delete the app and the folder ~/Library/Containers/de.keitgen.BentoSort.
For troubleshooting, the app also writes a few short lines per drop to the macOS system log, which stays on your Mac. File names and paths in those lines are marked private, so macOS hides them.
iCloud sync of your workflows
If you are signed in to iCloud, BentoSort keeps your workflows in sync between your Macs. They are stored in the app’s private CloudKit database in your iCloud account. Apple operates iCloud and processes this data under its own privacy policy; the private database is tied to your Apple Account, and we, the developer, have no access to it.
What syncs, for each workflow and box: names, grid size and window options, icons and colors, the box rules (move or copy, name clashes, date subfolders, Finder tags), and the box’s target. For a folder target that includes the folder’s full path, the name of its volume and, for a network share, the share’s address, so that the same folder can be found on your other Mac. For other targets: the name of the share service, the Photos album’s identifier and title, or the chosen app’s name and identifier.
The files themselves are never synced, uploaded or stored in iCloud by BentoSort. If you are not signed in to iCloud, or switch iCloud off for BentoSort in System Settings, your workflows stay on this Mac only. A workflow you delete in the app is deleted from iCloud as well.
Photos access
BentoSort asks for access to your Photos library only when you use a box that sends to Photos. Without an album, it asks for “add only” access: it can add photos and videos, not see your library. If you choose an album for the box, it asks for full access, which it uses to list your album names for the choice and to add what you drop to that album. It does not read, analyze or upload your photos. You can change the access in System Settings › Privacy & Security › Photos at any time.
Sharing and other apps
When you drop items on a box that shares (for example with Notes, Mail, AirDrop or Messages), the app hands them to that macOS sharing service, and macOS asks you to confirm. When you drop items on a box that opens them with an app, they are handed to that app. Where they go from there is your choice, and the service or app you picked handles them under its own terms.
Exported workflow files
File ▸ Export Workflow… writes a .bentosort file to a place you choose. It contains the workflow’s settings as listed above, including the full paths of its folders. It is not sent anywhere unless you send it.
Purchase through the Mac App Store
BentoSort is sold through Apple’s Mac App Store. Apple processes your purchase and payment data under its own privacy policy; we have no access to it. We receive only aggregated sales figures from Apple, never your name, e-mail address or payment details.
Crash reports from Apple
If you have chosen in macOS to share analytics with app developers (System Settings › Privacy & Security › Analytics & Improvements), Apple may give us anonymized crash reports and usage statistics. Apple collects and anonymizes these; you can switch this off there at any time.
This website
This website sets no cookies, uses no analytics or tracking, and loads no fonts, scripts or other resources from other companies. Every script on these pages runs only in your browser: none has access to your files, and nothing you do on these pages is stored or sent. Where the site links to Apple’s websites, such as the Mac App Store, these are plain links; when you follow one, Apple’s privacy policy applies there.
The website runs on a server we rent from DigitalOcean, LLC (New York, USA), in its data center in Frankfurt, Germany. DigitalOcean processes data on our behalf under its data processing agreement (Art. 28 GDPR), which includes the EU standard contractual clauses. When you visit the site, the web server records technical access data in its log files: IP address, date and time, the page requested, the referring page and your browser’s user agent. We need this to deliver the site and keep it secure (Art. 6(1)(f) GDPR). The server deletes these logs automatically after two days at the latest.
If you write to us, we use your e-mail address and message only to answer you (Art. 6(1)(b) and (f) GDPR) and delete them once they are no longer needed, unless the law requires us to keep them.
If you choose Help ▸ Contact Support… in the app, it opens a draft e-mail in your mail app that already contains technical details to help us find the problem: your Mac model, the macOS version, the app version, your language and region, the iCloud sync status and whether you are signed in to iCloud, the app’s settings, and how many workflows, boxes and linked folders you have (never their names or folder paths). The app sends nothing on its own. The details reach us only if you send the e-mail, and you can read, change or delete them before you do.
Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to data portability. Since the app collects no data, these rights will mostly concern e-mails you sent us. Contact us at support at keitgen dot de.
You also have the right to lodge a complaint with a data protection supervisory authority. Ours is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz.
Changes
If the app ever starts handling data differently, this policy will change before the app does, and the date at the top will show when.