In March 2026, Signal published something most companies bury: a subpoena they’d already complied with. A federal grand jury in the District of Columbia had demanded subscriber information for 37 phone numbers. Not a hypothetical. Not a policy paper. An actual U.S. government agency, with actual legal authority, coming after actual user accounts on the messaging app privacy advocates recommend more than any other.
Here’s what Signal handed over: almost nothing. Seven of the 37 numbers weren’t even registered. Twenty-four numbers existed but had no data tied to them for the period in question. Only six accounts produced anything at all, and that “anything” was two timestamps, when the account was created, and when it last connected. The same two data points Signal disclosed in a nearly identical case a decade earlier, and again twice in between.
That gap between what governments can legally demand and what a well-built app can actually produce, is what this guide is built around. Most “best private messaging app” roundups rank Signal, WhatsApp, Telegram, Session, and others by feature checklists: disappearing messages, group size limits, desktop support.
Almost none of them show you what happens when the privacy promise gets tested by an actual subpoena, an independent audit, a court ruling, or a lawsuit still working through the system. This guide draws on all four kinds of evidence, and is explicit about which is which, since a filed allegation and a settled court record don’t carry the same weight.
- What four separate government subpoenas against Signal, spanning a decade, actually produced
- The WhatsApp whistleblower case and the two class-action lawsuits it triggered in 2026
- Why Session dropped a core cryptographic protection in 2021 — and where the fix stands now
- The Swiss Federal Supreme Court ruling that shields Threema from one specific real-time surveillance obligation, which almost no comparison article mentions
- How Matrix’s federation model trades one privacy risk for a different one
- Why Telegram isn’t end-to-end encrypted by default, and what changed after its founder’s 2024 arrest
- SimpleX Chat, the newest app here, which uses no user identifier of any kind
- How the EU’s “Chat Control” fight and the UK’s Online Safety Act threaten encryption at the legislative level
- Why message encryption doesn’t protect you once your phone itself is in someone else’s hands
- Why a stolen phone number can be a path into your account even when the encryption is never broken
- Briar, the peer-to-peer app built for internet blackouts and censorship — a genuinely different problem than the rest of this list
- A threat-model framework for picking between phone-number-based and anonymous messaging apps
What “End-to-End Encrypted” Actually Promises
Every app in this guide calls itself end-to-end encrypted. The term gets used loosely enough in messaging-app marketing that it’s worth pinning down before comparing anything.

End-to-end encryption (E2EE) is a system where a message is encrypted on the sender’s device and only decrypted on the recipient’s device. The company running the servers in between cannot read the content, not voluntarily, and not even if a court orders them to, because the readable version never touches their infrastructure.
It’s a real, mathematically verifiable property, and Signal, WhatsApp, Threema, Session, and Element (when set up correctly) all implement it for message content.
What E2EE does not cover is metadata: who messaged whom, when, how often, and from what device or IP address. That distinction is the entire story of this guide. WhatsApp encrypts messages with the exact same underlying cryptography Signal uses, WhatsApp adopted the Signal Protocol in 2016, and yet, as covered below, WhatsApp’s parent company is now defending two separate lawsuits over what happens to that data once it’s decrypted on WhatsApp’s own infrastructure.
End-to-end encryption tells you what happens to a message’s content. It says nothing about metadata collection, employee access policies, or what a company does with everything surrounding that encrypted core. Those three things vary enormously across the apps covered below, and that variance is what actually determines your privacy.
Privacy Is Not One Score
Before going app by app, it’s worth naming the mistake almost every “best private messenger” list makes: treating privacy as a single number you can rank apps on. It isn’t. Four separate questions are usually collapsed into one.

Content confidentiality asks whether the provider itself can read your messages. Identity unlinkability asks whether your account can be tied back to a phone number, email address, or other persistent identifier. Metadata privacy asks what an outside observer, or the provider, can infer about who you talk to, when, how often, and from where, independent of message content. Operational usability asks whether the people you actually need to talk to will install the app and use it correctly and consistently.
There’s no app in this guide that wins on all four. Signal is usually the strongest general-purpose compromise precisely because it’s good enough on all four rather than exceptional on one. Threema, Session, and SimpleX each reduce identity linkage in different ways, at different costs.
Element/Matrix optimizes for infrastructure control. And an app that’s technically superior on paper can produce less real-world privacy than a slightly less anonymous one, if the person you’re messaging won’t install it, mutes its notifications, or falls back to unencrypted SMS out of frustration. A privacy tool your contacts won’t actually use isn’t a private channel, it’s a channel you send messages into and hope someone reads.
Signal: Four Subpoenas, One Consistent Result
Signal is the default recommendation in most privacy communities, and the reasons are structural: a nonprofit with no advertising business model, an open-source protocol that’s been independently audited, and a design built to retain as little data as possible. But the strongest case for Signal isn’t in a whitepaper. It’s in what happened each time the U.S. government tried to compel it to hand over data.

