Signal vs Session: Phone Number vs No Identifier

Published: October 7, 2026

Short answer: Signal needs your phone number; Session needs nothing at all. You get a long Session ID instead of an account tied to a number, and your messages travel through a decentralized network of volunteer-run nodes with onion routing, so no single company holds your contact list or metadata. The trade-off is real: Session is slower, notifications are weaker on Android, and calls and large groups are more limited. Signal is faster and easier because it trusts a nonprofit's servers. Session is harder to use because it trusts almost nobody.

This comparison is really about two different answers to one question: who should know that you use the app? Signal's answer is pragmatic. It needs your phone number to make finding contacts easy, then works hard to store almost nothing else. Session's answer is radical. It removes the identifier entirely and decentralizes the network, so there is no central party to know anything. Both approaches are honest. They just optimize for different people.

Get the official Signal APK

from Signal's official site — file hosted by Signal, not by us

Comparison graphic showing a phone-number account for Signal versus an anonymous Session ID on a decentralized network for Session

The two apps, side by side

SignalSession
IdentifierPhone number required to registerNo phone number or email; you get a random Session ID
NetworkCentralized servers run by Signal FoundationDecentralized network of community-run nodes with onion routing
Message encryptionEnd-to-end encrypted (Signal Protocol)End-to-end encrypted
Metadata held centrallyMinimal: number, registration dates, last connectionNo central party holds the social graph; routing obscures it
Owner / fundingSignal Foundation, a nonprofit funded by donationsDeveloped around the Oxen privacy project, stewarded by the Session Foundation; no ads
Open sourceClient open source; server code publicOpen source
Contact discoveryEasy: your phone contacts who use Signal appearManual: share your long Session ID or QR code
Notifications on AndroidReliable, with or without Play ServicesA known weak point: can be delayed without exemptions
SpeedFast; direct server connectionSlower; messages hop through multiple nodes
Voice and video callsFull-featured, encrypted, group calls includedLimited compared with Signal
Network sizeLarge mainstream user baseMuch smaller, niche community

The table tells the story in one glance: Session wins the "who knows I exist" contest, and Signal wins nearly every "does it work well" contest. The rest of this page is about whether that trade is worth it for you.

The identity model: number vs Session ID

Everything about Signal starts with your phone number. You register with it, your contacts find you through it, and your account is anchored to it. Signal has softened this over time: usernames let you share an identity that is not your number, and granular settings control who can see the number or find you by it. But the number is still the root of the account. If your threat model includes "my phone number must not be linked to this account," Signal cannot fully satisfy it.

Diagram of the identity models: Signal verifies a phone number, Session uses a random ID
Your identifier is what the network, and other people, use to find you.

Session starts from the opposite end. There is no registration in the normal sense. The app generates a long Session ID, a random string of characters, and that is your identity. No phone number, no email, no name required. You share the ID (or its QR code) with people you want to talk to, and that is the entire onboarding. Nobody, not even the people running the network, can tie your account to a real-world identity unless you give them reason to.

The cost of that freedom is friction. Finding people on Signal is automatic: install it and your contacts appear. On Session, every new contact is a manual exchange of a long, unfriendly string. For a small circle of careful contacts, that is fine. For everyday social life, it is a real barrier, and it is the main reason Session stays niche.

The network model: nonprofit servers vs volunteer nodes

Signal runs on servers operated by Signal Foundation. That centralization is what makes Signal fast and reliable, and it is also the thing privacy purists object to: one organization sits in the middle of everything. Signal's answer is to make the middle know almost nothing. Messages are encrypted blobs the servers cannot read, sealed sender hides who is talking to whom from the servers themselves, and the organization publishes what little it stores. Centralized, but deliberately blind.

Session removes the middle instead of blinding it. Messages are onion-routed through several volunteer-operated nodes, each of which knows only the previous and next hop, so no single node knows both who sent a message and who receives it. There is no central database of users to seize, subpoena, or breach, because there is no center. This is a stronger structural guarantee than Signal's "trust us, we store almost nothing," and for people whose adversary includes state-level actors, structure beats promises.

The cost, again, is practical. Volunteer-run decentralized networks are slower and less reliable than professionally run servers. Messages can take longer to arrive. The network's capacity depends on volunteers. And decentralization does not remove trust entirely; it spreads it across node operators you do not know. Different trust model, not zero trust model.

