Skip to content
NGARO
How it works Your API FAQ
Join the waitlistJoin the waitlist
How it works Your API FAQ Join the waitlist

Last updated 14 August 2026

Privacy policy.

Ngaro is built so that most of the time we hold nothing. Your documents, the knowledge base built from them and every conversation you have stay on your own machine, on every tier, so this policy has far less to describe than most. What we do hold is your account, and on the hosted tiers we process, without storing, the questions and excerpts your app sends us to be answered.

Read the terms of service

On this page

01Who we are 02What this covers 03Two architectures, two answers 04What we collect 05Information about other people 06Cookies and tracking 07Why we use it 08Who else touches it 09Sending information overseas 10The web search toggle 11Your API key 12What we never do 13How long we keep things 14Security 15If something goes wrong 16Your rights 17Complaints 18Children 19Emails from us 20Changes to this policy 21Contact us

01Who we are

Ngaro is Ngaro AI Limited, NZBN 9429052572418, a company based in Auckland, Aotearoa New Zealand. We build a platform that lets people turn their own documents into a private AI assistant.

For the purposes of the Privacy Act 2020 we are the agency responsible for the information described here. If you are somewhere that uses different language, we are the data controller.

Anything to do with privacy, whether a question, a request or a complaint, goes to ngaro.help@gmail.com.

02What this covers

This policy covers the Ngaro website at ngaro.net, our waitlist, the builder you use to create an AI, the desktop app everyone installs, the hosted models the app can call, and the API your finished AI can expose.

There is one significant thing it does not cover, and it is not an oversight. The documents you give your AI, the knowledge base built from them and the conversations you have with it are not covered by this policy, because they live on your own computer and we never receive them. There is nothing for us to describe, protect, or hand over. That is the entire point of the product.

The one qualification, and it is set out fully in section 03: if you are on a hosted tier, your question and the passages your app retrieves are sent to us to be answered. They are processed and not stored.

03Two architectures, two answers

Everybody installs the same app, and the tier you choose decides only where the model that answers you runs. It does not decide where your material lives, because that answer is the same either way.

On every tier, we hold your account details, your subscription and billing record, and the list of devices registered to you. That is all. Your documents, your knowledge base and every conversation you have with your AI live on your own computer. They are not copied to us, not synchronised, and not readable by us. We could not produce them for a court, an acquirer or an attacker, because we do not have them.

If you are on a hosted tier, there is one addition, and it is about processing rather than storage. When you ask your AI a question, your app searches your own local index and sends us the question together with the passages it found, so that a model we run can compose an answer. Those passages are held in memory for as long as answering takes, and are not written to disk, not logged, and not used for anything else. The answer comes back and your app writes the conversation to your machine, not to ours.

So the honest summary of the hosted tier is: your documents are never stored by us, and parts of them are regularly processed by us. Those are different claims and we would rather you had both.

04What we collect

Things you give us

  • Your name, email address and profile image, when you sign in with Google.
  • Whatever you type into our contact form or the waitlist.
  • What you say to the onboarding agent while you are building your AI: the description of the job, and what you want your AI to know about and refuse to do.
  • Your computer's specifications, if you let us detect them, so we can recommend a model that will actually run well on it.
  • The devices and groups you register on your account, so the app can manage them.
  • Payment details, which go straight to Stripe. We never see or store your card number.

Not on that list, deliberately: the documents themselves. They are read and indexed by the app on your own machine and are never uploaded to us.

Things we collect automatically

  • Server logs: your IP address, the pages you asked for, and when.
  • Your browser and operating system.
  • Which features you use, and your subscription record: your tier, when it renews, and what you have paid.

Things we collect from somewhere else

Sometimes we end up holding information that did not come from you. That has its own section below, because a new part of the Privacy Act now governs it.

05Information about other people

If you ask the onboarding agent to gather knowledge from the web, such as public recipes, product manuals or industry guides, it fetches that material and puts it in your knowledge base. Sometimes that material contains personal information about people who have never heard of Ngaro.

Since 1 May 2026, information privacy principle 3A of the Privacy Act 2020 has required agencies that collect personal information indirectly to take reasonable steps to make the person concerned aware of it. Much of what the agent gathers is already publicly available, which is one of the exceptions. Not all of it is. So here is how we handle it.

  • The agent prefers publicly available sources.
  • Before your build finishes, you are shown every source in the knowledge base editor and have to approve the list. Nothing is gathered invisibly.
  • You can remove any source at any time, during the build or years later.
  • You are responsible for what you direct the agent to collect, and for having a proper basis to hold information about other people.

If you think we hold information about you that arrived this way, email ngaro.help@gmail.com and we will tell you what we have and remove it.

06Cookies and tracking

We run no analytics. We set no tracking cookies. There is no advertising pixel on this site and no third party watching you move around it.

