# Secure messaging apps

Messaging apps rated on default end-to-end encryption, phone number requirements, metadata protection and open source.

A secure messenger encrypts every chat end to end by default, collects as little metadata as possible and publishes its code. Every app below encrypts by default; compare phone number requirements and metadata protection on each page.

1. [Briar](https://privacyratings.com/messengers/briar/): A (94/100). Peer-to-peer encrypted messenger for Android and desktop that syncs over Tor, Wi-Fi or Bluetooth. Messages, forums and blogs are stored only on users' devices.
2. [Ricochet Refresh](https://privacyratings.com/messengers/ricochet-refresh/): A (94/100). Desktop instant messenger that runs each user as a Tor onion service and connects contacts peer to peer, hiding identity, IP address and metadata. Maintained by Blueprint for Free Speech.
3. [Session](https://privacyratings.com/messengers/session/): A (94/100). End-to-end encrypted messenger that uses a random Account ID instead of a phone number and sends messages through onion routing over a decentralized network of community-operated nodes. Stewarded by the Session Technology Foundation in Switzerland.
4. [SimpleX](https://privacyratings.com/messengers/simplex/): A (94/100). End-to-end encrypted messenger that has no user identifiers of any kind, not even random ones. Messages pass through relay servers that anyone can run.
5. [Berty](https://privacyratings.com/messengers/berty/): B (89/100). Peer-to-peer, end-to-end encrypted messenger built on IPFS by the French non-profit Berty Technologies. It needs no phone number or email and can exchange messages offline over Bluetooth and local networks.
6. [Cwtch](https://privacyratings.com/messengers/cwtch/): B (89/100). Decentralized, metadata-resistant messenger from the non-profit Open Privacy Research Society. Contacts talk peer to peer over Tor onion services, and optional group chats use untrusted servers that anyone can run.
7. [Quiet](https://privacyratings.com/messengers/quiet/): B (89/100). Peer-to-peer team chat, similar to Slack, that runs without servers: community members' devices sync messages directly over Tor. The developers warn it is not yet audited.
8. [Conversations](https://privacyratings.com/messengers/conversations/): B (83/100). XMPP (Jabber) client for Android that works with any standard XMPP server, with OMEMO end-to-end encryption on by default for one-to-one and private group chats.
9. [Threema](https://privacyratings.com/messengers/threema/): B (83/100). Paid end-to-end encrypted messenger from Switzerland that works with a random Threema ID instead of a phone number. The apps are open source; the server is proprietary.
10. [Tox & qTox client](https://privacyratings.com/messengers/tox-qtox-client/): B (83/100). Peer-to-peer encrypted messaging protocol with no central servers, and qTox, its desktop client for chat, voice, video and file transfer. qTox is now maintained by the TokTok project after the original repository was archived.
11. [Olvid](https://privacyratings.com/messengers/olvid/): B (81/100). End-to-end encrypted messenger from France that needs no phone number, email or other personal data; contacts are added by exchanging keys. Certified under the French ANSSI CSPN scheme.
12. [Dino](https://privacyratings.com/messengers/dino/): B (78/100). Desktop XMPP (Jabber) client for Linux built with GTK, with group chats, file transfers, and voice and video calls. OMEMO end-to-end encryption is on by default for one-to-one and private group chats.
13. [Molly](https://privacyratings.com/messengers/molly/): B (78/100). Independent fork of the Signal Android app that connects to the Signal network and adds database encryption with a passphrase, UnifiedPush notifications and a Molly-FOSS build without proprietary Google components.
14. [Signal](https://privacyratings.com/messengers/signal/): B (78/100). End-to-end encrypted messenger for text, voice and video calls, and groups, built on the Signal Protocol. Run by the non-profit Signal Foundation.
15. [Jami](https://privacyratings.com/messengers/jami/): B (75/100). Peer-to-peer encrypted messenger from the GNU project for text, audio and video calls, screen sharing and conferences, with apps for desktop and mobile.
16. [Keybase](https://privacyratings.com/messengers/keybase/): C (61/100). End-to-end encrypted chat, group chat and file sharing tied to public-key identity proofs. Owned by Zoom since its acquisition, with little ongoing development.
17. [Wire](https://privacyratings.com/messengers/wire/): C (61/100). End-to-end encrypted messenger and team collaboration app from Switzerland, with chats, calls and file sharing using Proteus and MLS. Accounts use an email address, and organizations can self-host federated backends.
18. [iMessage](https://privacyratings.com/messengers/imessage/): D (42/100). Apple's end-to-end encrypted messaging service built into the Messages app on iPhone, iPad, Mac and other Apple devices, addressed by phone number or Apple Account email.
19. [Viber](https://privacyratings.com/messengers/viber/): F (22/100). Messenger owned by Rakuten for chats, groups, voice and video calls, communities and channels, tied to a phone number. Private chats, groups and calls are end-to-end encrypted; the app is funded by ads.
20. [WhatsApp](https://privacyratings.com/messengers/whatsapp/): F (22/100). Messenger owned by Meta for text, voice and video calls, groups and channels, tied to a phone number. Personal chats and calls use the Signal Protocol for end-to-end encryption.

## Is WhatsApp secure?

WhatsApp encrypts messages end to end by default, but it is owned by Meta, requires a phone number and collects metadata. See its full rating and alternatives.

## Which messenger does not need a phone number?

Several apps below let you register without a phone number. Check the "No phone number" answer on each rating.

Source: https://privacyratings.com/secure-messaging-app/
