← Back to Jango

Jango · Your information

Privacy Policy

Last updated: October 5, 2026

Penumbra Holdings Inc., based in the United States, operates Jango (“Jango”, “we”, or “us”). We collect personal information to provide accounts, build and run AI agents, connect services, and manage payments. This policy describes those data flows and how to contact us about your information. It covers Jango’s website and app.

Information we collect and why

  • Account information. Your phone number, name, username, optional profile photo, authentication identifiers, and session information are used to sign you in and manage your profile and access.
  • Content you provide. Prompts, messages, links, uploaded files, agent instructions, and generated content are processed and stored to build and run agents, display their history, and investigate problems.
  • Connected-service information. Depending on the services and permissions you choose, this can include access tokens or API keys, account identifiers, balances, holdings, orders, transactions, emails, documents, social content, and tool results.
  • Billing information. Payment-provider identifiers, payment method summaries (such as card brand and last four digits), receipt email, subscription status, purchases, and usage records are used for billing and account support. Card entry is processed by Stripe.
  • Technical and usage information. Device and browser details, network information, app activity, errors, performance measurements, and diagnostic records help operate, secure, and troubleshoot Jango.
  • Support communications. Information you send when contacting us is used to respond and investigate your request.

Purposes and legal bases

Where European or UK data-protection law applies, we rely on performance of our contract with you for processing needed to provide the account, AI agents, connections, and billing you request. We rely on legitimate interests in securing and troubleshooting the service and responding to support requests, subject to your rights, and on legal obligations for required records and disclosures. These bases do not replace consent where consent is required for a particular activity, such as optional tracking.

Providing information is your choice, but we cannot supply features that need it without that information. For example, phone sign-in requires a phone number, and a connected-service task requires the relevant access permissions.

How AI uses your information

Jango sends prompts, conversation context, instructions, uploaded content, and relevant connected-service information to external AI providers to generate responses and build or run agents. Tool calls can send information to connected services and return their results to the AI model. Agent activity, generated outputs, and diagnostic traces can also be retained by Jango.

Depending on the feature and model, supported providers include Anthropic, OpenAI, DeepSeek, Moonshot, and OpenRouter. OpenRouter can route requests to other model providers. The provider can change when you change models or use a different feature. A selected model does not necessarily handle every stage of building and running an agent.

Providers’ processing and retention depend on the applicable service terms and account settings. This policy does not promise that all providers have zero retention or exclude every use for model improvement. Avoid including sensitive information that is unnecessary for your task, and only submit information you are authorized to share.

AI outputs can be inaccurate. Agents may take actions through the services you connect, including financial transactions when authorized. Review agent instructions, permissions, and outputs before relying on them.

Connected accounts and tools

When you connect an account, Jango stores credentials such as authorization tokens or API keys so agents can access it. The information accessed and actions available depend on the provider, granted permissions, and agent configuration. Connected data may become part of prompts, tool results, agent history, or logs.

Review each service’s permissions and privacy policy before connecting it. You can revoke access through the provider’s account controls. Revocation stops future authorized access but does not automatically erase information already received or reverse completed actions. Contact us about retained copies.

Who receives information

Information is processed by providers that support the features you use, including:

  • Supabase for authentication, databases, and file storage, and messaging providers such as Twilio for sign-in codes and account text messages.
  • Vercel and Fly.io for hosting and running application services.
  • Stripe for payment methods, charges, and subscriptions.
  • Sentry for errors, performance diagnostics, logs, and session replay when configured, as described below.
  • AI providers described above and the brokers, exchanges, wallet services, data sources, and other tools involved in your agents’ tasks.

Providers receive information relevant to the services they perform. Connected services also handle information under their own policies. Information supplied to support may be accessed to investigate your request. Disclosure may also be necessary to comply with applicable legal obligations or protect the service. None of this includes text messaging opt-in data and consent, which are not shared with any third parties.

Text messages

We use your phone number to send sign-in codes. If you opt in, we also text you account alerts, such as low credits, paused bots, and failed payments, and we record when you opted in. Reply STOP to stop account alerts or HELP for help.

Text messaging opt-in data and consent are not shared with any third parties. No mobile information is shared with third parties or affiliates for marketing or promotional purposes.

Diagnostics, session replay, and browser storage

Jango uses browser storage for sign-in sessions, preferences, and application state. When Sentry is enabled, it receives diagnostic information and may record a reconstruction of your interaction with the app, including page content, clicks, and input. Some sensitive fields are masked, but not all page content and inputs are masked. Prompts and connected content may appear in these records.

Blocking or clearing browser storage may sign you out or affect functionality. Jango does not currently provide an in-app switch for session replay. A link to this policy is a notice, not a request for consent to optional tracking.

The app does not currently change its collection behavior in response to a browser’s Do Not Track signal. Third-party services may receive information when you interact with them through Jango and process it under their own policies, including information from your use of their services elsewhere.

Public profile photos

Profile photos are optional and stored at publicly accessible URLs. Anyone with a photo’s link can view it without signing in. Do not upload a photo or document that you need to keep private. You can replace or remove your profile photo in Settings; removal cannot recall copies already saved by others.

Retention and deletion

Information can remain in account records, uploaded files, conversations, agent history, logs, and backups after an agent stops running. Removing a bot from the interface does not by itself erase all associated information. Retention varies with the type of record, service operation and support needs, security investigations, billing requirements, and applicable legal obligations.

You can start account deletion in Settings, under Account, after verifying your identity. Your account closes to new activity while background cleanup cancels subscriptions without waiting for the billing period to end, stops agents, and removes your profile, conversations, uploads, and saved connections. Broker accounts, holdings, and open orders remain with their providers. Deletion does not automatically refund payments or settle unpaid invoices.

To prevent repeated claims of free signup credit, we retain a protected, keyed fingerprint of your verified phone number and the date it was first recorded, including after account deletion. This limited eligibility record does not contain the raw phone number and remains while needed to enforce the one-time signup-credit offer. Creating another account with the same number does not provide another free credit. Contact support if you believe your eligibility is incorrect, including if a number was reassigned to you.

For help with account deletion or a request about specific uploaded content, email support@jango.ai. Identify the account and the information concerned without sending passwords, API keys, or payment-card numbers. We may need to verify account ownership. Some records may need to be retained for legal or security reasons; third-party retention and backups can affect the scope and timing of deletion.

Your choices and privacy requests

You can edit your profile in Settings, choose which information to submit, and control connections through the relevant provider. Depending on where you live and which laws apply, you may have rights to access, correct, delete, or obtain a copy of personal information, restrict or object to processing, or withdraw consent for processing based on consent.

Email support@jango.ai to make a privacy request, ask about a response, or have an authorized representative contact us. Include your country or state so we can assess the applicable rights. You may also contact your local data-protection authority about a privacy concern.

International users and age

Jango is intended for adults aged 18 and over in the United States and internationally. Providers may process information in the United States and other countries, whose privacy protections can differ from those in your location. Contact us for information about processing locations and applicable transfer arrangements. Contact us as well if you believe a child has provided personal information.

Contact and policy changes

Send privacy questions to Penumbra Holdings Inc. at support@jango.ai. Updates to this policy will appear on this page with a revised date. Check this page when deciding whether to provide new information or connect a service.