What happens when a government asks Signal for your data
Published: October 7, 2026 Updated: October 8, 2026
When a government demands user data from Signal, Signal can hand over very little: essentially the date the account was created and the last time that account connected. That is not a marketing claim; it is what Signal's own published subpoena responses have shown, and it follows directly from the app's design. Message text, call content, contact lists, and group chat history are end-to-end encrypted, which means Signal never has them in the first place, and no court order can compel a company to hand over data it does not possess. This page explains what a government request actually returns, what Signal's transparency reporting shows, and, honestly, where the real risks are.
The short answer
Signal was built so that the answer to "give us this user's data" is nearly always "we don't have it." The service is designed around end-to-end encryption for everything substantive:
- Message text.
- Voice and video calls.
- Attachments.
- Group chat history.
- Even most metadata about who is talking to whom.
When investigators have served legal process on Signal in the past, the responses Signal published were strikingly short. In the most discussed cases, the complete production was two fields: the account creation date and the last time the account connected to Signal's servers. No message content, no contact list, no call logs, no location history, because those things do not exist on Signal's servers in readable form.
This is the honest version of the story, and it matters because it is not absolute. There are real limits to what "we don't have your data" covers, and pretending otherwise would be misleading. Signal does hold some account records. Your phone number is necessarily known to the service, since it is how your account is addressed. And there is one large practical caveat that sits outside the server entirely: if someone physically takes your unlocked phone, encryption on the server side cannot help you. This page separates the three layers clearly: what the server holds, what legal process can reach, and what actually threatens a real user.
What Signal actually stores about you
Understanding a government request starts with understanding what there is to request. Signal keeps its server-side records deliberately thin. The account is anchored to your phone number, because Signal uses phone numbers as identities and needs to route messages to devices. Alongside that, the service keeps basic account records such as when the account was created and when it last connected. Profile information you choose to share (a name, a photo) is stored so contacts can see it, and some cryptographic material needed to deliver messages exists on the server in encrypted form.
What is not stored: the substance
What is not stored is the substance. Message text passes through Signal's servers as encrypted ciphertext that only the recipient's device can open; the server never holds the keys. Voice and video calls are encrypted end to end as well. Attachments, stickers, group message history, and your address book are not sitting on a Signal hard drive waiting for a subpoena. Signal's contact discovery works by sending hashed, truncated versions of your contacts for matching and does not retain your address book in readable form. Our guide on how Signal's encryption actually works walks through the mechanics if you want the detail.
Data minimization as a design principle
The design principle is sometimes called data minimization: collect the least amount possible so there is little to lose, leak, or hand over. It is a deliberate choice, and it is the reason Signal's lawyers can answer a data demand with a two-field spreadsheet. Compare that with mainstream services that keep years of searchable message history, full contact graphs, ad profiles, and location timelines. The difference is not that Signal's lawyers are braver; it is that the data cupboard is nearly empty.
What a government request really returns
Here is the core of the answer this page exists to give. Signal has published its responses to subpoenas. For example, its published response to a federal grand jury subpoena: the complete user data produced was the date the account was created, and the last time the account connected. That is the whole thing. When the demanding party asked for more, the answer was that more does not exist on Signal's servers.
How the legal process works
To be precise about how this works in practice: a government agency serves legal process on Signal, the legal entity behind the service. Depending on jurisdiction and the stage of an investigation, that process is a subpoena, a court order, or a search warrant. Signal's counsel reviews it, and then the company produces whatever responsive records exist in its systems. Because of the architecture described above, the responsive records for an account are limited to the minimal account record. There is no content to produce, no contact list to produce, and no group history to produce. The process is short, and the result is short.
One honest nuance
One honest nuance: a request can cover multiple accounts, and it can ask for non-content records around those accounts, such as creation and last-connection dates for each. What it cannot do is widen the set of records Signal holds. Legal process compels production of existing records; it does not create records that were never kept. That distinction is the whole reason minimal architecture matters: it turns "we refuse" into "there is nothing to give," which is a much stronger position, legally and practically.
What governments cannot get from Signal
This is the information-gain core of the page, so here it is as a clean table.
| Data | Can a government request get it from Signal's servers? |
|---|---|
| Message text | No: end-to-end encrypted; Signal never has the plaintext |
| Voice / video call content | No: encrypted end to end |
| Photos, videos, attachments | No: encrypted; server holds only ciphertext blobs |
| Contact list | No: not retained in readable form |
| Group chat history | No: not stored on servers in readable form |
| Who you message (sender/receiver) | Mostly hidden: sealed sender hides this from the server |
| Account creation date | Yes: part of the minimal account record |
| Last connection time | Yes: part of the minimal account record |
| Your phone number | Yes: it is the account identifier |
Two rows in that table deserve a footnote. "Who you message" is only partially answered, which leads to the metadata discussion below. And "your phone number" being visible is by design: it is the address of the account. Nobody can message you without the system knowing the number exists, the same way the postal service knows your address exists even though it cannot open your letters.
The metadata question and sealed sender
The careful reader will have noticed the hedge in the table. Encryption protects content, but who talks to whom is a separate kind of information, and it is the kind investigators care about most. Traditionally, a messaging service's server sees the sender, the recipient, and the time of every message, even when the text itself is encrypted. Signal addressed this with a feature called sealed sender, which encrypts the sender's identity so the server knows which account should receive a message without knowing which account sent it.
