The admin can see the private messages of the members

    Hello there,

    I noticed that the admin can see the private messages that the members send and receive. I think that this occur a lot of privacy concerns.

    What do you think about this?

    Furthermore is anything we can do in order the private messages to remain private?

  • danbp


    nobody forces the admin to read private messages, except, depending the country, some laws or other regulations. Any other reason to read is a personnal option.

    And it is anyway possible by reading the message table in the db.

    To disambiguate any further question around this, read the answer of @johnjamesjacoby



    Hi @danbp, @johnjamesjacoby

    Thank you for your response.

    Like @jetlej here I find horrible the idea that in a community the private messages can be read by the admin of the community.

    I don’t believe that a community would have a lot of registrations if the users knew that the admin has the option to read their private messages, even if he is not forced to do it.

    Anyway I see that there is no option to avoid this.

    P.S. Please, allow me to ask something: You said that it is also possible by reading the message table in the db. Does this mean that event the users passwords can be read from a table in the db?

    Thank you again for the conversation.



    No, passwords are encrypted !

    And for your misfortune, any thing encrypted can be decrypted ! With more or less effort, time and money.

    Are you living in a candy world ? 😉

    To avoid any temptation, the only option is to deactivate the private message component.



    Hi again,

    I wish I was living in a candy word but it seems that this world is not somewhere close 🙂

    At least for the passwords it will take some effort! 🙂

    But it would be your effort wouldn’t it? or have you given a whole heap of people access to your DB, I do hope not.

    I would suggest that the best way of looking at this is that messages are private only in the sense that they may not be publicly seen by others but that in order to run a site the owner/admin has to have access in full to all sorts of aspects, and state as such in a set of terms & conditions for site use.



    Hi @hnla,

    I respect your approach but I can’t totally agree :-). Anyway, your suggestion about the statement in a set of terms & conditions is the solution I all ready choose.

    Of course there is always @danbp’s solution about deactivating the private message component. It will “break” the community spirit though.

    Thank you all for sharing your thoughts on this 🙂