2016: Eastern District of Virginia
The first documented case. A federal grand jury subpoena arrived asking for a wide range of account data tied to two phone numbers. With the ACLU’s help fighting an accompanying gag order, Signal disclosed exactly what it had: the registration date and the date of last connection for one of the two numbers. Nothing about contacts, groups, or who that person had talked to, because Signal’s own transparency page for the case explains that data was never collected in the first place.
2021: Central District of California, twice
This is the part most current comparison articles miss entirely, because it happened years before the 2026 case that tends to get all the attention. In April 2021, a subpoena from the U.S. Attorney’s Office in the Central District of California asked for addresses, correspondence, and account names tied to Signal users. Signal’s response was the same as 2016: creation and last-connection timestamps, nothing else. Six months later, a second subpoena from the same district asked for essentially the same categories of data, names, contacts, groups, call records, and got the identical answer.
2026: District of Columbia
The case that opened this guide. A grand jury subpoena requested account information for 37 phone numbers, along with a nondisclosure order barring Signal from even acknowledging the request existed. After the ACLU’s involvement led to that order being modified in late 2025, Signal published the full breakdown in March 2026: 7 of 37 accounts didn’t exist, 24 had no data for the relevant period, and the remaining 6 produced only the same two timestamps every prior case had produced.
What Four Cases Across a Decade Actually Prove
This isn’t a policy promise being tested once. It’s the same architecture surviving four separate legal demands, from three different federal jurisdictions, spanning ten years, and producing nearly nothing every time. That’s a meaningfully stronger claim than most “Signal is private” articles make, because they usually cite only the highest-profile case and miss the pattern.
None of this means Signal is invisible to a sophisticated, targeted adversary. Device compromise, a court order for a specific unlocked phone, or metadata inference from network timing all sit outside what a subpoena to Signal itself can reach. What these four cases do prove, repeatedly, is that Signal’s minimal-data design holds up outside a whitepaper, it’s been stress-tested against real federal process and has survived every time.
Best for: People who want audited, nonprofit-backed encryption with mainstream usability, and whose actual concern is data-mining or casual surveillance rather than avoiding phone-number linkage entirely.
WhatsApp: The Encryption Is Real. The Question Is What Happens After
WhatsApp uses the same Signal Protocol as Signal itself for message content, a fact WhatsApp leans on constantly in its own marketing. What that framing leaves out is a formal whistleblower lawsuit and two class actions that followed it, all arguing the protection stops well short of Meta’s own servers.

The Whistleblower Complaint
Attaullah Baig, who joined WhatsApp in 2021 and later described himself as the app’s head of security, filed suit in the U.S. District Court for the Northern District of California in September 2025, naming Meta and several executives including CEO Mark Zuckerberg.
According to his complaint reported by CNBC, a red-team exercise Baig ran shortly after joining found that roughly 1,500 WhatsApp engineers had unrestricted access to user data, with no audit trail if that access were misused. The suit also alleges WhatsApp lacked a basic inventory of what user data it collected, something required under a 2020 FTC privacy settlement Meta had already agreed to.
Baig says he escalated these findings repeatedly, including a formal SEC whistleblower filing in November 2024, and was terminated in February 2025. Meta disputes the framing on every front: a company spokesperson told SecurityWeek that Baig held the title of level-1 software engineering manager, not head of security, and that his termination followed poor performance reviews. Meta also notes that a separate OSHA retaliation complaint Baig filed was dismissed.
Two Class Actions Followed
The whistleblower suit is no longer the only legal challenge to WhatsApp’s privacy claims. In January 2026, plaintiffs from Australia, Brazil, India, Mexico, and South Africa filed Dawson et al. v. Meta Platforms, alleging Meta can store, analyze, and access WhatsApp communications despite marketing the app as end-to-end encrypted.
A federal judge dismissed the complaint for relying too heavily on anonymous whistleblower accounts, giving plaintiffs until August 2026 to refile, and by July 2026, a judge had separately compelled the underlying dispute into arbitration rather than letting it proceed as a class action, effectively pausing it.
In April 2026, a second suit, Shirazi et al. v. Meta Platforms, went further, alleging Meta gave contractors working through Accenture the same kind of access, according to reporting from MyDataZero; that case remains active as of mid-2026.
Meta’s public response across all three cases has been consistent and blunt: spokesperson Andy Stone called the claims “categorically false and absurd,” and Meta maintains that WhatsApp’s encryption keys never leave a user’s device.
None of these are settled facts, they’re allegations Meta disputes, at different, still-moving procedural stages:
| Case | What’s alleged | Status as of mid-2026 | What it doesn’t prove |
|---|---|---|---|
| Baig v. Meta | Internal access-control failures, retaliation against a whistleblower | Active in federal court; Meta disputes the plaintiff’s job title and rationale for termination | Doesn’t establish that the Signal Protocol itself was broken |
| Dawson v. Meta | Meta can store, analyze, and access user communications | Dismissed once for relying on anonymous sources; compelled into arbitration rather than proceeding as a class action | Doesn’t establish plaintext message access as a proven fact |
| Shirazi v. Meta | Accenture contractors had the same kind of access | Filed April 2026; still active | Remains an allegation, not a court finding |
What This Does and Doesn’t Say About the Encryption Itself
None of these three cases allege that Meta has broken the Signal Protocol or can read message content in transit. What they allege, consistently, is that a large population of people inside Meta, employees in Baig’s account, contractors in the Shirazi case, could reach account-level and metadata information around that encrypted core with little oversight.
That’s the distinction this guide keeps returning to: message-content protection and organizational access discipline are separate guarantees. A company can hold one tightly while multiple lawsuits allege it failed at the other. None of this is settled, and Meta disputes all of it, but it’s a materially different category of concern than anything documented about Signal.
Best for: People who need to reach the largest existing contact network and are comfortable with Meta’s broader data practices around the encrypted core, with these three legal disputes, filed but not yet resolved, weighed as a real, if contested, factor.
Telegram: The Biggest Gap in Most Comparison Guides
No messaging-app comparison is complete without Telegram, and most skip it anyway, usually because it doesn’t fit neatly into an “encrypted apps” list. That omission matters, because Telegram has more than 900 million monthly users and a sizable share of them believe it’s encrypted the same way Signal or WhatsApp is. It isn’t.

