Field Guide to AI, Security and Cybercrime

What Makes a Messaging App Actually Private

"Encrypted" on the homepage answers the least important question. Defaults, metadata, backups and the two phones decide the rest.

Field Guide to AI, Security and Cybercrime·Abdolmadjid Masoomi·4 October 2026·6 min read

A messaging app that says it is encrypted has answered the least important privacy question. What decides whether a private messaging app is private is whether end-to-end encryption is on by default for every chat, what metadata the service keeps, where your backups go, whether you can verify keys, and what happens on each device.

"Encrypted" is where the questions start

You see the word "encrypted" on a messaging app's homepage and assume your conversations are private. That word answers the least useful question. Almost everything you send over the internet is encrypted on the way somewhere. What matters is who can decrypt it at the other end of each hop, what the service learns even when it cannot read the words, and what happens to the messages once they land on a phone.

Marketing language does not help. Phrases like the ones taken apart in "military-grade encryption" means nothing describe the strength of a lock without telling you who has the keys. A messaging app is private when the answers to five plainer questions are good. None of them requires you to read source code.

Question one: is end-to-end encryption on by default, for every chat?

End-to-end encryption means only the devices in the conversation hold the keys, so the service carrying the messages cannot read them. The first thing to establish is whether that applies to every chat automatically, or only when you switch it on.

The difference is large in practice. Signal and WhatsApp encrypt one-to-one and group chats end to end by default. Telegram's ordinary chats and groups are encrypted between your device and Telegram's servers, which means the service can read them; its end-to-end mode, Secret Chats, has to be started deliberately for each conversation and is not available in groups.

Opt-in privacy is mostly absent privacy. People take the default path, especially in a hurry, so a service that makes end-to-end encryption a special mode is a service that holds most of its users' messages in readable form.

Question two: what does the service know without reading anything?

When content is protected, attention moves to the envelope: who you talk to, when, how often, from which network, which groups you belong to, and your whole contact list if you uploaded it. That is metadata, and for many purposes it is more revealing than the messages themselves, as metadata is the message argues. A pattern of late-night calls to one number tells a story whatever was said.

Services differ widely here. Some are designed to keep as little as possible and to hide even the sender from their own servers. Others collect usage data and contact information as part of a wider business. Read the privacy policy for the section on what is collected and how long it is kept, and treat "we may share with affiliated companies" as an answer, not as boilerplate.

Question three: where do the backups go?

This is the gap most people miss. A conversation that is end-to-end encrypted on both phones stops being end to end the moment it is copied into a cloud backup the provider can read. Anyone who can get into that backup, by breach, by a legal demand served on the cloud provider, or by taking over your account, gets the history.

Some apps offer an end-to-end encrypted backup option, where the backup is locked with a key or passphrase only you hold. WhatsApp, for example, offers encrypted chat backups as an option you have to turn on. The price is the one set out in who holds the key: if you lose that passphrase, nobody can restore the backup for you. Check the backup setting in every messaging app you use, and remember that the other person's backup settings decide what happens to their copy of your conversation.

Question four: can you check who is on the other end?

End-to-end encryption guarantees that only the holder of a particular key can read your messages. It does not, by itself, prove that the key belongs to the person you think it does. If a server could swap in a different key, it could sit in the middle of the conversation.

Good apps let you check. They show a safety number or security code for each contact, which you can compare in person or over a separate channel. They also warn you when a contact's code changes. Usually that means a new phone or a reinstall, which is harmless. Occasionally it means something else. If a conversation is sensitive, verify the code once, and re-verify when it changes rather than tapping the warning away.

Question five: what happens on the two phones?

Encryption protects messages in transit and, usually, in storage on the server. It does nothing once a message is displayed on a screen. The weakest points in most private conversations are the devices at each end:

  • Lock-screen previews show message text to anyone who picks up the phone. Turn previews off for sensitive apps.
  • Linked desktop and web apps keep their own copies of your history on computers that may be shared or poorly protected.
  • Screenshots and photographs of the screen survive any encryption and any disappearing-message timer.
  • The other person's phone is outside your control entirely, including its backups, its lock and who else uses it.
  • A phone you are made to unlock shows everything on it, which is why preparing your devices for a border crossing matters if you travel with sensitive conversations.

Disappearing messages help by shrinking how much history sits on both phones. They are housekeeping, not a guarantee: they cannot stop a screenshot, and they do nothing about metadata the service already holds.

Questions people ask

What is the most private messaging app?

There is no single answer for everyone, but the questions above narrow it quickly. Prefer an app that encrypts every chat end to end by default, keeps minimal metadata, offers encrypted backups, lets you verify keys, and publishes its protocol and code for independent review.

Is WhatsApp private?

Its message content is end-to-end encrypted by default, which is strong protection. The weaker points are the metadata the service collects as part of a larger company, and backups, which are only end to end if you turn on the encrypted backup option.

Why does metadata matter if messages are encrypted?

Because it shows the shape of your life: who you are close to, when you talk, which groups you join and how your habits change. It is easier to collect and analyse at scale than message content, and often enough on its own to reveal what the content would have said.

What should I do when a contact's security code changes?

Do not ignore it. Ask the contact, through another channel, whether they changed phones or reinstalled the app. For sensitive conversations, compare the new code before continuing.

Close

A private messaging app is a system, not a label. The service decides the defaults, the metadata and the backup options; you decide the previews, the linked devices, the verification and whom you trust with the other end of the conversation. Ask the five questions of any app you use, and you will know exactly where your privacy actually rests.

Questions people ask

What is the most private messaging app?

There is no single answer for everyone, but the questions above narrow it quickly. Prefer an app that encrypts every chat end to end by default, keeps minimal metadata, offers encrypted backups, lets you verify keys, and publishes its protocol and code for independent review.

Is WhatsApp private?

Its message content is end-to-end encrypted by default, which is strong protection. The weaker points are the metadata the service collects as part of a larger company, and backups, which are only end to end if you turn on the encrypted backup option.

Why does metadata matter if messages are encrypted?

Because it shows the shape of your life: who you are close to, when you talk, which groups you join and how your habits change. It is easier to collect and analyse at scale than message content, and often enough on its own to reveal what the content would have said.

What should I do when a contact's security code changes?

Do not ignore it. Ask the contact, through another channel, whether they changed phones or reinstalled the app. For sensitive conversations, compare the new code before continuing.

Ask NEXUS about this article

Get an AI-powered summary, key points, or follow-up questions about What Makes a Messaging App Actually Private, grounded in the essay content and the broader corpus.