Private Communication for Everyone — Part Two: Beyond Email
May 22, 2026· updated May 25, 2026
See also Email Privacy — A Plain-Language Guide: The Problem, the Promises, and What You Actually Get
This is the second part of a plain-language guide to digital privacy. Part One covered email specifically — the problems, the promises, and what services like Proton Mail actually deliver.
This part broadens the lens: if email has so many structural limits, what does truly private communication look like, and how do the most popular messaging apps compare?
The Same Problem, Now on Your Phone
Email was designed in 1982, when the internet was a research network shared by a handful of universities. Nobody back then imagined private medical conversations, journalist tip-offs, or organizing protests over it. The protocol was never built for privacy — and as Part One explained, even the best encrypted email services inherit those limitations.
But here is the uncomfortable truth: most people’s daily communication has moved off email and onto messaging apps — WhatsApp, Telegram, iMessage, Instagram DMs — and the same gap between “encrypted” and “private” applies there too.
When WhatsApp says “your messages are end-to-end encrypted,” that is technically true. But what it does not say is that WhatsApp can still see who you talked to, when, how often, from which device, and where you were. For the company that runs WhatsApp — Meta, also known as Facebook — this metadata is extremely valuable. It reveals your social network, your sleeping schedule, whether you’re communicating with a lawyer or a doctor, and patterns in your relationships. In 2021, a ProPublica investigation found cases where WhatsApp shared this metadata with US law enforcement. Content? Hidden. Everything else? Very much visible.[whatsapp +2]
So before looking at what each app delivers, it helps to understand the two layers of private communication:
- Content — What you actually said. This is what “encryption” usually protects.
- Metadata — Who you talked to, when, how often, from where. This is what most apps still expose — and it often reveals more than the words themselves.
The Apps Everyone Uses
WhatsApp — Encrypted Content, But Meta Still Sees a Lot
WhatsApp uses the same underlying encryption technology as Signal — widely considered the gold standard. This means Meta cannot read the words of your messages or listen to your calls. That is a genuine protection.[malwarebytes +1]
But Meta collects extensive metadata: your contact list, who you message, how often, your IP address, your device type, your location if enabled, and status information (when you were last active, when you read messages). In January 2026, researchers from the University of Vienna demonstrated that WhatsApp’s contact system exposed data on roughly 3.5 billion registered accounts — including phone numbers, profile photos, and status text — through an automated querying method.[newspointapp +1]
Furthermore, cloud backups of WhatsApp chats — the option most users leave turned on — are stored on Google Drive or iCloud and are typically not end-to-end encrypted by default. Your messages may be locked on your device but sitting readable in the cloud.[newspointapp]
The bottom line: WhatsApp is fine for keeping casual conversations away from hackers or café Wi-Fi eavesdroppers. It is not appropriate for sensitive communications where you need to hide who you are talking to, or where you do not want a company with Meta’s advertising model building a profile of your relationships.
Telegram — The Biggest Misconception in Digital Privacy
Telegram is perhaps the most widely misunderstood app in terms of security. It has over a billion users who largely believe it is a privacy-focused, encrypted platform. This reputation is largely undeserved.
The critical fact: By default, Telegram messages — including all standard chats, group chats, and channels — are not end-to-end encrypted. They are encrypted in transit (between your phone and Telegram’s servers), but Telegram’s servers store them in readable form. This means Telegram staff can read your messages. It means if Telegram’s servers are hacked, your messages are exposed. It means when governments ask Telegram for messages, there is something to hand over.[discuss.privacyguides +2]
Telegram does offer “Secret Chats” — a feature you must manually enable, per conversation, for one-on-one chats only — that activates genuine end-to-end encryption. But group chats (where most Telegram conversations happen) have no E2EE option at all. Desktop clients do not support Secret Chats.[josa +1]
A clever sleight of hand: Telegram uses the same word — “MTProto” — to describe both its server-side encryption (which protects messages in transit, but not from Telegram) and its Secret Chat encryption (which is true E2EE). This makes it easy for users to believe all chats are equally protected when they are not. In September 2024, Telegram’s founder Pavel Durov was arrested in France, and the company subsequently confirmed it has shared IP addresses and phone numbers with law enforcement since 2018.[discuss.privacyguides]
The bottom line: Telegram is better thought of as a social broadcasting platform with some messaging features than a private communication tool. Do not use it for anything you would not be comfortable with Telegram’s servers seeing.
