DEV Community

Cover image for Is your privacy messenger actually private? Check for yourself
Yuurin Bee
Yuurin Bee

Posted on

Is your privacy messenger actually private? Check for yourself

Privacy Messenger Infographic

Infographic by Formless Labs last updated on 8/15/2026

"Privacy messenger" has become one of the most overloaded phrases in tech, just like "decentralized". Almost every chat app now claims end-to-end encryption, and most of them genuinely have it. But encryption only protects what you say. It says nothing about who you talked to, when, from where, and what identity you had to hand over to sign up.

That gap is why this Privacy Messengers infographic was originally made and kept up to date. This post explains how each column is defined, why some apps land on "Partial," and, just as important, what the chart doesn't measure.

Privacy BSOD Image

Three Layers of Privacy

It helps to separate privacy into three layers:

  1. Content: the messages themselves. End-to-end encryption solves this and most serious messengers do it well, but there are also degrees of encryption.
  2. Metadata: the envelope around the message and the trail. Who talks to whom, how often, at what times, from which location (IP address). Metadata can reveal your relationships and routines even when every message is encrypted.
  3. Identity: what ties your account to you as a real person. A phone number or email address links your chat identity to your legal identity, your carrier, and often your contacts. KYC is the greatest enemy here.

Most marketing talks about layer one. Most real-world privacy failures happen in layers two and three.


The Criteria

Column "Yes" means "Partial" means
Open-Source Client and server code are public Only the client is public
Reproducible Builds Published builds can be verified against the public source Only on some platforms
Independent Audit Protocol and app have both had a public third-party audit Protocol only, or the audit predates major changes
Decentralized No single company operates all the infrastructure Single or few points of failure
Self Host An individual can run their own server or relay Possible but limited, or only part of the stack
No KYC You can create an account without a phone number, email, or real identity An identifier is required or strongly recommended
Contact Discovery You can find and be found without uploading your address book Upload is hashed, or optional but strongly nudged
Default E2EE Every chat is end-to-end encrypted with no action from the user Encryption exists but is opt-in, or covers only some chat types
Group E2EE Group chats are end-to-end encrypted by default Not on by default, but could be enabled
Metadata Privacy The service is designed so operators can't easily build a social graph Content is protected, but servers can see who talks to whom
IP Protection A built-in way to hide your IP address from servers and other users Only during calls, or requires configuring an outside tool
Data at Rest The local message database is encrypted by the app itself Relies on the operating system's disk encryption
Encrypted Backups Backups are end-to-end encrypted by default Available but opt-in, or the provider holds a recovery key
Censorship Resistance Works where blocked without third-party tools Needs manual proxy or bridge configuration

excluded from table (available in infographic)

Ads: Whether the app shows advertising
Cost: Whether using it costs money


Why some apps score "Partial"

Signal is the benchmark for content encryption, and its protocol is used by many other apps. It scores Partial on metadata because its servers still see connection information like IP addresses, even though features like Sealed Sender hide the sender of most messages and Signal retains very little data. It's centralized (run by one organization on commercial cloud infrastructure), and registration still requires a phone number (development mentioned around account creation without a phone number in the near future). Usernames now let you avoid sharing your number, but you still need one to sign up.

Matrix is open, federated, and encrypts private rooms by default. But homeservers see room membership, who's messaging whom, and timestamps, and federation copies that metadata to every server participating in a room. Whether you need an email depends on the homeserver you pick. Self-hosting is fully possible but takes real sysadmin skill.

DeltaChat runs on email infrastructure, which makes it decentralized and self-hostable in a very practical sense. Mail servers still see sender and recipient addresses and timing, hence Partial on metadata, though DeltaChat encrypts subjects and other headers where it can.

Session routes traffic through an onion-routing network and requires no phone or email, which makes it strong on metadata and identity. Self-hosting is Partial because you can run parts of the network, not your own full independent service.

SimpleX has no user identifiers at all, not even random ones, and its message queues can run on anyone's server, including your own. It's one of the strongest designs on metadata. Self-hosting is fully possible but technical.

Telegram is the outlier. Regular chats are encrypted between you and Telegram's servers, not end to end. Opt-in "Secret Chats" are end-to-end encrypted, but only one-on-one, so groups get no E2EE. It requires a phone number, is centralized, only publishes its client code, and shows sponsored messages in large public channels.

Vector is built on Nostr, a protocol where messages travel through independent relays that anyone can run. Direct messages use NIP-17 gift-wrapped events, which hide the sender and the real timestamp from relays. Communities run on Concord, Vector's own protocol, where a Community's address derives from its owner's key and membership is the encryption key: removing someone triggers a key rotation, so they are cryptographically locked out rather than just hidden from a list. Honest caveat: relays can still see the recipient's public key, and your IP address is visible to them unless you route around it. Vector embeds Tor directly, using the Tor Project's own Rust implementation, so one toggle in Settings covers that without a separate browser or proxy.


What the chart doesn't measure

This is the section most critics like to look over. A single table can't capture everything, and several things that matter a lot aren't on it:

  • Forward secrecy. If someone obtains your key today, can they read what you sent last year? Protocols that rotate keys continuously limit a compromise to very little history; protocols that encrypt to long-lived keys don't. Designs across this chart differ, so check how your app handles it.
  • Audit depth and recency. The column says whether an audit happened. It can't say how deep it went, how long ago, or how much has changed since. Signal has been audited repeatedly over many years; a single audit from three versions ago is not the same thing.
  • Anonymity set. A privacy app with millions of users makes it harder to stand out than one with thousands. Newer apps, Vector included, are at a disadvantage here.
  • Track record. Years of surviving attacks, subpoenas, and researchers is evidence no feature checklist replaces.
  • Usability. The most private app in the world doesn't help if the people you need to talk to won't install it.

So Vector being the all-green row means it checks every box in these eight categories. It does not mean it's the most secure messenger overall nor the most private. If your threat model depends on a long audit history and a huge user base, Signal checks those boxes. If we've learned anything, audits are good on paper, but don't stop hacks, exploits, or poorly designed systems... especially in the age of AI. If it depends on not handing over your phone number, not trusting a single operator, or running your own infrastructure, the other columns matter more.


Pick by Threat Model, Not Checkmarks

A Few Quick Guides:

  • Content Interception? Almost everything here except Telegram's default chats has you covered.
  • Identity being linked to your account? Look at the No KYC column: SimpleX, Session, DeltaChat, and Vector.
  • One company controlling or shutting down the service? Look at Decentralized and Self Host.
  • Who can map your relationships? Metadata Privacy is the column that matters, and it's the hardest one to get right. There are also varying degrees of metadata privacy, so dig deeper.

Corrections Welcome

Accurate as of 8/15/2026, but apps change fast. The full infographic and sources live here. If something is wrong about any app, including Vector, leave a comment or open an issue and it will be seen to.

Feel free to recommend any other apps that should be added in a bigger infographic or other content columns you would like to see.


Add me on Vector:
https://vectorapp.io/profile/npub12w73tzcqgpr2pcy4el5x60d2emeud4cyeeayynzqqg2fefzgytaqm4ktz3
Invitation to Vector by YuurinBee

Top comments (0)