SMS was never private, and what that actually means for you
Text messages travel in the clear through infrastructure built in the 1980s. That is not a scandal, but it should change what you send.
SMS is the most widely supported messaging system on earth. Every phone has it, no account is required, and it works when nothing else does. It is also, by any modern standard, completely unprotected.
This is worth understanding precisely, because the useful conclusion is not "stop using SMS". It is "know which messages belong somewhere else".
What actually happens when you send a text
Your message leaves your phone over the mobile network, reaches your carrier's messaging centre, gets routed to the recipient's carrier, and is delivered. At several of those points it exists as readable text, and it is stored: for delivery retries, for billing, and for whatever retention period the law and the carrier require.
There is no end-to-end encryption anywhere in that chain. There was never meant to be: SMS was specified in the 1980s as a way to use spare signalling capacity, and confidentiality was not a design goal.
Who can read your texts
Being concrete is more useful than being alarming.
- Your carrier and the recipient's carrier. They handle the message in plain text and retain it for a period.
- Law enforcement with legal process. Access to stored messages is a routine and well-established procedure in most jurisdictions.
- Anyone who compromises the network. SS7, the signalling protocol underpinning international routing, has known weaknesses that have been demonstrated repeatedly.
- Anyone holding your unlocked phone. Usually the most realistic risk on this list.
Notably absent: random people nearby. The link between your phone and the tower is encrypted. SMS interception is not something a stranger in a café does.
What this means in practice
Treat SMS roughly the way you would treat a postcard: fine for most things, wrong for a few specific ones.
Reasonable over SMS: delivery notifications, appointment reminders, "running ten minutes late", the vast majority of everyday coordination.
Better somewhere encrypted: passwords and access codes, financial details, medical information, anything you would not want read out in a room you are not in.
The two-factor problem
The exception worth knowing about: SMS is still the most common second factor for logging in, and it is the weakest one in common use. SIM-swap attacks, where someone convinces your carrier to move your number to their SIM, are not exotic. They are a service you can buy.
If an account matters, move its second factor to an authenticator app or a hardware key. SMS 2FA is better than no 2FA, and worse than everything else.
Encryption on the wire and encryption at rest are different problems. SMS has none in transit. But the copy sitting in your phone can absolutely be protected, and on most devices that copy is the one an attacker will actually get at.
Where Textly sits in this
We cannot fix SMS. Nobody can; it would require replacing global carrier infrastructure. Any app claiming to make your texts end-to-end encrypted is either describing a different protocol or misleading you.
What we can control is the part on your device. The local message store is encrypted behind Android's hardware-backed keystore, tied to your screen lock. Nothing is copied to a server, because we do not run one. And the intelligence that reads your messages runs locally, so understanding them never requires transmitting them.
That is the honest division of responsibility: the carrier owns the wire, and we own the device. We take the part we own seriously, and we do not pretend to own the rest.
Textly brings WhatsApp, Telegram, Discord, Slack and Android SMS into one inbox, and understands it on your device rather than ours.
Get Textly