> ## Documentation Index
> Fetch the complete documentation index at: https://developers.workchats.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data & security

> Where message content lives, and what deleting it does

Messages your App sends can carry personal data — names, emails, phone
numbers, whatever you put in `text`, `blocks`, or `metadata`. For your own
data-processing records:

<Info>
  Stored in AWS eu-west-2 (London). No automatic expiry: messages are kept
  until deleted. Deleting a message removes it from all clients and APIs
  immediately. Notifications already delivered to devices are not recalled.
</Info>

## What that means for you

* There's no automatic message expiry. If your product needs a message
  removed, call [`DELETE /v1/messages/{id}`](/guides/sending-messages#delete)
  — don't rely on time to do it for you.
* Deletion is immediate and visible everywhere: every Workchats client and
  every API response stops showing the message's content right away.
* A push notification that already reached someone's phone or desktop
  before you deleted the message isn't recalled. If a message shouldn't
  have gone out at all, deleting it stops it from being read going forward,
  but can't un-notify someone who already saw the push.
* `metadata` is stored with the message and isn't secret from anyone who
  can read the message. Don't put credentials or anything you wouldn't want
  a conversation member to see in it.

## Keep the footprint small

Send only what the message needs. If a field isn't shown to the recipient
and isn't needed for your own callback handling later, it doesn't need to
be in `metadata`.
