How Aphotic compares
Signal, Telegram, Threema, Session and the peer-to-peer messengers such as Briar are all serious projects. This page looks at what each one guarantees by the way it is built, and at the few things only Aphotic does.
How we did this: we compare only what each app guarantees by the way it is built and leave its advertising claims out. Every mark in the table can be checked against public documentation, and the sources are listed underneath.
Checked in August 2026 against public documentation, with the sources listed under the table. Spot something out of date? Tell us and we will correct it in the open. Report an error →
Five verdicts
Signal
The reference everyone else gets measured against: open source, run by a US non-profit. It is tied to your phone number, though, and it connects over the ordinary internet, so the servers can see where you are.
→ Choose Aphotic if you want to hand over nothing at all, or want the server itself hidden behind Tor and the sender hidden on every direct text message, including the first one from a stranger.
Telegram
A messenger packed with features and enormous groups, where the company can read your ordinary chats. Only the chats it calls secret chats are encrypted end to end.
→ Choose Aphotic if you want everything encrypted end to end without switching anything on, and no sender on the envelope of a direct text message.
Threema
A mature paid messenger from Switzerland that lets you have an anonymous ID. The connection underneath is ordinary, though, so the servers still see your IP address.
→ Choose Aphotic for everything over Tor, senders hidden by default, a Monero payment that cannot be traced to your chat identity, and a vault built for the day somebody makes you unlock your phone.
Session
The closest neighbour in spirit: no phone number, onion-routed by default, spread over many independent nodes. To get there it gave up the protection that keeps old messages safe if your keys are ever stolen.
→ Choose Aphotic if you want keys that keep moving, so a break-in today does not open yesterday and the conversation repairs itself afterwards. You also get self-deleting messages the server cannot interfere with, and a panic PIN.
Peer-to-peer messengers such as Briar
There is no server anywhere. Each phone runs its own Tor onion service and talks straight to the other phone, and the apps are free and open source, with a Bluetooth mesh for the days the internet is down. Nothing exists to seize, subpoena or shut down. The price is that both phones have to be online at the same moment for a message to arrive, unless you run your own always-on mailbox device, and the onion address you connect from is your identity, so the device on the other end knows exactly who reached it.
→ Choose Aphotic if a message has to arrive while the other phone is switched off, held encrypted on our own servers in the EU for up to seven days, with sealed sender so the relay never learns who sent it. You also get groups under one shared key that scale to 5,000 people, where a removed member is removed by the encryption itself.
The comparison table
Identifier required
- Aphotic
- None (random ID)
- Signal
- Phone number
- Telegram
- Phone number
- Threema
- None (random ID)
- Session
- None (derived ID)
- Peer-to-peer (Briar)
- None; your device's onion address is the identity
Transport
- Aphotic
- Tor only, hidden service
- Signal
- TLS to central servers
- Telegram
- TLS to cloud DCs
- Threema
- TLS to Swiss servers
- Session
- Onion-routed (Lokinet)
- Peer-to-peer (Briar)
- A Tor onion service on each phone, device to device, plus a Bluetooth mesh when the internet is down
Offline delivery
- Aphotic
- Held encrypted on the relay for up to 7 days
- Signal
- Queued on the server until you reconnect
- Telegram
- Kept in the cloud
- Threema
- Queued on the server until delivery
- Session
- Held by the storage nodes for a limited window
- Peer-to-peer (Briar)
- Both phones have to be online at the same moment, unless you run your own always-on mailbox device
Jurisdiction & exposure
- Aphotic
- No ordinary web address; our own servers in the EU
- Signal
- US nonprofit; centralized clearnet servers
- Telegram
- Dubai HQ; closed-source server, distributed DCs
- Threema
- Swiss company; own data centre in Zurich
- Session
- Decentralized node swarm; no central servers
- Peer-to-peer (Briar)
- No servers at all, and no company running them
What a subpoena yields
- Aphotic