The only cookies we set are the session and authentication cookies that make signing in work. Without them you could not stay signed in.

One honest caveat: this site loads the Geist typeface from Google Fonts, so Google receives your IP address when a page loads. We intend to serve the fonts ourselves and remove that.

07Why we use it

  • To give you what you asked for: building your AI, answering its questions if you are on a hosted tier, and letting your own devices find each other.
  • To bill you: your subscription, invoices, and the tax records we are required to keep.
  • To keep the service working: diagnosing faults, preventing abuse, enforcing rate limits.
  • To answer you: when you email us or fill in the form.
  • To email you about Ngaro: only if you asked us to, and you can stop it at any time.

Where the law asks us to name a legal basis, the first four are performing our contract with you or our legitimate interest in running a functioning business, and the last is your consent.

08Who else touches it

We use other companies to run parts of the service. Here is the complete list, what each one does, and where it is.

WhoWhat forWhere
GoogleSign-in only. The typeface on this site is served from our own domain, so visiting these pages does not call Google at allUnited States
StripePayments and invoicesUnited States / Australia
SupabaseContact form and waitlist entriesSydney, Australia
ResendSends us the notification email when you join the waitlist. It handles the message, not the listUnited States
RunPodGPU compute for hosted model inference, on their vetted Secure Cloud tier rather than community hosts. Your question and the passages sent with it are processed and never storedUnited States / Europe
AnthropicThe onboarding agent, during your build session only. It is sent what you type to it, and never your document contentsUnited States
Brave SearchWeb search, and only when you turn the search toggle onUnited States

Two rows deserve saying out loud rather than leaving in a table.

RunPod is where hosted answers are computed. It is given your question and the excerpts your own app retrieved, for as long as it takes to answer, and nothing else: not your account, not your document library, not your history. Nothing is retained there. If you are on the self-hosted tier this row does not touch you, because the model runs on your own machine.

The onboarding agent is a commercial AI model run by Anthropic, so what you type during a build session is processed by them under their terms. That is the one moment in the whole product where an outside AI vendor is involved. Your document contents are not part of it: the agent is told what you have, not what is in it. The AI you end up with does not work this way at all. It runs on an open-weight model, on your machine or on our compute.

We do not sell, rent, trade or licence personal information to anyone. There are no advertising networks, no data brokers, and no analytics companies in this list. If that ever changed we would have to tell you, and we would rather not have to.

09Sending information overseas

Information privacy principle 12 of the Privacy Act governs sending personal information to someone outside New Zealand. Several of the companies in the table above are outside New Zealand, so this applies to us and it is worth being direct about it.

That table is the complete list, and there is no longer one hiding elsewhere. Each of those companies is contractually required to protect what we send them to a standard comparable to the Privacy Act. Where a country's own law is weaker than New Zealand's, the contract carries the obligation instead.

What crosses the border is worth being precise about, because it is not what people usually assume. Your documents and your knowledge base do not: they sit on your own machine, wherever that is, and are never sent to us or to anyone in that table. What crosses the border on a hosted tier is a question and the excerpts your app selected to answer it, sent for processing and not kept. On the self-hosted tier not even that leaves during a conversation.

10The web search toggle

Every AI built on Ngaro has a switch that decides whether it can search the web during a conversation. It is off when you get it, and we never turn it on for you.

Off means it answers only from the documents you gave it. This is enforced by the application rather than by an instruction to the model: with the toggle off, no search tool is handed to it. It is not asked politely to behave, it is given no way to search.

On means your questions, or queries derived from them, can reach the search provider named in section 08, so they leave your machine. That is the trade, it is yours to make, and you can change it back at any time from the settings panel.

Either way this switch has no bearing on where your documents live, and it is not an offline mode for the app. The app signs in and checks your subscription regardless of how the toggle is set.

11Your API key

Your finished AI can issue an API key so your other software can talk to it. We log requests made with that key, including timestamps, volume and whether they succeeded, so we can apply rate limits and spot abuse. We do not log the contents of your prompts or the answers.

Once you give that key to another tool, whatever that tool does with your data is between you and them. We cannot see it and we cannot control it. There is more on this in the terms of service.

12What we never do

  • We do not train any model on your documents, your conversations, or anything else of yours.
  • We do not read your documents for any purpose other than answering your own questions with them.
  • We do not sell, rent or trade your information.
  • We do not use your content to improve our product, benchmark it, or demonstrate it.

This is not a promise we are making reluctantly to satisfy a regulator. It is the reason the product exists. A version of Ngaro that mined your documents would have no reason to be built.

