PRIVACY REPORT:
Why We Do Not Recommend the Signal “Privacy” App
I want to be clear up front: this decision to remove Signal from our list of recommended privacy apps is not based on some over‑zealous, purist view of privacy.
The concerns I’ve uncovered are serious enough that my conclusion is simple:
Do not use Signal for anything that genuinely requires privacy.
Context: OS Upgrades, Broken Apps, and Spyware
I recently upgraded my Mac from Catalina to Ventura because most of my apps had simply stopped working. I delayed that upgrade as long as possible for two reasons:
- Stability and breakage
There was a time when everything on a Mac “just worked”. We’re well past that. These days every major OS update seems to break more things, kill more apps, and risk data loss. - Privacy erosion at the OS level
macOS has gone from being relatively good on personal privacy to racing Microsoft for the title of “worst spyware OS”. With each release, the amount of telemetry, lock‑in and baked‑in surveillance gets worse.
(For the record: I’m moving to Linux. I already have a Linux system next to me that will replace my old Mac desktop as soon as it’s ready to fully take over.)

I recently had to re-install Signal on my Desktop and was forced to verify it on a mobile device which was already annoying. I shocked to see this message popup when installing Signal on my de-googled phone.
My Research Into Signal
I started looking into Signal with four major concerns that, in my view, immediately disqualified it as a true Digital Freedom technology.
At that point, I still thought Signal might qualify as a Level 2 – “Privacy‑focused on legacy platforms” in our Trust Ranking framework.
But those 4 concerns turned into 5 groups of 13 specific concerns once I dug deeper.
The result:
We have moved Signal from Level 2 down to Level 4 in our Trust Ranking Scoreboard and removed it entirely from our list of recommended privacy apps.
| Score Range | Level | Color | Label | Summary |
|---|---|---|---|---|
| 81–99 | L1 | 🟦 Blue | Digital Freedom Technology | Requires P1–P4. Sovereign stack with no Big Tech or centralized control. |
| 61–80 | L2 | 🟩 Green | Privacy-Focused on Legacy Platforms | Privacy-strong, FOSS-based, but hosted within or distributed through centralized platforms. |
| 41–60 | L3 | 🟨 Yellow | Neutral / Unknown | Lacks strong evidence either for or against digital freedom. Often semi-proprietary, privacy-ambiguous, or under-documented. |
| 21–40 | L4 | 🟧 Orange | Part of Big Tech Ecosystems | Relies on closed, centralised systems or cloud infrastructure. Standard commercial behavior. |
| 0–20 | L5 | 🟥 Red | Hostile to Digital Freedom | Built for surveillance, profiling, lock-in. Should be avoided entirely in privacy-respecting environments. |
In plain language:
Signal is now on our “do not use for real privacy” list,
only marginally more trustworthy than WhatsApp.
PRIVACY CONCERNS:
Concerns Regarding Signal Messenger
1. Identity, Metadata, and Centralization
2. Governance, Institutions, and Culture
3. Platform Dependence and Device Model
4. App Integrity, Distribution, and Updates
5. Protocol and Trust Model
ALTERNATIVES:
So What To Use Instead?
Nothing is perfect. There is no such thing as 100% guaranteed privacy. But the following projects, with all their own flaws, come significantly closer than Signal to our Digital Freedom criteria:
We’ll explore each of these in future reports, including where they still fall short and how they can be safely combined in a broader digital‑freedom toolkit.
