Encrypted Messaging Apps
End-to-end encrypted messaging is a baseline expectation, not a differentiator. Nearly every major messenger now claims some form of encryption. The real differences lie in what metadata is collected, how identity works, what the backup model looks like, and how the app behaves on a hardened operating system like GrapheneOS. This guide covers practical setup and configuration for the two messengers most relevant to privacy-focused users: Threema and Signal.
Why it matters
The content of your messages is only one dimension of messaging privacy. Who you talk to, when, how often, and from what device — all of this is metadata, and for many threat models, metadata is more revealing than content.
Choosing a messenger is about understanding the trade-offs in identity requirements, metadata handling, backup security, and operational behaviour on your specific device. On GrapheneOS, you have additional tools like profile separation and Contact Scopes that let you control messenger behaviour more precisely than on stock Android.
How the main messengers compare
End-to-end encryption is now a standard claim — the meaningful differences are in metadata, identity, and server retention. An honest survey of the options most people choose between:
- WhatsApp uses the Signal protocol for content encryption but is owned by Meta and collects metadata extensively — who you message, when, how often, your number, device and IP — feeding Meta's wider advertising infrastructure.
- Signal collects almost no metadata and is widely respected, but requires a phone number to register and runs on centralised US-based servers subject to US legal process. Excellent for most people; the number requirement is a real limit for anonymity-critical work.
- Telegram is not end-to-end encrypted by default — standard chats are stored readable on its servers, and only opt-in "Secret Chats" are encrypted. Treat it as a social platform, not a private messenger.
- iMessage encrypts between Apple devices but falls back to plain SMS for non-Apple contacts, and stores message keys with Apple when iCloud Backup is on — meaning Apple can be compelled to hand over content.
- Threema requires no phone number or email, retains minimal metadata, deletes messages from its servers after delivery, and is hosted in Switzerland under a strict privacy regime. The absence of a registration identifier is its defining advantage.
This guide focuses on setting up the two that fit privacy-focused use best — Threema and Signal. For a fuller side-by-side, see the private messaging apps comparison for Australia, the Signal vs Threema on GrapheneOS head-to-head, and Signal vs WhatsApp for Australian users.
Choosing a messenger by threat model
Before installing anything, consider three questions:
- What identity does the messenger require? Signal requires a phone number. Threema can be used with only a randomly generated ID. This distinction matters if you want to communicate without linking the conversation to your phone number.
- What metadata does the service retain? Signal retains minimal metadata by design but still requires a phone number as an identifier. Threema stores less metadata and does not require a phone number, though linking one is optional.
- What is the backup model? How you recover your account and messages after a device wipe or loss varies significantly between apps and directly affects your resilience.
Neither app is universally "better." Each fits different requirements. Some users run both, in different profiles, for different purposes. In concrete terms:
- Everyday privacy — to stop ad-driven data collection and keep ordinary conversations private, Signal is ideal: free, excellent, and the people you talk to probably already use it.
- Identity minimisation — if you do not want your account tied to a phone number or your contact graph exposed by registration, Threema is the stronger fit because there is no number to link.
- Source or contact protection — when another person is at risk if your relationship is revealed, use Threema registered without a number, inside an isolated profile, behind a VPN. See the journalists & activists guide.
Threema on GrapheneOS
Installation: Threema can be installed directly from the Threema Shop (threema.ch) as an APK, or from the Google Play Store if you have sandboxed Google Play Services installed. It does not require Google Play to function.
Notifications without Google: Threema includes Threema Push, its own push notification system that operates independently of Google's Firebase Cloud Messaging (FCM). This means notifications work reliably on GrapheneOS without Google Play Services. If you do have sandboxed Google Play installed, Threema can use FCM instead.
Setup:
- Install Threema from your preferred source.
- Open the app and create a new Threema ID, or restore from a backup.
- Optionally link a phone number or email for discoverability — this is not required.
- Configure Threema Push under Settings > Notifications if not using Google Play Services.
Backup — understanding the three types:
- Threema Safe: Backs up your Threema ID, contacts, group memberships, and app settings to a server (Threema's or your own). This is your primary recovery mechanism. It does NOT back up message history. Enable it under Settings > Backups > Threema Safe.
- ID Export: Exports only your Threema ID as a file. This is a minimal backup that lets you reclaim your identity on a new device but restores nothing else. Useful as a secondary safeguard.
- Data Backup: A full local backup of all messages, contacts, and media. This is stored as a file on the device and must be manually copied to external storage. It is encrypted with a password you set during creation.
These three backup types serve different purposes. For resilience against device loss, enable Threema Safe and periodically create a Data Backup stored externally. The ID Export is a lightweight insurance policy for identity recovery only.
Signal on GrapheneOS
Installation: Signal can be installed from signal.org as a direct APK download, or from the Google Play Store with sandboxed Google Play. It does not require Google Play to run.
Identity: Signal requires a phone number to register. This phone number becomes your identifier. You can set a username for discoverability without sharing your number, but registration still requires one.
Setup:
- Download the Signal APK from signal.org or install from the Play Store.
