Signal
Nonprofit private messenger with default end-to-end encryption (Signal Protocol). Free forever; optional Secure Backups $1.99/mo for full media history up to 100 GB.
Pricing
Contact Sales
freemium
Category
messaging
0 features tracked
Quick Links
Overview
Signal is a free, open-source private messaging app run by the Signal Foundation (a U.S. 501(c)(3) nonprofit) through subsidiary Signal Messenger LLC. It grew out of Moxie Marlinspike’s Open Whisper Systems work (TextSecure and RedPhone) and launched as a unified iOS/Android product in the mid-2010s. In 2018, WhatsApp co-founder Brian Acton and Marlinspike created the Signal Foundation with a large personal loan from Acton so the project could stay independent of ads, data brokers, and acquisition by big tech. President Meredith Whittaker leads the organization today.
Signal’s job is simple and strict: private 1:1 and group chat, voice and video calls, and file sharing with end-to-end encryption on by default for every conversation—not as an optional “secret chat” mode. The open-source Signal Protocol (Double Ratchet, X3DH/PQXDH handshakes, and more recently post-quantum ratchets) is also licensed into other products such as WhatsApp’s encryption stack, but the Signal app itself keeps a much smaller server-side data footprint than Meta-owned messengers: registration phone number, account creation time, and last connection time are the classic “what Signal can produce under legal process” set.
Clients ship for iOS, Android, and Desktop (Windows, macOS, Linux). Desktop and secondary devices link to a primary phone registration. There are no ads, no affiliate trackers in-product, and no paid “premium chat” tier for core messaging. The only optional paid product as of 2025–2026 is Signal Secure Backups for long-term encrypted media history. Independent privacy reviews (for example Mozilla’s 2025 hands-on review) routinely rate Signal near the top of consumer messengers for default privacy; store ratings commonly sit around the mid-to-high 4s out of 5.
Quick take: Choose Signal when verifiable default encryption, minimal metadata, and a nonprofit incentive model matter more than stickers-everywhere social features or a global contact graph already living on WhatsApp or Telegram. It loses on network effects and enterprise admin tooling; it wins on the privacy threat model most journalists, activists, and security-conscious families actually have.
Key features
- Default end-to-end encryption — Every text, voice note, photo, video, file, sticker, group message, and call uses the Signal Protocol. Privacy is not a toggle. Forward secrecy and post-compromise security come from continuous ratcheting; sessions heal after key material compromise.
- Signal Protocol + post-quantum upgrades — Classical Double Ratchet plus PQXDH for quantum-resistant session establishment, and the Sparse Post-Quantum Ratchet (SPQR) / Triple Ratchet path (announced 2025) for ongoing FS/PCS against future quantum adversaries. Protocol specs and libsignal implementations are public.
- Sealed sender — Reduces what servers see about who sent a message (delivery address remains; sender authentication is sealed). Academic work has studied residual linkability; the feature still meaningfully shrinks classic “who messaged whom” logs.
- Usernames & phone number privacy — Register with a phone number (still required), then create a username and control who can find you by number. Lets contacts reach you without broadcasting the number in every group profile view.
- Disappearing messages & view-once media — Per-chat timers (seconds to weeks/custom) delete messages from participants’ devices after read/send rules. View-once photos/videos open once then disappear. These are hygiene tools, not anti-screenshot magic.
- Groups, polls, stickers, stories — Private group chats with admin controls; encrypted stickers (including custom packs); stories-style short-lived posts; polls in groups (2025) for lightweight decisions without leaving the chat.
- Voice & video calls — 1:1 and group calling over data with no long-distance fees. Optional relay/IP protections trade some quality for stronger IP hiding (privacy reviews note defaults that protect more against non-contacts than everyone).
- Linked devices & transfer — Desktop links via QR to the phone. Recent work improves first-link history transfer (messages plus recent media windows) and expands tablet / secondary-phone linking in beta waves so multi-device use is less painful than early Signal years.
- Signal Secure Backups — Opt-in, end-to-end encrypted cloud archives refreshed daily, unlocked only by a user-held recovery key Signal cannot reset. Free tier: full text history (compressed message budget) + last 45 days of media. Paid tier: full media history within a large storage cap.
- Registration lock, Signal PIN, screen security — PIN-backed registration lock frustrates number hijack re-registration. Desktop “screen security” helps against OS screenshot/Recall-style capture. App lock can require device biometrics/passcode.
