Privacy policy
Dango is a deck builder your own AI agent drives over MCP. This page says exactly what we collect, why, who else touches it, and how to get it deleted. It describes what the product actually does today, not a category.
Last updated 27 July 2026
What we collect
Four kinds of data, and nothing beyond them.
- Your account. The email address you sign in with, your workspace name, and the short-lived one-time codes used to sign you in. We do not ask for a password, so there is not one to leak.
- Your content. The decks, slides, datasets, and comments you or your agent create, the images you upload, and the brand kit produced when you point Dango at a website. This is the substance of the product and it belongs to you.
- Connection metadata. For each agent connected to your workspace we record the client it declares itself to be (for example
claude-code), its user agent, the most recent IP address and origin it called from, a request count, and first and last seen timestamps. This is what draws the “connected” state in the app, and it is what lets you notice a connection you did not make. - Deck view analytics. When someone opens a deck you shared, we record a per-session token, a two-letter country code, a device class (desktop, tablet, mobile), the referring host, and how long each slide was open. We do not store the viewer’s IP address. A viewer’s email is recorded only when they signed in or the link asked them to identify themselves.
What we use it for
To run the product: authenticate you, store and render your decks, show you which agents are connected, tell you who opened a deck you sent, take payment, and answer you when you write in. We use aggregate product analytics to work out which parts of Dango are worth building on.
We do not sell personal data, we do not share it for advertising, and we do not use your decks to train models.
AI, and where your decks are not sent
Dango is deliberately the wrong shape for a company that wants your content. The agent that writes your slides is yours: it runs in Claude, Claude Code, ChatGPT, or Codex, under your own account and your own provider’s terms. Dango is the tool it calls. Your deck content is never sent from Dango to a model provider.
There is one exception, and it is the brand scan. When you point Dango at a website, the pages it reads are processed by Anthropic’s API to extract colors, type, logo, and tone. That runs under Anthropic’s commercial API terms, which do not permit training on the content. The input is a public website you nominated, not your decks.
How long we keep it
Your account and content are kept for as long as your workspace exists. Delete a deck and it goes, along with its revision history and its view analytics.
Ask us to close your workspace and we delete your account, your decks, your uploads, and your connection metadata within 30 days, apart from records we are required to keep for tax and accounting (Stripe holds the payment record itself). Backups age out on their own cycle within 35 days.
Security
Traffic is encrypted in transit and data is encrypted at rest. Your MCP URL contains a secret token and is the credential for your workspace: treat it like a password, and if it leaks, rotate it in the app, which revokes the old one immediately.
Dango is an early-stage product and does not hold a SOC 2 report or any other third-party certification yet. We would rather say so here than let a badge imply otherwise.
Your choices
Write to [email protected] and we will give you a copy of your data, correct it, or delete it. You can rotate or revoke your MCP token yourself at any time, and turning off a share link stops any further views being recorded against it.
If you are in the UK, EU, or a US state with a privacy statute, you have rights of access, correction, deletion, and portability, and you can complain to your regulator. The same mailbox is the fastest route either way.
Children
Dango is a tool for work and is not intended for anyone under 16.
Changes and contact
If this policy changes in a way that matters, we will email the address on your account before it takes effect. The date at the top is the version you are reading.
Questions, requests, or anything that reads wrong: [email protected]. Our terms of service cover the rest of the relationship.