The phrase appears every time you open a new conversation: messages are protected with end-to-end encryption. The question that remains is what exactly this covers — and the answer matters, because the protection is strong in one specific area and nonexistent in others.
What cryptography actually does
End-to-end encryption means that the message is scrambled on your device and only unscrambled on the recipient's device. On its way between the two, it travels as an unreadable block.
The practical consequence is stark: whoever intercepts the message along the way—on the Wi-Fi network, at the carrier, or on the service's own server—gets a meaningless jumble. Not even the company that operates the app can read the content.
But look at the drawing: the protection is of the way. At both ends, the message is open, because it needs to be—that's where it's written and read.
The three places where a conversation leaks.
If the middle ground is safe, everything else remains. And it's always just what remains.
1. The unlocked device
This is by far the most common scenario. Anyone who picks up your unlocked phone can read everything, without needing any special skills. No encryption in the world can protect against an open screen left on a table.
The same applies from the other side: the person you're talking to can show the screenshot to whomever they want. The conversation has two owners.
2. Connected sessions
The app allows you to use the same account on other devices — computer, tablet, browser. A session like this, opened once and never closed, continues to receive conversations.
This is the point that almost no one checks. It's worth opening the connected devices area within the app and looking at the list: each item there is a place where your messages are arriving. Disconnect the ones you don't recognize. It's the most effective and least strenuous security measure in this whole process.
3. Cloud backup
Herein lies the biggest confusion. The conversation travels encrypted, but the backup copy that goes to the cloud is a different file, stored on a different service, under different rules.
The app offers an option to protect this backup with a password or your own key — and it's not enabled by default in all configurations. Without it, the backup is only protected by your cloud account login. In other words, anyone who accesses your email account can view the history, even without touching your phone.
If you're only going to change one thing after reading this text, change that one.
What does not exist
It's best to be direct, because this search leads to bad places.
There is no legitimate app that can read another person's conversation remotely. Using only a phone number, encryption prevents exactly that, and that's why it exists.
What exists are programs that need to be installed on the victim's device, with physical access to it, and that capture the screen after the message has already been decrypted. It's not broken encryption — it's spying on the device.
Installing this on someone else's cell phone without their knowledge is a crime in Brazil. Invading someone else's computer system is a crime under the Penal Code, and the fact that the program is for sale doesn't change that.
In fact, many of the ads in this category don't deliver what they promise: they charge a subscription and return an empty panel. The victim of the scam ends up being the person who paid for them.
How to know if someone has access
Some signs are worth checking:
- A message that appears as already read even though you haven't opened it.
- Unknown device in the list of connected sessions.
- A verification code arrived via SMS without your request — a sign that someone tried to register your account on another phone.
- Battery and data consumption are much higher than normal, with no change in usage.
The third item is the most serious. If a code arrives without you having requested it, Do not forward this to anyone., Absolutely not. That's exactly what the scammer needs to take over your account.
The adjustment that closes the main door.
Two-step verification within the app creates a PIN that is required to register your account on any new device. With it enabled, stealing the code via SMS is no longer sufficient.
It's the difference between an account that falls for the classic scam and one that doesn't. It takes a minute to set up and is located in the account and security section of the settings.
Summary
Encryption protects the transmission between one phone and another very well. It doesn't protect against open screens, forgotten sessions on other devices, or backups without a password. Anyone who truly wants to protect their conversations addresses these three points—and ignores any advertisement promising to read other people's conversations, because it's either a scam or a crime.
