Signal vs SimpleX vs Session: Which Is Most Private?
What each messenger still reveals. Registration and delivery-path differences between four end-to-end encrypted messengers.
Data behind this diagram
| App | phone at signup | global identifier | delivery path | main limit |
|---|---|---|---|---|
| SIGNAL | required | phone account + optional username | central delivery service | number still required at registration |
| SIMPLEX | no | none — no global user id | separate relay queues, self-hostable | invitation links are credentials |
| SESSION | no | random account id | onion-routed, distributed storage | no forward secrecy in current protocol |
| MATRIX | varies by homeserver | user id on a homeserver | federated homeservers | servers process account + room state |
Signal is the strongest default for most people. SimpleX removes a global account identifier. Session removes phone registration but has a different key and recovery model. Matrix is useful for federated groups, but its privacy depends on the client, room settings, and homeservers.
Encryption protects message content in transit. It does not erase account identifiers, discovery records, delivery metadata, backups, linked devices, or readable data on an unlocked phone. This comparison covers those boundaries for Signal, SimpleX, Session, Matrix, Molly, Briar, Cwtch, and Ricochet Refresh.
Choose by need
Identity and network comparison
Names open official sites. Service details are linked where available.
| App | Identifier and phone | Discovery and metadata path | Best for |
|---|---|---|---|
| IdentifierPhone: RequiredPhone account; optional username for discovery | Discovery / Metadata path / Server trustNumber, exact username, link, or QRCentral delivery service; message content is end-to-end encrypted | Best forPrivate everyday messaging | |
| IdentifierPhone: NoNo global user identifier | Discovery / Metadata path / Server trustOne-time or reusable invitation linkSeparate encrypted relay queues; relays can be self-hosted | Best forContacts without a platform-wide address | |
| IdentifierPhone: NoRandom Account ID | Discovery / Metadata path / Server trustAccount ID, QR, or communityOnion-routed requests and distributed message storage | Best forPhone-free messaging with routed requests | |
| IdentifierPhone: VariesUser ID on a homeserver | Discovery / Metadata path / Server trustUser ID, room invite, or optional identity serviceFederated homeservers process account and room state | Best forFederated groups, teams, and communities | |
| IdentifierPhone: RequiredSignal account; optional Signal username | Discovery / Metadata path / Server trustSignal discovery modelSignal network with extra Android storage controls | Best forSignal on Android with a locked local database | |
| IdentifierPhone: NoLocal profile joined through contact exchange | Discovery / Metadata path / Server trustIn-person QR or invitation linkDirect Tor, Wi-Fi, or Bluetooth; optional owned Mailbox | Best forOffline and censorship-resistant messaging | |
| IdentifierPhone: NoPublic-key profile | Discovery / Metadata path / Server trustInvitation or shared contact addressTor peer connections; group design changes the trust boundary | Best forTor-based peer and small-group messaging | |
| IdentifierPhone: NoTor onion service address | Discovery / Metadata path / Server trustShare the address through another channelDirect Tor onion connection between contacts | Best forFocused desktop chat without a central account |
Features and setup
| App | Calls | Groups | Platforms | No internet | Run your own |
|---|---|---|---|---|---|
| CallsVoice + video | GroupsChats + calls | PlatformsMobile + desktop | No internetNo | Run your ownNo | |
| Calls1:1 audio + video | GroupsChats; no group calls | PlatformsMobile + desktop | No internetNo | Run your ownRelays + TURN | |
| Calls1:1 beta | GroupsPrivate groups | PlatformsMobile + desktop | No internetNo | Run your ownCommunities only | |
| CallsClient-dependent | GroupsRooms | PlatformsClient-dependent | No internetNo | Run your ownHomeserver | |
| CallsSignal calls | GroupsSignal groups | PlatformsAndroid | No internetNo | Run your ownNo | |
| CallsNo | GroupsGroups + forums | PlatformsAndroid | No internetBluetooth + Wi-Fi | Run your ownMailbox | |
| CallsNo | GroupsExperimental | PlatformsDesktop + Android | No internetNo | Run your ownGroup server | |
| CallsNo | GroupsNo | PlatformsDesktop | No internetNo | Run your ownPeer-to-peer |
Backup, recovery, and device access
| App | Backup or recovery | Multi-device | If a device is seized |
|---|---|---|---|
| Backup or recoveryEncrypted backup or device transfer; separately protected | Multi-deviceLinked devices keep their own local history | If a device is seizedUnlocked app data and linked-device history | |
| Backup or recoveryEncrypted local export and client transfer | Multi-deviceAdditional profiles and devices need deliberate setup | If a device is seizedLocal database and notification content | |
| Backup or recoveryRecovery password restores the account and limited recent state | Multi-deviceDevices share account keys and state | If a device is seizedRecovery material or unlocked local data | |
| Backup or recoveryKey backup depends on the client and homeserver | Multi-deviceEvery verified session can receive room keys | If a device is seizedLocal stores, exported keys, and authorized sessions | |
| Backup or recoverySignal transfer rules; optional local passphrase | Multi-deviceUses Signal linked devices | If a device is seizedPassphrase protection helps only while the app is locked | |
| Backup or recoveryManual encrypted app backup | Multi-deviceNo general synchronized multi-device account | If a device is seizedLocal database and any unlocked paired Mailbox | |
| Backup or recoveryManual password-protected profile export | Multi-deviceImported profiles are not live synchronization | If a device is seizedProfile files and unlocked local conversations | |
| Backup or recoveryLocal desktop profile | Multi-deviceNo synchronized multi-device account | If a device is seizedCopied or unlocked profile, contacts, and local history |
Set up the leading options
Signal
Phone: Required- 01
Install the mobile app and register a phone number. Link desktop devices only after the phone works.
