When people talk about secure messaging, the conversation usually stops at content. Is the message body encrypted? Can the server read it? Those are the right first questions, and end-to-end encryption answers them well. But content is only one layer. Around every encrypted message sits a halo of presence and delivery signals, and those signals are often not encrypted, not optional by default, and far more revealing than people expect.
Three signals, and what each one leaks
The features feel like conveniences. Each one also functions as a small sensor pointed at you.
Read receipts
A read receipt confirms the moment you opened a message. That single timestamp, collected over weeks, sketches your daily rhythm: when you wake, when you check your phone, how long you take to respond to different people, and whether you read a message and chose not to answer. In a personal conflict, a read receipt showing that a message was seen and ignored can become evidence in an argument. In a workplace, it can become an expectation of instant availability.
Typing indicators
The typing indicator is real-time. It fires the instant your fingers touch the keyboard and stops when you pause. It reveals that you are present, actively engaged, and composing right now. It can also reveal hesitation, the message you started, deleted, and rewrote, which is a surprisingly intimate thing to broadcast to the other side of a conversation.
Online and last-seen status
Presence status is the most continuous of the three. "Online now" and "last seen at 11:47 pm" are generated whether or not you send anything. Watched over time, they expose sleep schedules, time zones, and patterns of who is online at the same moment as whom. That last inference matters: correlated presence can suggest a relationship between two accounts even when their messages are perfectly encrypted.
Encryption protects what you say. Presence and delivery signals expose when you are there, how you behave, and who you are near in time. An observer who cannot read a word of your chat can still learn a great deal from the pattern of your activity.
Why this counts as surveillance data
This is the metadata problem in miniature. As we covered in metadata surveillance, the who, when, and how-often of communication frequently reveals more than the content, because patterns are easier to analyze at scale than prose. A former NSA general counsel is widely quoted summarizing the agency's view of communications metadata bluntly:
We kill people based on metadata. Attributed to Michael Hayden, former Director of the NSA and CIA
Read receipts and presence status are metadata your own device generates and volunteers. In most consumer messengers this data is visible to the person you are talking to, and depending on the product's architecture, potentially to the service operator that routes it. It is a channel that runs alongside your encrypted content, and it is usually on unless you turn it off.
How to turn the signals off
Most mainstream messengers let you disable at least some of these. The controls vary, and a few come with reciprocity rules worth knowing about.
| App | What you can control |
|---|---|
| Signal | Read receipts and typing indicators can each be disabled globally in Privacy settings. Turning off read receipts also stops you seeing others' receipts. |
| Read receipts can be turned off, but the setting is reciprocal: disable them and you lose the ability to see others' too. Group read receipts stay on regardless. Last-seen and online presence have their own controls. | |
| iMessage | Read receipts can be set globally or per conversation. Typing indicators are shown while the field is active and are not separately toggleable. |
| Telegram | Last-seen and read timing can be restricted, again with a reciprocity rule that hides others' timing from you in return. |
The reciprocity rule in WhatsApp and Telegram is deliberate. It nudges you to keep the signals on by making privacy cost you the same visibility into others. That is a design choice, not a technical necessity, and it is worth recognizing as such when you decide what to disable.
The design question underneath
Toggles help, but they put the burden on you to find and flip each one, on every app, on every device, and to re-check them after updates. A stronger position is to prefer tools where the privacy-respecting behavior is the default and the presence signals are minimized by construction rather than by a settings page.
This is the same reasoning behind features like sealed sender and disappearing messages: reduce the amount of ambient data the system produces in the first place, so there is less to leak, less to subpoena, and less to correlate. When you evaluate a messenger, look past the encryption badge and ask what it broadcasts about your presence, whether those signals are off by default, and whether the operator can see them at all.
Encrypted content with loud presence signals is a partial defense. The people whose safety depends on not being profiled, the readers we think about most when we build, need the quiet defaults, not the ones they have to go hunting for.