# Messengers privacy ratings

Chat and calling apps, including peer-to-peer ones.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Briar](https://privacyratings.com/messengers/briar/) | A (94/100) | Unknown | Peer-to-peer encrypted messenger for Android and desktop that syncs over Tor, Wi-Fi or Bluetooth. Messages, forums and blogs are stored only on users' devices. |
| [Ricochet Refresh](https://privacyratings.com/messengers/ricochet-refresh/) | A (94/100) | Unknown | Desktop instant messenger that runs each user as a Tor onion service and connects contacts peer to peer, hiding identity, IP address and metadata. Maintained by Blueprint for Free Speech. |
| [Session](https://privacyratings.com/messengers/session/) | A (94/100) | Switzerland | End-to-end encrypted messenger that uses a random Account ID instead of a phone number and sends messages through onion routing over a decentralized network of community-operated nodes. Stewarded by the Session Technology Foundation in Switzerland. |
| [SimpleX](https://privacyratings.com/messengers/simplex/) | A (94/100) | United Kingdom (Five Eyes) | End-to-end encrypted messenger that has no user identifiers of any kind, not even random ones. Messages pass through relay servers that anyone can run. |
| [Berty](https://privacyratings.com/messengers/berty/) | B (89/100) | France (Nine Eyes) | Peer-to-peer, end-to-end encrypted messenger built on IPFS by the French non-profit Berty Technologies. It needs no phone number or email and can exchange messages offline over Bluetooth and local networks. |
| [Cwtch](https://privacyratings.com/messengers/cwtch/) | B (89/100) | Canada (Five Eyes) | Decentralized, metadata-resistant messenger from the non-profit Open Privacy Research Society. Contacts talk peer to peer over Tor onion services, and optional group chats use untrusted servers that anyone can run. |
| [Quiet](https://privacyratings.com/messengers/quiet/) | B (89/100) | Unknown | Peer-to-peer team chat, similar to Slack, that runs without servers: community members' devices sync messages directly over Tor. The developers warn it is not yet audited. |
| [Conversations](https://privacyratings.com/messengers/conversations/) | B (83/100) | Unknown | XMPP (Jabber) client for Android that works with any standard XMPP server, with OMEMO end-to-end encryption on by default for one-to-one and private group chats. |
| [Threema](https://privacyratings.com/messengers/threema/) | B (83/100) | Switzerland | Paid end-to-end encrypted messenger from Switzerland that works with a random Threema ID instead of a phone number. The apps are open source; the server is proprietary. |
| [Tox & qTox client](https://privacyratings.com/messengers/tox-qtox-client/) | B (83/100) | Unknown | Peer-to-peer encrypted messaging protocol with no central servers, and qTox, its desktop client for chat, voice, video and file transfer. qTox is now maintained by the TokTok project after the original repository was archived. |
| [Olvid](https://privacyratings.com/messengers/olvid/) | B (81/100) | France (Nine Eyes) | End-to-end encrypted messenger from France that needs no phone number, email or other personal data; contacts are added by exchanging keys. Certified under the French ANSSI CSPN scheme. |
| [Dino](https://privacyratings.com/messengers/dino/) | B (78/100) | Unknown | Desktop XMPP (Jabber) client for Linux built with GTK, with group chats, file transfers, and voice and video calls. OMEMO end-to-end encryption is on by default for one-to-one and private group chats. |
| [Molly](https://privacyratings.com/messengers/molly/) | B (78/100) | Unknown | Independent fork of the Signal Android app that connects to the Signal network and adds database encryption with a passphrase, UnifiedPush notifications and a Molly-FOSS build without proprietary Google components. |
| [OpenPGP](https://privacyratings.com/messengers/openpgp/) | B (78/100) | Unknown | Open standard for public-key encryption and signing of messages and files, defined in RFC 9580. It adds end-to-end encryption to existing channels such as email, through implementations like GnuPG. |
