Use Signal for Encrypted Messaging
The gold standard for private communication. End-to-end encrypted, open source, no ads, and run by a non-profit -- Signal is trusted by journalists, activists, and anyone who values real privacy.
01. What Is Signal?
Signal is a free, end-to-end encrypted messaging app for text messages, voice calls, and video calls. Every message you send is encrypted on your device and can only be decrypted by the recipient -- not by Signal, not by your phone carrier, not by anyone in between.
Signal is developed and maintained by the Signal Foundation, a non-profit organisation funded entirely by donations and grants. There are no ads, no data collection, no venture capital investors demanding that user data be monetised. The business model is simple: build the best private communication tools in the world and give them away for free.
Because of this, Signal has become the tool of choice for people who genuinely need privacy: journalists talking to sources, activists organising in repressive regimes, lawyers discussing client matters, and anyone who simply believes their private conversations should stay private.
The Signal Protocol -- Signal's encryption technology -- is so well-regarded that WhatsApp, Google Messages (RCS), and Skype have all adopted it for their own end-to-end encryption. The difference is that those apps still collect metadata about who you talk to and when, while Signal collects almost nothing.
What Signal is -- and is not
- •End-to-end encrypted. Every message, call, and video chat is encrypted. No one but the recipient can read or hear it.
- •Open source. All of Signal's code is public on GitHub. Anyone can audit it, and many security researchers have.
- •No ads. No trackers. No data collection. Signal does not know who you are, who you message, or what you say.
- •Non-profit. Run by the Signal Foundation, funded by donations. No shareholder pressure to mine user data.
- •NOT anonymous. Signal requires a phone number to register. It hides your conversation content, not the fact that you have a Signal account.
Step 1. Install and Register
Getting Signal running takes about two minutes. The registration process verifies your phone number -- Signal only uses this once, to prove you control the number. It is not stored or associated with your activity.
Install the app
- •iOS: App Store
- •Android: Google Play Store -- also available as a direct APK download from signal.org for those who avoid Google services.
- •Desktop: signal.org/download -- available for Windows, macOS, and Linux. The desktop app links to your phone; it does not work independently.
Register your number
- 1.Open Signal and enter your phone number.
- 2.Signal sends a one-time verification code via SMS. Enter the code. Signal only uses your phone number this once -- to verify you control it. It does not store or use it as a searchable identifier.
- 3.Enter your name. This is what your contacts will see. You can use your real name, a nickname, or just a first name.
Set up your PIN
Signal will prompt you to create a PIN. This is not for unlocking the app day to day -- it is for account recovery. If you switch phones or reinstall Signal, your PIN restores your profile, settings, and (if you enable it) your contacts and groups. Choose a PIN you will remember. Signal will ask you to re-enter it periodically so you do not forget it.
What the PIN protects: Your profile name and avatar, your settings (disappearing message defaults, blocked numbers), and optionally your contacts. It does not recover your message history -- messages are stored only on your device.
Step 2. Send Messages and Make Calls
Signal works like any messaging app on the surface -- text, voice, video, group chats. The difference is that everything is end-to-end encrypted by default. There is no "encrypted mode" to toggle on; it is always on.
Text messaging
Tap the pencil icon (new message), select a contact who also uses Signal, and type. Messages are encrypted with the Signal Protocol, the same encryption used in WhatsApp. You can send text, photos, videos, documents, voice notes, and location -- all encrypted.
Voice and video calls
From any conversation, tap the phone icon (voice call) or camera icon (video call) in the top bar. Both are end-to-end encrypted. Signal's voice and video quality is comparable to FaceTime or WhatsApp.
Group chats
Signal supports group chats of up to 1,000 people. Group messages are encrypted the same way as one-on-one messages. You can create groups, name them, set a group avatar, and add or remove members. Group calls support up to 40 participants.
Disappearing messages
You can set messages to automatically delete after a set time. Open any conversation, tap the contact or group name at the top, then tap Disappearing messages. Choose a timer: 30 seconds, 5 minutes, 1 hour, 1 day, 1 week, or 4 weeks. After the timer expires, messages vanish from both devices.
Pro tip: Set disappearing messages as the default for all new conversations. Go to Settings → Privacy → Disappearing messages, choose a default timer, and every new chat will start with that timer enabled. You can always change it per-conversation.
Step 3. Explore Privacy Features
Signal's default encryption is strong, but the app has several deeper privacy features worth turning on. These are the settings that separate Signal from "encrypted but still tracking you" messengers.
Sealed Sender
Normally, when a message passes through Signal's servers, the server knows the sender and the recipient (but cannot read the content). Sealed Sender encrypts the sender's identity inside the message envelope, so even Signal's servers cannot see who sent it. Only the recipient, after decrypting the message, learns who it came from.
Sealed Sender is on by default for contacts you have messaged before and for anyone who shares their profile with you. You can enable it for all senders in Settings → Privacy → Sealed Sender.
Screen security
When enabled, Signal blocks screenshots and screen recordings inside the app. On iOS, it also hides the content of Signal in the app switcher. Turn this on in Settings → Privacy → Screen Security. This is especially useful if you discuss sensitive topics and worry about other apps or malware capturing your screen.
Relay calls
By default, voice and video calls connect directly between you and the recipient -- which means both parties can see each other's IP addresses. Always relay calls routes all calls through Signal's servers, hiding your IP address from the person you are talking to. Enable this in Settings → Privacy → Advanced → Always relay calls. The trade-off is slightly higher latency, but most people will not notice.
Incognito keyboard (Android)
On Android, keyboards can learn from what you type and store custom words (effectively building a dictionary of everything you have ever typed). Signal can request that the keyboard use incognito mode, which disables personalised learning and prevents your typing data from being stored while you are in Signal. Find it in Settings → Privacy → Incognito keyboard.
