Skip to content
Mango
Launch Mango

Mango — Privacy Policy

Last updated: 2026-07-02

Mango (“Mango”, “we”, “us”) is an AI marketing operator that helps you research, create, and publish content from tools you already use, including Slack. This policy explains what data we collect, how we use it, how long we keep it, who we share it with, and the choices you have. If you have questions, contact us at andros@wonderverse.xyz.

Information we collect

  • Account information — your name, email, and workspace details when you sign up.
  • Content & messages — the prompts, messages, drafts, and files you send to Mango (e.g. in Slack), which we process to generate responses and content.
  • Connected-account credentials — OAuth tokens and session credentials for the platforms you choose to connect (e.g. Slack, social accounts), stored encrypted so Mango can act on your behalf.
  • Generated assets — videos, images, and posts Mango produces for you.
  • Performance & usage data — engagement metrics on content you publish, and basic product-usage logs used to operate and improve the service.
  • Billing information — processed by our payment provider (Stripe); we do not store full card numbers.

How we use your data

  • To provide the service — research, draft, edit, schedule, and publish content at your direction.
  • To send AI prompts and content to our LLM providers to generate responses.
  • To operate, secure, debug, and improve Mango.
  • To communicate with you about your account.

We do not sell your data. We do not use your content to train third-party models — see “AI / LLM processing” below.

AI / LLM processing

Mango is powered by large language models — primarily Anthropic (Claude), with OpenAI models as fallback. Your messages and content are sent to these providers in isolated, per-request API calls scoped to your workspace, solely to generate a response. The models are accessed as a stateless API: there is no shared context between customers. Per Anthropic and OpenAI commercial API terms, your data is not used to train their models; providers may retain inputs/outputs for a limited period (up to 30 days) for abuse monitoring, then delete them.

Data storage & security

Customer Data is stored encrypted at rest, scoped per workspace, in a managed PostgreSQL database and in object storage for media assets. OAuth tokens and credentials are encrypted with application-managed keys and are never exposed to other tenants. Data is transmitted over TLS. Our infrastructure is cloud-hosted in the United States.

Sub-processors

We use trusted third parties to operate Mango. The current list, and what each one does, is maintained at mangoagent.ai/sub-processors.

Data retention & deletion

We retain Customer Data for as long as your account is active, to provide the service. On account termination or your deletion request, we remove the associated data from active systems and revoke connected-account credentials; residual copies in encrypted backups are purged within 30 days on the standard backup rotation. To request deletion, email andros@wonderverse.xyz.

Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact us at the email above and we will respond within a reasonable timeframe.

Mango Agent Chrome extension

The Mango Agent browser extension connects your own social accounts to your own Mango workspace so your Mango agent can act on your behalf, with your approval. It never stores or transmits your password.

What the extension reads:

  • Session cookies for the platforms you choose to connect (Instagram, TikTok, Threads) — only when you click Sync — to pass your logged-in session to your own Mango workspace so it can post and engage for you.
  • Your Mango API key and, if you enable outreach, your workspace agent credentials, stored locally in the browser (chrome.storage), scoped to the extension.
  • The logged-in account name in your open platform tab, read only to verify the correct account before a sync or an approved send. No other page content is read.

Approved outreach (opt-in): if you enter agent credentials, the extension can send outreach messages you have already approved in your Mango dashboard, from your real logged-in tab — only to the recipients you approved, within a strict per-account daily limit. It verifies the recipient and sending account before each send and never composes new messages. Leave the agent credentials blank and it only syncs sessions and never sends.

The extension never reads your password, browsing history, or other page content; never tracks you across the web; and never sells, rents, or shares your data. Session data is sent solely to your own Mango workspace endpoint.

Permissions (cookies, storage,tabs, scripting, alarms, proxy/webRequest) are used only for the actions above, scoped to the connected platforms. Remove data anytime: clear agent credentials to disable sending, uninstall to clear local storage, or clear connected accounts from your Mango dashboard to delete the stored session.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to you directly.

Contact

Mango / Wonderverse — andros@wonderverse.xyz