What runs on our site?
An async script delivered from Cloudflare’s global network. It isn’t sandboxed. Like any script in your <head>, it can read and change your page.
The detailsRightMessage adds one script to your pages. It runs with the same permissions as any other JavaScript you load, so you should know exactly what it does. Here’s what it can access, where your data goes, what it costs in performance, and what breaks when something fails.
Last reviewed
An async script delivered from Cloudflare’s global network. It isn’t sandboxed. Like any script in your <head>, it can read and change your page.
The detailsThree separate paths: script delivery on Cloudflare, analytics to a separate ingestion service, and form submissions to our integration API, which calls your email platform.
The detailsRightMessage does, on its servers. They’re used by the integration API and aren’t part of the script your visitors download.
The detailsIt loads async, compiles per project, and caches script revisions for a year. It still runs on the main thread, so measure it on your own templates.
The detailsIf the script can’t load, your page renders without it. If a form can’t reach your email platform, the visitor sees an error and can try again.
The detailsChanges are drafts until someone publishes. You can preview on your live pages, restore an earlier published version, or remove the snippet.
The detailsInstalling RightMessage means pasting a short snippet into your <head>. It adds one async script tag for your project’s script and two small style rules. Those rules hide only elements you’ve explicitly marked as conditional, so they don’t flash before the script picks a version. They’re removed when the script is ready, when it fails to load, or after 20 seconds.
script-src: the RightMessage script host from your install snippet, plus a nonce or hash for the inline snippet itself.connect-src: the RightMessage endpoints for analytics events, contact lookups and form submissions. Email hello@rightmessage.com and we’ll send the current list.style-src: the snippet adds an inline style element and the script injects style elements for its widgets, so your policy has to allow them.'unsafe-eval' is only needed if you use the after-submit JavaScript hook or code steps in flows. If your policy forbids it, leave those two features off.The script your visitors download, the analytics it sends, and the form submissions it makes each go somewhere different. None of them sits in front of your website.
Standard installation. Dashed outlines are ownership boundaries. Your site serves its own HTML; RightMessage never proxies it.
Your script is delivered from Cloudflare’s global edge network. When you publish, RightMessage compiles a script for your project and stores it in Cloudflare R2 as an immutable revision, and Cloudflare Workers serve it close to each visitor, along with a small loader that tells browsers which revision is current. Nothing is generated per page view.
Page views, campaign and form views, flow answers and conversions go to a separate ingestion Worker on Cloudflare, which writes them to Elasticsearch for reporting. This path measures. It never delivers a lead.
Form submissions and contact lookups go to our integration API on Laravel Cloud. It calls your email platform or CRM with the credentials you connected and returns the result to the browser.
The integration API runs in its own Laravel Cloud environment. The dashboard, public API, MCP server, publishing and background workers run in a second one, so dashboard load doesn’t compete with your visitors’ form submissions for compute.
Separate workloads, shared storage. Both environments are deployed from the same commit and share a managed MySQL database and Valkey cache on a private network. That’s workload separation, not full fault isolation: a database or cache problem affects both. Traffic between browsers, RightMessage and connected platforms uses HTTPS.
Here’s the path a signup takes. Every email platform and CRM follows the same shape: the browser talks to RightMessage, and RightMessage talks to your email platform or CRM.
The upgrade offer is an illustrative example of what a recognized visitor could see instead.
A visitor becomes known only after an identification event: a RightMessage form submission, a supported third-party form the script can detect, a click on an identifying link in your marketing email, or an email query parameter. Being on your list doesn’t make a browser recognizable by itself.
After that, the browser is remembered through first-party storage until it’s cleared. Another device stays anonymous until it’s identified too. Tags, fields and purchase data from your email platform apply only after identification, and only when that integration is on your plan.
Requests to the integration API are logged with what was sent, how your email platform responded, the status and the timing. Those logs contain what visitors submitted. That’s what makes them useful: if your email platform rejected or missed submissions, our support team can find the recorded requests and resend them once the cause is fixed.
That’s a support process, not automatic delivery. Nothing retries in the background, there’s no exactly-once guarantee, and the analytics pipeline isn’t a backup copy of your leads.
