This Privacy Policy explains how MsgBox ("we", "us", "our") collects, uses, stores, and protects personal information when you use our service. We are committed to protecting your privacy and complying with the Israeli Protection of Privacy Law 5741-1981 and the EU General Data Protection Regulation (GDPR).
MsgBox is an AI-powered chat widget platform operated by NBPlugins, based in Israel. We act as a data processor on behalf of website owners (our customers), and as a data controller for our customers' own account data.
For questions about this policy: support@nbplugins.com
| Data | Purpose | Retention |
|---|---|---|
| Email address | Login, password reset, service notifications | Until account deletion |
| Website domain | Widget configuration and verification | Until account deletion |
| Business information (name, description, hours) | AI chatbot context | Until account deletion |
| IP address (login) | Security, fraud prevention, IP lock | 90 days |
| Last login timestamp | Security monitoring | Until account deletion |
| Data | Purpose | Retention |
|---|---|---|
| Chat messages (encrypted) | AI response generation, conversation history | 90 days by default |
| Visitor IP address | Rate limiting, security, order lookup | 90 days |
| Browser language | Auto-translation of widget interface | Not stored independently |
| Session ID | Conversation continuity | 90 days |
| Contact form submissions (name, phone, email) | Lead delivery to site owner | 90 days |
We do not use your data or your visitors' data for advertising, profiling, or selling to third parties.
| Processing Activity | Legal Basis |
|---|---|
| Account management | Contract performance (Art. 6(1)(b)) |
| Service delivery (AI responses) | Contract performance (Art. 6(1)(b)) |
| Security & fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
We share data with the following sub-processors to deliver our service:
| Service | Purpose | Location |
|---|---|---|
| DeepInfra | Primary AI response generation | United States |
| Google (Gemini API) | Fallback AI response generation | United States |
| OpenAI | Widget UI translation only | United States |
| MailerSend | Transactional email delivery | EU / United States |
| Firebase (Google) | Push notifications to site owners | United States |
Each of these providers has their own privacy policy and data processing terms. International transfers to the US are covered by Standard Contractual Clauses (SCCs) where applicable.
Under GDPR and Israeli privacy law, you have the right to:
To exercise any of these rights, email us at support@nbplugins.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Israeli Privacy Protection Authority or your local supervisory authority.
See our Cookie Policy for full details. In brief: we use only essential session and login cookies — no tracking or advertising cookies.
MsgBox is not intended for use by persons under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
We may update this policy periodically. We will notify you of significant changes by email or through the dashboard. The "last updated" date at the top of this page reflects the most recent revision.
For privacy-related requests or questions:
Email: support@nbplugins.com
Website: msgbox.nbplugins.com