Legal
Privacy Policy
Last updated: September 1, 2026
Mangrove One PBC (“Mangrove,” “we,” “us”) operates the Mangrove platform at try.mangrove.one and this website at mangrove.one. Mangrove helps people who care about AI safety find each other, form small teams, and ship real work together. This policy explains what personal information we collect, why, who we share it with, and the choices and rights you have.
Contents
1. Information we collect
We collect information you give us, information from accounts you connect, and a small amount of technical information that is created automatically when you use the platform.
Information you provide
- Account details: your email address (used to sign you in with a 6-digit email code), display name, username/handle, and initials or avatar.
- Profile & matching preferences: your time zone, the weekly availability you paint on your calendar grid, how many hours per week you want to commit, and the roles or skills you bring.
- Activity: ideas you react to, projects you participate in, and peer ratings that you give and receive.
- Communications: messages you send us, and your notification preferences.
Information from connected accounts
- Sign in with LinkedIn (optional): if you choose “Sign in with LinkedIn,” we receive your name, profile photo, and email address, so we can create your Mangrove profile and save you re-typing it during onboarding. We use this only to sign you in and set up your profile. We do not post anything on your behalf, and we do not read your contacts, messages, posts, files, or anything else in your account. You can sign in with a 6-digit email code instead at any time, and you can ask us to remove any imported details.
- Sign in with Google (optional): if you choose to sign in with Google, we receive your name, email address, and profile photo, and use them the same way: to sign you in and set up your profile, nothing else. Signing in does not give us access to your Google Drive, your Google Calendar, or your Gmail: the Google Calendar and Google Meet features described below and in section 2 are a separate connection that you grant separately. If you already have a Mangrove account under the same email address, signing in with Google attaches to that account rather than creating a second one.
- Google Calendar: to schedule team kickoff and check-in meetings, we create Google Calendar events with Google Meet links on the team’s behalf.
- Apple Calendar: if you connect a published calendar link or your Apple Account, we read your calendars to work out when you are busy, and keep only the start and end times of those busy periods, not what the events are. With your permission we also add your team’s Mangrove meetings to a calendar you pick.
- Meeting notes: for team meetings held over Google Meet, we ingest the notes Gemini generates for the call (its AI-written summary and transcript) so the platform can turn them into a shared record and action items for your team. See section 2 and section 4.
Information collected automatically
- Technical & usage data: basic log information such as your IP address, browser type, pages viewed, and timestamps, used to keep the service secure and working.
- Product & site analytics: privacy-friendly, cookieless usage analytics, such as pages viewed, referrers, and which features are used, that help us understand how Mangrove is used and improve it. These do not set tracking cookies, do not track you across other sites, and are never used for advertising. When you are signed in, everything our product analytics provider PostHog holds about you, listed in section 5, is tied to your name, your Mangrove handle, and your email address, so we can tell whose activity we are looking at when you report a problem. Browsing while signed out is not linked to you, and other members never see any of this. See section 6.
- Essential cookies: to keep you signed in and protect your session. See section 6.
If you register for an event without a Mangrove account
Some events on Mangrove are open to people who are not members. If you register for one of those, we store only what the sign-up needs. We do not create an account for you.
We do not sell it, or use it for advertising.
2. How we use your information
- Run the platform: authenticate you, show you ideas, and match you into teams based on shared availability and mutual interest.
- Form & run projects: assemble teams when an idea reaches its threshold, and schedule the kickoff and check-in meetings.
- Facilitate collaboration: Take meeting notes during Google Meet calls to help you track your action items. These are kept strictly confidential- only visible to your team.
- Schedule on your calendar: if you connect your Google or Apple calendar, we use their APIs to read your free/busy times for scheduling and, with your consent, to add your team’s meeting events on your own calendar.
- Team compatibility: use your peer reviews to match you via AI to people you are likely to work well with.
- Run events: show events, record who is coming, and send the confirmation, calendar invitation, reminders, and change notices for an event you registered for.
- Notify you: send in-app, email, and Slack notifications about project activity, according to your preferences.
- Improve & secure: understand how the platform is used, troubleshoot, prevent abuse, and keep accounts safe.
- Comply with law: meet legal and regulatory obligations.
3. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on these legal bases:
- Performance of a contract: to provide the platform and its features, including Ibis, the team AI assistant.
- Legitimate interests: to secure, maintain, and improve the service, and to build the matching features that make the platform work (balanced against your rights).
