Ops opens the meeting chat, chooses Everyone, pastes a database temporary password, and says “rotate it in ten minutes.” They click Leave. The next morning someone who never screenshotted the pane opens Teams Chat, finds the row with a calendar icon and the same title as the meeting, and the password is still there. Someone else uses only Tencent Meeting, opens Past Meetings, taps View all, and the same line sits in the local record. A third person started a Zoom cloud recording. Under Recordings they now have a chat TXT: Everyone messages in plaintext, no private chats.
An earlier piece covered if you put a meeting password in a calendar invite, what reminders, sharing, and sync still keep: that is “once the password is in the event description, can a guest copy or a lock-screen reminder still show it.” This piece asks a different question: once the password is in in-meeting chat, which leftover copies can you still open. If the secret instead travels on a one-time link, the shape is still s.html?id=…#…. Create and read need no account. MyPassGen’s tools open without sign-up. This is not a tour of meeting buttons. It is a walk through official help pages and what you can see in a chat list, a past-meeting pane, and a folder on disk.
Split two things first
Leaving the meeting only ends this call. The chat thread, past-meeting history, a locally saved chat file, and a cloud-recording TXT do not empty with it. Recalling or deleting your own bubble also does not reach a copy someone already saved, a frame already in a recording, or a line already in a transcript.
Why leaving the call does not erase the password
Meeting chat is not scratch paper that lives only while the call window is open. Common products keep it in at least three ways. Do not take the slogan of one product and guess the other two. The first kind binds chat to the calendar event: after the call, the conversation stays in the chat list and people can keep typing. Microsoft’s Chat in Microsoft Teams meetings writes it that way: you can view and send messages before, during, and after a meeting; after it ends, return to the chat to continue. Google calls the same idea Continuous meeting chat in Learn how to use Chat with Google Meet: on Business and Enterprise accounts, with the feature on, messages sync into Google Chat, and people in the same organization can open them before, during, and after the call.
The second kind drops a record into “past meetings” on the device or the account. Tencent Meeting’s in-meeting chat help says that after the call you can open All meetings or Past meetings, open details, then View all, and you will see the chat. You can also clear it. After a clear, the same page says the record cannot be recovered. That page also says the chat is saved locally and does not roam: leave and rejoin and you can still see what you already received; a second device that never synced may not have it.
The third kind is an optional sidecar file. Zoom’s Saving in-meeting chat splits “save chat” from “save chat with a cloud recording.” A local save writes the messages you can see, including private chats sent to you and messages to Everyone. A cloud save keeps only Everyone messages, and only for the stretch while cloud recording is on. Private chats do not enter that TXT. If nobody saved, and nobody started a cloud recording with the chat file enabled, that Zoom in-meeting chat usually has no after-call door — which is not the same thing as Teams leaving a thread by default.
So “the meeting ended, the password should be gone” first needs the product, whether anyone recorded, whether anyone saved, and whether this was a channel or meeting-group call. While the password is still in the live chat, someone else’s Save, export, or screenshot is another plaintext copy. A later recall does not rewrite the copy they already took.
Teams and Meet: chat that follows the calendar
The Teams after-call door is the chat list. The same official page says: after the meeting, open Chat and pick the row whose title matches the meeting and that starts with a calendar icon. Messages sent before the call are visible to everyone during and after it. Recurring meetings are blunt: the chat continues from one occurrence to the next. Open the window and you can read what the last slot already exchanged. A person removed from the series loses access to that chat. People who were only forwarded a single occurrence, or nudged in, sit on the side Microsoft lists as unable to keep after-meeting access. Anonymous guests outside the org sit there too.
Who stays in the thread also has a headcount. Microsoft’s Access meeting chat in Microsoft Teams writes: when a single-instance meeting ends, up to about 1,000 people keep permanent access; a series keeps permanent access for up to about 750 invitees at schedule time, plus up to about 250 people who join mid-series and get in-meeting access only. A contact list over 150 people is another cut: in a series, those members get in-meeting chat only — not before, not after. Channel meetings widen the audience a different way: channel meeting chats are available only to channel members. A member who never joined the call can still open the channel thread. Someone invited who is not a channel member cannot use that chat.
Hiding the row on your own list does not empty everyone else’s copy. Hide a chat, remove chat history or leave a chat thread says a participant can leave a meeting chat and tick the box that removes history from their own list and search. A meeting owner cannot delete or leave that meeting chat. Your Hide click leaves the organizer’s thread, and every other invited person’s thread, in place. If the tenant has a retention policy or eDiscovery hold, admin-side copies may exist as well. Trust your actual setting. Do not treat “I left the chat” as a wipe.
