Guide

Where does a password go after you send it by email, Slack or WhatsApp?

Email, Slack, Microsoft Teams, WhatsApp and text messages all keep your messages somewhere. Here is how long each one holds on to a password you sent, from their own documentation.

You needed to get a password to someone, so you sent it the quickest way you had: an email, a Slack message, a WhatsApp chat. They logged in, the job got done, everyone moved on.

The password didn’t. It’s still sitting in that conversation, and probably in a few other places you didn’t think about. Here’s where it goes, according to each service’s own documentation.

Email

An email lives in at least two places: your Sent folder and the recipient’s inbox. Each of those is copied to every phone, laptop and tablet that syncs the mailbox. Nothing removes them automatically. They stay until someone deletes them.

Deleting doesn’t finish the job either. In Gmail, a deleted message sits in Trash for 30 days before it’s permanently removed. Work and school accounts can be different again: organisations often keep their own copies of email for legal or compliance reasons, whatever you delete.

Slack

On Slack’s paid plans, messages and files are kept for the lifetime of the workspace by default, unless an administrator sets a shorter retention period. A password posted in a channel or a direct message stays searchable by everyone in that conversation for years.

Free workspaces are different: since August 2024, Slack shows only the last 90 days of history and deletes messages and files older than one year. That still means a year in which the password can be found.

Microsoft Teams

Microsoft’s documentation says Teams chats and channel messages are kept indefinitely by default, unless a user deletes them or an administrator applies a retention policy. In many organisations, retention policies are there to keep messages longer, not shorter, because of compliance rules.

WhatsApp

WhatsApp messages are end-to-end encrypted in transit, so WhatsApp itself can’t read them. But the password is stored in the chat on both phones, and it’s included in chat backups to Google Drive or iCloud. Those backups are only end-to-end encrypted if you’ve turned that option on.

WhatsApp’s disappearing messages help: you can set a chat to delete messages after 24 hours, 7 days or 90 days. The timer runs whether or not the message has been read, and the recipient can still screenshot or copy it before it goes.

Text messages and iMessage

SMS and iMessage conversations are kept on both phones until deleted, and often synced to other devices and cloud backups, such as Messages in iCloud. A text from a year ago is usually a quick search away.

The pattern

ChannelKept by defaultWho can find it later
EmailUntil both sides delete it, plus 30 days in Gmail’s TrashAnyone with access to either mailbox
Slack (paid)For the life of the workspace, unless changedEveryone in the conversation
Slack (free)Visible 90 days, deleted after 1 yearEveryone in the conversation
Microsoft TeamsIndefinitely, unless a policy says otherwiseEveryone in the chat, plus compliance tools
WhatsAppUntil deleted, plus backupsAnyone with either phone or the backup
SMS / iMessageUntil deleted, plus backupsAnyone with either phone or the backup

None of these services are doing anything wrong. They’re built to remember conversations, and that’s usually what you want. A password is the exception: the message stops being useful the moment it’s read, but it stays dangerous for as long as the password works.

A better habit

  1. Send the password as a one-time link, so the chat only ever contains a link that stops working after it’s opened. With TxtVanish, the link only opens when the recipient presses “Show message”, so chat previews don’t spend it.
  2. Split it up. Put only the password in the link, and send the username and website by another route.
  3. Add a link password for anything important, and tell it to them by phone.
  4. Check it arrived. If the link shows as opened and it wasn’t them, change the password straight away.
  5. For ongoing sharing, use a password manager. Family and team plans in password managers are built for passwords that several people need permanently.

Already sent passwords the old way? Search your chats and sent mail for words like “password”, “login” and “pw”, delete what you find, and change any password that’s still in use.

Ready to send one properly? Here’s how to share a password with a one-time link.

Sources

Questions

Is it safe to send a password by email?

The email itself is usually encrypted in transit, but it stays in the sender’s Sent folder and the recipient’s inbox until someone deletes it, and on every device that syncs that mailbox. Send a one-time link instead, and the password doesn’t sit in either mailbox.

Does deleting a chat message remove the password everywhere?

Not always. Deleting removes your copy, but backups, other people’s devices, synced computers and company retention policies can keep their own copies.

What is the safest way to share a password with family or a team?

For ongoing sharing, use a password manager’s built-in sharing. For a one-off, send a one-time link, tell them the link password by phone, and change the password if it was ever exposed.

Share something that shouldn’t stick around

Create a private link that self-destructs. Free, no account.

Create a message