Last updated: 2026-09-27
Privacy policy
This text is a draft and is still with our lawyers. It says what we actually do, and we will publish the reviewed version before launch. Questions in the meantime: contact us.
Who we are
Tangu is a product of Tangu, Nairobi, Kenya. We turn a chat you already have, from WhatsApp, Telegram, Instagram, Messenger, Slack, Discord or a spreadsheet export, into something you can give to a person in it: a free Card for your Status, or a private Story that opens at a time you choose. Teams can also use Tangu to honour a colleague from a work chat.
For anything about your data, write to privacy@tangu.co.ke. We answer within 7 days.
We are the data controller for the personal data described here.
The short version
1. Your chat file is read on your device, in your browser. We never receive it. 2. When you ask us to build your Story, a shortlist of messages is uploaded so we can build it. Names and numbers are stripped out first, and it is deleted within 24 hours. Making a Story is free; paying is what creates the link you send. 3. We keep only the moments you approve, until you delete them. 4. We do not sell your data, we do not advertise to you, and we do not train AI on your chats.
What we collect, why, and on what legal basis
Under the Data Protection Act, 2019, we rely on contract (we cannot make your Tangu without this), consent (you can withdraw it), and legitimate interests (keeping the service safe and working) as set out below.
| What | Why | Basis |
|---|---|---|
| Your chat export | Read in your browser to find moments and numbers | Consent |
| Photos you pick from your chat export, and when each was sent | Shown in the Story, and used for "When was this photo sent?" questions | Contract |
| The shortlist: selected messages, with phone numbers, emails and links replaced | To build your Story | Contract |
| The moments, captions, photos, video and letter you approve | They are the Story itself | Contract |
| Your phone number | Sign in, M-Pesa payment, receipts | Contract |
| Your email, if you give one | Receipts | Contract |
| The recipient's phone number, if you add airtime | To send that airtime | Contract |
| Payment records: reference, amount, status, date | Accounting, refunds, support | Legal obligation |
| A device cookie | Counting opens once, rate limits, abuse | Legitimate interests |
| Consent records | Proving you agreed, and when | Legal obligation |
| Analytics events, with no content and no names | Improving the product | Consent |
| Error reports, with personal data removed | Keeping the service working | Legitimate interests |
How your chat is handled, in detail
On your device. When you choose your exported chat, it is read inside your browser by code that has no network access. Statistics and a preview are produced there. If you stop at this point, nothing about your chat has ever reached us.
Photos from your chat. If your export includes photos, they stay inside the file on your device. Only the ones you pick (up to 10) are resized on your device, which also strips location and camera details, and they are uploaded only when you add them to a paid Story. We keep the date each one was sent so the Story can ask when it was sent. Photos you do not pick never leave your device.
When you build. To build a Story we upload a shortlist: the candidate messages only, never the whole chat. This happens when you ask for the Story, before any payment. Before upload we automatically remove phone numbers, email addresses and links, and we drop messages that look like M-Pesa confirmations, one-time codes or card numbers. Messages matching sensitive subjects (sexual content, health, money disputes, threats, death and grief, break-ups) are excluded entirely and are never uploaded.
What the AI sees. The people in the chat are labelled only as "A" and "B". The AI provider never receives your name, the recipient's name, your phone number or your account details. The AI never receives photos.
Deletion. The shortlist is deleted as soon as your Story is built, and always within 24 hours, by a job that runs every 15 minutes. What stays afterwards is only the moments you kept.
Your copy. The parsed chat also sits in your own browser's storage for up to 24 hours so you can reload the page without starting again. Clearing your browser data removes it.
Who processes data for us
| Processor | What they do | Where |
|---|---|---|
| Google Cloud and Firebase | Hosting, database, files, background jobs | European Union |
| OpenAI | Builds your Story from the redacted, A and B labelled shortlist | United States |
| Paystack | Payments. Never receives chat content | Nigeria and Kenya |
| Africa's Talking | Airtime and SMS. Receives phone numbers and message text | Kenya |
| Resend | Email receipts | European Union and United States |
| PostHog | Product analytics, only after you accept | European Union |
| Sentry | Error reports, scrubbed of personal data | European Union |
Each has a written data processing agreement with us and may use your data only on our instructions.
Transfers outside Kenya. Hosting is in the European Union and some processors are in the United States. We rely on the safeguards in section 49 of the Data Protection Act, including contractual protections with each processor, and we transfer the minimum needed.
How long we keep things
| Data | Kept for |
|---|---|
| Parsed chat in your browser | Until upload, "Start over", or 24 hours |
| Photos you picked, in your browser | Until you add them to the Story, or 24 hours |
| Shortlist | Deleted after the build, always within 24 hours |
| Moments, photos, video, letter | Until you delete them, or 24 months with no opens |
| A Story you build but never pay for | Deleted after 30 days |
| Cards | Until you delete them, or your account is deleted |
| Payment records | As long as Kenyan tax law requires, then anonymised |
| Recipient's number for airtime | 30 days after the airtime settles |
| Reports about content | 2 years after we resolve them |
| Consent records | 5 years after withdrawal or account deletion |
| Analytics events | 13 months |
| Error and application logs | 30 days |
Work chats and team channels
With the At work edition you can use a team chat, such as a Slack channel, to honour one colleague. Because a work chat includes other people, we do more on your device before anything is uploaded:
- Only the honoured colleague's messages, and messages that mention them or reply to them, can be chosen. Everything else colleagues said to each other is dropped on your device and never uploaded. - Messages about salary and pay, contracts, disciplinary or performance matters, complaints, health and leave are excluded, in addition to the sensitive subjects above. - Everyone other than the honoured colleague is labelled "A", and the AI is told to celebrate and never to rate, rank or evaluate anyone. - For a monthly or yearly review, only messages from that period are used.
The person making the Tangu confirms that their organisation allows the chat to be used this way and that the colleague knows about it, or will before it is shared. A Tangu is a gift. It is not a performance review, and it must not be used to make decisions about anyone's job. The organisation that decides to use a work chat is responsible for having a lawful basis to do so under its own policies.
The other person in the chat
A chat belongs to everyone in it. You make a Tangu for someone in the chat, and we designed it around that:
- You confirm you are part of the chat and are making something kind for them. - Nothing is published. A Story is a private link, and only you decide who gets it. - Link previews never show names, dates or messages. - The person who receives it can report it from the link. If the report says the Tangu is about them and they did not agree, we hide it immediately and decide within 24 hours. - We never contact anyone who has not asked us to.
Your rights
You may ask us to: give you a copy of your data; correct it; delete it; stop or limit how we use it; or object to our use of it. You may withdraw consent at any time, and doing so is as easy as giving it. Settings has a one-tap data download and account deletion.
We answer within 7 days and do not charge for reasonable requests.
You can complain to the Office of the Data Protection Commissioner, Britam Tower, Hospital Road, Upper Hill, Nairobi, or at odpc.go.ke, if you think we have got this wrong.
Children
Tangu is for adults. You must be 18 or older to make one. If we learn that a child's data is involved, we hide the content and delete it.
Security
Everything travels over HTTPS and is encrypted at rest. PINs are stored only as a cryptographic hash and we cannot read them. Message text, letters, PINs, full phone numbers and email addresses never appear in our logs. Access to production data is restricted, and every time a person at Tangu opens content for review it is recorded with a reason.
If a breach puts you at risk, we tell the Office of the Data Protection Commissioner within 72 hours of becoming aware, and we tell you.
Changes
If we change this policy we update the date at the top, and for important changes we tell you in the app before the change takes effect.