Privacy Mode
Open in CMSPrivacy mode makes an organization's conversation content unreadable after a short window β not just hidden from a report, but gone. Once it expires, nobody can read it again: not a contributor, not an Admin, not an Owner, not even Qlar's own platform team.
It is off by default. Turning it on only protects messages sent from that moment on β it is not retroactive.
What privacy mode does
While it is on:
- Every new message is encrypted as soon as it's stored.
- The message stays readable for a retention window that resets every time a new message arrives in that conversation.
- No matter how long the conversation keeps going, content older than a hard cap is deleted regardless.
- Once a message's window closes, its content is replaced everywhere with a placeholder. This cannot be undone β there is no way to recover it, by anyone.
Mental model: think of it as a self-destructing note, not a lock with a key someone could be given. Nobody holds a master key β not your organization's Owners, not Qlar's support or engineering teams.
Where to find it
Open the Organization page β click your organization β open the Privacy tab.
Turning it on
| Setting | What it controls | Range | Default |
|---|---|---|---|
| Retention (hours) | How long a conversation stays readable after its last message. Every new message pushes this back out. | 1β168 | 24 |
| Hard cap (days) | The absolute limit, counted from a conversation's first protected message β content is deleted by this point even if the conversation is still active. | 1β30 | 7 |
Set the retention and hard cap you want, then switch Privacy mode enabled on and click Save privacy settings. A confirmation dialog, Turn on privacy mode?, asks you to confirm before it takes effect β click Turn on.
Who can manage this? Only Owner and Admin.
What changes when it's on
- Organization staff, including Owners and Admins, can never read conversation content. Transcripts and conversation analysis show no content.
- Personalization (what agents remember about people) is not saved.
- Query logging for the SQL DB Reader plugin is turned off.
- Sending canvases to WhatsApp during voice calls is turned off.
- Statistics are still kept: message counts, tokens, channels, times, and user IDs.
Each of these is explained on its own page β see Related pages below.
Keeping the conversation service in sync
Your setting is saved on the Organization page, but it's a separate service β the one that actually runs your agents' conversations β that has to receive and enforce it. The Privacy tab shows a status banner so you can confirm the two are in agreement:
| Banner | Meaning |
|---|---|
| Conversation service: up to date | The setting is active and being enforced. |
| Conversation service has not received the latest setting | Enforcement is behind. Click Resend. |
| Could not check the conversation service | The status itself couldn't be checked; try again shortly. |
If you just changed the setting and the banner has not caught up yet, wait a few seconds and refresh before clicking Resend.
Turning it off
Turning privacy mode off stops protecting new messages. It does not restore anything:
Warning: messages that were already protected keep counting down and still expire on schedule, whether privacy mode is on or off at that moment. Turning the setting off and back on never brings back content that has already been removed.
How this is different from Conversation history access
Managing Agent Access has a Conversation history switch on each contributor's card. That switch decides which contributors are allowed to open a transcript β the conversation itself is kept in full, and an Owner or Admin can always read it.
Privacy mode is a different kind of control:
- It applies to the whole organization, not one contributor at a time.
- It doesn't decide who is allowed to read β it makes the content genuinely unreadable to everyone, permanently, once the window closes.
- It works even against Owners and Admins, who are otherwise exempt from every other access permission.
The two are independent and can both apply to the same conversation: a contributor with Conversation history switched on can open a transcript right up until privacy mode's retention window closes it for good.
Worked example
Sehat Clinic handles patient questions about prescriptions through an agent. Some patients mention symptoms and medication details they don't want sitting in a system indefinitely.
Dina, an Owner, turns on privacy mode with a 24-hour retention and a 7-day hard cap. A patient chats with the agent over three days, asking follow-up questions each day β the retention window resets each time, so the conversation stays open for support to keep helping. On day 7, the hard cap kicks in regardless, and the whole conversation's content is replaced with a placeholder. If anyone β support staff, Dina herself, or Qlar's own team β opens that conversation afterward, there is nothing left to read.
Related pages
- Managing Agent Access β the per-contributor permission that decides who may open a transcript, independent of privacy mode
- Personalization β what agents remember about people, and why privacy mode turns it off
- SQL Database Reader β Usage Logs β the query logging that privacy mode disables
- Escalation β how escalation summaries and the supervisor console behave under privacy mode
- Voice β why canvas sharing to WhatsApp is turned off during a call