Encrypted backup: how a cloud backup can defeat encryption
A backup is a copy of your messages outside the encryption. Whoever holds the key to it decides everything, and sometimes it is not even your decision.
The good news first: end-to-end encryption works. What you write on WhatsApp, Signal or iMessage normally cannot be read by the provider. The bad news sits one menu over, in the backups. A backup can undo the whole encryption with a single checkbox, and sometimes it is somebody else's checkbox that does it.
Why a backup bypasses the encryption
Encryption protects the path. A backup is something else: a copy of your messages that sits outside that path, so you can get them back after losing a device. That copy does not automatically have the same protection as the conversation itself. The digital rights group EFF puts it plainly: such backups do not necessarily carry the same protections as the chats, and they can make conversations "which were sent with strong, privacy-protecting end-to-end encryption" readable by whoever runs the cloud.
The default case is the problem
The tricky part is not the exception, it is the default setting. On WhatsApp the backup usually goes to Google Drive or iCloud without the extra layer. There is an end-to-end encrypted backup, but WhatsApp explicitly calls it "an extra, optional layer of security". Optional means: off until you switch it on. If you do, you secure the backup with a password or a 64-digit key, and after that, in WhatsApp's words, "neither WhatsApp nor your backup service provider" can read it. You just have to know about it and do it.
Apple is similar. Under standard protection the keys to your iCloud backup sit with Apple. Only Advanced Data Protection encrypts the backup end to end, and Apple itself shows how much that extra adds: the number of data categories protected with end-to-end encryption rises "from 14 to 23", and only among those additional nine does iCloud Backup appear. iMessage on its own is encrypted, but the moment iCloud Backup is on, a copy of the message key travels into the backup. That is exactly what makes the messages readable again.
And then there is everyone else's backup
Here is the part almost nobody considers. You can do everything right, switch your backup off or encrypt it end to end, and your messages still sit in the cloud. Because your conversation partner has the same conversation, and if they make a backup without that encryption, they save your half along with it. The EFF says it without ambiguity: "…even if you take the extra step to turn on end-to-end encryption, everyone else you converse with would have to do the same to protect their own backups." A chat always belongs to two people. You have no control over how the other one backs it up.
What authorities make of it
That this is not a theoretical risk is shown by an internal FBI document. It is dated 7 January 2021, reflects the state of November 2020, and was made public by the organisation Property of the People under a freedom-of-information law. On iMessage it states: if a user has iCloud backups enabled, "a copy of the encryption key ... backed up along with the messages" is disclosed as part of a warrant return to Apple, "enabling the messages to be read". For WhatsApp the same applied back then via the cloud detour: a search warrant to iCloud or Google Drive could yield "WhatsApp data including message content", while a warrant to WhatsApp itself returned no content.
To be honest about it, because it changes the picture: this state is from 2020, before WhatsApp's optional encrypted backup arrived in late 2021. Whoever switches that on closes this one hole. The underlying pattern remains: the encryption is not broken, the backup next to it is opened.
How the messengers handle it today
| As of July 2026 | Cloud backup of chats | Who holds the key |
|---|---|---|
| yes, end-to-end encryption optional | the provider, unless you set a password or 64-digit key | |
| Apple iMessage | via iCloud backup | Apple, unless Advanced Data Protection is on |
| Signal | Secure Backups, opt-in | 64-character key, "never shared with Signal's servers" |
| Threema | Threema Safe backs up ID and contacts, explicitly not the chats | password |
| PriChat | no automatic cloud backup | you, locally |
What happens at PriChat
This trap does not exist with us, because the convenient cloud backup does not exist. Your messages live encrypted in your browser and nowhere else; the key is created from your password when you sign in and exists only in memory, and with passkey login your passkey unlocks it instead. There is no history on the server that we could read, only a mailbox for undelivered messages: encrypted beyond our reading, deleted on delivery, and after 14 days regardless.
If you want to carry your history to a new device, that is a deliberate act here, not an automatism. You create a transfer file, encrypted with six random words that are stored nowhere in the file. Your contacts come along; the message history only if you tick that box.
No cloud backup also means no net to catch you. Lose your only device without having made a transfer file first, and the history is gone, and we cannot bring it back either. That is the price of nobody else being able to bring it back.
What this means for you
- With any messenger, check who holds the key to your backup. If it sits with the provider or in the cloud, it is not an end-to-end backup.
- Actively switch on the encrypted backup where it exists, and write down the password or key where your passport lives. Nobody can replace it for you.
- Remember that the other side backs up too. For anything truly confidential, only a messenger where no readable backup is created at all, on either side, will do.
- And decide deliberately whether you even want a permanent copy of your chats. What is stored nowhere cannot surface anywhere.