"I have nothing to hide" is something people say who have never had last year's texts read back to them by a stranger. There's no conspiracy in there. There's the address you live at, the diagnosis you discussed with your sister, the fight with your partner, a photo of your kid, a password you carelessly typed into a chat. None of it is secret in the spy-novel sense. It's just your life — and the question was never whether you have something to hide, it's who gets to decide who sees it. Right now, that decision belongs to whichever company built the app sitting on your phone.

The good news: fixing this doesn't require a cryptography degree. It takes one evening and the willingness to survive five minutes of mild awkwardness asking someone to "please install this app."

Who's actually reading your messages

Plain SMS is an open book — your carrier can technically read the text, and in a fair number of jurisdictions is obligated to hand it over on request without much friction. A regular messaging app isn't much better if the service doesn't encrypt in a way even the service itself can't undo.

This is where most people's understanding gets fuzzy: "encrypted" and "end-to-end encrypted" (E2E) are not the same claim. Plenty of services encrypt traffic between your phone and their server — that stops someone snooping on public wifi, but not the service itself: the message arrives at the server in readable form, gets decrypted there, and the company can technically read it, hand it over on request, or feed it into ad-targeting models. End-to-end encryption works differently: the message is encrypted on your device with a key nobody else holds, and only decrypted on the recipient's device. The server sees an unreadable blob the whole way through. Even if it's breached, subpoenaed, or an employee decides to peek — there's nothing there to see.

WhatsApp and iMessage use end-to-end encryption for message content by default. Telegram doesn't: ordinary chats sit on Telegram's servers in a form the company can technically read; true end-to-end encryption only exists in a separate "Secret Chat" mode almost nobody enables, because nobody's thinking about it mid-conversation.

Metadata: the other half of the problem

Even with content encrypted, there's still the question of who talks to whom, when, and how often. That's metadata, and it reconstructs almost as much as the text itself. Someone once put the core of it precisely: the content of a call is often less important than the fact of the call — a call to a divorce lawyer says plenty before a single word is spoken.

Most messengers, WhatsApp included, collect this metadata and use it — at minimum for internal analytics, and WhatsApp is owned by Meta, whose entire business model runs on behavioral data. Which is why choosing a messenger isn't just "is content encrypted" — it's also "how much does this company know about the shape of my life without reading a single message."

Signal: the privacy workhorse

Signal is a nonprofit app funded by donations — in 2018, one of WhatsApp's co-founders put roughly fifty million dollars into the Signal foundation after leaving the company he'd sold to Facebook. Signal has no ad business and no investors who need your data to pay off, and its underlying protocol is good enough that WhatsApp itself licenses it, along with parts of Google Messages — the difference is that Signal builds its whole architecture around collecting minimal metadata, not just encrypting text.

Setting it up:

If Signal doesn't fit: alternatives

Signal isn't the only option, and it isn't always the best fit for a given need.

Threema — a Swiss app, a one-time paid purchase, no phone number required at all: you can create an anonymous ID instead. Good if you don't want your messaging tied to your SIM card.

Session — built on a fork of the Signal protocol, but strips out even the phone number and routes messages through a decentralized network designed to hide who's talking to whom from the infrastructure itself. Slower and less convenient, but it's the option for genuinely high anonymity needs.

iMessage — if your whole circle is on iPhone, Apple's built-in end-to-end encryption works transparently with nothing new to install. The weak point is cloud backups: by default, Apple historically retained the ability to decrypt an iCloud backup under a court order. Turn on Advanced Data Protection in iCloud settings and that closes — but it's not on by default, you have to find it and flip it yourself.

Wire — used by teams and businesses, also end-to-end encrypted, also headquartered outside the jurisdictions with the most aggressive data-disclosure laws.

What encryption doesn't solve

It won't protect a conversation from someone with physical access to your unlocked phone — put a passcode on the device itself, separate from the app. It won't stop a screenshot taken on the other end. And it doesn't cancel out backups: if you're syncing chats to an ordinary, unencrypted cloud backup, you're opening with your own hands the door you just closed.

> Our record. In the system of Ma'at, a person's name — their Ren — isn't just a label: to name someone precisely is to hold power over them. Your messages are an unfolded Ren: who you are, who you're close to, what you're afraid of, what you hide even from yourself. Handing it over unencrypted to someone else's server is the same as writing your true name on the gate of a temple you don't own. End-to-end encryption doesn't hide you from the world. It just hands back the right to decide who gets to speak that name.

Do this today

Don't wait for a convenient moment to sort out apps. Install Signal right now, confirm your number, and send one message to the person closest to you asking them to move important conversations there. Five minutes, and one of the most intimate streams of your life stops being someone else's property.