In 2014, during a public debate at Johns Hopkins University, former NSA and CIA director Michael Hayden said something that has been quoted ever since: “We kill people based on metadata.” He was defending U.S. surveillance practices rather than talking about messaging apps, but the video clip of the exchange captures the point in six words: the envelope around a communication can reveal an extraordinary amount without exposing what was said.
End-to-end encryption, as WhatsApp, Signal, iMessage and other encrypted messaging apps implement it, protects the message body between the communicating devices. The server relays ciphertext it cannot read, but encryption alone does not dictate what account, connection, timing or network records a provider keeps around that delivery.
What metadata actually contains
Metadata is a soft word for a hard set of fields. Depending on the service, it can include account identifiers, timestamps, IP addresses, device information, call records, contacts or group information, while a mobile carrier separately creates records showing which cell sites a phone connected to.
WhatsApp’s current government-request guidance says an appropriate request may return basic subscriber and account information such as IP address, device type, group information and a contact list. WhatsApp also says it does not ordinarily retain transaction logs for delivered messages, but under valid prospective legal process it can begin collecting message and call logs showing the communicating parties, time, source IP address and type of communication.
Signal sits at the opposite end of the spectrum. Its published responses to government requests say the service does not have access to users’ messages, calls, contacts, group information or call logs; historically, requests have yielded little more than when an account was created and when it last connected.
Why “just metadata” was never just metadata
The intuition that content is sensitive and metadata is not comes from an older telephone model, where the conversation was private and the surrounding record looked administrative. Smartphones and large datasets made that distinction much harder to defend.
In 2016, Jonathan Mayer, Patrick Mutchler and John C. Mitchell at Stanford published a study in the Proceedings of the National Academy of Sciences based on metadata volunteered by 823 people, covering 251,788 calls and more than 1.2 million text messages. Without reading the communications, the researchers showed that telephone metadata could support relationship inferences and reveal highly sensitive traits, including a participant’s cardiac condition and another participant’s firearm ownership.
One participant received a long call from a cardiology group, spoke briefly with a medical laboratory, received several short calls from a local drugstore and called a self-reporting hotline used with a cardiac-arrhythmia monitoring device. The researchers later confirmed through public sources that the participant had a cardiac arrhythmia; no recording of those conversations was needed.
A separate 2013 Scientific Reports study led by Yves-Alexandre de Montjoye examined 15 months of mobility data from 1.5 million people. With locations recorded at roughly cell-antenna resolution and time rounded to one-hour windows, four randomly chosen time-and-place points were enough to uniquely characterize 95 percent of the traces.
A day reconstructed without a single message read
Consider what can be assembled when an investigator lawfully obtains records from more than one layer: a service that retains some account or timing information, plus carrier records showing where a handset connected. Neither dataset needs to contain the sentence typed into a chat box.
A phone repeatedly appears on one cluster of cell sites overnight and another during weekday working hours, establishing two strong location patterns. Records from a service that retains communication metadata might then place repeated contact with the same account at particular times, while ordinary carrier call records can add the destination and duration of phone calls.
A long call to a medical practice, repeated contact with one person late at night and a change in the phone’s usual movement pattern can become meaningful when viewed together. None of those clues proves what anyone said, but patterns across independent records can expose routines and relationships that are invisible in any single entry.
Group information can add another layer where a provider actually retains it. Membership in a work group, neighbourhood group or other identifiable cluster provides social context before the first encrypted sentence is examined.
What the apps do and do not hide
That is why comparisons among WhatsApp, Signal and Telegram turn on more than the cipher protecting the message. Two services can both advertise end-to-end encryption while keeping very different amounts of information outside the encrypted payload.
Signal developed sealed sender to reduce what its own service learns during message delivery by concealing the sender’s identity from the server. Signal has also built private contact discovery so a user’s device can determine which contacts use Signal without revealing the address book to Signal’s service.
Apple’s position is narrower than a simple claim that it knows who exchanged iMessages and when. Apple’s legal-process guidelines say iMessage communications are end-to-end encrypted and that Apple has no iMessage communication logs; it does retain iMessage capability-query logs showing that a device asked whether a phone number, email address or Apple ID was iMessage-capable, but Apple explicitly says those records do not prove that any communication occurred.
Telegram is the awkward case often mistaken for the strongest one. Its own FAQ says Secret Chats use end-to-end encryption and remain on their devices of origin, while ordinary Cloud Chats use client-server/server-client encryption and are stored in the Telegram cloud.
The carrier layer underneath
Even an app engineered to retain almost nothing cannot prevent the mobile network from knowing that a handset connected to the cellular system. Cell-site location information belongs to a different layer from messaging-app metadata.
In Carpenter v. United States, the U.S. Supreme Court described how wireless carriers create time-stamped records when phones connect to cell sites and how those records can reveal a person’s movements over time. The Court held that obtaining historical CSLI is generally a Fourth Amendment search requiring a warrant supported by probable cause, while leaving room for case-specific exceptions.
An encrypted message still has to cross a physical network, and traffic can therefore leave traces at layers the messaging provider does not control. IP connections, timing and carrier-side cell records are part of the physical infrastructure underneath the app, even when the words riding across it remain unreadable.
What end-to-end encryption is actually promising
The promise is narrow, and that precision is what makes it useful. Proper end-to-end encryption keeps the message content readable only at the endpoints holding the necessary keys, protecting the conversation from the provider, network operators and attackers who merely intercept encrypted traffic.
It does not automatically erase every record surrounding the conversation. Whether a service retains contacts, IP addresses, group information, capability queries or communication logs depends on the architecture and retention choices of that particular service, while the carrier operates a separate network with separate records.
Signal’s near-empty responses to legal demands are therefore not simply the automatic consequence of using encryption. They reflect additional engineering decisions intended to keep the service from possessing metadata in the first place.
Hayden’s remark came from a national-security debate, not a discussion of private messaging, and different apps expose radically different amounts of information. But the sealed message and the traces around it remain two separate things: the words can stay unreadable while times, connections and locations still form a pattern around them, like footprints left outside a locked room.