When a user taps Send on an encrypted chat, a small piece of theatre plays out that most people never see. The message is scrambled on the phone before it ever leaves, using a key the server does not possess. It travels across the network as a blob of ciphertext, lands on the company’s infrastructure, waits its turn, then hops out to the recipient’s device, where their key unlocks it. If a subpoena arrives, or a rogue engineer goes looking, the words themselves really are unreadable. That much of the marketing is true.

What the marketing tends to skip is everything else the server can see while ferrying that opaque blob. The timestamp on the send. The account it came from. The account it went to. The size of the payload, which hints at whether it was a short text or a photo. The IP address behind each end, and therefore a rough location. Whether the two accounts have chatted before, and how often. In the industry’s own vocabulary, this is metadata, and it is the part encryption was never designed to hide.

What “end-to-end” actually promises

End-to-end encryption (E2EE) is a specific claim: only the endpoints — the sender’s device and the recipient’s device — hold the keys needed to decrypt the message content. The server in the middle relays ciphertext. Signal’s protocol, which also underpins WhatsApp and Messenger’s encrypted chats, uses a scheme called the Double Ratchet, layered on an initial key agreement — now the post-quantum PQXDH exchange — so that each message gets a fresh key and earlier messages stay sealed even if a later key is stolen.

That specification is a live document, not a historical artifact. The current revision is dated November 2025 and adds post-quantum ratcheting on top of the elliptic-curve design Trevor Perrin and Moxie Marlinspike published a decade ago. The mathematics is not the weak part of the system.

The guarantee is narrow and real, and it says nothing about the envelope. A postal analogy holds up well: imagine every letter sealed in a tamper-evident pouch the post office cannot open, but the pouch still carries a from-address, a to-address, a weight, a postmark and a route stamp. Delivery requires that outer information. Sealing the contents does not erase it, which is why comparisons between encrypted messaging apps turn less on the cipher than on what each operator writes down.

The envelope, in detail

Start with identity data: the phone number or account ID that registered the app, usually tied to a device fingerprint, a push-notification token and a registration date. This is the layer that connects an account to a person, and it is the layer a subpoena reaches first.

Then social-graph data and timing data. The first covers who has whom in their address book, who has messaged whom, and when the connection was first made. The second covers precise timestamps on sends, delivery receipts and read receipts — a transcript of attention rather than content, showing not just that a message arrived but when it was opened.

Then traffic data and network data. Message sizes, message frequencies, and the durations of voice and video calls sit in the first category. IP addresses on each end sit in the second, and from an IP address you can usually infer an approximate location, an internet provider, and sometimes a device type.

None of that requires reading a single decrypted word. In many investigations, it is more useful than the words would be. A pattern of 3 a.m. messages between a journalist and an official, spiking around the day a story broke, tells a coherent story without any content at all.

How much of this the big apps actually keep

The differences among mainstream apps are less about what encryption does and more about what metadata the operator chooses to store. WhatsApp’s own guidance for law enforcement describes what is available: basic subscriber information, device data, and — when compelled by a “pen register” or trap-and-trace order — routing information for messages going forward, meaning sender, recipient and timestamps. It does not hand over message content, because it cannot read it. The routing ledger is a different matter.

A 2021 FBI legal-access guide, reported by Rolling Stone, put a number on the cadence: under a pen register, WhatsApp returns that routing metadata roughly every fifteen minutes, while most comparable services deliver logs after the fact, with a lag. WhatsApp told the magazine the guide lacked context — pen registers yield no message content and apply only prospectively, never retroactively. Both things are true at once, and the fifteen minutes is the part worth remembering.

The same document describes what a search warrant produces: the target’s address-book contacts, plus the other users who have the target saved in their contacts. That is the contact-list claim in its plainest form. Nobody read a message to assemble it.

Apple’s Legal Process Guidelines, published October 2025, describe something narrower but structurally similar. iMessage content is end-to-end encrypted, Apple cannot intercept it, and Apple states it has no iMessage communication logs at all. What it does have are iMessage capability query logs: records that a device asked Apple’s servers whether some phone number, email address or Apple ID was reachable over iMessage. Apple retains those for up to 25 days, releases them only on a court order under 18 U.S.C. §2703(d) or a warrant, and is explicit that they do not show any communication took place and do not identify which app on the device asked. FaceTime call-invitation logs carry the same 25-day window and the same caveat. It is a thinner record than a chat history, and it is not nothing.