Google Meet’s default is more brittle. Help writes Continuous meeting chat for Business and Enterprise. When it is on, people in the host’s organization who are on the calendar invite can see the full history in the Chat conversation list, including if they join late. When it is off, or not offered, messages live only in the call and disappear when the meeting ends. Guests outside the organization, and people who are not signed in, see the chat only while they are in the call even if the host left continuous chat on; after the meeting their side of the messages is gone. Vault has a matching split: with continuous chat on, meeting conversations are saved as Chat spaces and follow Google Chat retention; if the host turns it off, in-meeting messages are not saved in Chat and are not under those Chat retention rules. Empty, unused meeting conversations may be auto-deleted within about 8 days of creation — that is an empty conversation, not “a password typed into the thread will burn itself.”
Tencent Meeting: past meetings and a local copy
Tencent Meeting does not, by default, turn in-meeting chat into a group you can keep typing in next week. Review lives under past meetings. The help page sends desktop users to All meetings and mobile users to Past meetings, then details, then View all. You can clear the record there. Official wording: after a clear, it cannot be recovered. That action clears this client’s copy. It does not promise the other person’s device is empty, it does not promise an enterprise archive is empty, and it does not promise an already-exported file is empty. Tencent Cloud’s English Viewing Past Meetings page adds the web-side window: records of meetings ended in the last 30 days can be retained on the web; the client does not use that same cap.
Roaming is a separate switch. Tencent Cloud’s past meetings notes say a personal account keeps at most the last 30 days under Ended meetings on the official site, and the client can look up in-meeting chat, recordings, annotations, and documents. After you turn on “sync past meetings,” only meetings from that point on sync across devices. Records from before the switch stay on the original machine. Turn sync off and each device keeps its own store. That is the same fact as “saved locally, does not roam”: a test password you can open on the office PC may be missing on a home laptop that never synced; the other way around, clearing the office client can leave the home copy sitting there.
Do not mix Everyone with a private chat. In-meeting chat can address Everyone or one person. On-screen captions, when they are on, push Everyone text onto the left or bottom of the picture. A private chat does not print the body on that overlay; it only hints that a private message arrived and should be read in the chat pane. A password sent to Everyone is visible to everyone still in the call, and the history keeps it under that audience. A password sent privately does not land in other people’s records when you leave, but the other person’s own past-meeting history can still keep that line. If an enterprise tenant has chat archive on, the open interface Export meeting chat records lets a user with meeting-admin rights export in-meeting public chat for same-enterprise meetings. Clearing your own pane does not close that admin door.
Zoom: Save Chat, auto-save, and the cloud TXT
Zoom in-meeting chat is not, by default, a Teams-style conversation that hangs in the chat list after you leave. Whether you can open it later depends on a save, or on a cloud-recording sidecar. Official local save: the ellipsis at the top of the chat pane, Save Chat, and the file lands in the local recording directory — by default a folder under Documents / Zoom named with the meeting topic plus date and time. On Windows that is often C:\Users\YourUsername\Documents\Zoom. On a Mac it is /Users/YourUsername/Documents/Zoom. The local file includes private chats you can see and Everyone messages.
Auto-save is a host setting first. Enabling meeting and webinar auto-saving chats says that after Meeting chat → Auto-save is on, the host no longer has to click Save. Auto-save applies to the host, and the host has to be in the meeting for a transcript to land on that machine. Official note: start the meeting from the Zoom mobile app and in-meeting or in-webinar chat will not be saved. The transcript is “messages you could see after you joined,” including private chats sent to you and private chats you sent. It does not include a private chat between two other people.
Cloud recording is the third path. Changing basic and advanced cloud recording settings writes “Save chat messages from the meeting / webinar” as: you get a TXT; for a meeting it holds only messages sent to Everyone; for a webinar it holds messages from the host and panelists to all participants; private messages between individuals are not saved on the cloud. The time window is the stretch while cloud recording is on. After a cloud recording goes to Trash, Finding your computer and cloud recordings says you can recover it for 30 days, then it is permanently deleted within about 24 hours. A local recording you deleted by mistake belongs in the operating-system Recycle Bin first. Do not expect the Zoom website to spit that file back.
So “leave Zoom and the chat is gone” is close to true only under one stack of conditions: nobody saved by hand, the host did not turn on auto-save, and there was no cloud recording with the chat file checked. If any one of those is on, the password can sit as a TXT in Documents or under cloud Recordings, named with the meeting topic and start time. Full-text search will find it faster than you remember typing it.
