When I help a client prepare for a sensitive conversation, I do not just ask which app they use. I want to know what leaks out of it, who holds the backups and what device is at the other end. Encryption matters, but on its own it is no reason to relax.
A sensitive conversation starts not with the app, but with what leaks about you
I see encrypted communication as the first layer, not a finished solution. End-to-end encryption (E2EE) protects the content of a message as it travels between devices. Neither the provider nor anyone intercepting it along the way can see that content. That is a fundamental difference from encryption in transit only, where the server still sees the message in readable form.
In practice, for truly sensitive conversations I aim to leave as few direct traces as possible. The fewer people and systems that can see the content, the less room there is for error or outside pressure. I put it to clients simply: one good lock is useful, but it does not secure the whole house.
That is why I regard E2EE as a basic standard, not a luxury extra. When the subject is sensitive, my first question is whether the content is genuinely protected at both ends, and whether the rest of the route is being exposed in the process.
Signal is my reference standard
If I have to recommend one default choice for sensitive conversations, it is Signal. The reason is not marketing but the way it is built. The protocol has been publicly audited by independent cryptographers, the app is open source, and Signal is run by a non-profit foundation funded by donations. That removes any pressure to make money from data or advertising.
Signal also makes sense to me because it keeps minimal metadata. Served with a court order, it is technically able to hand over little more than the date an account was created and the time it last connected. Its Sealed Sender feature also hides the sender from the server itself. The server is then just a relay, not a party that reads more than it has to.
One more thing matters to me here. When I am protecting a client, I do not want something that merely sounds secure. I want a tool that limits both the content and the traces around it. That is why Signal is the reference standard: it relies not on grand claims but on minimal data and an open model.
Metadata can matter as much as the content itself
People often hear the word encryption and assume the job is done. But E2EE does not hide metadata. Depending on the service and on who is looking (the provider, someone watching the network or the device itself), it may still be possible to see who is talking to whom, when, how often, from where and for how long. In sensitive relationships, that trail can say more than the message itself.
That is why I distinguish between services. WhatsApp does encrypt content and is built on the Signal Protocol, but it collects extensive metadata: phone numbers, your network of contacts, group memberships, IP addresses and usage patterns. For everyday use that may be enough; for a sensitive conversation it makes a material difference.
The analogy I use is a door that someone closes while leaving clear tracks outside the house showing who comes and goes, and when. What is inside may be protected, but the movement around it much less so. That is exactly where an attacker or observer can make use of metadata.
WhatsApp, iMessage, Telegram and RCS each have their own limits
With WhatsApp, I see one more practical risk: cloud backups. By default they are not end-to-end encrypted, and encrypted backups have to be switched on manually. Without that, the content of a conversation can be reached another way, through the backup, even though the messages themselves travel end-to-end encrypted.
iMessage has a similar weak spot. Messages between Apple devices are end-to-end encrypted, but the standard iCloud backup has historically included keys that made the content accessible. Full protection only comes with Advanced Data Protection. Without it, the cloud backup is a weaker link than people tend to admit.
Telegram is the subject of a common misconception. Its ordinary cloud chats are not end-to-end encrypted, so Telegram can technically access their content. E2EE is available only in Secret Chats, which work only one-to-one and do not sync across devices. RCS is a more recent story: E2EE between Android and iPhone began rolling out in beta in May 2026, but it works only when both sides run current software and the mobile operator supports it. The metadata does not disappear, and the rollout varies by country and network.
- enable end-to-end encrypted backups in WhatsApp
- enable Advanced Data Protection for iCloud on iPhone where it is available (Apple no longer offers it to new users in the UK)
- do not treat ordinary Telegram chats as E2EE
- with RCS, remember that availability depends on both software and operator
The other party's identity and the state of the device matter as much as encryption
Whenever I talk about secure communication, I always add one more step: verifying the other party's identity. Signal uses safety numbers; WhatsApp uses a security code. Verifying in person by scanning a QR code, or comparing the numbers over a different channel, protects you against a substituted key. Without it, you cannot be sure who is at the other end.
It is just as important to look beyond the channel to the device itself. A compromised phone gets round any E2EE. Spyware such as Pegasus reads messages while they are on the screen in readable form, that is, before encryption or after decryption. Encryption then protects the route, but not a device the attacker controls.
That is also why disappearing messages make sense to me. They reduce the amount of history on the device and therefore the damage if it is ever compromised. They do not, however, stop the other person from photographing or saving a message. To be honest about it, disappearing messages are no shield against the human factor.
- on first contact, verify the safety number or security code
- use disappearing messages for sensitive chats
- keep the operating system and apps up to date
- keep installed apps to a minimum and keep physical control of your phone
Why I also follow the legislation on sensitive communication
Legislation comes into it too. With the EU Chat Control / CSAR proposal for mass scanning of private messages, one thing stands out for me: it is not a closed chapter, and the situation keeps changing. The temporary derogation for voluntary scanning, known as Chat Control 1.0, lapsed in April 2026; in July the European Parliament voted to reinstate it with an exemption for end-to-end encrypted communications, and the Council gave its final approval on 23 July 2026. It is due to apply until 3 April 2028. The permanent CSAR regulation is still under negotiation. At the end of 2025 the Council removed blanket mandatory detection orders from it, but the text is still evolving. Even so, I would never describe the matter as settled for good.
From a client-protection point of view, I look at it in purely practical terms. If mandatory mass scanning of content were eventually adopted, it would weaken the very end-to-end encryption this whole approach rests on, and with it the confidentiality you expect from secure communication. That is why, for sensitive matters, I stick with audited E2EE tools and do not assume the legal environment will stay as it is. I follow where the debate is heading and adjust my recommendations accordingly.
Speaking as a practitioner, I would sum it up like this: encryption is an essential foundation, but not the whole security system. You also need a verified identity, a protected device, sensible backups and a service that collects minimal metadata. If you want to set up communication for a sensitive conversation in a practical way and without needless drama, this is exactly the kind of adjustment best made calmly and in advance.
“Encryption is one good lock on the door, not the whole security system of the house.” — Robert Václavík





