good point... / #2898

Private messages should not be listed to anybody but the creator and users with User-right "RIGHT_VIEW_ALL" (This should be Admin only).

Can you provide some more information on, who (which which profile and Project memeberships), creates what where, which is visible for whom (which profile)?