Mindful Messaging
Our decisions compound over time, and choosing the systems we use to communicate is a direct expression of whether we preserve control over our data or gradually give it away. And control, once given away, is not only used to watch: whoever can read your messages can also decide which of them get through
The case for Signal

Signal hits the sweet spot between easy-of-use, features, and privacy. No self-hosting required, account setup is minimal, and all platforms are supported
Signal gives you protection from casual data harvesting, corporate data aggregation, legal access / subpoenas, and network-level surveillance
The proof is in the legal requests where only registration date and last connection time could be provided. Further evidence comes from regular third-party audits and constant peer-reviewed academic scrutiny. It has also been tested in real-world high-risk environments for usage by journalists, activists, and security professionals globally. It also continues to function under censorship attempts and is reported by wide media outlets to continuously operate in restricted environments like Iran, Egypt, and UAE. This censorship resistance is not a separate feature but a consequence of the privacy design: end-to-end encryption and Sealed Sender leave nothing to selectively filter, and built-in proxy support keeps the service reachable when a network tries to block it
The key piece here is privacy.
- Minimal data collection
Signal strives to know as little about its users as possible. There is no way to access the contents of messages being sent over signal without control of the end pieces (e.x. recipient’s laptop)
- Metadata protection
Metadata is often more valuable than content!
Encryption protects content, but metadata must also be protected. Metadata includes who you talk to, when, and how often. Signal uses a “Sealed Sender” system to hide this, so you can’t see who is messaging whom. Signal is the only mainstream messenger which can do this
- Open-source transparency
Claims are verifiable. Long-term resilience
Both client and server are open sourced on GitHub. Even if a server is owned by a malicious actor, the claim that everything being sent to and from it is encrypted and not stored can be verified. The Sealed Sender protocol protects anyone except your recipient from knowing where the message originated. This is enforced client-sided, so you can be confident the server isn’t pretending to mask your metadata
External audits can be done without NDA constraints. Large pools of contributors increases chances of finding subtle bugs. Academics and industry experts can continuously analyze the system
If the original code takes a wrong direction, it can be forked
- Non-profit structure
Incentive. Independence.
Signal has no pressure to monetize your data. Decisions to make encryption stronger even if it complicates features can be made. Refusal to weaken protocols under external pressure. Reduced risk of “business model drift” or objectives changing. No acquisition or exit strategy and governance is mission-driven, not investor-driven. Independent from government, corporate partners, and advertising ecosystems
- Encrypted backups
Backups create a whole new level of risk. Signal encourages a local-first design, and backups are done encrypted. Other messaging platforms typically fall short on one or both of these
- Secure by default
Nothing to configure. No strange user-experience checkboxes. All conversations are “secret”. No gotchas or behind-the-scenes deals happening. No reliance on users “doing the right thing”
The common pushback against Signal
My contact is not on Signal
Every network grows through incremental migration, not mass switching. Individual adoption is the mechanism that resolves the problem
Dual use is frictionless. No loss of reach. No lock-in. No downside of partial adoption
Privacy benefits scale per conversation
It's just another US company-owned messaging app
Signal Foundation is non-profit, and the software is open-sourced. This means it operates largely independent of government or national influence
I don't need that level of privacy
Don’t assume that your data isn’t valuable, or that you are not a target of surveillance. In general, security benefits are undervalued in comparison to convenience. This is a misunderstanding. Privacy is in your control.
Surveillance is also the precondition for censorship. What is acceptable to say can change, but archives of who said what persist and can be acted on later
I don't want to give out my phone number
A phone number is still needed to register, but it no longer has to be shared. Usernames let anyone reach you without knowing your number, and phone number discovery can be turned off entirely under Settings -> Privacy -> Phone Number
My chat history is not in Signal
If your chat history is important to you then you should definitely have it backup up so you can preserve it for the long term
On Telegram Desktop you can export it easily by going to Settings -> Advanced -> Export Telegram Data. Doing this will save your conversations including what the sender sent, but only for 1-1 chats. Group conversations only include your messages and media
On Whatsapp Desktop you can’t do much. On mobile you can export to Google Drive, but you can’t use this backup for personal usage. In order to do a real
offline backup you need to copy the /Android/media/com.whatsapp/WhatsApp/ folder off your phone.
