cometchat-compliance

SkillCommunication

Guides your agent through GDPR compliance tasks for CometChat like deleting users' data, exporting it, and picking a hosting region.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the cometchat-compliance skill

About this skill

Data governance & compliance for CometChat, pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery records. Cross-family: all server/REST/dashboard-side. Triggers: 'is cometchat GDPR compliant', 'delete a

What this skill tells your AI

The instructions your AI receives, as published by cometchat/cometchat-skills in skills/cometchat-compliance/SKILL.md and read by ahel’s review.

Ground truth: REST shapes are FETCHED from the live docs — {DOCS_BASE}/rest-api/users/delete (erasure), /rest-api/messages, /rest-api/conversations (access/export), /articles/properties-and-constraints (regions, retention behaviour), /moderation/reviewed-messages (audit). DOCS_BASE = https://www.cometchat.com/docs; append .md. Where a control is a dashboard setting or a sales/plan item (a managed retention policy, a signed BAA, certifications), this skill says so plainly rather than inventing an API. Certification status (SOC 2, ISO 27001, HIPAA) is a business fact — confirm current scope at {DOCS_BASE}/the trust page, don't assert it from here.

Use this skill when

A privacy/security/compliance review, a data-subject request (delete/export), choosing where data lives, or planning retention and audit. All actions here are server-side; there is no client code to write.

1. Data residency — choose the region up front

CometChat hosts each app in one region: us, eu, or in ({DOCS_BASE}/rest-api/chat-apis → Data Center Hosting — re-fetch before quoting to a customer; regions can be added). The region is fixed to the app and is part of every API/SDK endpoint (https://{APP_ID}.api-{REGION}.cometchat.io/v3, and the SDK init region). To keep EU data in the EU (GDPR) or meet a residency clause, create the app in that region — you cannot silently move an app's region afterward; migrating regions means a new app + a data migration (cometchat-migrate-from-* machinery / CometChat support). For full data sovereignty (your own infrastructure), see cometchat-self-host.

2. Right to erasure (GDPR Art. 17 / CCPA delete)

Call the REST Delete User endpoint (DELETE https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}; see the docs at {DOCS_BASE}/rest-api/users) with the REST API Key:

  • Default (no body) → deactivates the user (recoverable; keeps data).
  • { "permanent": true } → permanently deletes the user with all their messages, conversations and associated data. Irreversible.
DELETE https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}
apikey: {REST_API_KEY}
content-type: application/json

{ "permanent": true }

Wire this to your account-deletion flow so a "delete my account" request erases the user in CometChat too. Also flush their auth tokens (cometchat-security) so no session lingers.

3. Right of access / portability (data export)

To answer a data-subject access request, export the user's data server-side via REST and hand it over in a portable format:

  • their messages — the Messages REST collection ({DOCS_BASE}/rest-api/messages, filtered by the user);
  • their conversations — {DOCS_BASE}/rest-api/conversations;
  • their profile — the Users API. Run it with the REST API Key from a server job; never expose these to the client. Fetch the exact filter params from the docs before writing the exporter.

4. Retention & purge

CometChat keeps messages until they are deleted. Behaviour to know (/articles/properties-and-constraints): soft-deleted messages are retained; messages permanently deleted via the API are not. To enforce a retention window:

  • run a scheduled server job that deletes messages/conversations older than your policy via the REST APIs (delete-message / delete-conversation / user permanent-delete);
  • a managed/automatic retention policy (auto-purge at N days) is a dashboard/plan capability — confirm availability and configure it with CometChat rather than assuming an API. Do not invent a retention endpoint.
  • on-prem gives you full control of storage lifecycle and backups (cometchat-self-host).

5. Audit & eDiscovery

  • Moderation audit trail: the dashboard's Moderation → Reviewed Messages records moderator activity and decisions for compliance ({DOCS_BASE}/moderation/reviewed-messages); pair with cometchat-moderation.
  • eDiscovery / legal hold: export the relevant conversations and messages via the REST collections above (by user, group, or time range) — that is the supported way to produce chat records; there is no separate "eDiscovery API." For a legal hold, export before any retention purge runs.
  • Webhooks ({DOCS_BASE}/rest-api/management-apis/webhooks/overview) can stream message/user events to your own immutable audit store in real time if you need a tamper-evident log outside CometChat.

6. Certifications & agreements (business, not code)

SOC 2, ISO 27001, HIPAA (with a BAA), GDPR/CCPA posture, and pen-test reports are handled through CometChat's trust/compliance process, not the API. Point the reviewer to the current trust page and get agreements in writing; encryption in transit (TLS) is standard, and at-rest/e2e options + key management vary by plan/deployment — confirm the specifics for the customer's plan.

Common pitfalls

  1. Region chosen by accident — the default is us; an EU customer needs the app created in eu from day one.
  2. "Delete" that only deactivates — omitting permanent: true leaves the data; erasure requests need the flag.
  3. Deleting the user but leaving live sessions — also flush auth tokens (cometchat-security).
  4. Assuming an automatic retention policy exists — implement purge via REST/on-prem, or confirm the managed setting; don't invent it.
  5. Asserting a certification from memory — verify current SOC 2 / HIPAA / ISO scope with CometChat.

Verify it works

A test user permanently deleted returns success and their messages/conversations are gone · an access-request export produces the user's profile + messages + conversations · the app's region matches the customer's residency requirement · a retention job (or the confirmed managed policy) removes data past the window · moderation decisions appear in Reviewed Messages · webhooks (if used) land audit events in your store.

Signals

GitHub stars
120
Forks
2
Last commit
Sep 2026
Advanced
Item type
skill
Key
cometchat-compliance
Source
github.com/cometchat/cometchat-skills