Chat does not keep a second domain list. If the page origin is not in the project's allowed domains, the bubble does not appear. How to edit the list is in Project settings.
Message content
ConsoleLive chatChat settingsPrivacy| Switch | Behavior |
|---|---|
| Mask sensitive data | Before storage, both sides' text is rewritten. Card numbers that pass a checksum, Chinese national ID numbers, Chinese mobile numbers, and numbers with an international prefix keep only the last 4 digits. Email is left as-is, because offline messages need it. The inbox marks the message as masked |
| Link preview cards | For a public link in the text, the server fetches title, description, and image and caches them for 24 hours. Private, local, and cloud-metadata addresses are not fetched |
Previews are only for public http and https URLs, with a timeout and a size cap. If the fetch fails or is refused, the message stays plain text. Attachment types and sizes are in Message types.
Showing the bubble writes nothing to browser storage. A session token is stored only after the visitor opens the chat. IPs are used in memory for rate limiting only and are not stored with the conversation.
Bans
From the inbox you can ban the current visitor for 1, 24, 72, 168, or 720 hours (720 hours is 30 days). During the ban they cannot send, and the current conversation is resolved. The reason is optional and visible only to agents. After you lift a ban, the visitor can send again immediately.
On the strict privacy preset the visitor ID rotates daily, so a ban effectively ends that day. Agent only members can ban by default. Who can change that is in Agents & routing.