cometchat-compliance

v2026.09.25

Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery records. Cross-family: all server/REST/dashboard-side. Triggers: 'is cometchat GDPR compliant', 'delete a user and their data', 'right to be forgotten', 'export a user's data', 'data residency EU', 'which region', 'message retention policy', 'audit log', 'eDiscovery', 'HIPAA/SOC2 chat', 'compliance review'.

GitHub
Install command
npx skhub add cometchat/cometchat-compliance
Markdown
SKILL.md

Ground truth: REST shapes are FETCHED from the live docs — {DOCS_BASE}/rest-api/users/delete (erasure), /rest-api/messages, /rest-api/conversations (access/export), /articles/properties-and-constraints (regions, retention behaviour), /moderation/reviewed-messages (audit). DOCS_BASE = https://www.cometchat.com/docs; append .md. Where a control is a dashboard setting or a sales/plan item (a managed retention policy, a signed BAA, certifications), this skill says so plainly rather than inventing an API. Certification status (SOC 2, ISO 27001, HIPAA) is a business fact — confirm current scope at {DOCS_BASE}/the trust page, don't assert it from here.

Use this skill when

A privacy/security/compliance review, a data-subject request (delete/export), choosing where data lives, or planning retention and audit. All actions here are server-side; there is no client code to write.

1. Data residency — choose the region up front

CometChat hosts each app in one region: us, eu, or in ({DOCS_BASE}/rest-api/chat-apis → Data Center Hosting — re-fetch before quoting to a customer; regions can be added). The region is fixed to the app and is part of every API/SDK endpoint (https://{APP_ID}.api-{REGION}.cometchat.io/v3, and the SDK init region). To keep EU data in the EU (GDPR) or meet a residency clause, create the app in that region — you cannot silently move an app's region afterward; migrating regions means a new app + a data migration (cometchat-migrate-from-* machinery / CometChat support). For full data sovereignty (your own infrastructure), see cometchat-self-host.

2. Right to erasure (GDPR Art. 17 / CCPA delete)

Call the REST Delete User endpoint (DELETE https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}; see the docs at {DOCS_BASE}/rest-api/users) with the REST API Key:

  • Default (no body) → deactivates the user (recoverable; keeps data).
  • { "permanent": true } → permanently deletes the user with all their messages, conversations and associated data. Irreversible.
DELETE https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}
apikey: {REST_API_KEY}
content-type: application/json

{ "permanent": true }

Wire this to your account-deletion flow so a "delete my account" request erases the user in CometChat too. Also flush their auth tokens (cometchat-security) so no session lingers.

3. Right of access / portability (data export)

To answer a data-subject access request, export the user's data server-side via REST and hand it over in a portable format:

  • their messages — the Messages REST collection ({DOCS_BASE}/rest-api/messages, filtered by the user);
  • their conversations — {DOCS_BASE}/rest-api/conversations;
  • their profile — the Users API. Run it with the REST API Key from a server job; never expose these to the client. Fetch the exact filter params from the docs before writing the exporter.

4. Retention & purge

CometChat keeps messages until they are deleted. Behaviour to know (/articles/properties-and-constraints): soft-deleted messages are retained; messages permanently deleted via the API are not. To enforce a retention window:

  • run a scheduled server job that deletes messages/conversations older than your policy via the REST APIs (delete-message / delete-conversation / user permanent-delete);
  • a managed/automatic retention policy (auto-purge at N days) is a dashboard/plan capability — confirm availability and configure it with CometChat rather than assuming an API. Do not invent a retention endpoint.
  • on-prem gives you full control of storage lifecycle and backups (cometchat-self-host).

5. Audit & eDiscovery

  • Moderation audit trail: the dashboard's Moderation → Reviewed Messages records moderator activity and decisions for compliance ({DOCS_BASE}/moderation/reviewed-messages); pair with cometchat-moderation.
  • eDiscovery / legal hold: export the relevant conversations and messages via the REST collections above (by user, group, or time range) — that is the supported way to produce chat records; there is no separate "eDiscovery API." For a legal hold, export before any retention purge runs.
  • Webhooks ({DOCS_BASE}/rest-api/management-apis/webhooks/overview) can stream message/user events to your own immutable audit store in real time if you need a tamper-evident log outside CometChat.

6. Certifications & agreements (business, not code)

SOC 2, ISO 27001, HIPAA (with a BAA), GDPR/CCPA posture, and pen-test reports are handled through CometChat's trust/compliance process, not the API. Point the reviewer to the current trust page and get agreements in writing; encryption in transit (TLS) is standard, and at-rest/e2e options + key management vary by plan/deployment — confirm the specifics for the customer's plan.

Common pitfalls

  1. Region chosen by accident — the default is us; an EU customer needs the app created in eu from day one.
  2. "Delete" that only deactivates — omitting permanent: true leaves the data; erasure requests need the flag.
  3. Deleting the user but leaving live sessions — also flush auth tokens (cometchat-security).
  4. Assuming an automatic retention policy exists — implement purge via REST/on-prem, or confirm the managed setting; don't invent it.
  5. Asserting a certification from memory — verify current SOC 2 / HIPAA / ISO scope with CometChat.

Verify it works

A test user permanently deleted returns success and their messages/conversations are gone · an access-request export produces the user's profile + messages + conversations · the app's region matches the customer's residency requirement · a retention job (or the confirmed managed policy) removes data past the window · moderation decisions appear in Reviewed Messages · webhooks (if used) land audit events in your store.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.25

Published

Sep 25, 2026

Category

Uncategorized

License

MIT

Source path

skills/cometchat-compliance

Default branch

main

Latest commit

f92ff9e

Tree SHA

f40470f