Signal is the outlier that proves the rule. When served with legal process, the organization publishes its responses at signal.org/bigbrother, and the responses are almost comically short: a 2016 grand jury subpoena from the Eastern District of Virginia produced two dates, the day the account registered and the day it last connected. A grand jury subpoena in the District of Columbia in March 2026 produced the same near-empty answer, with Signal restating that it has no access to messages, calls, profile details, group information, contacts or call logs. That posture is deliberate and expensive to maintain. It is not what encryption gives an app for free; it is what a project has to build on top of encryption if it wants the metadata trail to shrink.

Why metadata is often the whole story

Intelligence agencies worked this out long before consumer apps did. In April 2014, debating Georgetown law professor David Cole at Johns Hopkins University, former NSA and CIA director Michael Hayden agreed that metadata can be more revealing than content and added six words that have followed him since: “We kill people based on metadata.” He immediately drew a line — that, he said, is not what is done with the domestic metadata under discussion. The line does not soften the first sentence.

Two years later, Jonathan Mayer, Patrick Mutchler and John C. Mitchell of Stanford published a controlled test of the idea in the Proceedings of the National Academy of Sciences. Volunteers installed an Android app that logged call and text metadata — numbers, timestamps, durations — for a few months each. The resulting graph was densely interconnected and, the authors found, trivially reidentifiable: matching numbers against public listings was enough to put names to nodes.

The sensitive inferences were case studies, and they did not need a clever model. One participant’s calls went to several neurology practices, a specialty pharmacy and a hotline for a drug prescribed only for relapsing-remitting multiple sclerosis. Another placed short calls to a home-reporting line for a cardiac arrhythmia monitoring device, after a long call from a cardiology group. Another called a firearms dealer that advertises a particular specialty. Nobody listened to a single call.

The same principle applies inside a messenger. If an account chats daily with an oncology clinic’s line, then starts messaging a funeral home, the content is nearly redundant. If two accounts always come online within seconds of each other from the same IP block at night and different ones by day, they probably share a household. Building profiles from this kind of pattern-of-life data is routine work at ad-tech firms and threat-intelligence shops alike.

What actually stays private, and what does not

A grounded version of the promise looks like this. On a properly implemented E2EE app, an outside attacker who breaches the company’s servers, or an insider with database access, cannot read the text of past messages, the audio of past calls, or the pixels of past photos. That is a meaningful floor, and it is why encrypted messaging matters for journalists, lawyers, domestic-abuse survivors and ordinary users alike.

What that same attacker, or a subpoena, can often still get: the fact that two accounts have been in contact, when, how often, from roughly where, using which device, for how long. Combined with data from elsewhere — a phone bill, a follow list, a cell-tower log — the outline fills in fast.

Metadata is not a footnote to the encrypted content. It is a parallel record of the relationship, written in a format designed to be queried.

What a user can actually change

Cloud backups are the largest single leak, because a backup that is not itself end-to-end encrypted converts a sealed conversation into a readable file sitting in someone else’s data center. Apple’s guidelines state the position bluntly: for iCloud data Apple can decrypt, Apple holds the keys in its US data centers, and only Advanced Data Protection moves backups, photos and notes behind end-to-end encryption. On Android the equivalent decision is whether chat history goes to Google Drive at all, or stays in a local backup on the phone.

Disappearing messages shrink the on-device record, which matters mostly if a phone is later seized or synced. Most apps bury the timer in per-chat settings rather than turning it on globally, alongside the read-receipt and last-seen switches in the same privacy menus.

Routing traffic through a VPN or Tor blurs the IP layer, and Signal’s call-relay setting does the same for voice calls, which would otherwise expose both parties’ addresses to each other. Registering an account with a number not tied to a real identity, where that is legal, cuts the link between the metadata and the person.

None of these are defaults. None of them touch what the server itself writes down about who talked to whom.

The padlock icon in the corner of the chat window is telling the truth about the letter. Meanwhile the envelope is still being filled out — one row per tap of Send, timestamped to the second, two account numbers, a byte count, the IP address the packet came in on. A decade from now the words inside will still be unreadable. The ledger of who wrote to whom, at 3 a.m., in the week the story broke, will still read perfectly.