Skip to main content

Your Data Is Yours

Better Messages stores all messaging data in your WordPress database. The WebSocket relay routes encrypted events to facilitate real-time delivery. It never stores message content or conversation history, and the little it keeps to deliver messages (which user is in which conversation, delivery and read times) is listed below. You maintain full ownership and control of your data.

WebSocket version

Data ownership is preserved even when using the WebSocket-version cloud relay. The cloud is a router, not a database.

What it adds#

  • All messages stored in your WordPress database only — no external data store
  • No message content ever stored on WebSocket servers
  • Message content, attachment details, link previews, translations, conversation names and user profiles cross the relay encrypted with your site's own key, which the relay does not have
  • The relay keeps only routing data: who is in which conversation, unread counts, and message IDs with their delivery and read times for 7 days
  • Full data portability — export, backup, migrate via standard WordPress tools
  • GDPR data sovereignty compliance built-in

Data location matrix#

Data typeLocation
Message content (text, formatting)Your WordPress database (wp_bm_message_messages table)
Attachments / filesYour WordPress media library (uploads folder)
User profilesYour WordPress wp_users + custom fields
Conversation metadata (participants, subjects, timestamps)Your WordPress database
Reactions, mentions, pinned messagesYour WordPress database
Read receipts, delivery statusesYour WordPress database
Routing data on relayConversation membership and unread counts while in use; message IDs, senders and times for 7 days, for delivered and read statuses
Profile cache on relayDisplay name, avatar and profile URL encrypted with your site's key, plus hashed role names — 24 hours, renewed while the user is connected
Mobile push tokens on relayKept so pushes can be sent to the app
AI bot conversation contentRouted through AI provider (OpenAI / Anthropic / Google) per their terms

What the relay can read#

Everything the relay forwards in a conversation is encrypted with your site's own key: message text, attachment details, link previews, translations, transcriptions, locations, conversation names and the names, avatars and profile links of users, including on call screens. The relay never has that key. Every logged-in user's browser does, so this encryption protects your data from the relay, not from your own users.

A few things the relay has to read to do its job:

  • Routing data: user IDs, conversation IDs, message IDs and times.
  • Push notifications: when they are enabled, their title and text, because the relay hands them to Apple, Google or the browser's push service.
  • Calls: who is in a call and for how long.
  • AI features (translation, moderation, AI bots): only if you enable them, the text they work on.

How it works#

When a message is sent:

  1. Browser → your WordPress server: the message text and metadata
  2. Your server: stores the message in the database, then encrypts a routing payload
  3. Your server → WebSocket relay: pushes the encrypted payload with routing info (user IDs, thread ID)
  4. Relay → all participants' browsers: forwards the encrypted payload
  5. Relay: discards the payload after forwarding, keeping only the message's ID, sender and time for delivered and read statuses
  6. Recipient browsers: decrypt and render the message

The relay is stateless for message content — it has no persistent storage of what a message says.

When data ownership matters most#

Use caseWhy it matters
GDPR / DSAR requestsYou can export and erase data without involving third parties
Site migrationStandard WordPress backup/restore preserves all chat history
Compliance auditsSingle point of data residence is auditable
Self-hosted requirementsCombine with the self-hosted plan for full sovereignty
Data residency rulesData stays in your hosting's region (the relay routes ephemeral packets only)

Frequently asked questions#

What if the WebSocket relay is breached?#

A breach of the relay would expose only encrypted packets (which would still need AES-256 and your site's key to decrypt), routing metadata (user IDs, conversation IDs, message IDs and times), push notifications in transit, and the encrypted profile cache. Historical messages, profiles, and attachments are not at risk — they're on your server.

Can I migrate away from Better Messages and keep my data?#

Yes — all data is in standard WordPress tables. Export via WordPress's built-in tools or directly from the database. The plugin doesn't lock you in.

What about voice / video calls?#

Call metadata (participants, duration, started time) is stored in your WordPress database. The actual audio/video streams flow peer-to-peer (for 1-on-1) or through the media server (for groups) — never stored anywhere.

Does AI bot content stay in my database?#

The AI conversation itself (user message + bot response) is stored in your database like any conversation. But the user's message is also sent to the AI provider's API (OpenAI / Anthropic / Google) to generate the response — that's a one-time transit, subject to the AI provider's terms.

How does the self-hosted plan differ?#

The self-hosted plan moves the WebSocket relay onto infrastructure you control. The data ownership pattern is the same (data stays in your DB), but the relay infrastructure also stays on your servers — useful for very strict data-sovereignty requirements.

See also#