It’s Not End-to-End Encrypted by Default
Telegram’s regular chats, one-on-one conversations, groups, channels, everything most people actually use, run on a custom protocol called MTProto and are encrypted only between your device and Telegram’s servers, not end-to-end. Telegram can technically read that content on its own infrastructure.
Genuine end-to-end encryption exists only inside a separate feature called Secret Chats, which has to be turned on manually for each one-on-one conversation, doesn’t sync across devices, and was never extended to group chats. Security researcher Matthew Green has been blunt about the gap between Telegram’s reputation and its default behavior, arguing directly that the app doesn’t meet the bar most people assume it clears.
What Changed After Durov’s Arrest
In August 2024, Telegram founder Pavel Durov was detained at a Paris airport and later indicted on charges connected to insufficient moderation of criminal activity on the platform, including child exploitation material and drug trafficking. A month later, Telegram rewrote its terms of service to state it would hand over the IP addresses and phone numbers of users flagged in “valid legal requests”, a policy shift Durov announced directly on the platform.
The transparency numbers back up that this wasn’t just a statement. Telegram’s own quarterly transparency data, compiled and reported by Gizmodo, and independently tracked in an aggregated public dataset built directly from Telegram’s own disclosure bot, show requests fulfilled for French authorities alone jumped from 54 users in the first half of 2024 to 1,386 users in the final quarter of that year, a roughly 25-fold increase in disclosures within months of the arrest. In the U.S., fulfilled requests went from 14 covering 108 users in the first nine months of 2024 to roughly 900 requests covering over 2,000 users by year’s end.
What This Means in Practice
None of this makes Telegram unsafe to use for ordinary conversations, and Secret Chats do provide real end-to-end encryption when both people remember to use them. But treating Telegram as a private-by-default alternative to Signal or WhatsApp is a factual error, not a matter of preference.
The vast majority of what happens on Telegram, group chats, channels, and regular one-on-one messages, sits on Telegram’s servers in a form the company can read, and the post-2024 policy shift shows Telegram is now disclosing far more user identifiers, such as phone numbers and IP addresses, to law enforcement than it used to.
That transparency data is about who’s behind an account, not proof that Telegram has handed over plaintext message content, but it undercuts any assumption that Telegram won’t identify you to a government requesting it.
Best for: Large group broadcasting, channels, and bots where reach matters more than confidentiality, not for anything where message privacy is the actual requirement, unless Secret Chats are used deliberately for every sensitive conversation.
Session: The App That Traded a Cryptographic Guarantee for Anonymity
Session started in 2020 as a fork of Signal’s protocol, with one foundational change: no phone number, no email, nothing tying an account to a real identity. Registration generates a key pair on your device, and your identity inside the app is a long random string called a Session ID.
How It Actually Routes Messages
Instead of Signal’s centralized servers, Session runs on a decentralized network of community-operated Service Nodes built on the Oxen network, using onion routing conceptually similar to Tor.
A message passes through multiple independent nodes before reaching the recipient’s “swarm”, a small cluster of nodes that temporarily holds their messages. No single node sees both who sent a message and where it’s ultimately going, and there’s no central company holding a subpoena-able log of who’s talking to whom.
The Trade-Off Most Reviews Skip
In 2021, Session removed Perfect Forward Secrecy (PFS), citing stability problems when combined with its decentralized architecture. PFS is what stops a compromise of your long-term key from letting an attacker decrypt messages you sent in the past, every conversation generates fresh keys that get thrown away afterward. Without it, if a Session user’s key material were ever compromised, previously sent messages could theoretically become readable, in a way Signal’s architecture specifically prevents.

Session’s team hasn’t hidden this. Independent audits, including one from Quarkslab in 2021, confirmed no fundamental break in the protocol but flagged the missing forward secrecy directly. The response from the wider security community was concrete: Privacy Guides’ community openly debated disqualifying Session from its recommended-messenger list specifically over this gap.
That’s starting to change. In December 2025, the Session Technology Foundation announced Session Protocol V2, which reintroduces PFS alongside post-quantum cryptography and better linked-device controls. As of mid-2026, the protocol is still in the design and community-review phase, a real commitment, not yet a shipped fix.
There’s a second honest limitation worth naming: Session’s parent organization sits in a jurisdiction covered by Australia’s Assistance and Access Act, which includes provisions for compelling “systemic” technical capabilities from companies. Whether that framework could realistically be applied to Session’s decentralized architecture hasn’t been tested in public.
Best for: People whose primary risk is phone-number linkage itself, pseudonymous organizing, regions where Signal is blocked, or any situation where tying a messaging account to a real identity is unacceptable, who understand the current forward-secrecy gap and are watching for V2 to ship.
Threema: A Real Court Case, Not Just a Jurisdiction Argument
Threema is a paid, Swiss-based app that needs no phone number or email to register, is built on the open-source NaCl cryptography library, and has been through professional security audits. Most roundups describe it in language borrowed almost word-for-word from Proton Mail coverage: Swiss privacy law, no ad business model, no reason to monetize your data. That comparison is worth checking against the actual record rather than repeating on faith.