iMessage — Good, But Apple-Only
Apple’s iMessage uses genuine end-to-end encryption for messages between Apple devices. If you and your contact are both using iPhones or Macs, iMessage is a strong default choice for everyday conversations. Apple also allows users to enable “Advanced Data Protection,” which extends encryption to iCloud backups of messages — a meaningful upgrade.[optf]
The limitation is that it only works within Apple’s world. The moment you text someone on Android, iMessage falls back to standard SMS — a completely unencrypted system from the 1990s. These messages appear in green bubbles, and they offer zero privacy protection. If your contact group includes anyone not on Apple hardware, you are mixing protected and unprotected conversations in the same app, which is confusing and easy to mismanage.
The bottom line: iMessage is a solid everyday option if everyone you communicate with uses Apple devices. For anything sensitive, or for cross-platform communication, you need something better.
The Better Alternatives
Signal — The Closest Thing to a Benchmark
Signal is consistently recommended by security researchers, journalists, privacy advocates, and the Freedom of the Press Foundation as the most private mainstream messaging app available. It is free, open-source, run by a non-profit (the Signal Foundation), and accepts no advertising revenue.[pcmag +2]
What Signal does differently from WhatsApp:
- Every message, call, video call, and group chat is end-to-end encrypted by default — no secret settings needed.[softmaker +1]
- Signal collects almost no metadata. It does not log who you talk to or when. In multiple US court cases, the only data Signal could produce was the date an account was created and the date it last connected to the internet.[malwarebytes]
- A feature called “Sealed Sender” even hides the sender’s identity from Signal’s own servers — the server knows a message is going to someone, but not who sent it.[wired +1]
- Disappearing messages can be set to auto-delete after any time period from a few seconds to weeks.[malwarebytes]
- Calls can be routed through Signal’s servers to hide your IP address from the person you are calling.[malwarebytes]
- Since 2024, users can create a username instead of sharing a phone number with contacts — your phone number is no longer visible in the app to people who do not already know it.[techradar]
Signal’s remaining limitations:
- You still need a phone number to register (though it no longer needs to be visible to anyone).[reddit +1]
- Everyone in a conversation must have Signal installed — there is no interoperability with WhatsApp or regular SMS.
- Signal is centralized (run by one organization on one set of servers). If Signal goes down or is compelled to change its behavior under legal pressure, all users are affected.
Practical verdict: For the vast majority of people — including journalists, doctors, lawyers, activists, and anyone handling sensitive conversations — Signal represents the best available balance of strong security and ease of use.[cloudsek +1]
Matrix / Element — Signal for People Who Want Full Control
Matrix is an open communication protocol, similar to how email is a protocol rather than a single app. Element is the most popular app built on Matrix. Together, they offer end-to-end encrypted messaging, voice calls, video calls, and file sharing.[westack-it +2]
The key difference from Signal: Matrix is federated and decentralized. This means you can run your own Matrix server (as you might already run other self-hosted services) and your messages never leave infrastructure you control. You can also communicate with users on other Matrix servers around the world, similar to how email works — but with end-to-end encryption.[reddit +1]
This model is attractive for:
- Organizations and teams who want to ensure their communications never touch a third-party server
- Privacy-conscious individuals who already self-host infrastructure
- Governments and enterprises (notably, France’s government runs its own Matrix deployment; it is used by NATO, Bundeswehr, and others)[element]
The trade-offs:
- More technical to self-host correctly
- The user experience in Element is less polished than Signal or WhatsApp
- End-to-end encryption in Matrix requires correct key management, which can be confusing for non-technical users — messages can become unreadable if cross-signing between devices is not set up properly
Practical verdict: For a technically confident user or organization wanting full data sovereignty, Matrix/Element is the most powerful option. For everyday personal use, Signal is simpler and just as secure.
