# What end-to-end encryption actually means

> End-to-end encryption means only the two devices in a chat can unscramble it, not the servers. What it covers, what it can't, and a 20-second check.

By LustAI Editorial · Published September 5, 2026 · 6 min read
Section: [Privacy & safety](https://heylust.app/blog/topic/privacy) · Canonical: https://heylust.app/blog/what-end-to-end-encryption-means

## In short

- End-to-end encryption means the message is scrambled on your device and only unscrambled on the other person's device; the servers in between carry a locked box they can't open.
- It doesn't stop the person you're chatting with from screenshotting, forwarding or saving what you send. The lock protects the journey, not the destination.
- It doesn't hide metadata: who you talk to, when, and for how long usually stay visible to the service.
- On Telegram, regular cloud chats are encrypted between you and the server; only secret chats and one-to-one calls are end-to-end encrypted. Other apps draw the line in different places.
- A 20-second check: find the app's own words on which chats are end-to-end, look for a key-verification screen, and remember the other person can always show your messages to someone else.

End-to-end encryption means your message is scrambled on your phone and only unscrambled on the other person's phone. The app's servers pass it along but can't read it. That's useful, and it's also narrower than the banner makes it sound. It protects the journey, not the two people at either end, and not the record of who talked to whom.

## What does "end-to-end encrypted" mean, in plain words?

Picture a small lockbox with two keys. You have one, the person you're chatting with has the other, and nobody else has a copy. You put your message inside, click it shut, and hand it to a courier. The courier can carry it across town, store it overnight, and drop it in a sorting depot. At no point can they open it.

That's the whole idea. In a chat app, "the courier" is the company's servers and every network in between. The [EFF's plain-language guide to encryption](https://ssd.eff.org/module/what-should-i-know-about-encryption) describes it as making a message unreadable to everyone except the person who holds the key to open it. When the box is only ever opened at the two ends, the encryption is "end-to-end".

The word "encryption" on its own doesn't promise that. Lots of things are encrypted somewhere along the way. The question that matters is who holds a key.

## How do two phones agree on a key without sending it?

This is the part that feels like a magic trick, so it's worth 90 seconds. If your phone simply sent the key across the internet, anyone watching could copy it, and the box would be pointless.

Instead, each phone keeps one secret number that never leaves the device. From that secret it makes a public piece, which it's fine for anyone to see. The two phones swap only the public pieces. Then each phone combines its own secret with the other side's public piece, and the maths is arranged so both arrive at the same shared key. A server sitting in the middle sees two public pieces go past and can't rebuild the key from them.

Telegram's own [secret-chat documentation](https://core.telegram.org/api/end-to-end) describes this exchange (it's called Diffie-Hellman, after the two people who published it). Once both sides hold the same key, they can show each other a little picture or a string of emoji made from it. If your pictures match, you know nobody swapped keys on you in the middle.

> Illustration: The grey secrets never leave either phone. Only the white public parts travel, and the server cube in the middle sees nothing but those. Both phones still end up with the same rose key.

## End-to-end encryption vs encryption in transit

Nearly every modern app uses encryption in transit. That's the padlock in your browser's address bar, and it's good. But it works in hops. Your message is locked between you and the server, the server opens it, does whatever it needs to do (store it, scan it, sync it to your laptop), then locks it again for the next hop.

| | Encryption in transit | End-to-end encryption |
| --- | --- | --- |
| Who can open it on the way | The service's servers | Nobody between the two devices |
| Can the company read the text | Yes, if it wants or is ordered to | No |
| Can you open the chat on a new phone | Usually, because the server has a copy | Only if the app has a way to move your keys |
| Does it stop the other person from copying it | No | No |

The EFF's [Communicating With Others](https://ssd.eff.org/module/communicating-others) guide draws exactly this line: transport-layer encryption protects the message from the network, while end-to-end protects it from the service as well. Neither is "fake". They're answers to different questions.

## Can end-to-end encrypted messages be read?

Not by the server, if the app has done its job. But "can anyone read my messages?" has three more honest answers, and vendors tend to skip them.

**The other person can.** They hold the second key. They can read, screenshot, forward, or read your message aloud to a friend. You can [set boundaries about sharing](https://heylust.app/blog/how-to-set-boundaries-with-someone-new-online), though no setting can enforce them. [Encryption has never made a person trustworthy](https://heylust.app/blog/is-anonymous-chat-safe). We cover what's actually capturable in [can someone screenshot your video chat?](https://heylust.app/blog/does-screenshot-notify-in-video-chat).

**Anyone holding an open phone can.** The box is opened on the device, so the message sits there in plain text. A stolen phone with no passcode, a shared laptop that stays logged in, or a backup that isn't itself encrypted all leak the contents.

**Metadata is usually visible.** Who you messaged, at what time, how often, and roughly where you were are not inside the box. They're the address label on the outside. The EFF guide above puts it bluntly: end-to-end encryption protects the content of your communication, not the fact that you're communicating. That label can say a lot on its own. Someone who messages a clinic every Tuesday at 9 a.m. has told a story without writing a word.