Where the Comparison to Proton Holds
The paid model really is structural: no advertising business creates no pressure to monetize what users send. Anonymous signup, no phone number or email required, with the option to buy the Android app using cryptocurrency, gives Threema a lower identity footprint at registration than Signal’s phone-number model.
The Part Almost No Comparison Article Mentions
Threema hasn’t just claimed Swiss jurisdiction protects it. It has tested that claim in Switzerland’s highest court and won. In 2018, Switzerland’s Federal Post and Telecommunications Surveillance Service tried to classify Threema as a telecommunications service provider, a designation that would have forced it to actively assist in real-time surveillance, including circumventing its own encryption.
Threema appealed and won at the Federal Administrative Court in 2020, and the government’s follow-up appeal was rejected by the Federal Supreme Court in a final ruling on April 29, 2021. The court held that Threema qualifies as a lower-obligation “provider of derived communications services,” not a telecom carrier subject to real-time surveillance duties.
That’s a materially stronger fact than the vague “Swiss jurisdiction should protect you” framing most articles lean on, it’s a specific, named ruling (case 2C_544/2020) that a Swiss government agency tried and failed to force Threema into a surveillance role.
It doesn’t mean Switzerland’s Article 271 blocking statute, which routes foreign legal requests through Swiss courts rather than letting them go direct, is absolute, Proton Mail’s own transparency reporting shows Swiss authorities do sometimes approve requests routed through official mutual-assistance channels. But unlike Proton, Threema’s core privacy architecture has already survived a direct government challenge to compel active surveillance cooperation, and won.
Best for: People who want a paid, ad-free model with genuinely low-friction anonymous signup, backed by an actual won court case rather than an untested jurisdictional argument, while still understanding that Swiss law routes foreign requests through courts rather than blocking them outright.
Private Email Services Compared: What Happens When Your “Zero-Access” Provider Gets a Court Order
Element and Matrix: Federation’s Real Strength, and Its Real Cost
Element is the most widely used client for Matrix, an open, federated messaging protocol that works more like email than a typical app: anyone can run their own server (a “homeserver”), and those servers talk to each other so people on different servers can still message one another.

Why Federation Genuinely Matters
No single company controls the whole network. An organization, a government agency, or an individual can self-host a homeserver and keep full control over their own data instead of depending on one corporate provider’s continued existence or goodwill. For NGOs, journalists’ organizations, and technical teams, that infrastructure independence is a real advantage none of the centralized apps in this guide offer.
The Metadata Cost Most Comparisons Underplay
Message content between Matrix users is end-to-end encrypted when set up correctly. But metadata is a different story. Matrix’s own documented notes on the protocol explain that its privacy protections mostly cover message content, and that who’s talking with whom, when, and from where isn’t protected the same way.
In practice, federation can expose conversation-related metadata to the homeservers involved in a room, depending on that room’s structure, the federation path a message takes, and how each participating server is configured, it’s not a blanket guarantee that every homeserver sees everything, but it’s a materially different privacy model from a single centralized provider.
Element has acknowledged this trade-off directly and sells a commercial gateway product aimed at organizations that need tighter control over which servers their traffic touches, a sign the concern is real enough to build a product around, not a hypothetical.
This is a fundamentally different service model from Signal’s: Signal’s own servers play a much narrower role than the multiple participating homeservers in a federated network.
Best for: Organizations and technical teams that want infrastructure independence and control over their own server, and who understand that federation trades away some metadata privacy in exchange, best mitigated by self-hosting and keeping federation limited to a small number of trusted homeservers rather than the fully open network.
SimpleX Chat: The App With No User Identifiers at All
Every app covered so far, even the anonymous ones, still assigns you something, a phone number, a Session ID, a Threema ID, a Matrix username. SimpleX Chat, a newer entrant that’s rapidly gained traction in privacy circles through 2025 and 2026, tries something more radical: it doesn’t assign you an identifier of any kind.

How That’s Even Possible
Instead of a persistent identifier tied to your profile, SimpleX uses one-way message queues. Each conversation gets its own pair of anonymous, single-direction addresses on relay servers, one for sending, one for receiving, and those addresses aren’t linked to each other or to any central account.
The project’s own technical documentation explains the practical effect: SimpleX server operators can’t even count how many people use their servers, because there’s no account layer to count. Message content is encrypted with the Double Ratchet algorithm, the same forward-secrecy mechanism Signal uses, so SimpleX gets PFS by default in a way Session currently doesn’t.
To connect with someone, you exchange a one-time link or QR code out of band. There’s no phone number, no email, and unlike Session or Matrix, where a persistent (if anonymous) ID still lets a sophisticated observer map who talks to whom over time, no persistent identifier for an adversary to correlate across conversations in the first place.
No User ID Doesn’t Mean No Observable Metadata
This is the caveat most SimpleX coverage skips, and it matters: no persistent identifier is not the same claim as no metadata at all. SimpleX’s own privacy policy is specific about where the remaining exposure sits. Relay servers can’t decrypt message or file content, or even see its size, messages are padded to a fixed size specifically to prevent size-based fingerprinting.
But the policy also documents that servers can temporarily retain undelivered messages for up to 21 days, that file relays hold files for a configured period, that iOS push notifications (when enabled) let Apple’s and SimpleX’s notification servers observe roughly how many messages arrive at a device even though they can’t read them, and that connecting to a destination server directly rather than through a forwarding relay exposes your IP address to it.
None of this breaks SimpleX’s core design, and the policy is unusually transparent about it, but the accurate description is that SimpleX minimizes persistent account identity and gives you more control over the relay layer than account-based messengers, not that it eliminates every observable trace.
Where It’s Still Catching Up
SimpleX is younger and smaller than everything else in this guide, which cuts both ways. Its protocol design went through a cryptographic review by Trail of Bits in 2024, following an earlier 2022 implementation audit, and it’s attracted real investment, including backing from Twitter co-founder Jack Dorsey.
But it doesn’t yet have the years of adversarial, real-world legal testing Signal has, the won court case Threema has, or the user base WhatsApp has. For most people, that’s a reason to watch it rather than adopt it as a daily driver just yet.
It’s among the most ambitious designs available for reducing persistent user identifiers, but that’s a narrower claim than “strongest architecture,” and it shouldn’t be confused with eliminating metadata altogether or with the broad real-world legal testing older apps in this guide have accumulated.
Best for: Privacy-focused users and sources who need to avoid not just phone-number linkage but any persistent identifier at all, and who are comfortable using a newer, less battle-tested app, and who use Tor or a VPN alongside it, since SimpleX’s own policy notes that connecting to servers directly exposes your IP.
When the Law Itself Targets Encryption
Everything above concerns individual subpoenas, lawsuits, and court rulings, the legal system testing one company at a time. There’s a separate, bigger threat sitting above all of it: legislation that would require scanning message content before encryption even happens, regardless of which app you use.

