Is Your Chat Really Private?
Encrypted content is only half the story. What your messenger still knows about you.

01 Encrypted content is only half the story — here's what your messenger still knows about you.
You turn on disappearing messages. You pick an app that promises end-to-end encryption. You feel, reasonably enough, like you've done the right things. And you have — partly. The content of your messages, the actual words, is genuinely protected by good encryption. Nobody in the middle can read what you said. But the content is only half the story, and in some ways it's the less interesting half — at least to the people collecting data about you.
The other half has a name: metadata. And it's almost never encrypted.
02 What the app still sees
Metadata is the data about your data. Not what you said, but that you said something — to whom, when, how often, from which device, from which rough location, and for how long you were typing before you hit send. It sounds abstract until you think about what it reveals: a pattern of messages to an oncologist's office every Tuesday morning tells a story. So does a sudden silence between two people who used to talk every day, or a burst of late-night contacts with a divorce attorney.
This is the data that survives even perfect encryption. Signal, the gold standard of private messaging, encrypts message content so thoroughly that even Signal's own servers cannot read it. But Signal still knows, at minimum, that your account exists and that it has been active. Telegram, by contrast, keeps your messages on its servers by default — its end-to-end encryption applies only to a specific "Secret Chat" mode that most users never open. WhatsApp encrypts content but is owned by Meta, which uses your account information, contacts list, and usage patterns across its family of apps. The encryption is real; the data collection around it is also real.
This is the gap that marketing copy almost never addresses: a messenger can be honest about encrypting your messages and still build a detailed profile of your social graph, your habits, and your location. These things are not contradictory.
The harder truth about group chats is that they are only as private as their least careful member.
03 The group chat problem
Private conversations are one thing. Groups add a new set of complications. When you join a group chat, every other member can see that you're there. Depending on the platform, the group's existence — its name, its member list, its creation date — may sit on a server in plaintext. Moderators and administrators typically have elevated visibility. And if any one member is using a compromised device or a client that logs messages, the encryption protecting the channel ends at their screen.
There's also the question of who can see your phone number. In many popular apps, joining a group reveals your number to every member who doesn't already have it, which is a meaningful exposure if the group is large or semi-public. Some apps have introduced mechanisms to limit this, but the defaults rarely favour privacy, and most users never change defaults.
The harder truth about group chats is that they are only as private as their least careful member. Good encryption protects the pipe; it does nothing about the person at the other end screenshotting the thread.
04 On-device, cloud, and the backup trap
Perhaps the most consistently overlooked privacy gap is the backup. Signal protects its backups with end-to-end encryption, and has done since bringing encrypted cloud backup to iOS and Android. But for years, WhatsApp chat backups stored in Google Drive or iCloud were not covered by WhatsApp's end-to-end encryption — they sat in cloud storage under the terms of those cloud providers, not WhatsApp's. WhatsApp has since introduced end-to-end encrypted backups as an option, but it is opt-in, and most users' backups still went up unprotected for years before that feature launched.
This is a version of a broader problem: the app itself may be secure while every adjacent system — the cloud backup, the carrier's network logs, the operating system's notification preview, the contact sync — quietly undoes the protection. Privacy is a system property, not a feature of a single app.
05 What actually helps
The practical picture isn't hopeless, but it requires being precise about what you're protecting against. Encrypting content protects against passive interception — someone snooping on traffic. It does nothing about the server, the backup, the metadata, or a bad actor with physical access to a device.
For genuine privacy, the checklist is short but meaningful. Use a messenger that collects minimal metadata by design — Signal's architecture is deliberately built to know as little as possible about who is talking to whom. Turn on disappearing messages, not because they defeat a determined adversary, but because they limit the data sitting on devices over time. Check your backup settings and understand which cloud account holds them. Be thoughtful about what goes into large group chats, where the threat model is fundamentally different from a one-to-one conversation.
And perhaps most importantly: understand that when an app says "encrypted," that is a true and important thing — and also an incomplete one. The question isn't whether your messages are encrypted in transit. The question is who else has a key, what they're logging around the edges, and how long they're keeping it.
Private enough is a moving target. It's worth knowing where the lines actually are.
◆ People & organisations
Signal
Referenced in this piece
privacy-focused messenger; E2E encrypted by default, minimal metadata retention
Telegram
Referenced in this piece
cloud-based messenger; E2E only in Secret Chat mode
Referenced in this piece
Meta-owned messenger; E2E content encryption, broad surrounding data collection
Meta
Referenced in this piece
parent company of WhatsApp, Facebook, and Instagram