- Open the app and register with a phone number. You will receive an SMS or voice verification.
- Set a Signal PIN during setup. This PIN protects your account registration and recovers your profile, contacts, and settings if you reinstall. Do not lose it.
- Configure notification delivery under Settings > Notifications.
Notifications without Google: If you do not have sandboxed Google Play Services, Signal uses a websocket connection to receive messages. This keeps a persistent connection to Signal's servers, which may increase battery consumption slightly. With sandboxed Google Play installed, Signal uses FCM for push notifications, which is generally more battery-efficient.
Backup: Signal supports encrypted local backups. Enable under Settings > Chats > Chat backups. The backup is encrypted with a 30-digit passphrase displayed during setup. Store this passphrase externally — without it, the backup is unrecoverable. Transfer to a new device can also be done via a direct device-to-device transfer during setup.
Profile placement
On GrapheneOS, each user profile is a separate environment with its own apps, data, and permissions. Use this to your advantage with messengers:
Place each messenger in the profile that matches its identity and purpose. If you use Signal with your personal phone number, it belongs in your personal profile. If you use Threema with an anonymous ID for a specific purpose, place it in a dedicated profile for that context.
Do not install all messengers in the Owner profile by default. The Owner profile is the only one that persists across all device states and has access to system-level settings. Keeping messengers in secondary profiles provides compartmentalisation — if one profile is compromised or accessed, the others remain separate.
If you use the same messenger for both personal and professional contexts, consider whether two separate accounts in two separate profiles better serve your needs.
Permissions
- Contacts: Both Signal and Threema request access to your device contacts. On GrapheneOS, use Contact Scopes instead of granting full access. This lets you share specific contacts rather than your entire address book. Configure under Settings > Apps > [App] > Permissions > Contacts.
- Storage: Grant only if you need to send or save files and media.
- Microphone and Camera: Required for voice and video calls. Consider revoking between uses if your threat model warrants it.
- Notification privacy: Control what appears on your lock screen via Settings > Notifications > Sensitive notifications.
Migration planning
Before you need to recover, document the following for each messenger you use:
- Your account identifier (phone number, Threema ID, username).
- Your backup method and where backups are stored.
- Any recovery credentials (Signal PIN, Threema Safe password, Data Backup password).
- What data each backup type includes and excludes.
Store this documentation externally, in a secure location. A device wipe — whether intentional (duress PIN) or accidental — will destroy all local messenger data. Your ability to recover depends entirely on preparation done beforehand.
Best practices
- Enable disappearing messages for sensitive conversations. This limits the window of exposure if a device is accessed.
- Keep messengers updated. Both Signal and Threema release security updates regularly. On GrapheneOS without Play Store auto-updates, check for updates manually or use a repository app.
- Use Contact Scopes rather than full contact access whenever possible. This is a GrapheneOS advantage — use it.
Common mistakes
- Installing all messengers in the Owner profile. This defeats the purpose of profile separation and concentrates all communication data in one place.
- Granting full contacts access without considering alternatives. Contact Scopes exists specifically to avoid exposing your entire address book to each app.
- No backup plan. Losing a device without external backups means losing your messenger identity, contacts, and message history. Threema IDs without a Threema Safe backup are not recoverable. Signal accounts without the PIN and backup passphrase require full re-registration.
- Assuming all encrypted messengers provide the same privacy. Encryption protects message content in transit. It does not standardise metadata collection, identity requirements, backup security, or server-side data retention. Evaluate each app on its full behaviour, not just the encryption label.
- Ignoring notification content on the lock screen. An encrypted message is no longer private if its preview is visible to anyone who glances at your lock screen.
Reality check
No messenger provides complete privacy in isolation. Encrypted messaging protects content between endpoints, but your device, your contact's device, the network metadata, and the app's server infrastructure all represent potential points of exposure. The value of these apps is that they significantly raise the bar — but they work best as one component within a considered, layered approach to communication security.
The Threema + Mullvad combination
Pairing Threema with an always-on Mullvad VPN removes two exposure points at once: Threema keeps your messaging metadata from being collected, and Mullvad keeps your IP address and DNS queries hidden from your ISP or network operator. Together they form a communication layer that does not leak identity, location, or behaviour patterns — and it is the default configuration on every device we ship, not an optional extra. Run any messenger behind an always-on VPN with a kill switch; see the VPN setup guide.
Conclusion
Threema and Signal are both strong choices for encrypted messaging on GrapheneOS, each with distinct trade-offs in identity, metadata, and backup models. The key decisions are not just which app to install, but where to install it, what permissions to grant, and how to ensure you can recover if the device is lost. Set up your backups, document your recovery paths, and use the compartmentalisation tools GrapheneOS provides. The messenger is only as resilient as the preparation behind it.
Every Privacy Devices phone ships with Threema and Mullvad VPN pre-configured on a de-Googled GrapheneOS base — encrypted messaging ready out of the box, with no phone number tying down your messenger.
Threema licence · Signal vs Threema · browse secure devices · ask us on WhatsApp.