The case against alternatives
Whatsapp
Whatsapp shares data with the Meta ecosystem
There are multiple major cases where Meta allowed, shared, or monetized access to user data in ways users did not consent to. One example is Cambridge Analytica (2013–2018) where data was used for political profiling and campaign targeting. Facebooks API (pre 2015) allowed apps to access user data + friends’ data by default. This created an ecosystem where user data flowed to external parties often beyond user awareness. Many other nefarious business practices are well documented on Wikipedia
Backups of Whatsapp data to Google Drive / iCloud (iOS). These backups are NOT encrypted. You can manually enable “End-to-end encrypted backups” in the settings, but many users do not know this
Brian Acton co-founded Whatsapp, but after it was sold to Facebook in 2014 he decided to target his efforts towards non-profit like Signal to address concerns with use around customer data and targeted advertising
Meta also moderates content, bans accounts, and complies with government blocking orders. Several countries block Whatsapp outright, and users have no recourse when access is cut
| Key area of concern | Signal | Implication | |
|---|---|---|---|
| Business model | non-profit, focused solely on privacy | Owned by Meta, part of an advertising ecosystem | Whatsapp is incentivised to collect and monetize data. Signal incentivised to minimise data collection |
| Source code | Fully open source client and server; publicly auditable | Proprietary; cannot be independently verified | Signal’s claims are verifiable, Whatsapp’s claims are trust in Meta |
| Legal | Cannot provide meaninful data under subpoena. Stores almost nothing | Can provide contacts and usage patterns | Metadata can reconstruct your social relationships and patterns even without message content |
| Censorship | Cannot read messages, nothing to selectively filter | Meta bans accounts and complies with government orders | Access to your communications becomes control over them |
Telegram
Misleading “secure” positioning: End-to-end encryption not enabled by default. This contradictory positioning is suspicious as hell.
Telegram is solely owned by Pavel Durov. There is limited transparency around corporate structure, jurisdictional influence, and their internal decision making
Chats are stored server-side and accessible to Telegram. This means Telegram can not only read your conversations but remove them. Since 2024 it discloses user IP addresses and phone numbers to authorities and takes down channels on government request
| Key area of concern | Signal | Telegram | Implication |
|---|---|---|---|
| Encryption default | Always on, E2EE everywhere | Off by default (only in Secret Chats) | Most users are not actually protected on Telegram |
| Server transparency | Open source (client + server) | Server closed source | Cannot verify Telegram’s claims |
| Metadata protection | Sealed Sender | No equivalent | Telegram can map your network |
| Storage model | Minimal server storage | Cloud message storage | Increased exposure and subpoena surface |
| Censorship exposure | Nothing stored to remove or block | Channels and content removed on request | A platform that stores your messages can also silence them |
iMessage
iMessage encrypts messages end-to-end in transit, but the default settings undo it. iCloud Backup includes the message encryption keys, so Apple can read backed-up conversations and can be compelled to hand them over. Advanced Data Protection closes this hole, but it is off by default and few users enable it
The client is closed source, tied to Apple hardware, and conversations with non-Apple contacts silently degrade to SMS/RCS with weaker or no encryption
| Key area of concern | Signal | iMessage | Implication |
|---|---|---|---|
| Backups | Encrypted, local-first | iCloud Backup includes message keys by default | “End-to-end encrypted” history is readable by Apple and courts |
| Source code | Fully open source client and server; publicly auditable | Proprietary; cannot be independently verified | Signal’s claims are verifiable, Apple’s claims are trust |
| Reach | All platforms | Apple devices only, falls back to SMS/RCS | Cross-platform conversations lose protection |
RCS
RCS is the next-generation form of SMS/MMS. It’s a nice addition, but ultimately falls short when it comes to security
| Key area of concern | Signal | RCS | Implication |
|---|---|---|---|
| Encryption | Always E2EE | Inconsistent / often absent | Messages may be readable in transit |
| Infrastructure | Independent non-profit | Telecom carriers | Subject to surveillance and interception |
| Standardisation | Single protocol implementation | Fragmented | Security varies unpredictably |
| Metadata exposure | Minimized | Fully exposed | Complete visibility into communication patterns |
| Censorship | Built-in circumvention, works in restricted environments | Carriers filter messages and follow government shutdown orders | Delivery of your messages depends on carrier and state approval |
The direction of travel
This is not a theoretical risk. The EU’s “Chat Control” proposal would mandate scanning of private messages on the device, before encryption, and keeps returning in new forms after each rejection. Signal has stated it would leave a market rather than weaken its encryption. Once a scanning capability exists, what it scans for is a policy decision, and policy changes
Palantir is an amplifier. Its business is turning scattered records into profiles and predictions for governments and corporations. If messaging platforms provide rich accessible metadata then it becomes analyzable at scale. And what can be analyzed at scale can be acted on at scale
Getting started
- Install Signal and move one frequent conversation over. Adoption grows one chat at a time
- Set a username under Settings -> Profile so contacts can reach you without your phone number
- Enable disappearing messages for casual chats. An archive that never exists can’t be leaked, subpoenaed, or acted on later
- Turn on encrypted backups so your history survives a lost phone without landing in a cloud you don’t control