By Chopa AI LTD

Privacy Policy

Last updated: August 17, 2025

Your Privacy Matters

At Msgly.AI, we are committed to protecting your privacy. This policy explains how we collect, minimize, use, and safeguard your information.

1. Information We Process

We process limited categories of information to provide and improve our Service:

Data Type What We Process Purpose
Account Information Google account details (email, name) Account creation and authentication
Your LinkedIn Profile (one-time setup) Scan of your own LinkedIn profile once on first run (name, headline, company, roles, etc.) Initialize your account and personalize the experience
Target Profile Processing (user-initiated) When you click Analyze, we upload the page's full HTML and immediately apply a reduction pipeline (~93–96% size reduction; e.g., ~1.7MB → ~80KB) to extract minimal structured fields (e.g., name, headline, company, role dates/summary) Real-time message personalization
Usage Data Messages generated, feature toggles, reply-rate metrics Service reliability, analytics, and improvement
Technical Data IP (truncated where possible), browser type, device information Security and platform optimization

1.1 User-Initiated Processing

All target profile analysis occurs only after you click Analyze. The sole exception is a one-time automatic scan of your own LinkedIn profile on initial setup to initialize your account.

1.2 Data Minimization Pipeline

Before any AI processing, we remove images, scripts, styles, media, and irrelevant markup, leading to an average ~95% reduction (range 93–96%) of the page size (e.g., ~1.7MB → ~80KB). Only minimized, text-centric HTML is processed for extraction.

2. AI Processing & Data Handling

Our Services use advanced large language models (LLMs) for processing, including but not limited to OpenAI GPT-5 nano, OpenAI GPT-5 mini, OpenAI GPT-5 (full), and Google Gemini 1.5 Flash. Msgly reserves the right to change, replace, or add additional AI providers or models in the future, in accordance with applicable law and company policy.

2.1 What We Store (JSON only)

We do not store raw HTML. After extraction, we store only minimal JSON fields necessary to provide the Service (e.g., name, headline, company, role dates/brief summaries). Raw or minimized HTML is handled transiently and discarded after processing.

Target Data Handling

Target profile data is processed in a minimal, structured JSON form exclusively for internal purposes, including analytics, reply-rate measurement, AI model improvements, personalization, and enhancement of overall service quality. Target Profile details are never displayed to end-users and are not shared with third parties except as required by law or under strict data-processing agreements.

3. How We Use Information

Our Commitments

We NEVER:

4. Limited Interactions on LinkedIn

Runs only on linkedin.com/in/*. When you press Analyze, the extension may click "See more" inside the Experience section to reveal role details. This behavior is capped (limited number of clicks with delays) and does not navigate or interact elsewhere.

5. What You See in the Dashboard

6. Data Security and Protection

We implement industry-standard security measures to protect your information:

Encryption

Data in transit is protected with HTTPS/TLS encryption protocols.

Secure Storage

Minimal JSON is stored with least-privilege access controls and regular security audits.

Access Control

Access is restricted and monitored. Raw/minimized HTML is not logged.

Data Backup

Regular encrypted backups ensure your data is protected against loss or corruption.

SOC 2 Compliant Infrastructure
GDPR Compliant
SSL/TLS Encrypted

7. Data Sharing and Third Parties

7.1 Service Providers

We work with trusted third-party services to operate our platform:

7.2 Geographic Restrictions

We do not select vendors outside Israel, the EU, or the United States. All processors are bound by contracts to protect data and use it only to provide services to us.

7.3 Legal Requirements

We may disclose your information if required by law, such as:

8. Your Privacy Rights

You have comprehensive control over your personal data:

Right to Access

Request a copy of all personal data we have about you, including your stored LinkedIn profile information.

Right to Correction

Update or correct any inaccurate personal information in your account or profile data.

Right to Deletion

Request permanent deletion of your account and all associated personal data.

Data Portability

Export your data in a structured, commonly used format to transfer to another service.

Right to Object

Object to certain processing of your personal data, such as for service improvements.

Processing Restriction

Request limitation of processing your personal data under certain circumstances.

8.1 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@msgly.ai. We will respond within 30 days and may require identity verification.

9. Data Retention

We retain your information for different periods based on its purpose:

Data Type Retention Period Reason
Account Information Until account deletion Service provision
LinkedIn Profile Data Until account deletion Message personalization
Target Profile Data (JSON) As needed for Service and analytics Analytics and service improvement
Raw HTML Transient only Immediate processing and discarded
Usage Analytics 2 years maximum Service improvement and analytics
Security Logs 1 year maximum Security and fraud prevention

10. International Data Transfers

Your data may be processed in Israel, the EU, or the United States. Where required, we implement appropriate safeguards (e.g., Standard Contractual Clauses) for transfers to countries without an adequacy decision. We do not select vendors outside Israel/EU/US.

11. Distribution via Chrome Web Store & Google Policies

Our Chrome Extension is distributed exclusively through the Chrome Web Store and is subject to Google's policies, including the Google API Services User Data Policy. By installing or using the extension, you agree that your use is also governed by Google's terms and applicable Chrome Web Store requirements.

12. Google APIs – Limited Use Compliance

Use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Human access to Google user data is restricted and allowed only for security, fraud prevention, compliance, or where you explicitly request support.

13. Website Analytics and Advertising

Extension: The Chrome extension does not include analytics/ads.

Website: We may use analytics and advertising tools (e.g., Google Analytics, Google Ads/Remarketing, Google Tag Manager) on our website only to measure campaign performance and improve marketing.

13.1 Cookies We Use

14. California Privacy (CCPA/CPRA)

15. Right to Lodge a Complaint

If you are in the EU/UK, you have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated. We encourage you to contact us first so we can address your concerns.

16. Children's Privacy

Msgly.AI is not directed to children under 18 and we do not knowingly collect data from children. In compliance with COPPA (U.S.), we do not allow use by children under 13. If you believe we have collected data from a child, please contact us and we will delete it.

17. Independent Service

Msgly.AI is an independent tool and not affiliated with or endorsed by LinkedIn or any third-party platform.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will:

19. Contact Us

Privacy Inquiries

For any privacy-related questions or requests, please contact us:

20. Regulatory Compliance

This Privacy Policy complies with:

Your Trust, Our Priority

We are committed to privacy-by-design: user-initiated collection, aggressive minimization (~93–96%), no raw HTML storage, and minimal JSON retention. At Msgly.AI, protecting your privacy isn't just a legal requirement—it's fundamental to who we are.