Data location statement
Your database is the permanent record of every message. We keep an encrypted copy of recent messages (7 days by default, down to 24 hours) to deliver, sync and retry, plus the IDs and memberships needed to route them. Encrypted backups of our database are kept for 7 days. Files go directly to your own Cloudinary account when you connect one (otherwise to ours).
What lives where (your own database)
| Data | Your database | Our infrastructure | Retention on our side |
|---|---|---|---|
| Message content, metadata, attachment refs | Permanent system of record | Encrypted buffer | Until replicated AND older than window (default 7 d; 24 h–30 d). Never purged while un-replicated |
| Edits, deletes | Version-guarded upserts, tombstones | Buffer | Same |
| Conversations, membership | Mirror | Authoritative | Lifetime |
| Users | Mirror (id, name, image_url, metadata) | user ID required; name/avatar optional | Lifetime |
| Read / delivery watermarks | Mirror (last_read_seq) |
Authoritative | Lifetime of membership |
| Attachment files | References only (in messages.attachments); files are on Cloudinary — your own account if connected, otherwise ours |
Cloudinary public ID + metadata (name, size, type, dimensions) | n/a |
| Push device tokens | No | Encrypted | Until invalid / unregistered |
| Presence, typing | No | Redis memory | Seconds |
| Webhook payloads, logs | No | Yes | 72 h / 14 d |
| Usage counters | No | Aggregates | 13 months |
Managed mode: the same data in our database, no expiry, export via API anytime. Managed-mode files are stored with our media provider.
Where data lives and for how long
| Data | Where | How long |
|---|---|---|
| Our database (content buffer, metadata, Managed-mode messages) | Our servers in the chosen data center (EU or US) | Buffer: 7 days default (24 h–30 d), never purged before replication; Managed: until deleted |
| Database backups | Cloudflare R2 bucket with EU jurisdiction (or US, matching our servers), encrypted | 7 days (rolling) |
| Attachment files (no own media account) | ByoTalk's Cloudinary account, folder byotalk/<env_id> |
Until deleted |
| Attachment files (own storage connected) | Your own Cloudinary account, S3-compatible bucket or Azure Blob container | You decide |
| Messages with your own database enabled | Your PostgreSQL, MySQL/MariaDB or MongoDB database, or wherever your HTTP endpoint stores them | You decide |
| Logs (no message text) | Our servers + observability provider | 14 days |
| Webhook payloads | Our database | 72 hours |
Erasure: deletions apply immediately in our live database and propagate to your database; copies in encrypted backups expire within 7 days. The DPA states this.
Push previews pass through our push worker and FCM/APNs unless the environment's push preview setting is none; with none, message text never reaches Apple or Google.
For delivery, ByoTalk provides at-least-once delivery with automatic de-duplication by clientMsgId and webhook webhook-id.