- Consent: for optional connections like Sign in with LinkedIn and for any non-essential communications. You can withdraw consent at any time.
- Legal obligation: where we must process data to comply with the law.
4. How we share your information
- With other members: Mangrove is a collaboration platform, so parts of your profile are visible to other members by design: your name, avatar, availability overlap, and the ideas and comments you post.
- With your project team: meeting notes and the action items we derive from them are shared with the members of the project team the meeting belongs to. They are not visible to the wider Mangrove membership or to anyone outside your team. The only other access is the service providers that help us run Mangrove, including the AI providers that power Ibis, described below.
- With an event’s host: if you register for an event, the people hosting that event can see that you registered, with the name and email address you gave, so they can run it.
- With service providers: vendors who process data on our behalf to run the platform (section 5).
- For legal reasons: if required by law, or to protect the rights, safety, and security of Mangrove, our members, or the public.
5. Service providers
We use a small set of trusted processors. Each handles only the data needed for its function, under its own security and privacy commitments:
| Provider | Purpose |
|---|---|
| Supabase | Authentication and database hosting |
| Vercel | Website and application hosting, and cookieless, aggregated web analytics (no tracking cookies; not used for advertising) |
| Resend | Transactional email (sign-in links, notifications) |
| Slack | Team chat and notifications for active projects |
| Calendar events, Meet links, and Gemini meeting notes for team meetings. Also Google Drive: when a project launches we create a folder for it in a Mangrove-controlled Google account and share the team’s subfolder with the confirmed email addresses of that project’s members. That folder is where your team works, and where the files you upload as project artifacts are stored. An uploaded artifact is additionally made readable by anyone who has its link, so finished work can be shown outside the team; that does not happen on a private project. Protected by Google’s Workspace Data Processing Addendum and not used for advertising | |
| Anthropic | AI processing for Ibis, your team’s AI assistant: answering your team’s questions grounded in its meeting transcripts and project content; does not train models on your data |
| Fireworks AI | Open-weight model inference provider for Ibis, your team’s AI assistant. Does not train on your data. |
| Stripe | Prize payouts for hackathon winners: identity and bank verification, and the transfer itself. Bank credentials are entered with Stripe and never reach Mangrove |
| PostHog (EU) | Privacy-friendly product analytics and, during the alpha, session recordings that replay the page content as it was rendered on your screen, used to understand how the platform is used and improve it; what you type into form fields is masked in your browser and does not reach us, while rendered text is masked only on the surfaces we have marked for it; hosted in the European Union, run without tracking cookies, under a data processing agreement, and not used for advertising |
Mangrove’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising and do not use it to develop, improve, or train generalized AI/ML models.
6. Cookies & sessions
We use strictly necessary cookies to keep you signed in and to protect your session against fraud and abuse. We do not use advertising or cross-site tracking cookies. Because these cookies are essential to signing in, disabling them may prevent the platform from working.
To understand how Mangrove is used, we rely on privacy-friendly, cookieless analytics (Vercel and PostHog). These do not set tracking cookies, do not track you across other sites, and are never used for advertising, so no cookie-consent banner is required for them.
7. Data retention
We keep your information for as long as your account is active or as needed to provide the platform. If you close your account or ask us to delete your data, we will delete or anonymize it within a reasonable period, except where we need to retain certain records to comply with legal obligations, resolve disputes, or enforce our agreements. Team compatibility data may be retained in de-identified, aggregated form that no longer identifies you.
8. Your rights & choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you, and receive a copy.
- Correct information that is inaccurate or incomplete.
- Delete your information.
- Object to or restrict certain processing, and withdraw consent.
- Port your data to another service.
To exercise any of these, email us at hello@mangrove.one. We will respond within the time required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
These rights do not depend on having an account. If you registered for an event here without one, write to us from the address you registered with.
9. International data transfers
Mangrove is operated from the United States, and our service providers may process your information in the United States and other countries. Where we transfer personal information out of the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
10. Security
We protect your information with encryption in transit, access controls, and row-level security on our database.
11. Children
Mangrove is not directed to children. You must be at least 16 years old to use the platform, and we do not knowingly collect personal information from anyone under 16.
12. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will provide a more prominent notice. Your continued use of Mangrove after an update means you accept the revised policy.
13. Contact us
Questions about this policy or your personal information? Reach us at:
Mangrove One PBC
hello@mangrove.one