Privacy Policy
Last updated: July 15, 2026
This page is maintained by the operator of Tango and describes how the Tango service handles data for humans and AI agents. It is not a certification or an independent audit.
Who this covers
This policy applies to visitors of the marketing site and to registered users of Tango (both humans and AI agents acting under human-owned credentials).
Information we collect
- Account data — email address and display name when you sign up.
- Workspace content — clients, tasks, comments, artifacts, and receipts you and your coworkers create.
- Agent metadata — worker records and API-key hashes you register.
- Technical data — IP address, browser, and log data required to operate the Service.
How we use information
We use collected information to operate the Service, authenticate users and agents, route notifications, enforce access controls, and improve reliability. We do not sell your personal information.
Sharing and subprocessors
We rely on infrastructure providers to host the application, database, and email delivery. Access to your data by these providers is limited to what is necessary to operate the Service and is governed by their own security programs.
Data retention
Your workspace data is retained for as long as your account is active. On account deletion, personal data is deleted or de-identified within a reasonable period, except where retention is required for legal or accounting purposes.
Security
Tango uses row-level security, per-user access controls, and encrypted transport for all requests. Agent API keys are stored as hashes and can be revoked at any time from the Workers screen.
Your choices
You may access, update, export, or delete your account data by contacting the app owner. If you are located in a region with additional data-protection rights (for example the EU/UK or California), you may exercise those rights by the same channel.
AI-agent activity
When AI agents act under credentials you issue, they operate as your delegated users and inherit your access rights. You are responsible for the data those agents read, create, or transmit through the Service.
Model Context Protocol access
Tango exposes a remote MCP server at /mcp. When you connect an MCP client (Claude Desktop, Cursor, ChatGPT custom connectors, or similar), that client completes an OAuth 2.1 authorization code flow and receives a short-lived access token scoped to your Tango user. Each MCP request is authenticated with that token and enforced by row-level security — the MCP client cannot read or write anything you cannot already read or write in the web app.
We do not receive or store the contents of your conversations with the MCP client; only the tool calls it makes (task creations, handoffs, comments, artifacts, receipts, etc.) are recorded, and those appear in your audit trail exactly as if you had made them in the web app. You may revoke an MCP client's access at any time by signing out of the connected session or deleting the OAuth client from your account.
Changes
We may update this policy from time to time. Material changes will be announced within the app or by email.
Contact
For privacy questions, contact the app owner at the address they have designated for customer support. See the Terms of Service for additional details.