GuideHQ

What does end-to-end encryption actually protect?

It protects the message in transit and at the service in the middle. It does not protect the phone at either end, the backup, who you talked to, or anything the other person does with what you sent — and those are where things usually go wrong.

Difficulty
beginner
Time
20 min
Read
8 min

Short answer

End to end means only the sending device and the receiving device can read the content — the company carrying it holds only scrambled data and cannot hand over what it cannot read. That is a genuine and significant protection. What it does not cover: anyone who can unlock either phone, an unencrypted backup, the record of who messaged whom and when, and screenshots. If you are relying on it, the weak point is the backup or the device, not the encryption.

End-to-end encryption is the most frequently used and least understood phrase in consumer security. People treat it either as making a conversation completely private, which it does not, or as marketing, which it is not. The plain version: the message is scrambled on your device with a key that only the recipient's device can undo, so every system it passes through on the way — including the company that built the app — carries something it cannot read. That is a real change and it is why it is worth choosing. Knowing precisely where its protection stops is what turns it from a comfort into something you can actually rely on.

Where end-to-end encryption starts and stops

Step by step

  1. Understand what is being protected and from whom.The content of the message, from everyone between the two devices. That includes the network you are on, your broadband provider, anyone intercepting the traffic, and the company running the service. Without it, the service holds a readable copy, which means it can be searched, leaked in a breach, or produced in response to a legal demand. With it, there is nothing readable to produce.
  2. Know that metadata is a separate question, and it is not protected.Who you messaged, when, how often, from roughly where, and how large the message was. Different services collect very different amounts of this and it is where they genuinely differ. A service can carry perfectly encrypted content while keeping a detailed record of every conversation you have had, and for some purposes that record is more revealing than the words.
  3. Recognise that the ends are the weak points, and they are yours.Encryption protects the middle. It does nothing about someone who can unlock your phone, someone standing behind you, an app with screen access, or the recipient forwarding what you sent. Almost every real-world failure is one of these rather than a defeat of the encryption, which is why the catalogue's guides on phone passcodes and on who has access to your phone matter more than the choice of app.
  4. Look hard at the backup, because it is the usual leak.A conversation is encrypted in transit and then frequently saved to a cloud backup that is not encrypted in the same way. If that backup can be read by the cloud provider, the protection has been undone at the last step. Both major messaging apps now offer an encrypted backup option and it is not always on by default. This is the single most valuable setting in this guide, and the fewest people have looked at it.
  5. Know which everyday services have it and which do not.Ordinary text messages do not — SMS was never designed for it. WhatsApp and Signal are end-to-end encrypted for all messages and calls by default. Apple's own messages between Apple devices are; the green-bubble ones are not. RCS between Android users in Google Messages is. Email, in ordinary use, is not. Most social media direct messages are not by default. The catalogue's RCS guide covers the messaging distinction in detail.
  6. Understand cloud storage separately from messaging.Files in cloud storage are usually encrypted in transit and on the provider's disks, with the provider holding the keys — which protects against theft of the hardware and not against the provider. Some services offer an additional mode where only you hold the key. That is stronger and it has a real cost: lose your recovery method and the files are gone permanently, with nobody able to help.
  7. Judge a service by defaults rather than capability.The question is not whether an app can be encrypted but whether your conversations are, without you doing anything. Some well-known apps encrypt only in a special mode that must be started per conversation, which almost nobody does. Default-on is the property worth choosing.
  8. Verify the other end when it genuinely matters.Every serious implementation offers a way to check that you are talking to the person you think — a code or a set of numbers to compare over another channel. Nobody does this routinely and nobody needs to. For a genuinely sensitive conversation with someone you have never met in person, it is the step that closes the last gap.
  9. Be realistic about what it means for law enforcement.A properly implemented service cannot produce message content it does not hold, and that is the point of the design. It can still be required to produce account details and metadata, and none of it protects a device that has been seized and unlocked. The public debate about lawful access concerns the design of these systems and does not change what a given app does today.

