Signal vs SimpleX vs Session: Which Is Most Private?

At a glance

What each messenger still reveals. Registration and delivery-path differences between four end-to-end encrypted messengers.

Comparison of Signal, SimpleX, Session, and Matrix by phone requirement, identifier, delivery path, and main limit.
What each messenger still revealsCunicula
Data behind this diagram
Registration and delivery-path differences between four end-to-end encrypted messengers.
Registration and delivery-path differences between four end-to-end encrypted messengers.
Appphone at signupglobal identifierdelivery pathmain limit
SIGNALrequiredphone account + optional usernamecentral delivery servicenumber still required at registration
SIMPLEXnonone — no global user idseparate relay queues, self-hostableinvitation links are credentials
SESSIONnorandom account idonion-routed, distributed storageno forward secrecy in current protocol
MATRIXvaries by homeserveruser id on a homeserverfederated homeserversservers process account + room state

Signal is the strongest default for most people. SimpleX removes a global account identifier. Session removes phone registration but has a different key and recovery model. Matrix is useful for federated groups, but its privacy depends on the client, room settings, and homeservers.

Encryption protects message content in transit. It does not erase account identifiers, discovery records, delivery metadata, backups, linked devices, or readable data on an unlocked phone. This comparison covers those boundaries for Signal, SimpleX, Session, Matrix, Molly, Briar, Cwtch, and Ricochet Refresh.

01

Choose by need

02

Identity and network comparison

Names open official sites. Service details are linked where available.

Messaging identity, discovery, metadata path, and server trust
AppIdentifier and phoneDiscovery and metadata pathBest for
IdentifierPhone: RequiredPhone account; optional username for discoveryDiscovery / Metadata path / Server trustNumber, exact username, link, or QRCentral delivery service; message content is end-to-end encryptedBest forPrivate everyday messaging
IdentifierPhone: NoNo global user identifierDiscovery / Metadata path / Server trustOne-time or reusable invitation linkSeparate encrypted relay queues; relays can be self-hostedBest forContacts without a platform-wide address
IdentifierPhone: NoRandom Account IDDiscovery / Metadata path / Server trustAccount ID, QR, or communityOnion-routed requests and distributed message storageBest forPhone-free messaging with routed requests
IdentifierPhone: VariesUser ID on a homeserverDiscovery / Metadata path / Server trustUser ID, room invite, or optional identity serviceFederated homeservers process account and room stateBest forFederated groups, teams, and communities
IdentifierPhone: RequiredSignal account; optional Signal usernameDiscovery / Metadata path / Server trustSignal discovery modelSignal network with extra Android storage controlsBest forSignal on Android with a locked local database
IdentifierPhone: NoLocal profile joined through contact exchangeDiscovery / Metadata path / Server trustIn-person QR or invitation linkDirect Tor, Wi-Fi, or Bluetooth; optional owned MailboxBest forOffline and censorship-resistant messaging
IdentifierPhone: NoPublic-key profileDiscovery / Metadata path / Server trustInvitation or shared contact addressTor peer connections; group design changes the trust boundaryBest forTor-based peer and small-group messaging
IdentifierPhone: NoTor onion service addressDiscovery / Metadata path / Server trustShare the address through another channelDirect Tor onion connection between contactsBest forFocused desktop chat without a central account
03

Features and setup

Messaging calls, groups, platforms, offline use, and self-hosting options
AppCallsGroupsPlatformsNo internetRun your own
CallsVoice + videoGroupsChats + callsPlatformsMobile + desktopNo internetNoRun your ownNo
Calls1:1 audio + videoGroupsChats; no group callsPlatformsMobile + desktopNo internetNoRun your ownRelays + TURN
Calls1:1 betaGroupsPrivate groupsPlatformsMobile + desktopNo internetNoRun your ownCommunities only
CallsClient-dependentGroupsRoomsPlatformsClient-dependentNo internetNoRun your ownHomeserver
CallsSignal callsGroupsSignal groupsPlatformsAndroidNo internetNoRun your ownNo
CallsNoGroupsGroups + forumsPlatformsAndroidNo internetBluetooth + Wi-FiRun your ownMailbox
CallsNoGroupsExperimentalPlatformsDesktop + AndroidNo internetNoRun your ownGroup server
CallsNoGroupsNoPlatformsDesktopNo internetNoRun your ownPeer-to-peer
04

Backup, recovery, and device access

Messaging backup and seized-device comparison
AppBackup or recoveryMulti-deviceIf a device is seized
Backup or recoveryEncrypted backup or device transfer; separately protectedMulti-deviceLinked devices keep their own local historyIf a device is seizedUnlocked app data and linked-device history
Backup or recoveryEncrypted local export and client transferMulti-deviceAdditional profiles and devices need deliberate setupIf a device is seizedLocal database and notification content
Backup or recoveryRecovery password restores the account and limited recent stateMulti-deviceDevices share account keys and stateIf a device is seizedRecovery material or unlocked local data
Backup or recoveryKey backup depends on the client and homeserverMulti-deviceEvery verified session can receive room keysIf a device is seizedLocal stores, exported keys, and authorized sessions
Backup or recoverySignal transfer rules; optional local passphraseMulti-deviceUses Signal linked devicesIf a device is seizedPassphrase protection helps only while the app is locked
Backup or recoveryManual encrypted app backupMulti-deviceNo general synchronized multi-device accountIf a device is seizedLocal database and any unlocked paired Mailbox
Backup or recoveryManual password-protected profile exportMulti-deviceImported profiles are not live synchronizationIf a device is seizedProfile files and unlocked local conversations
Backup or recoveryLocal desktop profileMulti-deviceNo synchronized multi-device accountIf a device is seizedCopied or unlocked profile, contacts, and local history
05

Set up the leading options

Signal

Phone: Required
Install
  1. 01

    Install the mobile app and register a phone number. Link desktop devices only after the phone works.