Sealed sender meaningfully shrinks the metadata available, but honesty requires the limits stated plainly. It is not perfect or total. It is a specific technical protection on sender identity in message delivery. And it does not hide the fact that you use Signal, the size and timing patterns of your network traffic, or anything that happens on your own device. If you need the full picture of what stays private, read our deeper look at whether Signal is really private and the plain-English answer to can police read Signal messages.
The practical takeaway is proportionate. Sealed sender is one of the strongest metadata protections any mainstream messenger offers, and it makes bulk collection of "who talks to whom" far harder. It does not make you invisible. Targeted investigations have other tools, which brings us to the next section.
The real risk: device seizure, not server data
Here is the honest limit that matters more than everything above. All of Signal's server-side restraint becomes irrelevant the moment someone has your physical device, unlocked. A seized, unlocked phone shows everything: every chat, every photo, every contact, every group. Server-side encryption is the wrong layer to think about at that point; the data is on the screen because your own app decrypted it for you.
This is why experienced security advice focuses on the endpoint. A strong device passcode (not a four-digit PIN a shoulder-surfer can catch), biometric lock with attention detection, disappearing messages on sensitive conversations, and a screen that locks fast are the controls that actually defend against seizure and border searches. Disappearing messages deserve special mention: a message that has already vanished cannot be photographed from your phone later. They are not retroactive protection, though; they only help from the moment they are turned on. See our guide to disappearing message limits for exactly what they do and do not cover.
There is a second endpoint risk worth naming: the other person's phone. Your messages live on their device too, and their security posture is not yours. If you are discussing anything genuinely sensitive, the weakest device in the conversation sets the security of the whole thread. No server policy can fix that.
Signal's transparency reporting
Signal publishes transparency data about government requests it receives, so the public does not have to take the architecture claims on faith. These reports describe how many requests arrived in a given period and how they were handled. The pattern they show is consistent with everything on this page: small numbers of requests, and minimal production in response.
Transparency reporting is not unique to Signal, but the substance of Signal's reports is different from most companies' because the underlying data posture is different. When a large platform publishes that it complied with tens of thousands of requests and handed over content, account records, and location data, the takeaway is that the data existed to hand over. When Signal publishes its numbers, the takeaway is the opposite: the architecture capped what was possible. Read the reports as evidence of the design, not as a marketing document.
One caution about scope: transparency reports cover requests Signal received and can legally disclose. They do not cover, and cannot cover, requests that arrived with gag orders or requests directed at other parties in the chain, such as your carrier or your phone maker. If you are threat-modeling seriously, assume governments also hold whatever your carrier knows about you, which is a lot: call records, SMS records, coarse location. Your carrier is not Signal.
What you can do
Most readers of this page are not under investigation; they are doing threat homework, and that deserves concrete advice. First, keep the app updated: website-build users get updates from the app itself, and the current website build is 8.29.3, which you can always grab from Signal's official APK page. Second, verify safety numbers with people you message about sensitive things; it defeats impersonation. Third, turn on disappearing messages for conversations you would rather not exist on a seized device, and use the shortest timer you can tolerate.
Fourth, set a strong Signal PIN and enable registration lock, which stops someone who hijacks your phone number from re-registering your account; our SMS scam and SIM-swap guide explains that attack and the defense in full. Fifth, lock the phone itself properly: a long alphanumeric device passcode beats a short PIN, and a short auto-lock timer closes the seizure window. Sixth, keep backups and the recovery key somewhere that is not the same phone; if a device is lost or seized, the key is the difference between recovery and a dead account.
Finally, keep the trust model straight. Signal's architecture protects you from server-side exposure and bulk data demands. It does not protect you from a compromised phone, a careless conversation partner, or physical coercion. Knowing which layer a threat lives on is what turns privacy from a feeling into a plan.
from Signal's official site file hosted by Signal, not by us
Frequently asked questions
Can Signal read my messages if ordered to?
No. Messages are end-to-end encrypted, so Signal only ever holds ciphertext it cannot decrypt. A court order cannot produce plaintext that does not exist on their servers.
What exactly has Signal handed over in past subpoenas?
In the subpoena responses Signal has published, the complete production was the account creation date and the last time the account connected. No message content, contacts, or call records.
Does Signal keep a log of who I message?
Signal's sealed sender feature is designed to hide sender identity from the server. Content is encrypted, and contact lists are not retained in readable form, so there is little to log in the first place.
Can police get my Signal chats by seizing my phone?
Yes, and that is the real risk. If someone has your unlocked device, they can read everything on it. Server-side protections do not apply to a seized phone. Use a strong device lock and disappearing messages.
Does Signal publish transparency reports?
Yes. Signal publishes transparency data on government requests it receives, including how many arrived and how they were handled. The reports consistently show minimal data production.
Keep reading
- whether Signal is really private: the full privacy breakdown beyond government requests
- can police read Signal messages: the plain-English answer on law-enforcement access
- how registration lock stops SIM-swap attacks: the endpoint defense most people skip