13How long we keep things

WhatHow long
Your documents, knowledge base and conversationsWe never receive them, so we never hold them and never delete them. They are on your machine and they stay there
Questions and passages sent for hosted inferenceHeld in memory only, for the length of the request. Not written to disk
Account, device and subscription detailsWhile your account is open, then 30 days
BackupsPurged on their own rolling cycle, which runs behind live data
Billing and tax records7 years, because New Zealand tax law requires it
Server and API logs90 days
Waitlist entriesUntil we launch, or until you unsubscribe
Contact form messages24 months

The first row is the one that used to read differently, and it is worth pausing on: there is no retention period for your documents because there is no retention. Closing your account does not start a clock on your material, and it does not take it away from you either.

The backup row is the honest one. When you delete something it goes from the live service immediately, but backups are taken on a schedule and a copy can survive in one until that backup rolls over. Any service that claims instant and total erasure either does not take backups or is not telling you the truth.

You can ask us to delete your information sooner. See your rights.

14Security

Everything travels over encrypted connections. Data we hold for you is encrypted at rest. Access is limited to the people who need it to keep the service running, and we keep that number small.

The architecture has an advantage no amount of security engineering can match: data that never reaches our servers cannot be taken from our servers. A breach of Ngaro would expose account and billing records. It would not expose anybody's documents, on any tier, because we do not have them. If even the transit involved in hosted inference is more than you want, the self-hosted tier sends nothing at all during a conversation.

And the limit. No system is perfectly secure, ours included. Anyone who tells you their service cannot be breached is selling something. What we can promise is that we hold as little as possible, that we encrypt what we hold, and that if something goes wrong you will hear it from us.

15If something goes wrong

If there is a privacy breach and it is likely to cause serious harm, the Privacy Act 2020 requires us to notify the Office of the Privacy Commissioner and the people affected as soon as we reasonably can. We will do that, and we will tell you what happened rather than what our lawyers would prefer we said.

We will notify you within 72 hours of becoming aware of a breach that affects you. The GDPR requires that of us for users it covers. We apply it to everybody, because a deadline that depends on which country you live in is a strange thing to offer, and because "as soon as we reasonably can" is the kind of phrase that quietly stretches. The same commitment is stated on the security page.

16Your rights

The Privacy Act gives New Zealanders the right to see what we hold about them and to have it corrected. Other countries give people more. Rather than sorting you by passport, we give everyone the same set, wherever you live:

  • See it: ask what we hold about you and get a copy.
  • Correct it: tell us when it is wrong and we will fix it.
  • Delete it: ask us to erase it, subject to records we are legally required to keep.
  • Take it: get your account record in a portable format. Your documents and knowledge base need no request, because they are already on your own machine.
  • Object: tell us to stop a particular use.
  • Withdraw consent: for anything you consented to, at any time.
  • Complain: to us, and to a regulator.

Email ngaro.help@gmail.com. We reply within 20 working days, which is the limit the Privacy Act sets. Usually much sooner. We may need to check you are who you say you are first. Handing your account details to somebody who asked nicely would be its own privacy breach.

One thing we will not claim: Ngaro is a New Zealand company and we have not appointed a representative in the EU or the UK. We give you the rights above because they are the right rights, not because we have certified anything. If that changes we will say so here.

17Complaints

Come to us first at ngaro.help@gmail.com. Most things are a misunderstanding and take one email to sort out.

If we cannot resolve it, you can complain to the Office of the Privacy Commissioner at privacy.org.nz, or on 0800 803 909. You do not need our permission and you do not need to tell us first, though it usually helps.

If you live somewhere with its own privacy regulator, you can complain to them instead.

18Children

Ngaro is for people aged 16 and over. We do not knowingly collect information from anyone younger. If we find out we have, we delete it. If you think a child has given us their information, email us and we will deal with it.

19Emails from us

We only send marketing email to people who asked for it. Every one of those emails has a working unsubscribe link, and we action unsubscribes within five working days, which is what the Unsolicited Electronic Messages Act 2007 requires, and also just basic manners.

Service messages are different: invoices, security notices, a warning that your free hosting period is about to end. Those are part of the service and you cannot opt out of them while your account is open.

20Changes to this policy

We will update this page as the product grows. The date at the top always tells you when it last changed.

If a change materially affects how we handle your information, we will email account holders before it takes effect rather than quietly editing the page and hoping nobody notices.

21Contact us

Questions, requests, complaints, or a correction to something on this page: ngaro.help@gmail.com.

Ngaro is based in Auckland, Aotearoa New Zealand.

NGARO
NGARO

Ngaro: to be hidden, unseen. A private AI you build yourself and keep on your own machine. Made in Aotearoa New Zealand.

Join the waitlist

Product

How it works Your API FAQ

Company

Join the waitlist About Blog

Legal

Privacy policy Terms of service Security

© 2026 Ngaro. All rights reserved.

PrivacyTermsngaro.help@gmail.com