Android

Where Does Xabber Store Chats and Accounts?

Xabber keeps accounts with plaintext credentials plus messages in Realm and SQLite stores under its Android package. Export is per-chat HTML only.

Last updated

Xabber stores more locally than its security posture suggests. Accounts with credentials plus message copies sit in Realm and SQLite stores under the stable package, plaintext even where OTR flags claim encryption. No RAM-only mode exists by maintainer admission.

Exports stay minimal with per-chat HTML as the lone exit. Server archives depend on server settings rather than the app. Package variants split stable, beta and legacy dev trees that never intermingle.

Where Xabber stores this, by platform

Android
/data/data/com.xabber.android/files

Realm message and contact stores plus account Realm with credentials and SQLite avatars beneath. Plaintext throughout per forensic papers. Root needed with per-chat HTML as the only export.

Frequently asked questions

How do I back up Xabber chats?

There is no full backup to copy. Per-chat HTML export is the only supported exit with server archives where enabled. Forensic papers confirm plaintext credentials inside, so treat rooted copies as highly sensitive.

How does Xabber differ from Conversations storage?

It triples them. Realm files carry messages and contacts, a second Realm carries accounts with credentials, and SQLite holds avatars with OTR state. Conversations uses one SQLite instead, with OMEMO rather than OTR defaults.

Which Xabber package do I have?

Through stable, beta and legacy dev packages that must not mix. Forensic paths quote the stable ID. Beta and dev trees live apart with their own stores.

Notice an outdated path? Let us know.