Recordings, on-screen captions, and speech-to-text
Chat text and pixels are not the same leftover. With the chat pane open, on-screen captions on, or someone sharing the whole screen, Everyone text enters the picture. Tencent Meeting’s help says a member’s chat pops in the left or bottom caption area; those captions default to Everyone. Turning captions off on your machine changes only your display. It does not change anyone else’s history, and it does not change a local or cloud recording already running. Whole-screen share, window share, and meeting video carry those words as pixels, not as an HTTP request line. For albums, Desktop PNGs, and playback, see Who can still see a password — and the key after # — in a screenshot or screen share.
Speech-to-text turns a password you said into searchable text again. Feishu’s English help Generate AI Notes for Meetings (Lark has a matching article) says turning on AI summary produces a standalone AI Notes document; recording produces AI Notes inside Minutes after the call. By default every participant gets a bot message with the link. If a meeting group exists, the link goes to the group. If it does not, AI Notes Assistant sends it. A one-to-one call goes to that private chat. Tencent Meeting cloud playback can add captions separately. Those captions are speech, not the chat TXT — but if you read the password out loud, the CC on playback is searchable too.
A full one-time URL in meeting chat is still a plaintext credential. Putting the key after # only keeps that slice off the HTTP request line. See When you send a password once, why the decryption key belongs after # in the URL. Chat history, past meetings, Zoom’s TXT, Minutes, and a recording all store the whole string a person can see. Whoever copies it can open it before it burns. On channels that draw preview cards, run a test link and see whether the preview counts a read. See If you paste a one-time link into Slack or WeChat, does the preview burn it first. When meeting chat and those outbound channels stack, do not test only one path.
What leftover a meeting-chat password still has
Use the same test password and the same test meeting you control. Send Everyone only, send a private chat only, leave after the call, then turn recording on. The pages you can open are not the same. The table below is written as “places you can click,” not as product names.
| What you did | The live meeting window | What others often still have |
|---|---|---|
| Everyone in Teams, then you leave | The call is over | Invitees can still read the meeting chat with the calendar icon; a series also carries it into the next slot |
| The same line in a Teams channel meeting | You can still see it | Channel members who never joined the call can still read and reply |
| Everyone in Tencent Meeting, then you clear your own history | Your side is empty; official help says it cannot be recovered | The other device, a machine that never synced, and an enterprise public-chat archive can still keep it |
| Zoom, no save, no cloud recording with chat | After the call there is usually no after-call door | Someone may still have a screenshot, or the chat pane may be in the video |
| Zoom cloud recording with Save chat messages on | The in-meeting pane is closed | The cloud TXT holds Everyone messages; private chats stay out of that file; Trash is about 30 days |
| In-meeting chat holds only the one-time id; the key goes by phone | The chat has no key after # |
History, the TXT, and search cannot assemble a full credential; both halves are required to decrypt |
Do not mix the sixth row with the first five. If you paste a full s.html?id=…#… to Everyone, the chat list, past meetings, and the recording TXT still hold one complete credential. The host that parks ciphertext still cannot see the key. Split the id from the key, and an after-call search cannot find a link that opens. Treat a full link as the password itself. Do not store it in a long-lived meeting chat or a bookmark.
Check it on the spot
These steps do not depend on a brand promise. Use a test password that will never log into a real account, for example orange-lake-7. Title the meeting “test — do not open production.” Do not rehearse with a master password you still use, a production key, or a live one-time link.
- If you use Teams: with two same-org test accounts, create a one-off meeting, send the test password to Everyone, then end the meeting. Both sides open the Chat list and find the row with a calendar icon and the same title. The test password should still be there. A participant can then leave the chat and tick remove history: their list should drop the row; the organizer’s side should stay. Do not rehearse this on a production all-hands channel.
- If you use Tencent Meeting: send the same test password to Everyone, leave, then open All meetings or Past meetings, details, View all. You should see the test password. Sign into the same account on a device that never turned on “sync past meetings”: records from before that switch are often missing. Back on the original device, clear the record. Official help says it cannot be recovered. The other person’s device is not part of that click.
- If you use Zoom: first meeting, no save, no cloud recording. After you leave, confirm the chat pane has no after-call door. Second meeting, Save Chat, or have the host turn on Auto-save first. After the call, open the Zoom folder under Documents and search the system for
orange-lake-7. Third meeting, start a cloud recording with Save chat messages on, and send one private chat plus one Everyone line. The cloud TXT should hold only the Everyone line. - Run one test call with whole-screen share, chat pane or on-screen captions visible, and record a minute or two. After the call, watch only the video, not the chat file: if the test password appears on screen, the pixel layer kept it too. Handling is in the screen-share piece. Turn captions off and record again. Compare your picture with the other person’s history — they are not the same copy.
