What WhatsApp Collects That Signal Doesn't

Published: October 7, 2026 · Updated: October 8, 2026

Both WhatsApp and Signal encrypt the contents of your messages end to end, so neither company can read what you write. The real difference between them is everything around the messages: who you talk to, when, from which device, and how that information is stored and used. WhatsApp's privacy policy lists broad categories of data it collects. Signal publishes how little it keeps. This page compares only what is documented, no smear, no invented specifics.

Download the official Signal APK

from Signal’s official site — file hosted by Signal, not by us

Illustration comparing two data profiles: WhatsApp's full one against Signal's minimal one

Start with what is the same

Before the differences, the similarity that matters most: both apps use end-to-end encryption for message contents, and both use the Signal Protocol family to do it. WhatsApp adopted the protocol years ago, and its message content is not readable by Meta's servers in transit. So if your only question is "can the company read my texts," the answer is no for both, by design, not by promise.

This is exactly why comparisons that stop at encryption miss the point. Encryption answers one question: who can read the words? Data collection answers a different one: what does the company know about your life around the words? That second question is where the two apps diverge sharply, and it is the whole subject of this page.

What WhatsApp says it collects

Checklist graphic of the data WhatsApp says it collects in its privacy policy
None of this is secret. It's in the policy most people never open.

WhatsApp's privacy policy describes the data it collects in broad categories. In plain language: account information (your number, profile details), device and connection information (device identifiers, operating system, connection details), and usage information (how and when you use the service, including messaging patterns like who you communicate with and when). The policy also covers information shared with other Meta companies, since WhatsApp is part of Meta's family of apps.

Two points of honesty here. First, these are the categories WhatsApp itself discloses, this is not speculation, it is their own published policy. Second, collecting metadata is not the same as reading messages. WhatsApp's position is that message contents stay encrypted; the data business is everything around them. Whether that distinction satisfies you is a personal call, but the distinction itself is real and worth keeping clear.

What Signal stores

Signal's side of the ledger is short, and that is the point. The organization has said publicly that it stores your phone number, the profile information you choose to set, your account registration date, and the date you last connected. That is essentially the whole list. No message contents, no contact lists, no logs of who you called or when.

The strongest evidence for this is not a policy document but Signal's published responses to legal data requests. When compelled to hand over user data, the company has consistently produced only basic account dates, because there is nothing else to produce. A privacy policy is a promise about the future. An architecture that never collected the data in the first place is a fact about the past. Signal's design is the second kind, and that is a meaningful difference from any policy-based promise.

Side-by-side comparison

Comparison table of WhatsApp versus Signal data collection practices
Same encryption on messages. Very different appetites for metadata.

Here is the comparison kept strictly to what is documented on each side.

Data categoryWhatsAppSignal
Message contentsEnd-to-end encrypted; not readable by the serviceEnd-to-end encrypted; not readable by the service
Who you talk to and whenCollected as usage information, per its privacy policyNot stored; sealed sender also hides the sender from servers
Device and connection infoCollected, per its privacy policyMinimal: registration and last-connection dates
Your contact listUploaded to find contacts (standard address-book matching)Checked via private contact discovery, designed not to retain it
Data sharing with parent companyShared with Meta companies, per its privacy policyNo parent company; nonprofit structure, no ad business
Business model using your dataAdvertising-driven parent companyDonations and grants; nothing to sell
Open source clientsNoYes, see the open source guide

Read the table's first row again: identical. Every row below it is where your privacy actually lives.

Backups: the honest caveat

One more documented difference deserves its own section because it surprises people. WhatsApp offers chat backups to cloud storage, which is convenient. Historically those cloud backups were not end-to-end encrypted, so message contents could sit readable on a cloud provider's servers. (WhatsApp has since added an optional encrypted-backup feature; the key word is optional, and it has to be turned on.) Signal, by contrast, keeps backups local to your device, encrypted with a passphrase you control. There is no cloud copy of your chats to subpoena, breach, or misconfigure.

The lesson generalizes: encryption of messages in transit is only one surface. Where the messages rest, on servers, in clouds, on devices, is a separate question, and the two apps answer it very differently.

Why metadata matters

People dismiss metadata with "it's just who and when," as if that were harmless. Think about what a log of who-you-talk-to-and-when actually reveals over months: your close relationships, your work hours, your sleep schedule, when something urgent happened in your life, which groups you belong to. Intelligence agencies have a saying that content tells you what was said and metadata tells you everything else. You do not need the words of a conversation to learn a great deal from its shape.

This is why Signal's minimalism is not a minor detail. Encryption protects the words; minimal metadata collection protects the shape of your life. WhatsApp gives you the first and keeps the second. Signal is designed to keep both, which is the honest core of the is-Signal-really-private question answered at length.

What this comparison cannot verify

An honest limitation of this page: half of it is checkable and half is not. Everything said about Signal can be verified against public code, the clients are open source, the server code is published, and the data-minimization claims have been tested in public legal proceedings. Everything said about WhatsApp rests on its published privacy policy and public statements, because WhatsApp's clients are closed source. Nobody outside Meta can read the code and confirm the policy matches the software.

This asymmetry matters more than it looks. A privacy policy is a promise about the future, written by lawyers, changeable at any time. An architecture that never collected the data is a fact about the past. When you compare the two apps, you are not just comparing two lists of data categories, you are comparing a verifiable design against a documented promise. Both have value, but they are different kinds of evidence, and a careful reader should weigh them differently.

None of this is an accusation. WhatsApp's encryption of message contents is real and widely deployed, and that protects billions of conversations every day. The point is epistemic, not moral: with Signal you can check, with WhatsApp you must trust. Decide how much that difference is worth to you.

Which should you pick?

No smear, just the trade-off as it stands. Choose WhatsApp if your priority is reaching everyone, it is where the people are, the encryption of contents is real, and for casual conversation that is enough for most people. Choose Signal if your priority is keeping the service itself out of your life. That means minimal metadata, no advertising business on the other end, open code you can inspect, and a design where the company cannot hand over what it never collected.

Many people end up using both: WhatsApp for the contacts who will never switch, Signal for everything sensitive. That is a reasonable answer too. Privacy is rarely one app; it is matching the tool to the conversation. For the full head-to-head beyond data collection, the Signal vs WhatsApp comparison covers features, calls, and groups.

Frequently asked questions

Does WhatsApp read my messages?

No, WhatsApp encrypts message contents end to end, so the company cannot read what you write. The privacy difference from Signal is in metadata: who you talk to, when, and device data, which WhatsApp collects per its own privacy policy.

What data does Signal collect compared to WhatsApp?

Far less. Signal has said publicly it keeps your number, profile info, registration date, and last-connection date, no message contents, no contact lists. WhatsApp's policy lists account, device, and usage data categories, plus sharing with Meta companies.

Is Signal really more private than WhatsApp?

For privacy from the service itself, yes. Both encrypt message contents, but Signal is designed to minimize metadata too, has no advertising business, and its clients are open source.

Are WhatsApp backups private?

WhatsApp offers cloud chat backups; it has added an optional encrypted-backup feature, but it must be turned on. Signal keeps backups local on your device, encrypted with your passphrase, no cloud copy exists.

Can I use both apps?

Yes, and many people do: WhatsApp for contacts who won't switch, Signal for sensitive conversations. Match the tool to the conversation rather than treating it as all-or-nothing.

Keep reading