Privacy compared, honestly

Let us give each side its due without exaggeration.

Where Session is stronger: no identifier means there is no phone number to link, leak, or subpoena. Onion routing means the network cannot easily build a social graph of who talks to whom. There is no central company holding even minimal metadata, because there is no center. If your requirement is "no single party can know I use this or who I talk to," Session is in a different league from Signal, and from nearly every other messenger.

Where Signal is stronger: the Signal Protocol has deeper independent cryptographic scrutiny than Session's protocol work. Signal's sealed sender and minimal-metadata engineering are mature, battle-tested systems. Signal's nonprofit structure and public server code make its claims checkable. And paradoxically, Signal's centralization enables faster security updates and incident response: one professional team can patch the whole network quickly.

Where the comparison is overblown: for most people's actual threat model (curious employers, data brokers, nosy relatives, ordinary criminals), both apps are far beyond sufficient, and the difference between them is theoretical. The practical privacy gap that matters most is not between Signal and Session; it is between either of them and a mainstream app with an advertising business behind it.

Usability compared, honestly

This is where the trade-off bites, and Session's fans sometimes undersell it.

None of this is a criticism of Session's goals. It is the honest price of its architecture. Decentralized, identifier-free messaging is simply harder to make smooth than centralized messaging, and Session is upfront about being the harder choice.

Notifications and battery on Android

This deserves its own section because it is Session's most common real-world complaint. Most Android messaging apps use Google's push system for instant notifications. Session deliberately avoids it, since using Google's push would hand metadata to Google and undermine the point of the app. Instead it maintains its own background connection.

In practice, that means notifications can be delayed or missed, especially on phones with aggressive battery optimization (Xiaomi, Oppo, Vivo, Huawei, and Samsung's sleeping-apps feature are frequent culprits). The fix is the same manual routine every de-Googled app needs: exempt the app from battery optimization, allow background activity, and lock it in the recent-apps list. It works, but it is fiddly, and it is the kind of thing that makes non-technical users give up.

Signal, by contrast, handles notifications well with or without Play Services. On phones with Google services it uses push normally; on phones without them, the website build keeps its own connection and still notifies reliably once battery optimization is tamed. For most people, Signal's notification story is simply less trouble.

Who should pick which

Your situationThe honest pick
You need maximum unlinkability: no number, no centerSession. This is what it was built for, and nothing mainstream matches it.
Journalism, activism, or sensitive workSignal for most; Session if your threat model specifically includes the service provider or your phone number being linked.
Everyday private messaging with real contactsSignal. Easier, faster, better calls, and your contacts are there.
You make a lot of voice/video callsSignal. Session's calling is not in the same league.
You want to disappear from data brokers' graphsSession goes further, but Signal's minimal metadata is already excellent for this.
Non-technical family membersSignal. Session's Session IDs and notification tuning will lose them.
You distrust all centralized services on principleSession. No center to distrust.

A sensible pattern for the careful: Signal as the daily driver for real-world contacts, Session for the handful of relationships where unlinkability matters most. They solve different problems, and running both is not contradictory.

If Signal is your pick and your phone lacks the Play Store, start here: our Signal APK download guide covers getting the official build and verifying it. The APK vs Play Store comparison explains Signal's two official builds.

Frequently asked questions

Does Session need a phone number?

No. Session requires no phone number and no email. You get a randomly generated Session ID, which you share with contacts manually or via QR code.

Is Session more private than Signal?

In terms of unlinkability, yes: no identifier and onion routing through a decentralized network mean no central party holds your social graph. In terms of protocol scrutiny and maturity, Signal's system is more battle-tested. Which matters more depends on your threat model.

Why is Session slower than Signal?

Session onion-routes each message through several volunteer-run nodes, which adds latency. Signal connects directly to professionally run servers. Decentralization costs speed; that is the trade-off.

Can Session and Signal users message each other?

No. They are separate networks with separate protocols. You need the same app as your contact.

Why are my Session notifications delayed?

Session avoids Google's push system for privacy reasons and keeps its own background connection, which aggressive battery optimization can kill. Exempt Session from battery optimization and allow background activity to improve delivery.

Is Session open source?

Yes. Session's clients and protocol work are open source, developed around the Oxen privacy project and stewarded by the Session Foundation.

Related guides