End-to-end encryption, explained without the hand-waving
What the term actually promises, what it does not cover, and why "encrypted" on a marketing page can mean almost nothing.
"Encrypted" is the most overused word in messaging. Almost every service uses it, and it means dramatically different things depending on who is saying it. The distinction is not academic. It determines who can read your messages.
Two different promises
Encryption in transit
Your message is encrypted between your device and the company's server, and again between their server and the recipient. In the middle, on the server, it is decrypted.
The company can read it. Their employees can, under whatever internal controls exist. Anyone who compromises the server can. Anyone who compels the company legally can.
This is genuinely valuable, since it stops interception on the network, and it is what most services mean by "encrypted".
End-to-end encryption
Your message is encrypted on your device with a key the server never possesses, and can only be decrypted by your recipient's device. It passes through the company's infrastructure as data they cannot read.
The company cannot read it. Not through internal misuse, not after a breach, not under a court order. Not because they promise, but because the mathematics does not permit it.
If a service can show you your message history on a new device without you providing anything, that history was not end-to-end encrypted.
That test is a useful shortcut. Genuine E2EE means the server cannot reconstruct your messages, so restoring history requires a key that only you hold.
Where the messengers actually stand
| Service | In transit | End-to-end |
|---|---|---|
| SMS | Radio link only | No, the carrier holds plain text |
| Yes | Yes, by default | |
| Telegram | Yes | Only in "secret chats", not normal ones |
| Discord | Yes | No |
| Slack | Yes | No |
The Telegram row surprises people. Telegram is widely described as an encrypted messenger, and it is, but only in transit. Its default chats are readable on Telegram's servers, and that is what makes cross-device sync and cloud history work. Secret chats are end-to-end encrypted, single-device, and off by default.
None of that is a scandal. It is a trade-off between convenience and confidentiality, and it is a legitimate one to make. It just is not what most people assume they have.
What E2EE does not protect
Even perfect end-to-end encryption leaves several things exposed, and vendors tend to be quiet about them.
- Metadata. Who you messaged, when, how often, from where. This is frequently more revealing than content, and it is generally not encrypted.
- The endpoints. Your phone holds decrypted messages. Someone with your unlocked device reads everything, and no protocol prevents that.
- Backups. An E2EE messenger backing up to an unencrypted cloud has handed the plain text to a third party. This has been the single most common real-world failure.
- The recipient. They can screenshot, forward or simply show someone. Encryption protects the channel, not the audience.
The part we control
Textly does not create encryption where a protocol has none. WhatsApp messages stay end-to-end encrypted, and Textly never touches that: WhatsApp decrypts them on your phone exactly as before, and Textly reads the result from the notification without ever contacting WhatsApp. Telegram, Discord and Slack are exactly as private as those services make them. SMS has no end-to-end encryption at all, and no app can change that.
What we control is your device. The local message database and every channel credential sit behind Android's hardware-backed keystore, tied to your screen lock, because in practice the copy on your phone is the one an attacker actually reaches.
And the intelligence that reads your messages runs locally, which means understanding them never requires decrypting them anywhere else. That is not a marketing claim about encryption. It is the absence of a place where decryption would otherwise have to happen.
Textly brings WhatsApp, Telegram, Discord, Slack and Android SMS into one inbox, and understands it on your device rather than ours.
Get Textly