- 02
Open Settings, Privacy, Phone Number. Set number visibility to Nobody. Set discovery to Nobody if you will share a username instead.
- 03
Enable Registration Lock, verify important contacts, and remove any linked device you do not control.
SimpleX Chat
Phone: No- 01
Install the official app and create a local profile. No phone number or email is required.
- 02
Create a one-time invitation link for the first contact. Confirm the security code after connecting.
- 03
Protect the local database, hide notification previews, and use Tor or transport isolation when network linkage matters.
Session
Phone: No- 01
Install Session and create an Account ID. A phone number and email address are not required.
- 02
Write the Recovery Password down and keep it offline before adding important contacts.
- 03
Exchange the Account ID or QR through another channel. Review connected devices and call settings before use.
Matrix
Phone: Varies- 01
Choose a maintained client and homeserver. Check the homeserver policy before creating the account.
- 02
Create a private room with end-to-end encryption enabled. Set up Secure Backup and store its Security Key offline.
- 03
Verify every new session. Review room members, bridges, bots, and participating homeservers before sharing sensitive material.
Limits and useful settings
SignalLimit and settings
A phone number is still required for registration, and linked devices keep local copies.
Hide number visibility and number discovery; set a registration lock; verify safety numbers.
SimpleX ChatLimit and settings
Invitation links are credentials, and traffic correlation remains possible.
Verify security codes; protect the local database; use Tor or transport isolation where needed.
SessionLimit and settings
The current protocol does not provide perfect forward secrecy. Session Protocol V2 is planned work.
Store the recovery password offline and review every device connected to the Account ID.
MatrixLimit and settings
Homeservers still process account, device, membership, room-state, and routing data.
Verify devices; remove old sessions; review bridges and every homeserver used by a room.
MollyLimit and settings
It keeps Signal registration, discovery, protocol, linked devices, and network metadata.
Enable the local database passphrase, automatic locking, and RAM shredding where supported.
BriarLimit and settings
History remains on the device, and offline delivery depends on a reachable contact or Mailbox.
Exchange contact codes carefully; encrypt backups; keep any paired Mailbox patched and locked.
CwtchLimit and settings
Direct chats and group modes do not all have the same infrastructure or trust boundary.
Check the current group design; protect profile exports; verify contact addresses separately.
Ricochet RefreshLimit and settings
Stable V3 does not provide the profile-v4 SQLCipher design described on the development branch.
Verify the onion address through another channel and protect the local desktop profile.
A strong device passcode, current operating system, hidden notification previews, short local retention, and a review of linked sessions matter across every app. For the separate extraction threat, see what phone extraction tools target.
Telegram is not an equivalent default
Telegram describes itself as a cloud messaging service. Its privacy policy distinguishes cloud chats from end-to-end encrypted Secret Chats and says cloud chat content is stored on Telegram's servers for cross-device access. Do not treat an ordinary Telegram chat or group as equivalent to Signal's default end-to-end encryption.
Controls that matter on every app
- Verify contacts or devices through a second channel.
- Remove linked devices you no longer control.
- Lock the app and encrypt the device.
- Disable message previews on the lock screen.
- Install updates from the official project or app store.
- Assume the recipient can copy anything they receive.
Malware can read messages on screen or capture them before encryption. A hidden camera, notification preview, cloud device backup, or cooperating contact can do the same. Messenger choice narrows exposure. It does not replace endpoint security.
Sources
- Signal downloads
- Signal Support: phone number privacy and usernames
- Signal Support: backups and device transfers
- Signal Support: linked devices
- Signal Support: group calls
- Signal: published government requests
- SimpleX platform design
- SimpleX downloads
- SimpleX privacy and security settings
- SimpleX audio and video calls
- Session protocol documentation
- Session installation
- Session account restoration
- Session calls and groups
- Matrix end-to-end encryption guide
- Matrix private-room setup
- Matrix specification 1.19
- Matrix hosting options
- Molly features
- Molly: data encryption at rest
- Briar: how it works
- Briar groups and offline use
- Cwtch security components
- Cwtch groups and server experiment
- Ricochet Refresh stable release
- Telegram privacy policy
Reviewed 22 Aug 2026. Cunicula receives no funding from the projects named in this comparison.
Frequently Asked Questions
Which private messenger should I use?
Signal is the strongest default for most people because every conversation is end-to-end encrypted and its published legal responses show that it retains little account data. SimpleX removes the persistent user identifier but requires more deliberate contact exchange. Session requires no phone number, but its current protocol does not provide perfect forward secrecy. Matrix suits federated communities, though homeservers still process account and room data.
Can Signal be used without revealing a phone number?
Signal still requires a phone number for registration. Its usernames let people start a chat without receiving that number. Set both phone-number privacy controls to Nobody if you do not want other users to see your number or find your account by searching for it.
Does SimpleX have user accounts?
SimpleX does not assign a global user identifier. Contacts connect through invitation links and separate message queues. Relay servers temporarily hold encrypted messages until delivery. This reduces server-side linkage, but it does not defeat endpoint compromise or a capable observer watching traffic.
Does Session provide perfect forward secrecy?
Not in its current protocol. Session states that perfect forward secrecy is planned for Session Protocol V2. Session does provide end-to-end encryption, phone-free account creation, and onion-routed requests.
Is Matrix end-to-end encrypted?
Matrix supports end-to-end encryption through Olm and Megolm, and major clients enable it for private rooms. Encryption protects event content. It does not hide the account, room membership, device records, or all traffic metadata from the homeservers involved.