Ask most people which chat app is "the private one" and you'll get three different, confidently wrong answers. All three get lumped together as alternatives to standard SMS, and all three get called secure by someone in every group chat. In reality, they take genuinely different approaches to privacy, and the differences aren't subtle.

Here's what's actually true about each, as of 2026.

The quick verdict

WhatsAppSignalTelegram
Encrypted by defaultYes, all chatsYes, everythingNo, only opt-in "Secret Chats"
Group chats encryptedYesYesNo
Encryption protocolSignal ProtocolSignal ProtocolCustom (MTProto)
Open sourceClient onlyClient and serverClient only
Backups encryptedOpt-in, off by defaultOn-device, passphrase protectedNot for cloud chats
OwnerMetaSignal Foundation (non-profit)Telegram FZ-LLC
Business modelAds/data across MetaDonations, no adsAds, Premium subscriptions
Hide number behind usernameYes (2026)YesYes, longest-standing

If you read one sentence from this article: Telegram is the one most people wrongly assume is the private option. It isn't, by default. Signal is the actual gold standard. WhatsApp sits in the middle, genuinely encrypted but run by an advertising company.

WhatsApp: properly encrypted, run by Meta

WhatsApp's messages, calls and group chats are end-to-end encrypted by default, using the Signal Protocol, the same underlying encryption Signal itself uses. On the core "can someone reading the wire see my messages" question, WhatsApp does the job properly.

Where it gets weaker:

Signal: the actual gold standard

Signal is the reference point every other "secure messenger" gets compared to, and for good reason. Every message, call and group chat is end-to-end encrypted, with no setting to turn it off and no exceptions.

The trade-off is reach, not privacy. Signal has a fraction of WhatsApp's user base, so the honest limitation isn't the app, it's whether the people you need to talk to are actually on it.

Telegram: the one people get wrong

This is the one worth slowing down on, because the gap between Telegram's reputation and its actual defaults is the biggest of the three.

Regular Telegram chats, including every group chat and channel, are not end-to-end encrypted. They're stored on Telegram's servers, encrypted in transit and at rest, but with keys Telegram itself holds. That's a meaningfully different, weaker guarantee than WhatsApp or Signal's default.

Telegram does offer Secret Chats, a genuinely end-to-end encrypted mode. But it's opt-in, buried a couple of taps deep, one-to-one only, and doesn't sync to your other devices. Almost nobody uses it for their day-to-day conversations, which means almost nobody's day-to-day Telegram conversations are end-to-end encrypted.

Telegram also rolled its own encryption protocol, MTProto, rather than using the well-studied Signal Protocol. Cryptographers have repeatedly raised concerns about design choices in MTProto over the years.

Why the reputation, then? Telegram built its name on large public channels, bold content moderation stances, and being the app authoritarian governments try to block, which reads as "privacy-coded" even though the actual chat encryption underneath is the weakest of the three by default.

The one thing all three still have in common

Whichever you pick, there's a detail that doesn't change: all three still require a phone number to create an account. Usernames now let you hide that number from people you talk to, WhatsApp added this in 2026, Signal has offered it since 2024, and Telegram longer still, but the number remains the account's actual foundation. It's still what the provider holds against you, still what a data breach or subpoena would expose, and still the thing tying your "private" messaging account back to your real identity.

We wrote about this in more detail when WhatsApp rolled out usernames: a username is a new front door, but the number is still the foundation the whole house sits on.

Signal, minus the phone number problem

You pick Signal for its encryption, correctly. You still register it with your real mobile number, the one your bank and your contacts have. If that number ever leaks, or a contact you'd rather forget has it saved, it can still be used to find or message you, regardless of how good Signal's encryption is.

The practical fix, whichever app you choose

The encryption comparison above genuinely matters, and if you can get the people you talk to onto Signal, do it. But no chat app's encryption protects the one identifier all three still demand at sign-up. For that, the fix is the same regardless of which app wins the privacy argument: register with a private secondary number instead of your real one.

Privify gives you a genuine UK number that works exactly like a normal mobile, register WhatsApp, Signal or Telegram with it, and every call or text still reaches you, forwarded straight to your inbox. Your real number stays reserved for people who already have it. Get your number from £6.99/month →

The bottom line

Signal is the clear privacy winner: encrypted by default, minimal metadata, open source, no data business model. WhatsApp is genuinely encrypted but run by an advertising company, with unencrypted backups unless you switch that on yourself. Telegram's privacy reputation outruns its defaults by the widest margin of the three, your regular chats there are not end-to-end encrypted unless you specifically go looking for Secret Chats.

Whichever you land on, the number you register it with is still worth protecting separately from the app itself.

Keep your number out of it

Register any messaging app with a private UK number instead of your real one. Calls and texts forwarded straight to your inbox.

Get your Privify number →