Data location statement

Your database is the permanent record of every message. We keep an encrypted copy of recent messages (7 days by default, down to 24 hours) to deliver, sync and retry, plus the IDs and memberships needed to route them. Encrypted backups of our database are kept for 7 days. Files go directly to your own Cloudinary account when you connect one (otherwise to ours).

What lives where (your own database)

Data Your database Our infrastructure Retention on our side
Message content, metadata, attachment refs Permanent system of record Encrypted buffer Until replicated AND older than window (default 7 d; 24 h–30 d). Never purged while un-replicated
Edits, deletes Version-guarded upserts, tombstones Buffer Same
Conversations, membership Mirror Authoritative Lifetime
Users Mirror (id, name, image_url, metadata) user ID required; name/avatar optional Lifetime
Read / delivery watermarks Mirror (last_read_seq) Authoritative Lifetime of membership
Attachment files References only (in messages.attachments); files are on Cloudinary — your own account if connected, otherwise ours Cloudinary public ID + metadata (name, size, type, dimensions) n/a
Push device tokens No Encrypted Until invalid / unregistered
Presence, typing No Redis memory Seconds
Webhook payloads, logs No Yes 72 h / 14 d
Usage counters No Aggregates 13 months

Managed mode: the same data in our database, no expiry, export via API anytime. Managed-mode files are stored with our media provider.

Where data lives and for how long

Data Where How long
Our database (content buffer, metadata, Managed-mode messages) Our servers in the chosen data center (EU or US) Buffer: 7 days default (24 h–30 d), never purged before replication; Managed: until deleted
Database backups Cloudflare R2 bucket with EU jurisdiction (or US, matching our servers), encrypted 7 days (rolling)
Attachment files (no own media account) ByoTalk's Cloudinary account, folder byotalk/<env_id> Until deleted
Attachment files (own storage connected) Your own Cloudinary account, S3-compatible bucket or Azure Blob container You decide
Messages with your own database enabled Your PostgreSQL, MySQL/MariaDB or MongoDB database, or wherever your HTTP endpoint stores them You decide
Logs (no message text) Our servers + observability provider 14 days
Webhook payloads Our database 72 hours

Erasure: deletions apply immediately in our live database and propagate to your database; copies in encrypted backups expire within 7 days. The DPA states this.

Push previews pass through our push worker and FCM/APNs unless the environment's push preview setting is none; with none, message text never reaches Apple or Google.

For delivery, ByoTalk provides at-least-once delivery with automatic de-duplication by clientMsgId and webhook webhook-id.