Ideally Facebook would use public-key encryption for chats and allow each user to individually save the history with their own passphrase they input encrypting it client-side.
But hey, auto-saving history without prompting you is worth it, right? (Also figuring out what to advertise to a user.)