We rely on messengers constantly.
Even in countries where SMS is largely avoided, many people still default to messengers like Facebook, Snapchat, or Discord to communicate with most of their contacts.
But few people realize that these chats aren't as private as they seem. Whether one-to-one or in a group, there's always at least one more participant in some form or another.
This week, I'll share the three best messengers for actual privacy in 2026 and help you decide which one is right for you.
Why You Need an Encrypted Messenger
In order to understand how your messages aren't private, I need to quickly explain two things:
- How network communication works: All electronic communications - from text messages and phone calls to email and web pages - work by what could be over-simplistically described as "relays." When I call you on the phone, my phone doesn't connect directly to your phone. It hops through various cell towers, network cables, routers, and switches the same way that a piece of mail sent from the other side of the world would go through various trucks, planes, and sorting centers.
- Encryption. Encryption is what's made the modern internet possible at all. It's the science of using math to scramble data so that it's unreadable to anyone without the key. I have a more detailed explanation here:

Now that we know those concepts, to understand why your messages aren't currently private, let's imagine the electronic messages you send as physical letters going through the mail system.
SMS is like sending a postcard. SMS typically doesn't use any encryption at all, and even when it does it uses weak encryption standards that are easily bypassed. This means that as your standard text messages go from tower to tower and carrier to carrier, anyone along the way can read them with almost no effort.
Other messengers - like Discord and Facebook - are encrypted, however the providers possess a copy of the encryption keys.
Now you might be thinking that in the real world, nobody is supposed to open your mail at any point along the way. There is something like this in the digital space, too: end-to-end encryption (E2EE).
E2EE functions more like the way the mail works in reality in that once you seal the message, it doesn't get opened again until it gets to the recipient. The difference is that in the physical world, anyone can easily rip the paper and open the envelope. They simply choose not to for any number of reasons: integrity, lack of interest, fear of consequences if caught, etc. In digital space, properly implemented E2EE makes it technically impossible for anyone to open even if they wanted to.
You might think that settles it. Simply pick an E2EE messenger and you're set. But even E2EE isn't enough on its own. Some services - like iMessage and WhatsApp - can't read the message content but still collect metadata:
- Who you talk to
- When you communicate
- How long conversations last
- Your IP address and device information

A truly private messenger protects both content and metadata.
The Apps You Should Avoid
Usually I focus on suggesting apps I think people should use, but sometimes certain apps have such glaring concerns and are so popular that I have to - in good conscience - actively warn people against using them. In the case of encrypted messaging, there are two such apps:
WhatsApp uses the Signal Protocol, which is currently the golden standard in secure communication (more on that later). Despite that, there's a glaring reason people don't recommend it:
Meta owns WhatsApp.
Meta is one of the most anti-privacy companies on the planet. It's not even that they don't take privacy seriously, it's that they actively violate your privacy. There is literally an entire Wikipedia page dedicated to listing all the privacy concerns with Meta.