What About Video Calls?
This is an area where the market has genuinely failed privacy-conscious users — and where the ecosystem is still catching up.
Google Meet, Microsoft Teams, Zoom: These use encryption in transit (your call is scrambled while traveling to their servers), but the call is decrypted at the server and re-transmitted. The provider can, in principle, access your call. This is technically adequate for most business use, but it is not end-to-end encrypted in the meaningful sense.[symbolic]
FaceTime: Genuinely end-to-end encrypted for calls between Apple users — a rare exception among large platforms. Supports up to 32 participants. The limitation, as with iMessage, is that all participants must be on Apple hardware.[symbolic]
Signal video calls: End-to-end encrypted for both one-to-one and group video calls. This is a strong option when all participants have Signal installed.[softmaker]
Element Call (part of Matrix): End-to-end encrypted group video powered by the Matrix protocol. Usable even without an account through a web browser, though the video quality and reliability are still maturing.[discuss.privacyguides]
Jitsi Meet: An open-source video conferencing tool. It is free, requires no account, and anyone can host their own instance. However, the hosted public version (meet.jit.si) is not end-to-end encrypted by default for group calls — only one-on-one calls. For sensitive group video calls, you need to either self-host Jitsi or use Signal.[reddit +2]
Discord: As of May 2026, Discord has enabled end-to-end encrypted voice and video calling by default for all users — no opt-in required. This is a significant improvement, though Discord still collects extensive account and behavioral metadata.[techcrunch]
The Big Picture: Content vs. Metadata
One idea is worth repeating, because it matters more than any single app recommendation: Encrypting the content of a message is not the same as communicating privately.
Think of it like a postcard versus a sealed envelope. Encryption gives you the envelope. But the envelope still has your name and address on the front, a postmark showing when it was sent, and it passes through a sorting facility that logs every package.
If someone wants to build a picture of your life, the envelope data — who you write to, how often, at what hours — is often enough.
Practical Recommendations
- For most people who just want better privacy than WhatsApp without switching their entire social circle: Install Signal. It works exactly like a messaging app, is free, and requires no technical knowledge. Encourage your closest contacts to install it too.
- For groups and families who need a group chat that stays private: Signal supports group chats with full E2EE. It is the simplest upgrade from a WhatsApp or iMessage group.
- For journalists, activists, lawyers, or doctors handling sensitive communication: Signal is the baseline — not a luxury. Enable Sealed Sender, use a username instead of your phone number, set messages to disappear after a reasonable window, and route calls through Signal to hide your IP.[^14][^4]
- For organizations that want to own their communications infrastructure: Set up a Matrix homeserver (Synapse or Conduit) with Element clients. Your team’s messages never leave your servers, and you can federate with other Matrix users on the open internet.[^22][^19]
- For video calls when all participants are on Apple devices: FaceTime.
- For mixed platforms: Signal video.
- For open-source group video where you trust the server operator: self-hosted Jitsi.[^27][^25]
- Avoid Telegram for anything you consider private. It is a powerful social platform, but standard chats are not end-to-end encrypted, and the company has a history of sharing user data with law enforcement.[^8][^6]
The One Thing No App Can Fix
Every app above depends on one thing beyond its control: the device it runs on. If your phone is compromised by spyware (like Pegasus or Paragon), an attacker can read your messages directly on screen — before they are encrypted and after they are decrypted — because they have taken control of the device itself. No app can protect against a compromised device.
For extremely high-risk individuals (journalists in authoritarian countries, political dissidents, human rights workers), physical device security, keeping software updated, and being cautious about unknown links and files matters as much as which app you use. Disappearing messages on Signal also help here — if messages delete themselves, there is less to find on a compromised device.
Good digital hygiene — keeping your OS and apps updated, using a strong screen lock, and being skeptical of unexpected links — remains the foundation on which any private communication tool stands.
