Messengers sorted by what is encrypted and what is not
Two things decide how private a messenger is. First, whether messages are end-to-end encrypted by default or only in a mode you have to find. Second, how much metadata the service keeps: who you talked to, when, and how often, which is frequently more revealing than the messages themselves.
What each one protects
| App | End-to-end by default | Metadata kept |
|---|---|---|
| Signal | Yes, everything including calls | Very little by design |
| Yes, messages and calls | Substantial, and shared within its corporate group | |
| Telegram | No, only in Secret Chats | Substantial |
| Threema | Yes | Little, and no phone number required |
| Matrix clients | Yes, in most rooms | Depends on the server you use |
| SMS | No | Held by your network operator |
Advertisement
The apps
Signal. End-to-end by default for everything, minimal metadata, open source on both ends. The reference against which the others are measured.
End-to-end by default and very widely used, which is a real privacy feature since the alternative is often SMS. The metadata and the corporate ownership are the trade.
Excellent as a messenger: fast, large groups, good clients everywhere. Treat ordinary chats as visible to the service.
Goes further than Signal by not using any persistent user identifier at all. Smallest network of any app here.
Element, a client for the Matrix network. Encrypted by default and you can run your own server, which is unique in this list.
End-to-end encrypted with a strong track record for team use rather than personal messaging.
Messenger. Personal chats are now end to end encrypted by default; group features and backups vary.
Google Messages. RCS chats between compatible phones are end to end encrypted; SMS fallback is not.
Viber. End to end encryption for one to one and group chats, with a lock icon to confirm it.
LINE. Letter Sealing encrypts messages end to end, enabled by default for most chats.
Briar. Peer to peer over Tor, WiFi or Bluetooth, and it keeps working with no internet.
Threema. Paid once, no phone number required, and hosted in Switzerland.
Backups are where encryption leaks
An end-to-end encrypted conversation stops being private the moment it is backed up in plain form to a cloud account. This is the most common way private messages become readable, and it is a setting rather than a flaw.
- Check whether your backup is encrypted WhatsApp offers an end-to-end encrypted backup that is off by default. Turning it on requires setting a password you must not lose.
- Understand that the other person's backup counts too Your conversation is only as private as the least careful participant's settings.
- Turn off automatic media saving Received images copied into the gallery are then swept up by photo backup.
- Set disappearing messages for sensitive threads The only reliable way to limit how long a conversation exists anywhere.
The practical answer
- Conversations that genuinely need protection
- Journalism, legal and medical matters
- Anything you would not want retained
- When both people will install something new
- Talking to family who will not switch
- Group chats that already exist
- Work, where the platform is chosen for you
- Anywhere one app is the de facto standard
A messenger nobody you know uses protects nothing. The realistic approach is Signal for the conversations that warrant it and whatever everyone else uses for the rest, with the knowledge of what each one does and does not protect.
Signal for what matters, and know that Telegram's default chats are not end-to-end. Check your backup setting either way.
Frequently asked questions
Is WhatsApp actually end-to-end encrypted?
Yes, messages and calls, by default. The metadata around them is a separate matter, as is whether backups are encrypted.
Why does Signal want my phone number?
To find contacts. Usernames now exist so you can talk to people without sharing the number itself.
Is SMS secure?
No. It is unencrypted, retained by the operator, and unsuitable for anything sensitive including two-factor codes.
Read next
Nothing has infected your phone. Something you installed has permission, and the fix is a list in settings.
A phone will happily run a keyboard, a mouse and a memory stick. It will not power a desktop hard drive.
Hard and fast are different things. Almost every game confuses them, and these do not.

