Encrypted messaging, compared
10 minEasy“Encrypted” is marketing on most of these. The questions that matter are: is it end-to-end encrypted by default, can the company read your messages, and what does it know about who you talk to?
Metadata is the underrated part. Even when contents are sealed, who you messaged, when, and how often is usually visible to the provider. For most realistic purposes that pattern reveals more than the text would.
The short version
- Signal — end-to-end encrypted by default, for messages and calls. Nonprofit, open source, peer-reviewed protocol, and deliberately stores almost no metadata: it knows your phone number and roughly when the account last connected. Group membership, contacts, and profile are encrypted too. This is the recommendation.
- WhatsApp — contents are end-to-end encrypted by default, using Signal's protocol, and that part is solid. It's owned by Meta and collects extensive metadata: your contact graph, timing, frequency, and device details. Fine for ordinary conversation; not what you'd choose for something sensitive. Turn off unencrypted cloud backups or the encryption is moot.
- iMessage — end-to-end encrypted between Apple devices (blue bubbles). Two catches: any green bubble is SMS and not protected at all, and iCloud Backup includes your messages, which historically gave Apple a key. Turn on Advanced Data Protection to close that.
- Telegram — not end-to-end encrypted by default. Ordinary chats, and all group chats, are encrypted to Telegram's servers where Telegram holds the keys. E2E exists only in manually-started one-to-one “Secret Chats”. It has a reputation for privacy that its defaults don't earn.
- SMS — no meaningful protection. Readable by your carrier, interceptable, and the reason SMS 2FA codes are weak.
- Facebook Messenger and Instagram DMs — E2E has been rolled out but the behaviour varies by chat and feature. Assume not, unless the chat says so.
- Discord, Slack, Teams — not end-to-end encrypted at all. The operator, and in workplace tools your employer, can read everything. Useful, just don't confuse them with private.
Choosing
- Default to Signal for anything you'd rather not have stored. It costs one install and the person you're messaging almost certainly has it or will.
- WhatsApp is fine for logistics — it's where your family already is, and contents genuinely are encrypted.
- iMessage between Apple devices is fine if you turn on Advanced Data Protection.
- Don't use Telegram for privacy. Use it as a broadcast and community tool, which is what it's actually good at.
- Never send anything sensitive over SMS or email. Neither was designed for it.
Settings that matter more than the app choice
- Turn off unencrypted backups. The most common way “encrypted” messages end up readable is a plaintext backup in someone's cloud.
- Set disappearing messages as a default. A message that no longer exists can't be read off a seized or borrowed phone.
- Verify safety numbers with the people who matter — this is what stops an impersonation attack.
- Lock the app behind Face ID or a PIN, and hide message contents in notifications.
- Remember the other end. Encryption protects the message in transit, not from the person you sent it to. Screenshots are forever.
Next
Don't be evil
Google knows more about you than anyone. Here's how to see it, cut it down, and keep what's useful.
30 minModerate