Security End-to-end encryption Privacy policy Terms of use Data collection Delete account Abuse reporting
Mango Mango Private Your own messenger
Contact us
Home

Privacy Policy

Mango Private privacy policy

This policy describes what data Mango Private processes when deployed on your organization's infrastructure, why that data is needed, and what controls users and administrators have.

Effective date: 25 August 2026

In short

  • Mango Private is a corporate messenger deployed on your organization's own server. All data stays on your infrastructure unless your administrator explicitly configures otherwise.
  • OffshoreLabs Studio LTD develops the software but does not have access to the data on your Private node unless the operator grants access for technical support.
  • We do not collect or store phone numbers — registration does not require a phone, the user database has no phone field, and the system has no SMS / OTP infrastructure.
  • We do not sell user data and do not use it for ad targeting.
  • Media on the server acts as a temporary relay: copies are deleted after recipients confirm local storage or after a clean-up timer.
  • Camera, microphone, photos, notifications, and location permissions are managed at the iOS / Android level.

1. Who we are and where this policy applies

Mango Private is developed by OffshoreLabs Studio LTD, a company registered in the United Kingdom under company number 17387215. OffshoreLabs provides the Mango Private software and optional managed-deployment services. "We" in this document refers to OffshoreLabs as the software developer and licensor.

The operator and administrator of each Mango Private instance is the organization that deploys it. The operator determines the data-storage location, retention policies, access controls, and acceptable-use rules for their instance. This policy applies to the software as provided by OffshoreLabs and describes the data categories the software processes.

If a separate agreement or corporate contract describes a different data-processing regime for a specific deployment, that agreement applies in combination with this policy.

2. What data is processed

Account and profile

User ID, display name, nickname, avatar, registration date, block status, profile and notification privacy settings.

Chats and messages

Text, emoji, media captions, reactions, replies, forwards, edit and delete markers, send / delivery / read statuses, chat membership, and roles.

Media

Photos, videos, voice messages, video notes, plus the technical parameters of the file: type, size, link, ID, upload time, and recipient local-storage acks.

Calls

Call ID, chat, initiator, participants, call type, status, start / end times, LiveKit / TURN data needed for the connection. Call content is not recorded.

Device and delivery

APNs / FCM push tokens, platform, technical delivery events, WebSocket sessions, IP addresses, error and security logs, auth / refresh tokens.

At registration we derive a country from the IP address and store the resulting user region on the account. The IP address itself is not written to the account and is not retained on the server. The region is used to pick the nearest server and to decide which region a call's media is routed through. It is set at registration and may later be re-derived automatically. The country lookup uses IP Geolocation by DB-IP (CC BY 4.0): the database is held on our servers, is not shipped inside the apps, and has not been modified by us.

Support and administration

Support email content, server logs, user agent, language, approximate IP-based geo, and network requests to external assets such as fonts.

Applications submitted through the Mango Private website form are sent to our business email. A brief summary containing the applicant's name, organization, email, account count, and hosting choice is also delivered to the Mango service account we configure. The optional message is not included. This summary is not end-to-end encrypted and is transmitted and stored in readable form.

3. Data we do not collect by default

  • Phone number — not requested at registration or later. The user-table schema has no corresponding column.
  • The full device address book or contact list.
  • Payment cards or payment details.
  • Advertising identifiers for targeting.
  • Biometrics: Face ID, Touch ID, and Android biometrics stay inside the device's system mechanism.
  • Continuous background location. Location is processed only when the user actively shares a point in chat.

4. Where data is stored

All data processed by Mango Private is stored on the infrastructure chosen and maintained by the organization that deploys the instance. OffshoreLabs does not operate central servers that store Private node data.

If the organization uses a managed deployment by OffshoreLabs, the hosting location and provider are agreed upon during setup. In both cases, the organization retains full control over the data and its location.

5. Why this data is used

  • Create and maintain user accounts within the organization.
  • Deliver direct and group messages, media, reactions, and delivery / read statuses.
  • Connect voice and video calls.
  • Send push notifications and respect the "hide content" preference.
  • Operate security: authentication, rate limiting, abuse prevention, incident investigation.
  • Support users and respond to inquiries.
  • Meet the organization's legal obligations and protect the rights of users and the operator.

6. Who can access the data

Information a user sends to a chat becomes available to the chosen recipients or group members. Recipients can save, forward, take a screenshot, or screen-record; neither OffshoreLabs nor the operator can fully control what they do outside the service.

The organization's administrator has access to server-level data as determined by their deployment configuration and internal policies. OffshoreLabs engineers do not have access to the data on a Private node unless the operator explicitly grants access for technical support purposes.

To run the service the operator may use infrastructure providers: hosting, databases, object storage, Redis, APNs, FCM, LiveKit, TURN / STUN, and email. They receive only the data needed for that specific function.

7. Security and encryption

Mango Private uses TLS for network exchange, access tokens with refresh rotation, request rate limits, chat-level access controls, media upload restrictions, and isolated infrastructure secrets. End-to-end encryption protects direct chats, private groups, and calls.

8. Storage and deletion

  • Profile and account-level data are stored as long as the account is active or as long as needed for security and legal obligations, as determined by the organization.
  • Message history is stored for chat participants until it is deleted by the user, by a participant with delete rights, or by the operator for a lawful reason.
  • "Delete for me" hides the message for that specific user; "delete for everyone" turns the message into a shared deletion marker, where allowed.
  • Media relay is cleaned up after all active participants ack local storage or after a clean-up timer if no acks arrive.
  • Push tokens are kept while the device uses notifications and are deleted or replaced when the token is rotated, the provider returns an error, or the user signs out.
  • Account deletion is managed by the organization's administrator according to internal policies.

9. User rights

Subject to applicable law and the organization's internal policies, the user may request access to their data, profile correction, account deletion, restriction of processing, objection to processing, or export of data available to them. Requests should be directed to the organization's administrator or to OffshoreLabs at request@mango-private.com.

10. OffshoreLabs access

OffshoreLabs does not monitor, access, or process data on individual Private nodes. The only scenarios where OffshoreLabs may interact with node data are: (a) when the operator explicitly grants access for technical support or incident resolution, and (b) when required by lawful process directed at OffshoreLabs as the software provider.

11. Age

Mango Private is intended for users 18 years of age and older. The organization operator is responsible for enforcing age requirements within their instance.

12. Changes and contact

We may update this policy when the product, infrastructure, law, or data-processing model changes. Material changes will be published on the website or communicated through the software update process.

Privacy contact: request@mango-private.com. Technical support: support@offshorelabs.dev.

Mango Private Your own messenger for your organization. request@mango-private.com support@offshorelabs.dev © 2026 OffshoreLabs Studio LTD, a company registered in the United Kingdom under company number 17387215.
MangoConnect Security End-to-end encryption Privacy policy Terms of use Data collection Delete account Abuse reporting