The EU’s “Chat Control” Fight
The European Union has spent since 2022 negotiating the Child Sexual Abuse Regulation, nicknamed “Chat Control,” which in its strongest drafts would require messaging providers to scan users’ communications, including inside end-to-end encrypted apps, for known and previously unknown abuse material and for grooming behavior in text.
The mechanism critics object to is client-side scanning: inspecting a message on your own device in the instant before it gets encrypted, which sidesteps the protection E2EE provides rather than breaking the math itself.
A temporary, narrower version of this regime, voluntary scanning of unencrypted content, sometimes called Chat Control 1.0, expired on April 3, 2026, after Parliament declined to renew it. It was then unexpectedly revived on July 9, 2026: more MEPs actually voted against extending it than for it, but the vote fell under a procedural threshold requiring an absolute majority of the full Parliament rather than of those present, and the extension passed anyway, according to reporting on the vote.
That narrower rule now runs until 2028 or a permanent law, whichever comes first, and it explicitly excludes end-to-end encrypted apps like Signal and WhatsApp from its scope. The bigger fight, the permanent “Chat Control 2.0” regulation that would reach into encrypted apps directly, remains unresolved, with negotiations set to resume later in 2026.
Signal has been the most explicit about where it stands: company president Meredith Whittaker has stated Signal would leave the EU market entirely rather than implement client-side scanning, and Session’s decentralized architecture makes a mandated scanning backdoor practically difficult to bolt on in the first place.
The UK Has Already Gone Further
Britain’s Online Safety Act gives regulators the legal authority to compel scanning obligations, even on encrypted services, once the necessary technical accreditation framework is in place.
Apple responded pre-emptively: it withdrew Advanced Data Protection, its optional end-to-end encrypted iCloud backup feature, for UK users in February 2025 rather than build in the access UK authorities had reportedly demanded. Signal and WhatsApp have both said they would rather exit the UK market than weaken their encryption to comply.
What This Means for the Apps Above
This is the one category of threat that doesn’t depend on how well any single app is built. A subpoena tests what a company already holds; a court case tests a specific legal claim; a law like this would change what every app operating in a jurisdiction is required to hold in the first place.
None of it has forced a working backdoor into Signal, WhatsApp, or Session as of mid-2026, but it’s the threat every app in this guide is actively organizing against, and it’s worth tracking independently of which app you currently use.
What Happens If the Phone Itself Gets Taken
Every section above covers protecting messages in transit and on a company’s servers. None of it protects you if your unlocked or poorly-secured phone ends up in someone else’s hands.

Encryption in Transit Isn’t the Same as Encryption at Rest
Law enforcement and forensic firms don’t need to break E2EE to get message content off a physical device they extract it directly from the phone’s storage. Cellebrite and GrayKey are the two best-known commercial tools for this, marketed specifically to law enforcement, and both are built to bypass lock screens and extract app data directly from a device’s storage rather than intercept anything over the network.
Their real-world effectiveness varies a lot by device: modern iPhones and Pixel phones with a strong passcode and up-to-date software are meaningfully harder to crack than older or unpatched devices, and a phone that’s locked and hasn’t been unlocked since reboot is a materially different target than one seized while unlocked.
This is precisely the layer none of the subpoena or lawsuit evidence above touches. Signal’s four subpoena cases prove what Signal’s servers can’t produce, they say nothing about what a forensic tool can pull from a physical device someone already has in hand.
What Actually Helps at the Device Level
A few concrete, device-level habits matter more here than app choice:
- Use a long alphanumeric passcode rather than a 4- or 6-digit PIN, brute-forcing is dramatically harder against a longer, non-numeric passcode.
- Enable your phone’s full-device encryption and keep the OS current, since forensic tools’ success rates are tied closely to unpatched vulnerabilities.
- Turn on an app-specific lock where available, Signal supports a separate screen lock, and Session added screenshot-detection alerts as part of its late-2025 update cycle.
- Treat “duress PIN” or panic-wipe features with caution rather than as a guaranteed safeguard. Security researchers, including those behind the hardened Android OS GrapheneOS, have pointed out that an adversary who knows duress PINs exist can simply treat any PIN you offer as potentially fake and pressure further, the feature isn’t the safety net its marketing implies.
Message encryption protects your data in transit and on a company’s servers. It does nothing once someone has physical, unlocked access to your device, that’s a separate problem, solved with device-level security habits, not app selection.
Account Takeover Is a Separate Risk From Message Interception
There’s a gap between “is my message content encrypted” and “is my account secure” that most comparison guides never address, and phone-number-based apps make it a real one: taking over your phone number can be a path to taking over your messaging account, even when the encryption protocol itself is never touched.