> **One line to remember**
>
> End-to-end encryption answers "can the company read this?" It doesn't answer "can the person I sent it to share this?" That's a trust question, and no setting fixes it.

## Is Telegram end-to-end encrypted?

It depends on which chat you're in, and Telegram is fairly open about this in its [FAQ](https://telegram.org/faq). Regular chats, the ones that sync between your phone and your laptop, are "cloud chats". They're encrypted between your device and Telegram's servers, and the servers keep a copy so your history follows you to any device. That's encryption in transit plus encrypted storage, not end-to-end.

Secret chats are different. They're end-to-end encrypted, tied to the two devices that started them, can't be forwarded, and can be set to self-destruct. One-to-one voice and video calls are also end-to-end encrypted, with the same matching-emoji check to confirm nobody is in the middle.

Other apps make different trade-offs. Some encrypt every chat end-to-end and make multi-device sync harder. Some encrypt nothing beyond transit. None of them is being sneaky by choosing; the problem is only when the banner says "encrypted" and the reader hears "private".

## What to try: a 20-second check before you say anything private

1. **Find the app's own sentence.** Search its FAQ for "end-to-end" and read which chat types it names. If it only says "encrypted", assume in transit.
2. **Look for a verification screen.** Matching emoji, a key picture, or a safety number means there's a real key exchange behind it. No screen usually means the server holds keys.
3. **Check the sync.** If your full history appears on a brand-new device with nothing but a login, the server had a readable copy or your keys. That's convenient, and it's not end-to-end.
4. **Ask the trust question out loud.** Before you send something you'd hate to see forwarded, you could ask yourself: "would you be fine if this person showed it to a friend?" If not, the encryption setting doesn't change the answer.
5. **Lock the ends.** A passcode, a screen that locks quickly, and an encrypted backup do more for a typical person than any protocol choice.

## Who can read my messages, then?

Here's the short version for a chat that really is end-to-end encrypted. The other person: yes. Anyone holding either phone while it is open: yes. The company running the app: no, for the content, but usually yes for who-talked-to-whom-and-when. A network provider or someone on the same café wifi: no. Someone who took a photo of the screen: yes, and nothing in the settings could have stopped it.

If a company says it keeps nothing at all, that's a separate claim with its own fine print, which we unpack in [what "nothing stored" really means](https://heylust.app/blog/what-nothing-stored-really-means). And if you use a random-chat service that hides your name, it's worth reading why [anonymous doesn't mean untraceable](https://heylust.app/blog/myth-anonymous-means-untraceable) before you rely on it. Encryption is one of a few things that keep a conversation between two people, and the [privacy and safety guides](https://heylust.app/blog/topic/privacy) cover the rest.

One last piece of the puzzle: the fingerprints and safety numbers apps show you are made with a related trick, and it's a friendly one to learn. We explain it in [what hashing is, in plain language](https://heylust.app/blog/what-is-hashing-explained-simply).

## Questions people ask

**What does end-to-end encrypted mean in simple words?**

It means the message is locked on your phone and can only be unlocked on the other person's phone. The company running the app carries the locked box but doesn't hold a key, so it can't read what's inside.

**Can end-to-end encrypted messages be read by anyone else?**

Not in transit, if the encryption is done properly. But the person you sent them to can read, copy, screenshot and forward them, and anyone with access to either unlocked phone can read them too.

**Is Telegram end-to-end encrypted?**

Partly. Regular Telegram chats are encrypted between your device and Telegram's servers and stored in the cloud so you can open them on any device. Secret chats and one-to-one voice and video calls are end-to-end encrypted, which means Telegram itself can't read or hear them.

**Does end-to-end encryption protect against screenshots?**

No. Encryption protects the message while it travels. Once it's displayed on a screen, that screen can be photographed or captured. A few apps try to detect screenshots in certain chat types, but none can prevent a photo taken with a second device.

**What is the difference between end-to-end encryption and encryption in transit?**

Encryption in transit locks the message between you and the server, then the server unlocks it and locks it again for the next hop. End-to-end keeps it locked the whole way, so the server never sees the plain text.

## Sources

- [Electronic Frontier Foundation (2025). What Should I Know About Encryption?](https://ssd.eff.org/module/what-should-i-know-about-encryption) · EFF Surveillance Self-Defense
- [Electronic Frontier Foundation (2024). Communicating With Others](https://ssd.eff.org/module/communicating-others) · EFF Surveillance Self-Defense
- [Telegram. FAQ: Secret Chats and encryption](https://telegram.org/faq) · Telegram
- [Telegram. End-to-End Encryption, Secret Chats (API documentation)](https://core.telegram.org/api/end-to-end) · Telegram

---
LustAI Blog · https://heylust.app/blog · Editorial policy: https://heylust.app/blog/about