- Open source clients & server — Android, iOS, Desktop, server, libsignal, and storage-manager code live under the signalapp GitHub org. Security researchers and auditors can inspect implementations, not only marketing claims.
- No ads / no data-monetization product — Product surfaces stay free of ad inventory. GIF/search and maps integrations proxy or minimize third-party leakage where possible; privacy reviews still flag Maps API and phone-number identity as residual risks.
Pricing
Signal’s core product is free: messaging, calls, groups, stickers, usernames, disappearing messages, and multi-device use do not require a subscription. There are no ads and no “Pro chat” upsell. Funding is primarily donations and grants to the nonprofit (plus historical seed capital/loan support from Brian Acton). Signal has publicly discussed infrastructure and registration costs at multi-tens-of-millions of dollars per year as the user base scaled—transparent cost posts exist so users understand why donations matter.
| Plan / product | Price (USD) | What you get | Notes |
|---|---|---|---|
| Signal app (core) | $0 | Unlimited E2E messaging, calls, groups, stickers, stories, polls, usernames, linked Desktop | Supported by donations; never “freemium chat” gating |
| Secure Backups — free | $0 | Encrypted daily archives: all text messages (within free message storage budget, commonly cited ~100 MiB compressed) + media from last 45 days | Opt-in; recovery key is user-held only |
| Secure Backups — paid | $1.99 / month | Text history + media history beyond 45 days, up to 100 GB media storage | First paid Signal feature (rolled out from 2025); price subject to change |
| Donations | Optional (often from a few dollars one-time or monthly) | Funds servers, bandwidth, registration SMS, engineering | In-app Settings → Donate or signal.org/donate |
- Why a paid backup tier exists: Signal’s blog is explicit that large media storage and transfer are expensive, and a nonprofit that refuses ad/data revenue has to charge for bulk storage rather than monetize chats. Core messaging remains free so privacy is not paywalled.
- What backups exclude: View-once items and messages scheduled to disappear within roughly the next day are left out of archives so disappearance intent is preserved. Losing the 64-character recovery key means permanent loss of that backup—Signal cannot recover it.
- No business SKU: There is no Signal “Enterprise Grid,” no admin console SKU, no SSO add-on. Organizations that need MDM-managed team chat usually pick Slack/Teams or self-hosted stacks and use Signal for personal/sensitive side channels.
- Always re-check: Store prices and regional taxes can vary; Secure Backups availability rolled out by platform over time (Android first, then broader). Confirm current tier text in-app under Backups.
Cost reality: Your chat bill is $0 unless you buy media backups. The hidden “cost” of Signal is social—getting the people you need onto the app—not per-seat licenses. Budget donations if you depend on the service long-term; the foundation has been open that running a global private messenger is not cheap.
Limits & gotchas
- Phone number required — Registration still needs a mobile number (SMS/voice verification). Usernames reduce sharing that number, but the account identity remains number-backed. Signal can be compelled to confirm whether a number is registered and last connected. Threat models that demand no phone number look at Session, Briar, or Matrix instead.
- Network effect — Encryption only helps if the other party uses Signal. Many users dual-run WhatsApp/Telegram for large groups and family, which recreates the metadata/social problem Signal was meant to solve.
- Not a business suite — No shared team workspaces with compliance exports, DLP, or SCIM. Discovery for litigation/FOIA is intentionally hard; some government IT policies ban it for records reasons even while individuals use it for sensitive talk.
- Device model friction — Historically a primary phone was mandatory; Desktop is linked, not fully independent. Multi-phone and tablet linking improved in 2025–2026 betas, but power users still hit edge cases when reinstalling or switching ecosystems.
- Backup recovery key is unforgiving — Secure Backups are zero-knowledge. Lose the key, lose the archive. Free media window is only 45 days—photo-heavy chats need the paid tier or local discipline.
- Disappearing messages ≠ perfect deniability — Recipients can screenshot, photograph screens, or back up chats on their side (if they enable backups). Signal itself warns this is hygiene, not a shield against a hostile contact.
- Delivery & outage dependence — Centralized servers mean global incidents take everyone offline (historical multi-hour outages are documented in press). There is no federated fallback.
- Third-party feature edges — GIF search and maps/location flows touch external services; Signal works to proxy/minimize IP exposure, but pure offline maps fans prefer different stacks. Link previews and call IP relay defaults deserve a one-time settings pass for high-risk users.
- Feature pace vs chat apps — Telegram/WhatsApp often ship flashy social features first. Signal prioritizes security design reviews; users who want channels, bots, massive supergroups, or cloud multi-device without a phone will feel constrained.