We don’t publish a script size or benchmark, because both depend on what’s in your project. Here’s how we’d measure it:
Your site staying up, RightMessage’s widgets showing, and a lead reaching your email platform are three different things. Here’s how each one behaves.
What visitors see
Your page renders without RightMessage. The snippet removes its hide rules when the script errors. If the script hangs instead of failing, anything you marked as conditional stays hidden until it arrives or 20 seconds pass.
What happens to leads
No RightMessage forms appear, so nothing is submitted through them.
What visitors see
After up to 3 seconds, the browser runs the script revision it already has instead of waiting.
What happens to leads
Unaffected.
What visitors see
Nothing visible. Personalization and forms don’t wait on it.
What happens to leads
Unaffected. Reports can be incomplete for that period.
What visitors see
The form shows an inline error, keeps what they typed, and lets them submit again. It isn’t counted as a conversion and the flow doesn’t move on.
What happens to leads
Not delivered unless the visitor resubmits. The request is logged, and support can replay it once the cause is fixed.
What visitors see
Published scripts keep coming from Cloudflare storage, not the application. Contact lookups and anything that needs the integration API can fail.
What happens to leads
Form submissions can fail and show the error above. The dashboard is affected too.
The standard installation changes your page after the browser starts painting it, so visitors can briefly see the original version. RightMessage Edge is an optional, open-source way to apply supported campaigns to the HTML before the response reaches the browser.
This isn’t the same as our script delivery. RightMessage already serves its script from Cloudflare’s global network, but that sits beside your site, not in front of it. Edge is different: you deploy it in your own request path, on infrastructure you control.
The “first paint” marker shows when visitors first see the page relative to the change.
| Question | Standard installation | With Edge |
|---|---|---|
| What you deploy | The snippet in your <head> | The snippet, plus an Edge integration you run in your request path |
| DNS, CDN or hosting changes | None | Cloudflare adapter: your DNS proxied through Cloudflare and a Worker on your route. Next.js adapter: no DNS change, but it runs inside your Next.js app. |
| When the page changes | After the browser starts painting | Before the HTML leaves the edge (Cloudflare adapter) |
| What it can change | Anything the script can reach in the DOM | Supported campaign targets in server-rendered HTML |
| If something goes wrong | Your original page shows | Your origin HTML is returned unchanged |
If the published plan is missing, invalid or misses its 300 ms default deadline, or the HTML transform fails, the Worker returns your origin HTML unchanged. If your origin itself fails, that error passes through. Personalized responses are marked private and no-store, so shared caches don’t serve one visitor’s version to another.
For data processing terms, see our data processing agreement and privacy policy.
No. It runs in your page’s JavaScript context with the same access as any other script you load, and it renders forms and popups into your page rather than an iframe. Treat it the way you’d treat any third-party tag in your <head>, and give publish access in RightMessage the way you’d give CMS access.
The script technically can, like any script on your page. By default, RightMessage identifies visitors from its own forms, supported third-party forms the script can detect, identifying email links, and email query parameters. Email Watcher is an optional setting that picks up email addresses submitted through other forms on the site; it’s off unless you turn it on.
No. The standard installation is the snippet in your <head>, and RightMessage delivers its script from its own Cloudflare setup. Only the optional RightMessage Edge Cloudflare adapter needs your DNS proxied through Cloudflare, because it runs in front of your site.
On RightMessage’s servers. The integration API uses them to call your email platform when a form is submitted or a contact is looked up. They aren’t included in the script your visitors download.
Usually, with allowances. You’ll need to allow the RightMessage script host and the endpoints it calls, the inline install snippet, and the style elements it injects. The optional after-submit JavaScript hook and code steps in flows need 'unsafe-eval'; if your policy forbids that, don’t use those two features. Test in report-only mode first.
Use built-in A/B testing on the Pro plan to hold back a percentage of matched visitors on your original page. Compare your conversion goal within that same audience before rolling the change out to everyone.
Forward this page to whoever has to approve the script. If they want to go deeper, we’ll walk an engineer through your setup.