The mechanism is straightforward. If an attacker convinces your mobile carrier to port your number to a new SIM, a SIM-swap attack, they can potentially trigger a re-registration on a phone-number-based app and start receiving new messages sent to that number, all without breaking any cryptography.
Signal’s own documentation addresses this directly with a dedicated PIN system: your Signal PIN protects your profile, settings, and contact list, and can double as a registration lock that requires the PIN before your number can be re-registered on a new device, closing off the SIM-swap path if it’s enabled. Critically, Signal support is explicit that this PIN is not a chat backup, is different from the SMS verification code sent during signup, and is unrelated to your phone’s screen lock, three separate secrets that are easy to conflate.
Signal also documents a re-registration process where a device token combined with the correct PIN can restore an account without needing a fresh SMS code at all.
None of this is a flaw unique to Signal, it applies to essentially any phone-number-anchored app. The practical checklist is the same regardless of which app you use:
- Enable registration lock or its equivalent, so a stolen or ported phone number alone can’t re-register your account.
- Use a PIN or password that’s genuinely separate from your device passcode and your SMS code, treating them as interchangeable defeats the purpose of having three layers.
- Periodically review linked devices in your app’s settings and remove any you don’t recognize, since a linked device can keep receiving messages even after you believe an account is secure.
- Add carrier-level protection against SIM swaps, a PIN or port-freeze with your mobile provider, since that’s the actual point of failure in most account-takeover cases, not the messaging app itself.
End-to-end encryption protects message content; it does not by itself stop someone from taking over the account that content flows through. Registration locks, carrier-level SIM protection, and periodic linked-device review close a gap that pure cryptography can’t.
When Offline Communication Matters More Than Convenience
Every app covered so far assumes both people can reach the internet and the provider’s own infrastructure. That assumption fails during internet blackouts, heavy censorship, natural disasters, or protests where mobile networks are deliberately throttled, situations where the “best” messaging app on paper may simply be unreachable.
Briar is built specifically for that scenario, and it’s worth a mention here even though it doesn’t fit neatly into the rest of this guide’s framework. Rather than routing messages through a central server, Briar synchronizes data directly between nearby devices using its own Bramble protocol suite, which Privacy Guides confirms includes forward secrecy through its handshake and transport layer.
According to Briar’s own technical documentation, when the internet is unavailable, it can sync over Bluetooth, Wi-Fi, or physically transferred memory cards, keeping communication flowing during a blackout; when the internet is available, it routes through Tor to protect who’s talking to whom from network-level surveillance. Every forum subscriber keeps their own copy of shared content, so there’s no single server a takedown order or denial-of-service attack can target.
The trade-off is exactly what you’d expect from a peer-to-peer, offline-capable design: it’s less convenient than a centralized app for everyday use, message delivery depends on proximity or eventual connectivity rather than instant server relay, and it’s a poor fit as a universal replacement for messaging the people in your life who just want something that works like WhatsApp.
Briar solves a different problem than Signal, Threema, or SimpleX, communication that survives when the network itself is the adversary, and it’s worth knowing about specifically for that scenario rather than as a general daily driver.
| App | Registration | Forward Secrecy | Architecture | Tested By |
|---|---|---|---|---|
| Signal | Phone number | Yes (full) | Centralized, minimal data | 4 federal subpoenas, 2016–2026 |
| Phone number | Yes (Signal Protocol) | Centralized, Meta-owned | 3 ongoing lawsuits over internal access | |
| Session | None (random ID) | No (V2 in progress) | Decentralized, onion-routed | Quarkslab audit, 2021 |
| Threema | None (paid, anonymous) | Yes | Centralized, Swiss jurisdiction | Won at Swiss Federal Supreme Court, 2021 |
| Element/Matrix | Email or self-hosted | Yes (when configured) | Federated | Documented in Matrix’s own privacy notes |
| Telegram | Phone number | Only in Secret Chats | Centralized, not E2EE by default | 25x jump in police disclosures post-2024 |
| SimpleX Chat | None (no identifier at all) | Yes (Double Ratchet) | Decentralized, one-way queues | Trail of Bits protocol audit |
| Briar | No phone-number account; contact-based identity | Yes (Bramble protocol) | Peer-to-peer, offline-capable | Bluetooth/Wi-Fi/Tor sync, no central server |
Which App Actually Matches Your Threat Model?
Here’s the short version as a plain reference table, followed by an interactive version below:
| If you need… | Consider |
|---|---|
| Audited, mainstream, easy for contacts to adopt | Signal |
| To reach contacts who won’t switch off WhatsApp | WhatsApp, with the caveats above |
| No phone number or email linkage at all | Session |
| An ad-free, paid model with anonymous signup | Threema |
| Self-hosting and infrastructure independence | Element/Matrix |
| Large group broadcasting and channels | Telegram, with Secret Chats for anything sensitive |
| No identifier of any kind, even an anonymous one | SimpleX Chat |
| To stay reachable during internet blackouts or censorship | Briar |
Six Mistakes That Quietly Undo Your Privacy

Assuming “uses the Signal Protocol” means “as private as Signal.”
WhatsApp encrypts message content with the same math Signal uses. The three legal disputes above exist precisely because that single fact says nothing about internal access policies, metadata collection, or what happens once a message is decrypted on the recipient’s end.
Turning on cloud backups without checking if they break encryption
By default, a WhatsApp backup saved to iCloud or Google Drive sits there protected only by Apple’s or Google’s own encryption, not WhatsApp’s, which means it can be handed over in response to a legal request to Apple or Google rather than WhatsApp itself.
WhatsApp’s actual end-to-end encrypted backup option has existed since 2021, but it’s opt-in: you have to turn it on manually under Settings → Chats → Chat Backup, and secure it with either a password or a 64-digit key that only you hold. Skip that step and your “encrypted” chat history is only as protected as your Apple or Google account password.
Treating a phone-number account as anonymous just because it’s encrypted
Signal’s four subpoena cases show that an account’s existence and connection dates can still be confirmed for a specific number, even when nothing else exists to hand over. If avoiding any identity linkage at all is essential, a phone-number app is the wrong tool regardless of how strong its encryption is.
Assuming federation is automatically more private than centralization
Element/Matrix genuinely delivers infrastructure independence. It also introduces a metadata-visibility trade-off that a purely centralized, minimal-data app like Signal simply doesn’t have. More decentralization isn’t automatically more private, it depends entirely on what actually gets shared across that decentralized structure.
Trusting marketing language over testable claims
Signal’s minimal-data claims have now been tested against real federal subpoenas four times, with matching results each time. Threema’s Swiss-protection claim has been tested in Switzerland’s highest court and won. Session’s forward-secrecy gap is openly documented by its own team and by independent auditors. Look for this kind of falsifiable, checkable claim, and treat anything that hasn’t been tested by more than a company’s own marketing page with proportional skepticism.
Assuming an “encrypted messaging app” is end-to-end encrypted by defaul
Telegram markets itself as a privacy tool, and it does use real encryption between your device and its servers. But regular Telegram chats, groups, and channels aren’t end-to-end encrypted, Telegram itself can technically read that content, and post-2024 transparency data shows a sharp rise in disclosures of user identifiers like phone numbers and IP addresses, not proof that message content itself was handed over.
If a message actually needs to be private, check whether “encrypted” in an app’s marketing means end-to-end by default, or only in a separate mode most users never turn on.
The apps worth the most trust are the ones whose privacy claims have survived contact with an actual subpoena, an actual court ruling, or an actual lawsuit, not the ones with the cleanest landing page.
What Actually Changes When You Switch