  2. 02

    Open Settings, Privacy, Phone Number. Set number visibility to Nobody. Set discovery to Nobody if you will share a username instead.

  3. 03

    Enable Registration Lock, verify important contacts, and remove any linked device you do not control.

Signal privacy settings

SimpleX Chat

Phone: No
Install
  1. 01

    Install the official app and create a local profile. No phone number or email is required.

  2. 02

    Create a one-time invitation link for the first contact. Confirm the security code after connecting.

  3. 03

    Protect the local database, hide notification previews, and use Tor or transport isolation when network linkage matters.

SimpleX privacy settings

Session

Phone: No
Install
  1. 01

    Install Session and create an Account ID. A phone number and email address are not required.

  2. 02

    Write the Recovery Password down and keep it offline before adding important contacts.

  3. 03

    Exchange the Account ID or QR through another channel. Review connected devices and call settings before use.

Session recovery instructions

Matrix

Phone: Varies
Install
  1. 01

    Choose a maintained client and homeserver. Check the homeserver policy before creating the account.

  2. 02

    Create a private room with end-to-end encryption enabled. Set up Secure Backup and store its Security Key offline.

  3. 03

    Verify every new session. Review room members, bridges, bots, and participating homeservers before sharing sensitive material.

Matrix private-room setup
06

Limits and useful settings

SignalLimit and settings
Main limit

A phone number is still required for registration, and linked devices keep local copies.

Useful settings

Hide number visibility and number discovery; set a registration lock; verify safety numbers.

SimpleX ChatLimit and settings
Main limit

Invitation links are credentials, and traffic correlation remains possible.

Useful settings

Verify security codes; protect the local database; use Tor or transport isolation where needed.

SessionLimit and settings
Main limit

The current protocol does not provide perfect forward secrecy. Session Protocol V2 is planned work.

Useful settings

Store the recovery password offline and review every device connected to the Account ID.

MatrixLimit and settings
Main limit

Homeservers still process account, device, membership, room-state, and routing data.

Useful settings

Verify devices; remove old sessions; review bridges and every homeserver used by a room.

MollyLimit and settings
Main limit

It keeps Signal registration, discovery, protocol, linked devices, and network metadata.

Useful settings

Enable the local database passphrase, automatic locking, and RAM shredding where supported.

BriarLimit and settings
Main limit

History remains on the device, and offline delivery depends on a reachable contact or Mailbox.

Useful settings

Exchange contact codes carefully; encrypt backups; keep any paired Mailbox patched and locked.

CwtchLimit and settings
Main limit

Direct chats and group modes do not all have the same infrastructure or trust boundary.

Useful settings

Check the current group design; protect profile exports; verify contact addresses separately.

Ricochet RefreshLimit and settings
Main limit

Stable V3 does not provide the profile-v4 SQLCipher design described on the development branch.

Useful settings

Verify the onion address through another channel and protect the local desktop profile.

A strong device passcode, current operating system, hidden notification previews, short local retention, and a review of linked sessions matter across every app. For the separate extraction threat, see what phone extraction tools target.

Telegram is not an equivalent default

Telegram describes itself as a cloud messaging service. Its privacy policy distinguishes cloud chats from end-to-end encrypted Secret Chats and says cloud chat content is stored on Telegram's servers for cross-device access. Do not treat an ordinary Telegram chat or group as equivalent to Signal's default end-to-end encryption.

Controls that matter on every app

  • Verify contacts or devices through a second channel.
  • Remove linked devices you no longer control.
  • Lock the app and encrypt the device.
  • Disable message previews on the lock screen.
  • Install updates from the official project or app store.
  • Assume the recipient can copy anything they receive.

Malware can read messages on screen or capture them before encryption. A hidden camera, notification preview, cloud device backup, or cooperating contact can do the same. Messenger choice narrows exposure. It does not replace endpoint security.

Sources


Reviewed 22 Aug 2026. Cunicula receives no funding from the projects named in this comparison.

Frequently Asked Questions

Which private messenger should I use?

Signal is the strongest default for most people because every conversation is end-to-end encrypted and its published legal responses show that it retains little account data. SimpleX removes the persistent user identifier but requires more deliberate contact exchange. Session requires no phone number, but its current protocol does not provide perfect forward secrecy. Matrix suits federated communities, though homeservers still process account and room data.

Can Signal be used without revealing a phone number?

Signal still requires a phone number for registration. Its usernames let people start a chat without receiving that number. Set both phone-number privacy controls to Nobody if you do not want other users to see your number or find your account by searching for it.

Does SimpleX have user accounts?

SimpleX does not assign a global user identifier. Contacts connect through invitation links and separate message queues. Relay servers temporarily hold encrypted messages until delivery. This reduces server-side linkage, but it does not defeat endpoint compromise or a capable observer watching traffic.

Does Session provide perfect forward secrecy?

Not in its current protocol. Session states that perfect forward secrecy is planned for Session Protocol V2. Session does provide end-to-end encryption, phone-free account creation, and onion-routed requests.

Is Matrix end-to-end encrypted?

Matrix supports end-to-end encryption through Olm and Megolm, and major clients enable it for private rooms. Encryption protects event content. It does not hide the account, room membership, device records, or all traffic metadata from the homeservers involved.