- Public keys, group membership and unreadable data; the message queue clears after 7 days. No signup or last-seen times
- Signal
- Registration date + last-connection date¹
- Telegram
- Ordinary chats: the messages themselves, on a valid request
- Threema
- ID creation date, hash of linked phone/email if any²
- Session
- Nothing central to serve; nodes hold ciphertext briefly
- Peer-to-peer (Briar)
- There is nobody to serve it on. An order goes to the person holding a phone
E2EE by default
- Aphotic
- Always
- Signal
- Always
- Telegram
- Secret chats only³
- Threema
- Always
- Session
- Always
- Peer-to-peer (Briar)
- Always
Sender metadata
- Aphotic
- Sealed sender by default
- Signal
- Sealed sender, partly opt-in⁴
- Telegram
- Yes, the operator sees it
- Threema
- Visible, minimal retention
- Session
- No, hidden by onion routing
- Peer-to-peer (Briar)
- The device you reach sees which identity connected, and no server sits in between to see anything
Forward secrecy
- Aphotic
- Triple Ratchet (Double + PQ)
- Signal
- Triple Ratchet (Double + PQ)
- Telegram
- Secret chats only
- Threema
- Yes (Ibex)
- Session
- No, given up to allow several devices⁵
- Peer-to-peer (Briar)
- A ratchet per message, over a per-contact root key that stays the same across reconnects
Post-quantum key agreement
- Aphotic
- Hybrid PQXDH + continuous PQ ratchet
- Signal
- Hybrid PQXDH + continuous PQ ratchet⁶
- Telegram
- No
- Threema
- No
- Session
- No
- Peer-to-peer (Briar)
- Hybrid ML-KEM-768 with X25519 when you pair
Disappearing messages
- Aphotic
- Direct messages, 30 s to 7 days, timer sealed inside the message
- Signal
- Yes, incl. groups
- Telegram
- Secret chats / cloud timers
- Threema
- Limited
- Session
- Yes
- Peer-to-peer (Briar)
- Yes
Anonymous payment
- Aphotic
- Yes. The purchase cannot be traced to your chat identity
- Signal
- n/a (free, donations)
- Telegram
- Premium tied to account
- Threema
- On Android, yes: the Threema Shop takes Bitcoin or cash by post. App-store purchases run under your billing name
- Session
- n/a (free)
- Peer-to-peer (Briar)
- n/a (free)
Business model
- Aphotic
- You buy a license with crypto. Nothing is made from your data
- Signal
- Non-profit, donations
- Telegram
- Premium + ads
- Threema
- One-time paid app
- Session
- Free, token-incentivized nodes
- Peer-to-peer (Briar)
- Free and GPL, with no company in the loop
Group size
- Aphotic
- 20 per group, encrypted for each member; Communities up to 5,000
- Signal
- 1,000
- Telegram
- 200,000 (no E2EE)
- Threema
- ~256
- Session
- ~100
- Peer-to-peer (Briar)
- Small groups. Your phone sends a copy to each member, every member has to be one of your own contacts, and there is no shared group key, so removing someone rests on the other members obeying it
Calls
- Aphotic
- No calls. Voice messages instead, because a live call gives away the timing
- Signal
- Voice + video, groups
- Telegram
- Voice + video
- Threema
- Voice + video
- Session
- Limited
- Peer-to-peer (Briar)
- Briar has none; some forks add them
Multi-device
- Aphotic
- One device on purpose. Your keys never exist in two places
- Signal
- Native linking
- Telegram
- Full cloud sync
- Threema
- Yes (leader device)
- Session
- Seed-based restore
- Peer-to-peer (Briar)
- One device, because the identity is that device's onion address
Platforms
- Aphotic
- Android only
- Signal
- iOS, Android, desktop
- Telegram
- Everything + web
- Threema
- iOS, Android, desktop
- Session
- iOS, Android, desktop
- Peer-to-peer (Briar)
- Android, and a desktop client
| Aphotic | Signal | Telegram | Threema | Session | Peer-to-peer (Briar) | |
|---|---|---|---|---|---|---|
| Identifier required | None (random ID) | Phone number | Phone number | None (random ID) | None (derived ID) | None; your device's onion address is the identity |
| Transport | Tor only, hidden service | TLS to central servers | TLS to cloud DCs | TLS to Swiss servers | Onion-routed (Lokinet) | A Tor onion service on each phone, device to device, plus a Bluetooth mesh when the internet is down |
| Offline delivery | Held encrypted on the relay for up to 7 days | Queued on the server until you reconnect | Kept in the cloud | Queued on the server until delivery | Held by the storage nodes for a limited window | Both phones have to be online at the same moment, unless you run your own always-on mailbox device |
