Privacy

Privacy policy

Dango is a deck builder your own AI agent drives over MCP. This page says exactly what we collect, why, who else touches it, and how to get it deleted. It describes what the product actually does today, not a category.

Last updated 27 July 2026

What we collect

Four kinds of data, and nothing beyond them.

  • Your account. The email address you sign in with, your workspace name, and the short-lived one-time codes used to sign you in. We do not ask for a password, so there is not one to leak.
  • Your content. The decks, slides, datasets, and comments you or your agent create, the images you upload, and the brand kit produced when you point Dango at a website. This is the substance of the product and it belongs to you.
  • Connection metadata. For each agent connected to your workspace we record the client it declares itself to be (for example claude-code), its user agent, the most recent IP address and origin it called from, a request count, and first and last seen timestamps. This is what draws the “connected” state in the app, and it is what lets you notice a connection you did not make.
  • Deck view analytics. When someone opens a deck you shared, we record a per-session token, a two-letter country code, a device class (desktop, tablet, mobile), the referring host, and how long each slide was open. We do not store the viewer’s IP address. A viewer’s email is recorded only when they signed in or the link asked them to identify themselves.

What we use it for

To run the product: authenticate you, store and render your decks, show you which agents are connected, tell you who opened a deck you sent, take payment, and answer you when you write in. We use aggregate product analytics to work out which parts of Dango are worth building on.

We do not sell personal data, we do not share it for advertising, and we do not use your decks to train models.

AI, and where your decks are not sent

Dango is deliberately the wrong shape for a company that wants your content. The agent that writes your slides is yours: it runs in Claude, Claude Code, ChatGPT, or Codex, under your own account and your own provider’s terms. Dango is the tool it calls. Your deck content is never sent from Dango to a model provider.

There is one exception, and it is the brand scan. When you point Dango at a website, the pages it reads are processed by Anthropic’s API to extract colors, type, logo, and tone. That runs under Anthropic’s commercial API terms, which do not permit training on the content. The input is a public website you nominated, not your decks.

Who else touches it

Dango runs on other people’s infrastructure, and honesty about which is the whole point of this section. Our subprocessors:

  • Amazon Web Services (United States): hosting, the database, image storage, and sign-in email delivery via SES. Your content lives here.
  • Anthropic: brand-scan analysis only, as described above.
  • Stripe: payments. Card details go to Stripe directly; Dango stores only customer and subscription identifiers, never a card number.
  • PostHog: product analytics.
  • Google Analytics: aggregate traffic measurement on this marketing site (which pages people visit and how they found us).
  • logo.dev: given a domain during a brand scan, returns that company’s logo.
  • Cloudflare: DNS and email routing.

We also disclose data if the law requires it, and we would tell you unless we are prohibited from doing so. If Dango is ever acquired, your data moves with the product and this policy travels with it until you are given notice of a new one.

How long we keep it

Your account and content are kept for as long as your workspace exists. Delete a deck and it goes, along with its revision history and its view analytics.

Ask us to close your workspace and we delete your account, your decks, your uploads, and your connection metadata within 30 days, apart from records we are required to keep for tax and accounting (Stripe holds the payment record itself). Backups age out on their own cycle within 35 days.

Security

Traffic is encrypted in transit and data is encrypted at rest. Your MCP URL contains a secret token and is the credential for your workspace: treat it like a password, and if it leaks, rotate it in the app, which revokes the old one immediately.

Dango is an early-stage product and does not hold a SOC 2 report or any other third-party certification yet. We would rather say so here than let a badge imply otherwise.

Your choices

Write to [email protected] and we will give you a copy of your data, correct it, or delete it. You can rotate or revoke your MCP token yourself at any time, and turning off a share link stops any further views being recorded against it.

If you are in the UK, EU, or a US state with a privacy statute, you have rights of access, correction, deletion, and portability, and you can complain to your regulator. The same mailbox is the fastest route either way.

Children

Dango is a tool for work and is not intended for anyone under 16.

Changes and contact

If this policy changes in a way that matters, we will email the address on your account before it takes effect. The date at the top is the version you are reading.

Questions, requests, or anything that reads wrong: [email protected]. Our terms of service cover the rest of the relationship.