# End-to-end encryption, explained in plain English

> End-to-end encryption means a message is scrambled on the sender's device and can only be unscrambled on the recipient's device. The company in the middle passes it along but can't read it, because it never has the key. It protects the content of messages, not who you talk to or what the other person does with what you send.

"End-to-end encrypted" shows up on every messaging app's homepage now. It's a genuinely important feature, but it's often explained either too vaguely ("military-grade security!") or too technically to be useful. Here's the version we'd give a friend.

## The one-sentence version

End-to-end encryption means your message is locked on your phone and can only be unlocked on the other person's phone, so nobody in between, including the company running the app, can read it.

## An analogy: the locked box

Imagine sending a letter through a courier.

**Without encryption,** you hand over an open postcard. Anyone who handles it can read it.

**With ordinary encryption** (the kind most websites use, often called encryption "in transit"), you put the letter in a locked box, but the courier company has a key. They lock it when they pick it up, unlock it at their depot, and lock it again before delivery. Strangers on the road can't read it, but the courier can.

**With end-to-end encryption,** you lock the box yourself, and only your friend has the key. The courier carries it all the way without ever being able to open it. If someone breaks into the depot, all they find are locked boxes.

## How it works (a little more technically)

1. **Keys are created on the devices,** not on the company's servers.
2. **Your app encrypts each message** before it leaves your phone, using an established algorithm like AES.
3. **The server stores and forwards** the scrambled version. To the server it's just random-looking data.
4. **The recipient's app decrypts it** using a key that only their device has.

The hard part is getting the right keys to the right people without the server ever seeing them. Different apps solve it differently. The [Signal Protocol](https://signal.org/docs/), used by Signal and WhatsApp, has devices swap keys in a clever way that the server can relay but not use. [Talklio](/security) puts the key in the private link itself, in the part after the `#`, which web browsers never send to servers. Whoever has the full link has the key. Nobody else does, including us.

## What end-to-end encryption protects

- **The content of your messages,** photos, voice notes and calls, while they're traveling and while they sit on servers.
- **You from data breaches.** If the company is hacked, the attackers get scrambled data.
- **You from the company itself.** Staff can't read your messages, and neither can anyone who forces the company to hand data over.

## What it doesn't protect

This part gets left out of marketing pages, so it's worth spelling out:

- **Metadata.** The service usually still knows who talked to whom, when, and how much. Good apps keep as little as possible and delete it quickly.
- **The ends themselves.** Once a message is decrypted on someone's phone, they can read it, screenshot it or forward it. Encryption protects the journey, not the destination.
- **A hacked phone.** If malware is on your device, it can read messages after they're decrypted.
- **Backups.** Some apps back chats up to cloud storage. Unless the backup is also end-to-end encrypted, that copy may be readable by the cloud provider.

## Encryption at rest vs in transit vs end to end

You'll see all three terms:

| Term | What it means | Can the company read it? |
| --- | --- | --- |
| In transit | Encrypted while moving between you and the server | Yes |
| At rest | Encrypted while stored on the server's disks | Usually yes, they hold the key |
| End to end | Encrypted on your device, decrypted only on the recipient's | No |

If an app only mentions "in transit" or "at rest", it isn't end-to-end encrypted.

## How to tell if an app really uses it

- **Is it on by default?** Some apps only encrypt end to end in special modes. On Telegram, for example, only Secret Chats are end-to-end encrypted.
- **Does it cover everything?** Check photos, voice notes, calls and group chats, not just text.
- **Do they explain where keys live?** A trustworthy service tells you plainly, including the limits.
- **What happens to backups and metadata?** Look for clear answers on both.

## Frequently asked questions

### Can end-to-end encrypted messages be hacked?

The encryption itself is extremely hard to break. Attacks usually target the ends instead: a compromised phone, a stolen unlocked device, or tricking someone into sharing a key or password.

### Can the police read end-to-end encrypted messages?

Not from the company's servers, because the company can't decrypt them. They may be able to read messages on a phone they physically access, or obtain metadata the company holds.

### Is WhatsApp end-to-end encrypted?

Yes. WhatsApp encrypts personal messages and calls end to end by default using the Signal Protocol. Cloud backups are only end-to-end encrypted if you turn that option on.

### Is Talklio end-to-end encrypted?

Yes. Every message, photo and voice note is encrypted on your device with AES-256-GCM, and the key is kept in your link's fragment, which never reaches Talklio's servers.

---
Source: https://talklio.app/guides/end-to-end-encryption-explained · Updated 2026-10-10
