What the evidence actually shows
Most privacy claims in this catalogue are policies. Signal’s central claim is a court record.
Signal publishes the responses it has given to subpoenas, and what it has produced is the date an account was created and the date it last connected. Not messages, not contact lists, not group memberships, not who talked to whom. That is a far stronger form of proof than a privacy policy, because it is a description of what happened when a government asked, rather than a description of what a company intends.
Everything else in this review is context around that fact.
Ownership, and why the structure matters
Signal Messenger LLC sits under the Signal Technology Foundation, a United States non-profit. The foundation was capitalised by a large interest-free loan from a co-founder of WhatsApp, and it operates on donations and its endowment.
The structure is the point. Every other free messenger in wide use is either owned by an advertising company or funded by investors who will eventually want the product to make money, and messaging products that need to make money end up monetising the one asset they have, which is knowledge of who talks to whom. Signal has no such obligation, so the incentive that degrades its competitors does not exist here.
Our ownership explorer exists to make exactly this kind of structure visible across the privacy market, where independent branding usually conceals a shared parent.
The two compromises
A phone number is still required
You cannot create a Signal account without a phone number. Usernames, added recently, mean you no longer have to give that number to the people you message, which was a real and long-standing problem and is now largely solved. What remains is that the account itself is tied to a number, and in most countries a number is tied to identification documents.
For the overwhelming majority of readers this is irrelevant. For an activist in a country where the SIM register is a police tool, it is disqualifying, and the correct answer is a messenger with no identifier at all.
We say this plainly because most Signal coverage does not.
Centralised servers in a Five Eyes country
Signal is not federated and not decentralised. Traffic runs through infrastructure Signal operates, in the United States.
The confidentiality consequence is small, because the encryption is end to end and sealed sender removes the sender identity from what the server can see. The availability consequence is not small. A centralised service can be blocked at a national level, and Signal has been, which is why proxy support exists at all. If your requirement is a messenger that keeps working when the state switches things off, the answer is a peer-to-peer design, not this one.
What it costs
Signal is free, and there is no paid tier at all.
| Plan | Intro | Renewal | True cost per month over 3 years |
|---|---|---|---|
| Signal | $0 | $0 | $0 |
The substantive question with a free product is who pays for it, because someone does. Here the answer is donations and the foundation’s endowment, seeded by that interest-free loan. Signal accepts cryptocurrency donations. It does not sell advertising, it has no investors to satisfy and it has no data business.
The honest risk is not hidden monetisation, it is sustainability: running a global messaging service on donations is expensive and the endowment is finite. That is a different worry from the one you have about a commercial messenger, and a better one to have.
Features, briefly
End-to-end encryption on by default with no setting to get wrong. Encrypted voice and video calls, including group calls. Disappearing messages. Encrypted backups. Usernames. Apps on iOS, Android, macOS, Windows and Linux. Open source throughout.
The feature set is deliberately narrower than Telegram’s, and that is a design position rather than an oversight. Signal will not add a server-side message archive, because the absence of one is the reason its subpoena responses are empty. Compare it directly with Telegram, where the feature-rich cloud model is exactly what makes ordinary chats readable by the operator.
The iPhone app
Our App Store analysis for this collection used a sample of 150 recent reviews from the United States and Great Britain storefronts, alongside a listing rating of 4.74 stars from roughly 1.08 million ratings.
A sample that size is small and skews negative, because people with a working app rarely write about it: the sample mean was 3.62 against that much higher listing average, and the honest reading is that the sample tells you about complaints, not about quality. The largest complaint themes were billing and auto-renew at about 5 per cent, iOS integration at about 5 per cent, privacy concerns at 4 per cent and crashes at 3 per cent. Billing complaints on a product with nothing to buy usually mean donation confusion, and we note it without weighting it heavily.
Where it lands
Signal is the default recommendation on this site for encrypted messaging, and it is not close. It combines the strongest published evidence, the reference protocol, sane defaults and enough users that you can actually reach people, which is the criterion most privacy comparisons forget.
The phone number requirement and the centralised United States infrastructure are real, and they are why we do not describe it as the most private messenger available, only as the right one for almost everybody.
What we have not tested
We have not done our own hands-on testing of Signal’s clients, and we have not independently verified its subpoena disclosures against court records. Our provider record flags ownership, jurisdiction and audit history as still needing a primary-source check, and the audit entries have no published report URL on file. Nothing here is a measurement we made.



