Connector Privacy Notice
Last updated: August 28, 2026
This notice describes how Teambox handles your data when you connect a third-party AI assistant to your workspace through our Model Context Protocol (MCP) connector. It supplements our main Privacy Policy — if there is any conflict, the main Privacy Policy governs.
1. What is the Teambox Connector?
The Teambox Connector is a Remote MCP server that lets an authorized AI assistant (such as Claude by Anthropic) read from and act on your Teambox WhatsApp CRM on your behalf. Actions include listing conversations, sending replies, tagging contacts, and viewing campaign analytics.
2. What data can the Connector access?
When you authorize a Connector, you grant it the specific scopes shown on the consent screen. Scopes control what the connected AI can see or do:
- read — view conversations, messages, contacts, tags, campaigns, and analytics for the organization you signed in as.
- write — send WhatsApp replies, resolve conversations, tag contacts.
- campaigns — view campaign performance data.
- offline_access — issue a refresh token so the connection persists across sessions (up to 60 days).
Scopes are enforced at the API layer. A token can never access data outside the organization it was issued for, or perform actions beyond the scopes it was granted.
3. What data leaves Teambox?
Each time the connected AI calls a tool, we return only the data that tool is designed to return. For example, when Claude calls list_conversations, we return the requested subset of conversation summaries — not your entire database.
The connected AI provider (e.g. Anthropic) processes tool responses under their own privacy policy and terms. Data sent to Anthropic through Claude is subject to their Privacy Policy and Consumer Terms.
Under Anthropic's consumer terms, prompts and tool responses on claude.ai are not used to train models by default. Please review their policies for the most current terms.
4. What data does not leave Teambox?
- Your Teambox account password or authentication token.
- Meta / WhatsApp Business API credentials and access tokens.
- Data from other organizations.
- Billing information, team management, or user administration data.
- Anything the AI has not been given a specific tool to request.
5. Authentication and token security
- The connector uses OAuth 2.1 with mandatory PKCE (S256).
- Access tokens expire after 60 minutes. Refresh tokens (if granted) expire after 60 days.
- Only the SHA-256 hash of each token is stored in our database — we never store the raw token.
- All communication with the connector is transported over HTTPS/TLS.
6. Audit logging
Every tool call the connected AI makes is recorded in a per-organization audit log. The log captures:
- Which tool was called (e.g.
send_message) - The arguments passed to it
- Whether it succeeded, was denied, or errored
- How long it took
You can view your audit log at any time in Teambox → Settings → Integrations → Claude & AI Assistants.
7. Revoking access
You can disconnect any AI at any time from Settings → Integrations. Revocation takes effect immediately — the AI loses the ability to make any further tool calls. Previously received data remains subject to the AI provider's own retention policy.
8. Data retention
- Access tokens: kept until they expire (60 min) or are revoked. Revoked tokens remain as a hash for audit-trail integrity.
- Audit log entries: retained for the life of the organization, or until you delete your organization from Teambox.
- Registered OAuth clients: retained until you delete them, so we can recognize repeat connections from the same AI application.
9. Your rights
You retain all rights over data stored in Teambox. Consult our main Privacy Policy for information on data access, correction, deletion, and portability.
10. Contact
Questions about connector privacy? Contact us at support@teambox.app.
Teambox is operated by iProvider Pvt Ltd.