What Metadata Signal Stores: The Complete Honest List
Published: October 7, 2026 · Updated: October 8, 2026
Metadata is the “who, when, and how” around your messages, and it is the information Signal works hardest not to hold. Signal stores your phone number, your profile name and photo, and when you last connected. It does not store your message contents, your contacts, your location, or who you talk to. When law enforcement has demanded user data, Signal has handed over almost nothing: an account’s registration date and its last-connection date. This guide lists exactly what exists, what does not, and how to shrink the little that remains.
from Signal’s official site — file hosted by Signal, not by us
What is metadata, and why does it matter?
Every message has two parts: the content (what you said) and the metadata (the facts around it). Who sent it, who received it, when it was sent, how large it was, from which device, on which network. Encryption protects the content. Metadata is a separate battlefield, and in some ways the more revealing one.
A single metadata record is boring. A year of them is a biography. Who you talk to every morning, which numbers you call late at night, how your messaging patterns change before a trip, which group chats go quiet at the same time. From metadata alone, analysts can reconstruct relationships, routines, and life events without reading a single word. That is why privacy people say metadata is data, and why Signal treats minimizing it as a core design goal rather than a nice extra.
Most messaging companies treat metadata as an asset: they log it, mine it, and keep it for years. Signal treats it as a liability: every record it holds is something that could be breached, subpoenaed, or misused. The design philosophy is simple: hold as little as possible, so there is as little as possible to lose.
What Signal stores about your account
Here is the honest list of what Signal keeps, based on the company’s own statements and what it has produced when legally compelled. It is short enough to read in full.
| What is stored | Why it exists |
|---|---|
| Your phone number | It is the account identifier you register with |
| Profile name and photo | Shown to people you communicate with |
| Account registration date | Basic account record |
| Last-connection date | Needed to route messages and manage the service |
| Optional profile extras you set (about text) | Only what you choose to publish |
That is the list. There is no advertising profile, no interest graph, no location history, no record of your conversations. The company has described its approach plainly: the closest thing to metadata the server keeps about usage is when each account last connected, and even that is stored with reduced precision: the day, not the hour, minute, and second.
What legal requests have actually returned
The strongest evidence for a short list is what happens when someone with legal power demands the long list. US law enforcement has served Signal with demands for user data more than once. Each time, the company produced essentially the same minimal response: the account’s creation date and the date it last connected. In one widely reported case, investigators received exactly that and nothing else, and it was of no use to their case.
This is the practical payoff of the whole design. A subpoena can only reach what exists. Because Signal does not log who messaged whom, does not store message contents, and, with sealed sender, does not even learn the sender of most messages, there is no richer record to surrender. The company’s transparency here is not a policy choice that a future management team could quietly reverse; it is a consequence of the architecture.
Compare this with what typically comes back from mainstream messengers under similar orders: months of connection logs, contact graphs, group memberships, and location-adjacent records. The difference between those responses and Signal’s two timestamps is the difference the architecture makes.
What Signal does not store
The “does not” list is longer and, frankly, more important.
| Not stored | What this means for you |
|---|---|
| Message contents | Your texts, photos, and voice notes exist only on devices |
| Who you talk to | No contact graph is built; sealed sender hides senders from the server |
| Your contacts in readable form | Contact checks use hashed, privacy-preserving lookups |
| Location data | Signal does not track or store where you are |
| Call contents or call logs | Calls are encrypted; no record of who called whom is kept |
| Advertising or behavioral profiles | There is no ad business, so there is nothing to feed |
Two of these deserve emphasis. First, “who you talk to”: with sealed sender active, the server does not learn the sender of your messages, so it cannot build a record of your conversations even if it wanted to. Second, contacts: Signal needs to tell you which of your phone contacts use Signal, and it does that without ever receiving your address book in readable form, which the next section explains.
How contact discovery stays private
Contact discovery is the one place Signal must compare data with its servers. To show which contacts already use Signal, your phone scrambles each number into a one-way hash and checks those hashes against Signal’s directory. Your readable address book never leaves your phone. The honest edge is that the server does learn, in hashed form, which numbers were asked about during a lookup. “Checks contacts without uploading them” is more accurate than “the server learns nothing at all.”
For the full mechanics (how the private matching works, the caveats, and how to revoke or opt out of discovery), see how Signal checks your contacts without reading your address book.
What about groups, stories, and profile data?
Groups deserve a clear statement because they are the one place where Signal necessarily holds more structure. To run a group, the server keeps the group’s membership list, its name and avatar, and the admin roles. Group messages are still end-to-end encrypted, and sealed-sender protections extend toward groups, but the membership roster itself is server-side data by design. If you join sensitive groups, know that the roster exists.
Stories work like expiring profile broadcasts: they are encrypted, visible only to your chosen audience, and they disappear. Your profile name, photo, and optional about text are stored because other people need to see them; treat them as public within your circles. The pattern is consistent across all of these: Signal stores exactly what the feature needs to function, encrypted where possible, and nothing around it.
How to shrink your own footprint
Signal’s list is already minimal, but you control the remaining pieces. Four moves cover nearly all of it.
- Use a username instead of sharing your number. Your number is the one required identifier. Usernames let you be reachable without handing it out, and the phone-number privacy settings let you hide it from everyone except people who already have it saved.
- Keep sealed sender working for you. It is automatic in normal conversations, and you can widen it to accept sealed messages from non-contacts. This is the single biggest reduction in the metadata the server could ever hold about you.
- Keep your profile minimal. Your profile name and photo are visible to people you communicate with. Use a name and photo you are comfortable with strangers in group chats seeing, and skip the about text if you do not need it.
- Lock down your number settings. Review who can see your number and who can find you by it in the phone-number privacy walkthrough, so the one required identifier stays as private as you want it.
The through-line of this guide is worth restating: Signal’s metadata story is not a promise, it is an architecture. Short lists, sealed senders, hashed contact checks, and open code add up to a system designed so that the sensitive records simply do not exist. That is a stronger guarantee than any privacy policy, because policies can change and absent data cannot leak.
Frequently asked questions
Can Signal hand over my messages to the police?
No. Signal does not store message contents and does not hold the decryption keys, so there is nothing to hand over. Legal demands have returned only account registration and last-connection dates.
Does Signal know who I talk to?
Not in the way other apps do. With sealed sender active, the server does not learn the sender of messages, so it cannot build a record of your conversations.
Why does Signal need my phone number at all?
The number is the account identifier used for registration and sign-in. Usernames now let you keep it private in daily use, but the number is still required to create the account today.
Does Signal store my location?
No. Signal does not track or store your location. Calls and messages carry no location data to the server.
If I delete my Signal account, what remains?
Deleting your account removes your profile and account data from Signal’s servers. Messages on other people’s devices are unaffected. Deleting your account cannot delete what others already received.
Keep reading
- hiding the sender from the server: sealed sender explained
- keeping your number out of it: usernames vs phone numbers
- how the content is protected: beginner’s encryption guide
- the full settings walkthrough: phone number privacy settings