Your Data Is Yours
Better Messages stores all messaging data in your WordPress database. The WebSocket relay routes encrypted events to facilitate real-time delivery. It never stores message content or conversation history, and the little it keeps to deliver messages (which user is in which conversation, delivery and read times) is listed below. You maintain full ownership and control of your data.
Data ownership is preserved even when using the WebSocket-version cloud relay. The cloud is a router, not a database.
What it adds#
- All messages stored in your WordPress database only — no external data store
- No message content ever stored on WebSocket servers
- Message content, attachment details, link previews, translations, conversation names and user profiles cross the relay encrypted with your site's own key, which the relay does not have
- The relay keeps only routing data: who is in which conversation, unread counts, and message IDs with their delivery and read times for 7 days
- Full data portability — export, backup, migrate via standard WordPress tools
- GDPR data sovereignty compliance built-in
Data location matrix#
| Data type | Location |
|---|---|
| Message content (text, formatting) | Your WordPress database (wp_bm_message_messages table) |
| Attachments / files | Your WordPress media library (uploads folder) |
| User profiles | Your WordPress wp_users + custom fields |
| Conversation metadata (participants, subjects, timestamps) | Your WordPress database |
| Reactions, mentions, pinned messages | Your WordPress database |
| Read receipts, delivery statuses | Your WordPress database |
| Routing data on relay | Conversation membership and unread counts while in use; message IDs, senders and times for 7 days, for delivered and read statuses |
| Profile cache on relay | Display name, avatar and profile URL encrypted with your site's key, plus hashed role names — 24 hours, renewed while the user is connected |
| Mobile push tokens on relay | Kept so pushes can be sent to the app |
| AI bot conversation content | Routed through AI provider (OpenAI / Anthropic / Google) per their terms |
What the relay can read#
Everything the relay forwards in a conversation is encrypted with your site's own key: message text, attachment details, link previews, translations, transcriptions, locations, conversation names and the names, avatars and profile links of users, including on call screens. The relay never has that key. Every logged-in user's browser does, so this encryption protects your data from the relay, not from your own users.
A few things the relay has to read to do its job:
- Routing data: user IDs, conversation IDs, message IDs and times.
- Push notifications: when they are enabled, their title and text, because the relay hands them to Apple, Google or the browser's push service.
- Calls: who is in a call and for how long.
- AI features (translation, moderation, AI bots): only if you enable them, the text they work on.
How it works#
When a message is sent:
- Browser → your WordPress server: the message text and metadata
- Your server: stores the message in the database, then encrypts a routing payload
- Your server → WebSocket relay: pushes the encrypted payload with routing info (user IDs, thread ID)
- Relay → all participants' browsers: forwards the encrypted payload
- Relay: discards the payload after forwarding, keeping only the message's ID, sender and time for delivered and read statuses
- Recipient browsers: decrypt and render the message
The relay is stateless for message content — it has no persistent storage of what a message says.
When data ownership matters most#
| Use case | Why it matters |
|---|---|
| GDPR / DSAR requests | You can export and erase data without involving third parties |
| Site migration | Standard WordPress backup/restore preserves all chat history |
| Compliance audits | Single point of data residence is auditable |
| Self-hosted requirements | Combine with the self-hosted plan for full sovereignty |
| Data residency rules | Data stays in your hosting's region (the relay routes ephemeral packets only) |
Frequently asked questions#
What if the WebSocket relay is breached?#
A breach of the relay would expose only encrypted packets (which would still need AES-256 and your site's key to decrypt), routing metadata (user IDs, conversation IDs, message IDs and times), push notifications in transit, and the encrypted profile cache. Historical messages, profiles, and attachments are not at risk — they're on your server.
Can I migrate away from Better Messages and keep my data?#
Yes — all data is in standard WordPress tables. Export via WordPress's built-in tools or directly from the database. The plugin doesn't lock you in.
What about voice / video calls?#
Call metadata (participants, duration, started time) is stored in your WordPress database. The actual audio/video streams flow peer-to-peer (for 1-on-1) or through the media server (for groups) — never stored anywhere.
Does AI bot content stay in my database?#
The AI conversation itself (user message + bot response) is stored in your database like any conversation. But the user's message is also sent to the AI provider's API (OpenAI / Anthropic / Google) to generate the response — that's a one-time transit, subject to the AI provider's terms.
How does the self-hosted plan differ?#
The self-hosted plan moves the WebSocket relay onto infrastructure you control. The data ownership pattern is the same (data stays in your DB), but the relay infrastructure also stays on your servers — useful for very strict data-sovereignty requirements.
See also#
- Privacy & GDPR — full privacy posture
- Servers location — where the relay servers run
- Self-hosted plan — for strict data-sovereignty needs
- Auto-delete messages — retention policy
- End-to-end encryption — content-level protection