Common mistakes

  • Assuming encrypted means private — It means unreadable in transit. Who you spoke to, when, and what happens on either device are all outside it, and those are where information actually escapes.
  • Using an encrypted app and leaving an unencrypted backup on — It hands over in the last step exactly what the app spent the whole conversation protecting. Check the backup setting; it is the highest-value five minutes here.
  • Believing a padlock icon on a website means the same thing — It means the connection to that site is encrypted, so nobody in between can read it. The site at the far end can read everything, and that is a completely different arrangement.
  • Thinking a VPN provides it — A VPN encrypts traffic between you and the VPN provider, and beyond that the traffic continues normally. It changes who can see your connections; it does not make an unencrypted message encrypted.
  • Relying on it while the phone has no passcode worth the name — Every message is readable to anyone who can unlock the device. The screen lock is the front door, and the catalogue's guide on phone theft explains what happens when someone has the key to it.

If it doesn't work

You want to know whether a specific conversation is encrypted

Cause: It varies by app and by who you are talking to — Fix: Most apps state it in the conversation's information screen or with a notice at the top of the thread. On an iPhone, bubble colour is the quickest indicator. If the app does not tell you, assume it is not.

You use an encrypted app but back up to the cloud

Cause: The backup is a separate, often unencrypted, copy — Fix: Turn on the app's own encrypted backup option and store the key or passphrase somewhere safe. Without it, the backup is the readable copy of everything you thought was private.

Messages appear on a device you did not expect

Cause: A linked device, or a shared account — Fix: Encryption protects against outsiders, not against another device you have authorised. Check each app's linked-device list and your account's device list, and remove what should not be there.

You want privacy from a company but keep using its email

Cause: Email is not end to end encrypted in ordinary use — Fix: Do not send anything through email that you would mind the provider being able to read. For a genuinely private exchange, move to a messaging app that is encrypted by default.

A file in cloud storage needs to be private from the provider

Cause: Standard cloud storage encryption keeps the key with the provider — Fix: Either turn on the provider's advanced mode where one exists, or encrypt the file yourself before uploading — the catalogue's guide on password-protecting a document covers the simple version. Understand that you become solely responsible for recovery.

Someone forwarded a message you sent in confidence

Cause: Nothing technical failed — Fix: Encryption protects the message from third parties, not from the recipient. Disappearing messages raise the effort slightly and do not prevent a screenshot. This is a trust decision rather than a technology one.

Questions people ask

Are ordinary text messages encrypted?

No. SMS predates all of this and its contents are visible to the mobile networks carrying it. This matters more than it sounds, because one-time security codes are routinely sent by text — which is part of why the catalogue recommends an authenticator app over text codes.

Is WhatsApp really encrypted, given who owns it?

The message content is, by default, using a widely reviewed protocol. The reasonable concerns are about metadata — who you talk to and when — and about backups, both of which are outside the encryption. Judge it on those rather than on whether the encryption is genuine.

What is the difference between encrypted at rest and end to end?

Encrypted at rest means the provider stores it scrambled on its disks and holds the key, which protects against someone stealing the hardware. End to end means the provider does not hold the key at all. Most cloud storage is the first; good messaging is the second.

Should I use a disappearing message setting?

It is useful for reducing what accumulates on both devices, and it is not a control. The recipient can screenshot, photograph the screen, or copy the text. Treat it as tidying rather than as security.

Does any of this protect me from someone with my unlocked phone?

No, and that is the most important sentence here. Everything is readable to anyone holding an unlocked device. Screen lock, biometrics and the theft protections are the layer that actually matters day to day.

What to do next

Sources

  • NCSC guidance on end-to-end encryption and on what it does and does not protect for individuals
  • Published technical documentation for the Signal protocol and the messaging services that implement it, including their stated positions on metadata and backups
  • Apple and Google support documentation on encrypted messaging, encrypted chat backups and advanced cloud data protection options

Written and maintained by the GuideHQ editorial team. More in Technology.