| [Signal](https://privacyratings.com/messengers/signal/) | B (78/100) | United States (Five Eyes) | End-to-end encrypted messenger for text, voice and video calls, and groups, built on the Signal Protocol. Run by the non-profit Signal Foundation. |
| [XMPP](https://privacyratings.com/messengers/xmpp/) | B (78/100) | Unknown | XMPP, also known as Jabber, is an open standard for federated instant messaging maintained by the XMPP Standards Foundation, with many independent clients and servers. |
| [Jami](https://privacyratings.com/messengers/jami/) | B (75/100) | Canada (Five Eyes) | Peer-to-peer encrypted messenger from the GNU project for text, audio and video calls, screen sharing and conferences, with apps for desktop and mobile. |
| [Gajim](https://privacyratings.com/messengers/gajim/) | C (69/100) | Unknown | Desktop XMPP (Jabber) client for Linux, Windows and macOS that works with any standard XMPP server, with group chats, file transfer and optional OMEMO or OpenPGP end-to-end encryption. |
| [Keybase](https://privacyratings.com/messengers/keybase/) | C (61/100) | United States (Five Eyes) | End-to-end encrypted chat, group chat and file sharing tied to public-key identity proofs. Owned by Zoom since its acquisition, with little ongoing development. |
| [Wire](https://privacyratings.com/messengers/wire/) | C (61/100) | Switzerland | End-to-end encrypted messenger and team collaboration app from Switzerland, with chats, calls and file sharing using Proteus and MLS. Accounts use an email address, and organizations can self-host federated backends. |
| [Matrix](https://privacyratings.com/messengers/matrix/) | D (58/100) | United Kingdom (Five Eyes) | Open standard and federated network for real-time chat and calls, with end-to-end encryption through the Olm and Megolm protocols. Anyone can run a homeserver, and many clients such as Element support it. |
| [Telegram](https://privacyratings.com/messengers/telegram/) | D (44/100) | United Arab Emirates | Cloud-based messenger with large groups, public channels and bots. Regular chats and groups are stored on Telegram's servers with client-server encryption; only optional one-to-one secret chats are end-to-end encrypted. |
| [iMessage](https://privacyratings.com/messengers/imessage/) | D (42/100) | United States (Five Eyes) | Apple's end-to-end encrypted messaging service built into the Messages app on iPhone, iPad, Mac and other Apple devices, addressed by phone number or Apple Account email. |
| [Viber](https://privacyratings.com/messengers/viber/) | F (22/100) | Luxembourg | Messenger owned by Rakuten for chats, groups, voice and video calls, communities and channels, tied to a phone number. Private chats, groups and calls are end-to-end encrypted; the app is funded by ads. |
| [WhatsApp](https://privacyratings.com/messengers/whatsapp/) | F (22/100) | United States (Five Eyes) | Messenger owned by Meta for text, voice and video calls, groups and channels, tied to a phone number. Personal chats and calls use the Signal Protocol for end-to-end encryption. |
| [Facebook Messenger](https://privacyratings.com/messengers/facebook-messenger/) | F (19/100) | United States (Five Eyes) | Meta's messaging app for Facebook accounts, with chats, groups, voice and video calls. Personal chats and calls are end-to-end encrypted by default. |
| [Google Messages](https://privacyratings.com/messengers/google-messages/) | F (17/100) | United States (Five Eyes) | Google's default SMS, MMS and RCS messaging app for Android, with a paired web client. RCS chats between Google Messages users are end-to-end encrypted automatically; SMS and MMS are not. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?
- **End-to-end encrypted by default** (weight 3): Are all chats, including groups, end-to-end encrypted by default?
- **No phone number needed** (weight 2): Can an account be created without a phone number?
- **Metadata protection** (weight 2): Does the service minimize who-talks-to-whom metadata (for example sealed sender or no user identifiers)?
- **Decentralized** (weight 1): Can people run their own server or talk peer to peer?

Source: https://privacyratings.com/messengers/