Before, on SMS or an unencrypted chat app
SMS messages and their metadata pass through your carrier’s infrastructure using SS7, a signaling protocol dating to the 1970s with known, exploited weaknesses, and none of it is end-to-end encrypted, your carrier is a party to every message by design, not just an incidental relay.
Exactly what a carrier retains, and what legal process is required to obtain it, varies by jurisdiction, provider, and the specific type of data requested; older references to a flat “180-day rule” describe a narrow, dated reading of U.S. law and shouldn’t be treated as a current universal standard.
After switching to any app in this guide
Message content becomes unreadable to network-level interception, and for Signal, Session, Threema, SimpleX, Briar, and correctly configured Element, unreadable to the provider itself. That’s a real, substantial gain no matter which app you pick.
What doesn’t automatically change
Metadata protection varies enormously between them, from Signal’s four-times-tested minimal-data model, to Element’s federation-wide visibility, to WhatsApp’s disputed internal access practices working through the courts right now. Moving off SMS to any app here is a clear improvement. Picking the right one for your specific situation means actually weighing the distinctions above.
The Bottom Line
Four separate government subpoenas against Signal, spanning a decade and three federal jurisdictions, have produced the same negligible result every time, real evidence, not a marketing claim, that a minimal-data architecture holds up under actual legal pressure.
WhatsApp’s encryption protocol remains intact and unbroken by any of the three legal disputes challenging it, one dismissed once and compelled into arbitration, one still active in court, one from a whistleblower still working through litigation, but all three allege the organization around that encryption has serious access-control problems.
Telegram, despite its reputation, isn’t end-to-end encrypted for the vast majority of what people actually use it for, and it’s disclosing far more user identifiers to law enforcement since its founder’s 2024 arrest than it did before. Session traded away a cryptographic protection for stronger anonymity, said so openly, and is in the process of building it back.
Threema’s Swiss-jurisdiction advantage isn’t just an argument, it’s a specific court case the company already won. Element’s federation is genuinely powerful for organizations that need independence from any single provider, and it costs something real in metadata privacy to get there.
SimpleX Chat pushes the anonymity model further than any of them, though its own privacy policy is refreshingly honest that “no identifier” isn’t the same as “no metadata.” Briar solves a problem none of the others touch: staying reachable when the network itself is unavailable or hostile.
None of these eight apps is a universally correct choice, and none of them wins across every dimension of privacy at once, content confidentiality, identity unlinkability, metadata exposure, and whether your actual contacts will use it consistently are four different questions, not one score. Each app answers a different version of “private from whom, and at what cost”, and the documented record above, not the marketing copy, is what should decide which answer actually fits your situation.
It’s also worth remembering that two risks sit outside any app’s control entirely: legislation like the EU’s Chat Control proposal or the UK’s Online Safety Act, which could eventually change what every app is legally required to do, and account or device security, a stolen phone number, an unreviewed linked device, or an unlocked phone in the wrong hands can undo a perfectly encrypted conversation regardless of which app carried it.
A Note on the Evidence Used Here
Not every claim above carries the same weight, and it’s worth being explicit about that. A court record, a subpoena response, a published ruling, is the strongest evidence in this guide, because it reflects what actually happened rather than what a company says would happen.
A company’s own disclosure, like a transparency report or a privacy policy, is next: self-reported, but specific and checkable. An independent audit sits below that, valuable, but scoped to whatever the auditor was asked to review, not a full guarantee.
A lawsuit’s allegations are the weakest form of evidence here until a court rules on them, real and often well-documented, but one-sided by nature, which is why this guide flags them as allegations rather than settled fact throughout.
Frequently Asked Questions
Has Signal ever handed over user data to the government?
Yes, on public record at least four times. A 2016 subpoena from the Eastern District of Virginia and two 2021 subpoenas from the Central District of California each produced only account creation and last-connection timestamps. A subpoena unsealed in March 2026 from the District of Columbia targeted 37 phone numbers: 7 accounts didn’t exist, 24 had no responsive data, and only 6 produced any information at all — limited to the same two timestamp fields as every prior case. Signal’s architecture is designed so there’s no expanded category of data to disclose, even under a valid federal legal demand.
Is WhatsApp as private as Signal since they use the same encryption?
Not necessarily. Both use the Signal Protocol to encrypt message content, but three separate legal disputes now challenge what happens around that encryption: a September 2025 whistleblower lawsuit alleging roughly 1,500 WhatsApp engineers had unrestricted data access, a class action alleging Meta itself could access user communications (dismissed once and since compelled into arbitration), and a second class action alleging Meta’s contractors had similar access, filed in April 2026 and still active. Meta disputes all three, and none of them are settled. None of them claim the encryption protocol itself is broken — the dispute is entirely about organizational access controls around it.
Why did Session remove Perfect Forward Secrecy, and has it come back?
Session’s team removed PFS in 2021, citing stability issues when combined with the app’s decentralized, onion-routed architecture. It was an openly acknowledged trade-off rather than a hidden flaw — a 2021 Quarkslab audit confirmed no fundamental break in the protocol but flagged the missing forward secrecy directly. In December 2025, the Session Technology Foundation announced Session Protocol V2, which is designed to reintroduce PFS alongside post-quantum cryptography. As of mid-2026, the protocol is still in design and community review, not yet shipped.
