Signal is a nonprofit that genuinely cannot read your messages or listen to your calls — the encryption is architectural, not a promise — but it requires a real phone number to register, is subject to US law, and its privacy policy is conspicuously sparse: it hasn't been substantively updated since 2018 and lacks the specific retention periods, GDPR rights, or DPO contact that more thorough policies provide.
No known public data breaches
Signal does not appear in the Have I Been Pwned database of publicly disclosed data breaches.
See all Messaging privacy grades →
Display Signal's privacy grade on your own site. The badge links back to this analysis page.
<iframe src="https://privacy-decoded.com/badge/signal" width="240" height="72" frameborder="0" scrolling="no" title="Signal Privacy Grade — Privacy Decoded" ></iframe>