- Search again for
orange-lake-7in Teams search, Tencent Meeting history, the Zoom folder, and Lark or Feishu Minutes if you recorded or turned on AI summary. A hit means you still have an open door. If Feishu produced AI Notes, see whether they landed in the meeting group, from the bot, or in a one-to-one chat. - Create a MyPassGen one-time link with the same test sentence, expiry 24 hours, reads left at 1. In meeting chat, paste only the part before the hash,
s.html?id=…. Speak the key on a call or in person. Opens without an account. With only the id, the recipient should see an incomplete link; both halves are required to decrypt. After reading, overwrite the clipboard. Do not store an address that still has#in meeting chat.
On a company tenant, add half a step: ask whether meeting chat is archived, whether cloud recording is forced, and whether a channel meeting lets people who never joined still read. MyPassGen will not tell you whether a given gateway stored another copy. Trust the windows you just opened.
If the handoff has to happen in the call, split it
For a one-to-one handoff the other person can open now, do not put the password on Everyone. Generate it on this device, then wrap it in a one-time link. MyPassGen’s password generator uses a random mode of 6–128 characters, default 16, and warns below 8. It opens without an account. The result is not uploaded as business data. On create, the browser encrypts with AES-256-GCM. A single note caps at 32 KB. Reads default to 1 and cap at 10. Expiry can be 1 hour, 24 hours, 7 days, or count-only with no TTL. The server parks ciphertext only. Why the key belongs after # is in When you send a password once, why the decryption key belongs after # in the URL.
When the meeting window is required, split the channel. Chat carries only the time, the owner, the id, and the sentence “key by phone.” Do not paste a full link into a conversation that will sync, export, and be searched. A call, an in-person handoff, or a different messenger account carries only the slice after #. Neither half decrypts alone. That is a usage pattern, not a product default. The create page still emits one full link, which is convenient for a one-to-one send. On a channel that draws preview cards, run a test link first and see whether the preview counts a read before you send a live secret.
A certificate pack or export larger than 32 KB does not belong on a one-time text link. Use the file encryption box: streaming AES-256-GCM in the browser, one file up to 5 GB, output .lock / .enc, passphrase sent separately. Drive or a meeting file drop should hold ciphertext only. See Before you drop a file in the cloud, who can read the plaintext — and which path the passphrase should take. An unencrypted spreadsheet tossed into the call is the same class of problem as a password in chat: the attachment rides the thread, past meetings, and any recording share.
After you have checked “does the chat list or past-meeting pane still hit the test password after I leave” and “does the cloud-recording chat file hold only the Everyone line,” you can answer this article’s question: once a password is in meeting chat, the after-call thread, local history, a saved TXT, the recording picture, and a speech transcript can all show the plaintext again. Leaving the meeting ends this call. It does not take the current words with it. Channel members and a meeting group keep adding people who can still open it. Meeting chat is a fine channel for an id and a step list. It is a poor channel for the password itself.
FAQ
I deleted my own bubble when I left. Can the other person still see it?
Emptying your window does not empty their past-meeting history, a TXT they already saved, or a recording that was already running. A Teams meeting owner cannot leave that chat. A Tencent Meeting clear applies to your copy, and official help says it cannot be recovered. Search the after-call doors with a test password, then decide whether to rotate. Do not treat a deleted bubble as a password change.
Can a private chat stand in for a one-time link?
No. A Zoom local save can still write private chats you can see. In Tencent Meeting, the other person’s own history does not care that you left. The body is hosted by the meeting client or the account. Plaintext does not appear only in the recipient’s browser. To check “did the server see anything besides ciphertext,” use a one-time link and Network. Do not substitute “private chat.”
How is a full one-time URL in meeting chat better than the password itself?
Server logs and HTML-only previews usually cannot see the key after #, and the read page waits for script to fetch ciphertext before it counts. The after-call thread, past meetings, Zoom’s TXT, and a recording can still hold the whole URL. Whoever copies it can open it before it burns. Safer: put only the id in chat; send the key on another channel.
Do create and read need an account? If I send the wrong channel, can support recover it?
No sign-up. Create and read are public to a visitor. After ciphertext burns by count or expiry, there is no server-side plaintext backup and no support inbox that can recover it. Generate a new password and a new link. Do not keep refreshing the same URL to see if it comes back.