To name just a few notable incidents that drive the point home:
- The Cambridge Analytica Scandal. In the 2010s, a political consulting firm collected data on millions of Facebook users using an app called "This Is Your Digital Life," which masqueraded as a fun quiz to give you a snapshot of your profile but was secretly collecting multiple data points on both people who took the quiz and their friends. The data was later used for political advertising and is believed to have played huge roles in the 2016 election of Donald Trump and the passing of Brexit. This incident proved that Facebook was not properly securing user data and collecting more than users realized - an allegation further proven in 2022 when leaked documents suggested that Facebook can't even accurately keep track of all the data it collects.
- Shadow profiles. Facebook collects data even on people who haven't signed up for the platform in what are commonly called "shadow profiles." Zuckerberg denied this under oath, but a 2012 data breach all but proved it's true.
- App loopholes. Last year we learned that Meta apps like Facebook and Instagram purposely abuse technical workarounds to bypass privacy protections built into your phone, allowing them to collect much more data than they're supposed to without your consent. (Remember what I said about how Meta isn't just bad at privacy but actively violates it?)
- Data sharing. As of 2021, WhatsApp began sharing metadata with their parent company to improve ads across their ecosystem of apps like Instagram, Facebook, and Threads.
Unfortunately WhatsApp already has a huge market share in many parts of the world, including Europe and Latin America, making it difficult to avoid for most people. Still, I would advise you to only use it when you have no other choice and instead try to migrate all your friends and family to one of the other options I recommend below.
Telegram
Telegram markets itself as an encrypted messenger, but the truth is more "nuanced" (to put it diplomatically).
Only Secret Chats are end-to-end encrypted. Regular cloud chats store messages on Telegram's servers where they can be accessed if demanded. Many users never switch to Secret Chats for a number of reasons:
- This can only be done on mobile devices
- It must be done each time you install the app on a new device
- Each new device treats each Secret Chat as a new, unique chat instead of transferring between devices, making them very onery to use on multiple devices
- It can only be done for one-to-one chats, not group messages
Not that it really matters cause Telegram's encryption protocol was largely discredited by experts for years.
It's worth noting that Telegram has since upgraded their encryption protocol to MTProto 2.0. Experts have noted this as an improvement, but say that vulnerabilities remain. That's also based only on a single audit, so more peer review is needed.
Of course, Telegram shouldn't be trusted anyways, in my opinion. For years Telegram told users that:
To this day, we have disclosed 0 bytes of user data to third parties, including governments. (Emphasis mine)
But after their CEO got arrested in France in 2024 for allegedly failing to comply with legal demands related to Telegram's content moderation, they started publishing more transparency reports that showed that they'd actually handed over user data thousands of times in the past.
After Telegram fessed up, they then gaslit users by changing their FAQ to read:
To this day, we have disclosed 0 bytes of user messages to third parties, including governments. (Emphasis mine)
So sure, let's trust the company with shoddy home-made crypto that's not enabled by default and can't be enabled without using a phone (which are notoriously hard to make private) who overtly lies to their users.
The Best Private Messengers
Okay so now what we know what not to use, which apps should you use and why?
Signal

Signal remains my top recommendation for most users and use cases. Here's why:
- Strong cryptography. Every conversation uses the Signal Protocol with Perfect Forward Secrecy (PFS), meaning each message gets encrypted with a different key so that even if one key gets hacked, only one of your messages is exposed. This makes it impractical for adversaries to bother hacking messages this way. You can also verify safety numbers with contacts to confirm that your conversations aren't being intercepted and you can enable disappearing messages to ensure that if your device falls into the wrong hands, only so much data can be retrieved at all. Signal's cryptography has long been praised by experts for being the golden standard.
- Minimal data collection. Signal requires only a phone number to sign up and allows the use of Voice-over-IP (or burner) numbers. When it comes to connecting with others, you can share a username or QR code to protect your phone number. Signal's transparency reports show they retain almost no account data. When governments demand information, the only data they have to hand over is when the account was created and when the account last connected to Signal's servers.
- User friendly and feature rich. Despite being so private and secure, Signal is incredibly easy to install and use, and has tons of features that will help even casual users love it, such as GIPHY integration, stickers, voice memos, emoji reactions, and much more. There's no need for users to worry about technical things like managing keys or enabling settings. Everything is encrypted on every device and it all works together seamlessly.
Of course, there is no perfect privacy tool. While Signal is probably right for 95% of people, there are some reasons that it may not be right for everyone. For example:
- Centralization. While there are advantages to centralization (such as being able to ensure that every server is running the latest version with the latest security patches), there are also drawbacks like making it easier to censor. Signal does offer volunteer-run proxies to help with this, but they're much less agile and effective than a decentralized architecture.
- Phone numbers. In some countries phone numbers are tied to your legal government ID, meaning that you can't use a burner number to sign up for Signal. While you can hide your phone number from the public - and Signal encrypts phone numbers so they can't simply hand over a list of users - it's trivial for them to look up a phone number provided by law enforcement, which they have done.
Session