Does Threema’s Swiss jurisdiction actually protect it, or is that just marketing?
It’s a tested claim, not just marketing. In 2018, Switzerland’s surveillance authority tried to force Threema to actively cooperate with real-time monitoring, which would have meant weakening its own encryption. Threema fought this through Switzerland’s courts and won at the Federal Supreme Court in April 2021 (case 2C_544/2020), which ruled Threema isn’t subject to those surveillance obligations. That’s a specific, documented legal precedent — a stronger claim than the general “Swiss privacy law” framing most articles use, though it doesn’t make Switzerland’s legal-assistance process for foreign requests airtight.
Is Element/Matrix more private than Signal because it’s decentralized?
Not automatically. Matrix’s federated model gives you infrastructure independence — you can self-host rather than depend on one company — but conversation-related metadata can be exposed to the homeservers involved in a room, depending on that room’s structure and how each server is configured. Signal’s centralized model gives Signal’s own servers a much narrower role by comparison. Decentralization trades dependence on a single company for broader potential metadata exposure across federated servers; it doesn’t eliminate the risk, it relocates and reshapes it.
Can I use Signal without a phone number?
Not for registration — a phone number is still required to create an account, though Signal usernames, introduced in 2024, let you hide that number from other users and from search. If avoiding any phone-number linkage at the registration level is essential to your situation, Session or Threema are better architectural fits, since neither requires a phone number or email at any stage.
What’s the safest messaging app for journalists and activists?
Signal remains the security community’s default recommendation, given its audited protocol, nonprofit structure, and four documented subpoena cases all showing minimal disclosure under real legal pressure. Where phone-number linkage itself is the primary risk — not just message exposure — Session’s anonymous, decentralized registration is a reasonable specialized alternative, weighed against its current forward-secrecy gap until V2 ships. SimpleX Chat is worth watching for the same use case, though it has less real-world legal testing behind it.
Is Telegram end-to-end encrypted?
Not by default. Telegram’s regular chats, groups, and channels are encrypted only between your device and Telegram’s servers using its own MTProto protocol — Telegram itself can technically read that content. Genuine end-to-end encryption exists only in a separate “Secret Chats” feature, which has to be enabled manually for each one-on-one conversation and isn’t available for groups. Since founder Pavel Durov’s August 2024 arrest in France, Telegram has also significantly increased how much user data it discloses to law enforcement in response to legal requests.
What makes SimpleX Chat different from Session or Signal?
Session and Signal both still assign you some form of identifier — a Session ID or a phone number. That doesn’t automatically mean an observer can track you across conversations; it means a persistent identifier exists as a potential linking point if an observer ever obtains data tied to it or sees it reused in more than one context. SimpleX Chat removes that identifier entirely: each conversation uses its own one-way, anonymous message queues on relay servers that aren’t linked to each other or to any account, so there’s no comparable linking point in the first place. It’s a newer project than the others in this guide, with an external protocol audit from Trail of Bits, but fewer years of real-world adversarial testing.
Could a law force Signal or WhatsApp to add a backdoor?
It’s an active, unresolved fight rather than a settled question. The EU’s proposed “Chat Control” regulation has repeatedly considered requiring client-side scanning inside encrypted apps; a narrower, temporary version was revived in July 2026 but explicitly excludes end-to-end encrypted apps, while the permanent version that would reach into encryption directly is still being negotiated. The UK’s Online Safety Act already gives regulators legal authority to compel scanning once a technical framework is finalized, which is why Apple withdrew its encrypted iCloud backup option for UK users in 2025, and why Signal and WhatsApp have both said they’d leave the UK before weakening their encryption.
Can police read my messages if they take my phone?
Potentially — and no messaging app’s encryption prevents it, because this happens at the device level rather than over the network. What matters most is what you control directly: passcode length and type, whether the device was locked at the moment of seizure, and how current the operating system is. A phone seized locked, on current software, with a long alphanumeric passcode is a categorically harder target than an older or unpatched device seized unlocked. See the device-security section above for the specific habits that matter here.
Can someone take over my account with a SIM-swap even if the encryption isn’t broken?
Yes — on any phone-number-based app, a ported SIM can potentially trigger account re-registration without the attacker ever touching the encryption itself. The fix isn’t stronger encryption; it’s account-level hygiene: a registration lock enabled, carrier-level SIM-swap protection, and a habit of checking your app’s linked-devices list for anything you don’t recognize. See the account-security checklist above for the full breakdown.
Is there a messaging app that works without internet access?
Briar, and it’s the only app in this guide built for that specific case. It skips the central-server model entirely and moves data device-to-device, which matters most in exactly the moments when Signal or WhatsApp would simply fail to deliver anything: a blackout, a shutdown ordered by a government, or a disaster that’s taken down local infrastructure. The cost is convenience — it’s not something to hand your family as a WhatsApp replacement, but it’s worth having installed before a blackout happens rather than after.
Was this article helpful?










[…] Private Messaging Apps Compared: What Court Records, Audits, and Real-World Risks Show […]
[…] Private Messaging Apps Compared: What Court Records, Audits, and Real-World Risks Show […]
[…] Private Messaging Apps Compared: What Court Records, Audits, and Real-World Risks Show […]