ArkCentralArkCentral

privacymessagingencryption

Who Can Actually Read Your Family's Messages? And How to Fix It

Your family chats are probably private. Probably. Here is what encryption actually covers, the backup setting that undoes it, and what to check this week.

Francis Yu · Co-founder · July 31, 2026

Most people assume their family chats are private. That assumption is roughly right, and the gap between roughly and actually is where the interesting part lives.

Privacy in messaging is not one question. It is three, and they have different answers depending on which app you are in and which settings you turned on years ago and forgot about.

  1. Can anyone read what you wrote?
  2. Does anyone know who you talked to, and when?
  3. Who has a copy, and for how long?

What "encrypted" actually means

Two very different things get called encryption, and the difference decides who can read your family's conversations.

Encrypted in transit means the message is scrambled while it travels between you and the company's servers. It arrives at the company, is unscrambled there, and is stored in a form the company can read. This protects you from someone snooping on the coffee shop wifi. It does not protect you from the company, or from anyone who can compel the company to hand it over. Instagram direct messages work this way, as do ordinary Telegram chats, standard SMS, and most email.

End to end encrypted means the message is scrambled on your phone and can only be unscrambled on the recipient's phone. The company carries a sealed envelope it cannot open. Signal works this way, as does WhatsApp, iMessage between Apple devices, and one to one chats on Facebook Messenger.

The backup, which is where most families are exposed

Here is the gap that catches nearly everyone. Your messages can be end to end encrypted in the app and still sit in readable form in a backup.

When your phone backs up to a cloud account, the message history often goes with it. If that backup is not itself encrypted with a key only you hold, the content is readable by whoever holds the backup. Your chat app can be doing everything right while your backup quietly undoes it.

  • WhatsApp encrypts messages end to end by default, and separately offers an end to end encrypted backup which is off unless you switch it on. Look in Settings, then Chats, then Chat Backup.
  • iPhone users should look at Advanced Data Protection in their Apple account settings. Without it, Apple holds a key to your iCloud backup, which includes your messages. With it, they do not.
  • Android users should check what their device backup includes and whether it is protected by a password only they know.

One honest warning about Advanced Data Protection, because it is a real trade off rather than a free win. Once Apple no longer holds a key, Apple cannot get your data back for you. If you lose your password and your recovery method, the data is gone permanently, and no support call will change that. Apple makes you set up a recovery key or a recovery contact before it will let you turn the feature on. Do that part properly, write the key down somewhere physical, and give a trusted family member the recovery contact role. That five minutes is the difference between strong privacy and losing a decade of photos.

A quick reality check on the apps your family uses

Defaults change, sometimes suddenly, so treat this as a prompt to go and look rather than a permanent scorecard.

  • Signal. End to end encrypted by default, and built to hold almost nothing about who talks to whom. If you are choosing among services run by somebody else, this is the strongest one available, and it is free.
  • WhatsApp. Message content is end to end encrypted by default, which is genuinely good. The contents are sealed, but the record of who you talk to and how often sits with Meta, whose business is advertising. That surrounding information is worth understanding before you assume the whole picture is private, and it is covered in the next section.
  • iMessage. Strong between Apple devices, where messages are end to end encrypted by default and Apple cannot read them. The weak point is mixed households. As soon as a green bubble appears, the conversation has dropped to SMS and lost that protection entirely.
  • Telegram. This one surprises people. Ordinary Telegram chats are not end to end encrypted by default. They are encrypted to Telegram's servers, where the company holds them in readable form. Telegram does offer proper end to end encryption through Secret Chats, but you have to start one deliberately for each conversation, and they do not sync across your devices.
  • Instagram. Instagram removed end to end encryption from direct messages in May 2026. Meta can now see the contents of Instagram DMs, including photos, videos and voice notes. Meta's own advice to people who want encrypted messaging was to use WhatsApp instead.
  • Facebook Messenger. One to one chats and calls are end to end encrypted by default. Group chats are not, unless you turn it on, and business and Marketplace conversations are not covered either.
  • SMS. No end to end encryption at all. Your mobile operator handles it in a form it can read, and it can be produced in response to a valid legal request. Fine for a delivery code, wrong for anything you would not put on a postcard.

The part encryption does not hide

Even with flawless end to end encryption on the contents, the company running the service generally knows that you messaged your sister, at what time, how often, and from roughly where. That surrounding information is called metadata, and it is more revealing than most people expect.

Think about what can be worked out from the pattern alone, without a single word being read. Who is closest to you. When a relationship began, and when the messages stopped. When a new baby arrived, because the volume of photos to the same six people suddenly triples. When someone was unwell, because of a run of late night calls.

Information like that is the raw material of targeted advertising, and it supports inferences that go well past advertising. It can be retained for years, it can be handed over under legal process, and it can be exposed in a breach of a company you never chose to trust directly.

This is the honest limit of picking a better app. You are choosing which company holds the map of your family's relationships. You are not removing the company from the picture.

What to actually do this week

  1. Turn on encrypted backups. Enable WhatsApp's end to end encrypted backup, and turn on Advanced Data Protection if you are on Apple, with the recovery key stored somewhere safe. Nothing else on this list buys you as much.
  2. Check your linked devices. Every serious chat app has a screen listing the computers and tablets logged into your account. Old laptops and former partners linger there. Remove anything you do not recognize.
  3. Move the conversations that matter off the platforms that read them. Instagram DMs are now readable by Meta, and ordinary Telegram chats always were. If your family has been using either for anything real, move those threads to something encrypted by default, or at minimum start a Secret Chat in Telegram rather than typing into the normal one.
  4. Stop handing over your address book. Most chat apps ask to upload your contacts and most people tap yes without thinking. That upload is how your family's relationship map gets built, and it includes people who never agreed to it. Turn off contact syncing in the apps that do not need it, and check what you have already granted in your phone's privacy settings.
  5. Cut down how many companies hold the same map. If your family is spread across four messaging apps, four separate companies each hold a partial record of who your family is. Consolidating onto fewer services, chosen deliberately, shrinks that exposure more than any single setting.
  6. Watch for the green bubbles if your household is split between iPhone and Android, and move those conversations somewhere that protects everybody equally.

The thing you cannot fix with settings

Every step above is worth taking, and all of them share one limit. Each is a permission handed to you inside a system somebody else runs, and the company running it keeps the master key. Whatever protection you switch on, the same company can redefine it, reset it in an update, or take it away, and your only options afterward are to accept it or to leave and try to carry a decade of conversations with you.

Instagram showed how quickly that can happen. End to end encryption on direct messages was announced as ending in March 2026 and switched off in May. Nobody's settings changed. The rulebook did, and no setting inside the app could have prevented it.

The only way out of that pattern is for the messages to live somewhere you own. That is why we built The Ark. It is a small device that sits in your home and runs your family's chat on your own hardware, so conversations and everything shared in them stay in the house instead of passing through somebody else's servers. There is no monthly fee, and no terms that can be rewritten later, because there is nobody in the middle to rewrite them.

Setting it up is deliberately ordinary. You plug it in, follow a guided walkthrough that takes about ten minutes, and everyone else joins by scanning a code with their phone. If you can set up an iPhone, you can set up The Ark. No home server knowledge required, and nothing to maintain afterward.

If that is more than you need right now, go and do the six checks above. Most families are one backup setting away from a much better answer to the question in the title.

About the author

Francis Yu · Co-founder

Co-founder of ArkCentral. Writes about privacy, hardware, and getting your digital life off other people’s computers.