Session started off as a fork of Signal, but with a decentralized, onion-routed architecture like Tor. This strips your messages of metadata and makes the network more resilient against censorship.
Session also differentiates itself from Signal by not requiring a phone number. In fact, there's not even an option to enter things like email, phone number, or username. Session usernames are randomly generated, meaning you can't even accidentally create identifiable information (such as reusing the same username across multiple services).
Because of these design choices, Session is very popular with hardcore privacy maximalists.
Of course, Session has also drawn a lot of criticism for other things:
- Cryptocurrency. The Session network is powered by their in-house Session Token as an effort to resist Sybil attacks, which is where one entity can run a majority of nodes and thus defacto take over the network. The crypto aspect is completely optional and invisible to end-users, but crypto skeptics deride it anyways. There are also valid criticisms on how effective this approach is for actually resisting Sybil attacks in practice.
- Perfect Forward Secrecy. Session removed PFS from their fork to increase stability. They are hoping to re-add it in the near future. In my personal opinion, this is a very advanced feature that the average person doesn't need to worry about, but it's still drawn a lot of criticism from security experts.
- Sustainability. Session is facing a funding crisis and nearly shut down this year over it. They were forced instead to severely downsize their team and operations, thus slowing development. If you use Session, please be sure to donate to keep them around, and consider signing up for a Pro account once those are made public.

SimpleX

SimpleX is on the cutting edge of privacy design. SimpleX is decentralized and utilizes a type of onion-routing for maximum privacy, but the really unique feature is the lack of permanent user IDs.
In SimpleX, you generate new links or QR codes to add new contacts. What's more is that you can even use multiple profiles within the same account - gone are the days of needing multiple accounts or apps to separate various parts of your life.
SimpleX retains highly secure features like PFS and "double ratchet" (part of what makes Signal so secure) on top of this.
SimpleX's primary drawbacks are lack of features and a higher barrier to entry than Session or Signal. SimpleX's development team has largely been focused on security and scalability, so until now they haven't bothered with the "quality of life" features like GIFs and stickers. I'm told those are planned, but haven't yet arrived.
SimpleX's onboarding and use is also a bit more complicated. While Signal and Session are basically "just keep clicking and start using" to set up, SimpleX's UI offers a lot more options and thus may take some getting used to. I wouldn't say it's any harder to use, it's just not as "click and start using" as the competitors.
It's also important to note that SimpleX stores all data on device, so you'll have to be good about keeping backups or else it could all go away next time your phone goes for a swim. I've personally fallen victim to this a couple times.
The New Oil is supported by our audience. If you're getting value out of our work, please consider supporting us. (It gets rid of this banner!)
Honorable Mentions
Below are two messengers that don't get a full recommendation because they're both Android-only. However, if you are an Android user, you should do your research into these and see if they're right for you.
Briar

Briar stands out in the messaging space because of its unique peer-to-peer architecture. Messages are sent directly between devices over Bluetooth, Wi-Fi, or Tor—no central servers store your data.
This design provides exceptional resilience during internet shutdowns, censorship, and power outages. However, it requires both devices to be online simultaneously for most features, limiting practicality for most users (and also draining battery pretty heavily).
(You could work around this by hosting Briar Mailbox on a spare, always-on and always-connected Android device.)
It should be noted however that Briar is currently in Maintenance Mode, once again due to lack of funding. If you find Briar interesting and helpful, please consider donating.
Molly

Molly is a Signal client that adds additional hardening features on top of what Signal offers - things like encryption-at-rest, RAM shredding, and automatic locking.
Furthermore, it offers small quality of life features such as UnifiedPush support (making it more reliable on degoogled devices like Graphene OS) and multi-device support.
If you're using a degoogled Android like Graphene, Calyx, or Lineage, I strongly recommend considering Molly for extra functionality and security.
But keep in mind that:
- You are trusting an additional party with your data
- Updates may be slightly slower than if you were using Signal directly
Final Thoughts
It's important to remember that even E2EE only protects messages in transit. It locks out the provider so you can have true privacy, but if someone infects your device or physically confiscates it, the messages are there for them to see. (Hence why one of my criteria is "disappearing messages.")

Demanding E2EE messengers isn't paranoid, it's about self-respect.
Imagine if there was a stranger in the room every time you talked to your friends, writing down both sides of the conversation. While there are probably some things you wouldn't mind them hearing, there are others you probably wouldn't want them to know. (Plus it's just plain creepy.)
That's what mainstream messengers are like.
Apps like Signal, SimpleX, and Session - who go above beyond to protect both your content and metadata - offer you a truly safe space to be yourself with your friends.
Whatever you choose, abandon WhatsApp and Telegram for anything that matters.
Your conversations belong to you, not corporations. Take control.
Tech changes fast, so be sure to check out our website for all the latest recommendations, tools, services, and more.