References
- About end-to-end encryption – WhatsApp Help Center – End-to-end encryption keeps your personal messages and calls between you and the person you’re commu…
- Uncovering WhatsApp’s Metadata Practices: What You Need to … – WhatsApp utilizes encryption to ensure the safety of your messages, but it also collects metadata su…
- WhatsApp’s End-to-End Encryption Isn’t Privacy – Bob | Substack – End-to-end encryption (E2EE) means Meta can’t read the content of your WhatsApp messages. That’s acc…
- Moving from WhatsApp to Signal: A good idea? – Malwarebytes – Both WhatsApp and Signal offer end-to-end encryption, ensuring that only the sender and recipient ca…
- WhatsApp, metadata and privacy: when the problem is not the … – Two independent studies expose critical WhatsApp metadata leaks: 3.5 billion accounts enumerated, de…
- Telegram pledges to exit the market rather than “undermine … – The desktop clients do not support end-to-end encryption, which means 100% of desktop chats leak to …
- Telegram does not enable end-to-end encrypted conversations by … – Telegram does not enable end-to-end encrypted conversations by default. Unless you manually start an…
- Telegram is not end-to-end encrypted | Oli’s Blog – The vast majority of the messages sent through Telegram are not end-to-end encrypted. Most messages …
- How Secure is Telegram Actually? – Jordan Open Source Association – Therefore, it is not true that Telegram does not have end-to-end encryption, but it is true that it …
- Remote work and study platforms: A collaboration tool comparison – FaceTime supports end-to-end-encrypted video conferencing with up to 32 participants, and FaceTime c…
- The Best Private Messaging Apps We’ve Tested for 2026 – These are the top private messaging services we’ve tested to keep your conversations confidential fr…
- 8 Best Secure Messaging Apps For Encrypted Chats In 2026 – Signal is the best secure messaging app in 2026, with strong encryption and simple private chats. Ex…
- Signal, WhatsApp, Telegram – who actually protects your data? – What Signal gets right · End-to-end encryption across the board: All messages, calls, video chats an…
- Signal Has a Clever New Way to Shield Your Identity – WIRED – “Sealed sender” gives the leading encrypted messaging app an important boost, hiding metadata around…
- What does sealed sender do and what are the optimal settings for … – Sealed sender is about what signal’s servers (and whoever owns the infrastructure) can discern when …
- Signal officially abandons phone numbers sharing in the name of … – Signal officially said goodbye to phone numbers for good, in the name of privacy. This means that yo…
- Is it ok to put my phone number on signal since it’s a privacy … – Reddit – Signal doesn’t need your phone numbe in order to work. They require a phone number at registration t…
- Register a phone number – Signal Support – Requirements · Signal installed on your Android phone or iOS device. · Signal uses your existing pho…
- Matrix Chat – WeStack – Secure and decentralized communication with Matrix – self-hosted, encrypted, and interoperable with …
- Element: Open Source Alternative to Wire and Threema Work – Element is a secure, open-source chat app built on the Matrix protocol. It offers end-to-end encrypt…
- The Open-Source Federated System for Secure Messaging, Voice … – Element is a free, open-source app built on the Matrix protocol. It enables secure chats, voice call…
- Self-Host Your Own Private Messaging App with Matrix and Element – A full guide on how to self-host a private messaging app using Matrix and Element. This is a solid o…
- Element | Secure collaboration and messaging – Element is a Matrix-based end-to-end encrypted messenger and secure collaboration app. It’s decentra…
- Introducing Magicall: Encrypted video calls that actually work – The free tier gives you everything you need for secure video calling: end-to-end encrypted calls wit…
- Jitsi meet alternative – Questions – Privacy Guides Community – I want a private video conference with good video quality, ease of use, no interruptions, anonymous …
- Jitsi Meet team is working on end-to-end encryption for video … – Jitsi Meet team is working on end-to-end encryption for video conferencing … What are Google and F…
- Jitsi: Free Video Conferencing Software for Web & Mobile – Somewhat unexpected, but we now run our own videoconferencing software, #Jitsi It is 100% privacy fr…
- Discord enables end-to-end encrypted voice and video calling for … – “End-to-end Encryption is now standard for every voice and video call on Discord, outside of stage c…