What this protects, and what it doesn't
Protects
- Against choosing an app on reputation or marketing instead of documented facts.
- Against assuming every chat is end-to-end encrypted, when some apps encrypt only certain chats or only when you turn it on.
- Against backups that quietly undo end-to-end encryption by storing a readable copy in the cloud.
Does not protect
- It does not rank the apps or pick a winner. The right choice depends on your threat model and on who you need to reach.
- It does not cover metadata (who talks to whom, when, from where) in depth. Encryption of content is a different question.
- It does not protect you from a compromised phone, a contact who screenshots or forwards your messages, or someone who has your unlocked device.
- Facts change. This table reflects the vendors' pages on the date shown; check the sources before you rely on a cell.
Prerequisites
- A short threat model: who you need to talk to, and who you want to keep out. See <a href="/en/privacy-guides/threat-model">Threat modeling: start here</a>.
Step by step
-
Know what each column means
- End-to-end encrypted by default: only the people in the conversation hold the keys, without you having to switch anything on. Checked separately for one-to-one chats and for groups.
- Identifier needed: what you must hand over to create an account, and what others need to contact you.
- Encrypted backup: whether the app documents a backup that is end-to-end encrypted, and whether you must turn it on.
- Open-source clients: whether the vendor publishes the app's source code.
- Protocol: the encryption design the vendor names.
"Not confirmed" means the vendor's own pages that we checked did not state it. It does not mean the answer is no.
-
Read the comparison table
Messaging apps: properties stated in each vendor's official documentation (checked 2026-10-10) App E2EE by default, one-to-one E2EE by default, groups Identifier needed Encrypted backup Open-source clients Protocol Signal Yes ("every message, every call, every time") Yes: group messages travel over the same pairwise encrypted channels as one-to-one chats Phone number to register; an optional username lets people contact you without seeing it Secure backups: opt-in, end-to-end encrypted, 64-character recovery key (Android first, iOS and Desktop to follow) Yes: Android, iOS and Desktop apps published under AGPL-3.0 Signal Protocol (specifications include X3DH, PQXDH, Double Ratchet, Sesame, ML-KEM Braid) WhatsApp Yes, for personal messages, calls, photos and videos Yes, including group chats Phone number, verified with a 6-digit code by SMS or call Optional: you must turn on end-to-end encrypted backup (iCloud or Google Drive) Not confirmed Signal Protocol iMessage Yes (Apple: messages and attachments are end-to-end encrypted) Yes: each message is encrypted individually for every device of every recipient Phone number or email address Messages in iCloud is end-to-end encrypted only while iCloud Backup is off; iCloud Backup is end-to-end encrypted only with Advanced Data Protection (opt-in) Not confirmed PQ3 (post-quantum), from iOS 17.4, iPadOS 17.4, macOS 14.4 and watchOS 10.4 Telegram No. Default "cloud chats" use server-client encryption; optional "secret chats" are end-to-end encrypted between two devices No Phone number No separate backup: cloud chats are stored in the Telegram Cloud with server-client encryption; secret chats stay on the device that started them Yes ("All Telegram client apps are fully open source") MTProto Element (Matrix) Yes: Element creates encrypted direct-message rooms by default when the other person has keys on their account Private rooms: encryption on by default, with an opt-out when you create the room; your server's administrator can change the default An account on a Matrix server; phone registration is no longer possible; email is optional, at the server's discretion Encryption-key storage on by default, encrypted before it leaves the device, with a 48-character recovery key Yes: Element Web, Element X iOS and Element X Android published under AGPL-3.0 (or a commercial licence) Matrix; the specification names Olm and Megolm for end-to-end encryption Threema Yes (all communication is end-to-end encrypted) Yes (including groups and media) A random Threema ID; no phone number or email needed Threema Safe: backup encrypted with a password you choose Yes Built on the NaCl cryptography library (no protocol name given in the FAQ) SimpleX Chat Yes: Double Ratchet with forward secrecy and post-quantum cryptography Yes: every group message is sent separately to each member, over a double-ratchet end-to-end encrypted connection per member None: no user IDs, no shared identifiers across connections No cloud backup: you export the chat database to a file yourself (after setting your own database passphrase) and move devices with the app's own migration tool, not an iCloud backup Yes SimpleX Messaging Protocol with Double Ratchet -
Check which chats are encrypted on your own phone
An app that offers end-to-end encryption may not use it everywhere. In Telegram, only secret chats are end-to-end encrypted, and only between the two devices that started them. In Element, encryption is a per-room setting you can see and enable in Room Settings. Open the chats you care about and confirm before you share anything sensitive.
-
Fix your backups
A cloud backup can hold a readable copy of conversations that were end-to-end encrypted in transit.
- WhatsApp: turn on end-to-end encrypted backup in the app's backup settings.
- iMessage: with standard data protection, iCloud Backup includes a copy of the Messages in iCloud key, protected by keys Apple holds. Turn on Advanced Data Protection to make iCloud Backup end-to-end encrypted.
- Signal: secure backups are opt-in. Store the 64-character recovery key offline.
- Element: keep the recovery key safe; without it you can lose access to encrypted history.
- Threema: use a strong, unique Threema Safe password.
Remember the other side: your contacts' backup settings decide what happens to their copy of your conversation.
-
How to choose
There is no single best app. Work from your threat model:
- Who must you reach? An app your contacts will not install protects nothing. Many people end up using more than one.
- Is handing over a phone number a problem? If it is, compare the "Identifier needed" column.
- Do you need encryption on by default, everywhere? Compare both default-encryption columns and check the chats on your own device.
- Do you need backups? Prefer a documented end-to-end encrypted option and turn it on.
- Does open source matter to you or your organisation? Compare the open-source column.
Start with Threat modeling: start here. If you choose Signal, continue with Signal hardening.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Assuming "encrypted" means end-to-end encrypted. Server-client encryption lets the provider read the content.
- Leaving cloud backups unencrypted, which gives the backup provider a readable copy of end-to-end encrypted chats.
- Choosing an app nobody you know uses, then falling back to SMS or email for the sensitive conversation.
- Treating a table like this as permanent. Vendors change defaults; recheck the sources.
Going further
Content encryption is only part of the picture. Read each app's privacy policy for what metadata it keeps, set disappearing messages where the app offers them, and verify safety numbers or security codes with the people who matter most.