- SMS is not Signal — On Android, if you also handle SMS, unencrypted SMS/MMS to non-Signal contacts is a different security domain. Only blue/locked Signal sessions are E2E Signal messages.
- Human error still wins — High-profile “Signalgate” style incidents were about inviting the wrong person into an otherwise encrypted group, not breaking the crypto. Operational security remains on the user.
Community sentiment
Across r/signal, Hacker News, Privacy Guides, EFF materials, and privacy review sites, the durable consensus is: Signal is the default recommendation for private consumer messaging when both sides can install it. Praise centers on open-source clients, audited protocol lineage, sealed sender / minimal retention, nonprofit governance, and a UX that is “good enough” for daily family and work side-channels without teaching people what a ratchet is.
Recurring complaints are social and operational more than cryptographic: “nobody I know is on it,” phone-number registration, occasional message delays, Desktop secondary-device quirks, and slower social-feature velocity than Telegram. Secure Backups were long requested; community threads welcomed the free text tier and mostly accepted $1.99/mo for full media as honest nonprofit cost recovery, while still debating zero-knowledge key UX and platform rollout order.
“Best-in-class default encryption—just remember crypto can’t save you from adding the wrong person to the group.” — common paraphrase after 2025 public-sector chat mishaps and Mozilla’s privacy review framing
Security researchers argue about sealed-sender residual metadata, secondary device trust, and the politics of a U.S.-based nonprofit. Those debates rarely dethrone Signal for everyday private chat; they refine threat models. Migration stories usually start from WhatsApp policy/ad anxiety or Telegram’s optional-secret-chat model, and end with mixed networks (Signal for sensitive ties, something else for mass groups).
Who should use it
- Privacy-first individuals and families who want default E2E without configuring “secret chats,” and who can move their closest contacts onto one app.
- Journalists, activists, researchers, and high-risk professionals who need a well-studied protocol, open clients, and minimal provider-held content—with training on device security and contact vetting.
- Security-conscious teams using Signal as a sensitive side channel (incident response, executive private threads) while keeping formal work in Slack or Microsoft Teams.
- Users fleeing ad-supported messengers who want a free core product funded by donations rather than attention markets—and who accept optional paid encrypted media backups.
- Poor fit if you need anonymous registration without any phone number; federated self-host control; huge public channels/bots; or enterprise eDiscovery, DLP, and SSO-managed employee chat as the system of record.
Alternatives
- WhatsApp — Ubiquitous; uses the Signal Protocol for chats but is Meta-operated with a different metadata, backup, and business-feature story. Best when network effect beats threat model purity.
- Telegram — Cloud chats, huge groups/channels, bots; secret chats are optional. Choose for features and reach, not default E2E for all chats.
- iMessage / RCS — Fine inside Apple-to-Apple or carrier RCS contexts; not a cross-platform privacy standard comparable to Signal’s open protocol story.
- Threema / Wire / Session — Threema (paid, Swiss ID), Wire (business-oriented), Session (account-less design) trade different trust and UX models; evaluate when phone numbers or U.S. nonprofit jurisdiction are deal-breakers.
- Matrix / Element — Federated, self-hostable; more ops complexity, stronger data-control story for communities that will run servers.
- Briar — Peer-to-peer / local-first for extreme offline or internet-hostile environments; not a drop-in WhatsApp replacement.
- Discord — Communities, voice stages, servers; not positioned as a minimal-metadata private messenger.
- Slack / Microsoft Teams — Workplace channel chat with admin, compliance, and integrations; wrong tool if the goal is personal private messaging with nonprofit incentives.
Verdict
Signal in 2026 remains the reference consumer private messenger: free core messaging and calling, default end-to-end encryption, open-source clients, and a nonprofit that funds servers with donations instead of ads. Optional Secure Backups finally address the long-standing “lost phone, lost history” failure mode—free for text plus 45 days of media, $1.99/month for longer media history up to 100 GB—without turning chat itself into a subscription.
Pick Signal when you and your contacts will actually use it and when provider access to message content and rich social graphs is the risk you care about. Pick WhatsApp/Telegram when reach and features dominate. Pick Matrix/self-hosted or Session-class tools when federation or no-phone identity is mandatory. Configure usernames, registration lock, disappearing timers, and backup recovery keys on day one—and remember that the hardest part of private messaging is still social adoption and operational discipline, not the ratchet math.