What Is End-to-End Encryption? A Plain-Language Guide

You have probably seen messaging apps advertise end-to-end encryption. It is one of the most important privacy features available, and the idea is simpler than it sounds.
The basic idea
With end-to-end encryption, a message is locked on your device and can only be unlocked on the recipient’s device. The company running the service, your internet provider and anyone intercepting the data in between see only scrambled content.
How it differs from ordinary encryption
Most websites encrypt data in transit between you and the server, but the company can still read it there. In end-to-end encryption, the service passes along the message without holding the keys to read it.
What it protects
- Message content from the provider and from eavesdroppers.
- Messages from being read if servers are breached.
What it does not protect
- Metadata. Who you contact, and when, may still be visible, depending on the service.
- Your device. If someone has your unlocked phone or malware, they can read your messages.
- Backups. Cloud backups may not be end-to-end encrypted unless you enable it.
- Screenshots and forwarding by the person you are talking to.
Where you will find it
Many messaging apps, some email services, certain cloud storage tools and some video-call products offer it, often as a default or an optional setting. Check the settings and confirm that it is turned on.