One-minute privacy check: Go to Settings → Privacy and turn on Screen Security, set a default disappearing message timer, enable Sealed Sender from all sources, and (if you use Android) enable Incognito keyboard. Done.
Step 4. Verify Safety Numbers
End-to-end encryption is only as strong as the guarantee that the person you are talking to is actually the person you think you are talking to. Signal's safety numbers solve this problem.
What are safety numbers?
Every Signal conversation has a unique pair of safety numbers -- a 60-digit number derived from the encryption keys on both devices. If your safety number with Alice matches the safety number Alice sees with you, you can be mathematically certain that your conversation is not being intercepted by a man-in-the-middle attack.
In practice, safety numbers change when someone reinstalls Signal, switches phones, or adds a new linked device. Signal notifies you when a safety number changes so you can re-verify.
How to verify safety numbers
- 1.Open a conversation and tap the contact's name at the top.
- 2.Tap View safety number.
- 3.You will see a QR code and a string of numbers. The ideal method: meet in person and scan each other's QR codes from within the safety number screen.
- 4.If you cannot meet in person, read the numbers aloud over a different channel you trust (a voice call, or Signal itself -- if you are already talking there, the attacker would need to compromise both channels).
- 5.If the numbers match, tap Mark as verified. Signal will show a verified checkmark on that conversation.
Who should verify? You do not need to verify safety numbers with everyone you message. Reserve it for close contacts where you have a genuine security concern -- a journalist colleague, a family member in a sensitive situation, or when you are discussing particularly private matters. For everyday chats with friends, the encryption alone is likely sufficient.
Step 5. Signal vs Other Messengers
Not all "encrypted" messengers are created equal. Encryption protects the content of your messages, but many apps still collect metadata -- who you talk to, when, how often, from which device, at which location. That metadata alone can be more revealing than the message text.
| Feature | Signal | Telegram | iMessage | |
|---|---|---|---|---|
| Encryption | End-to-end by default (Signal Protocol) | End-to-end by default (Signal Protocol) | End-to-end only in Secret Chats; regular chats and groups are server-encrypted | End-to-end (Apple-to-Apple only; SMS fallback is not encrypted) |
| Metadata collected | Virtually none -- last connection date only | Who you message, when, how often, device info, IP, contacts | Who you message, when, IP, device info, contacts | Who you message, when, contacts (if iCloud enabled) |
| Open source | Yes -- all clients and server | No | Clients only; server is closed | No |
| Owned by | Signal Foundation (non-profit) | Meta (for-profit, ad business) | Telegram FZ-LLC (for-profit, Dubai) | Apple (for-profit, hardware/services) |
| Requires phone number | Yes | Yes | Yes | Yes (Apple ID, tied to phone) |
| Disappearing messages | Yes (configurable timer, all chats) | Yes (limited timers) | Yes (Secret Chats only) | No built-in support |
| Group size limit | 1,000 | 1,024 | 200,000 | 32 (iMessage) |
| Independent audits | Yes -- regularly published | Some | None published | Some |
The bottom line
WhatsApp uses the same encryption protocol as Signal, but Meta collects extensive metadata -- who you talk to, when, how often, and from which device -- and uses it for ad targeting and product integration across Facebook and Instagram. The encryption is solid; the business model is not.
Telegram does not enable end-to-end encryption by default. Regular chats and all group chats are encrypted only between your device and Telegram's servers -- meaning Telegram itself can read them if it chooses to. Only "Secret Chats" are end-to-end encrypted, and those are one-on-one only.
iMessage is end-to-end encrypted between Apple devices, but falls back to unencrypted SMS when messaging Android users. Apple also holds the encryption keys for iCloud backups, which means messages backed up to iCloud are accessible to Apple (and to anyone who can compel Apple).
Signal encrypts everything by default, collects virtually no metadata, publishes its code and security audits publicly, and is run by a non-profit with no incentive to exploit user data. It is the most trustworthy option for private communication.
Quick Tips
- •Set disappearing messages as the default. Go to Settings → Privacy → Disappearing messages and pick a default timer (4 weeks is a good starting point). Every new conversation starts with messages that auto-delete. You can adjust per-conversation for exceptions.
- •Verify safety numbers with close contacts. For the handful of people you discuss truly sensitive matters with -- a partner, a close friend, a work confidant -- take two minutes to verify safety numbers. Meet in person and scan QR codes. You get a verified checkmark and mathematical certainty that no one is intercepting your messages.
- •Signal is NOT anonymous. It requires a phone number to register. If anonymity is your primary need, Signal alone is not enough -- look into tools like Tor or Session. Signal protects your message content, not the fact that you have an account.
- •Use a profile picture that is not your face if you want extra privacy. Signal shows your profile picture to anyone who has your number, even before you message them. An abstract image, a pet, or a landscape protects you from being visually identified by strangers with your number.
- •Link the desktop app for easier typing. Long conversations are easier with a keyboard. Install Signal Desktop from signal.org, scan the QR code from your phone, and your messages sync across both devices. Both remain encrypted.
- •Turn on registration lock. In Settings → Account, enable Registration Lock. This prevents someone from re-registering your phone number with Signal without your PIN -- useful if your SIM gets swapped or cloned.
- •Do not rely on Signal's backups. Signal's message history is stored locally on your device. If you lose your phone without an external backup (iOS encrypted backup, or a manual transfer), the messages are gone. There is no cloud restore for message content.
Want Help Securing Your Digital Life?
From password managers to encrypted messaging, small changes make a big difference. If you would like a personalised walk-through of your privacy setup -- or help convincing friends and family to switch to Signal -- book a free session.