| Jurisdiction & exposure | No ordinary web address; our own servers in the EU | US nonprofit; centralized clearnet servers | Dubai HQ; closed-source server, distributed DCs | Swiss company; own data centre in Zurich | Decentralized node swarm; no central servers | No servers at all, and no company running them |
| What a subpoena yields | Public keys, group membership and unreadable data; the message queue clears after 7 days. No signup or last-seen times | Registration date + last-connection date¹ | Ordinary chats: the messages themselves, on a valid request | ID creation date, hash of linked phone/email if any² | Nothing central to serve; nodes hold ciphertext briefly | There is nobody to serve it on. An order goes to the person holding a phone |
| E2EE by default | Always | Always | Secret chats only³ | Always | Always | Always |
| Sender metadata | Sealed sender by default | Sealed sender, partly opt-in⁴ | Yes, the operator sees it | Visible, minimal retention | No, hidden by onion routing | The device you reach sees which identity connected, and no server sits in between to see anything |
| Forward secrecy | Triple Ratchet (Double + PQ) | Triple Ratchet (Double + PQ) | Secret chats only | Yes (Ibex) | No, given up to allow several devices⁵ | A ratchet per message, over a per-contact root key that stays the same across reconnects |
| Post-quantum key agreement | Hybrid PQXDH + continuous PQ ratchet | Hybrid PQXDH + continuous PQ ratchet⁶ | No | No | No | Hybrid ML-KEM-768 with X25519 when you pair |
| Disappearing messages | Direct messages, 30 s to 7 days, timer sealed inside the message | Yes, incl. groups | Secret chats / cloud timers | Limited | Yes | Yes |
| Anonymous payment | Yes. The purchase cannot be traced to your chat identity | n/a (free, donations) | Premium tied to account | On Android, yes: the Threema Shop takes Bitcoin or cash by post. App-store purchases run under your billing name | n/a (free) | n/a (free) |
| Business model | You buy a license with crypto. Nothing is made from your data | Non-profit, donations | Premium + ads | One-time paid app | Free, token-incentivized nodes | Free and GPL, with no company in the loop |
| Group size | 20 per group, encrypted for each member; Communities up to 5,000 | 1,000 | 200,000 (no E2EE) | ~256 | ~100 | Small groups. Your phone sends a copy to each member, every member has to be one of your own contacts, and there is no shared group key, so removing someone rests on the other members obeying it |
| Calls | No calls. Voice messages instead, because a live call gives away the timing | Voice + video, groups | Voice + video | Voice + video | Limited | Briar has none; some forks add them |
| Multi-device | One device on purpose. Your keys never exist in two places | Native linking | Full cloud sync | Yes (leader device) | Seed-based restore | One device, because the identity is that device's onion address |
| Platforms | Android only | iOS, Android, desktop | Everything + web | iOS, Android, desktop | iOS, Android, desktop | Android, and a desktop client |
- 1Signal's published record of government requests: the only account data it can produce is the date the account was registered and the date it last connected. signal.org/bigbrother/
- 2Threema's transparency report lists what it can hand over: when the ID was created, when it last logged in, and a scrambled form of any linked phone number or email address. threema.com/en/transparency-report
- 3Telegram's own FAQ: end-to-end encryption covers secret chats and calls. Ordinary chats are encrypted only between your phone and Telegram's servers, which means Telegram can read them. telegram.org/faq#q-how-are-secret-chats-different
- 4Signal's own announcement of sealed sender: on by default between saved contacts, while accepting it from strangers is a setting you have to switch on. signal.org/blog/sealed-sender/
- 5Session's whitepaper describes the deliberate move to long-lived keys, giving up the per-message protection in exchange for working on several devices and delivering while you are offline. arxiv.org/abs/2002.04609
- 6The PQXDH specification, which both Aphotic and Signal implement, is public. signal.org/docs/specifications/pqxdh/
- 7Briar's own documentation on how messages travel: phone to phone over Tor, Wi-Fi or Bluetooth, with an optional mailbox device you host yourself for delivery while a contact is offline. briarproject.org/how-it-works/
Built to leave the smallest possible data trail
Every design decision above serves that goal. If it's your goal too, it takes one license key to start.