In plain English

This table compares eight messengers across things that matter for privacy. beChat is ahead on anonymity, continuous post-quantum ratcheting with NIST-standardized algorithms, European hosting, and keeping Meta and law enforcement out of your metadata. It is behind on platform support, source-code openness, formal verification, and group calls. It is in open beta on Android only. If you need iPhone, desktop, or group voice/video calls today, use something else. If you want anonymous accounts with continuous post-quantum ratcheting hosted in Europe outside US jurisdiction, beChat is built for that. For definitions of any term, see the glossary.

Comparison table

PropertybeChatSignalWhatsAppiMessageTelegramSessionSimpleXThreema
Account identifier What the service needs to know who you are.Anonymous 8-char PIN + device fingerprintPhone numberPhone numberApple ID (email or phone)Phone numberAnonymous Session IDNone (no identifiers at all)Random Threema ID (phone/email optional)
Post-quantum key exchange Uses keys that a future quantum computer cannot break.Yes (ML-KEM-1024)Yes (PQXDH, Kyber-1024)No (ECDH)Yes (PQ3, since iOS 17.4)No (ECDH)No (planned in v2)Yes (sntrup761)No (ECDH)
Continuous post-quantum ratcheting Re-keys with post-quantum secrets throughout a session, not just at the start.Yes (ML-KEM-1024 in every ratchet step)Yes (SPQR / Triple Ratchet, since Oct 2025)NoYes (PQ3 ongoing rekeying)NoNo (planned in v2)Yes (sntrup761 in ratchet since v5.6, Mar 2024)No
Post-quantum signatures Signs keys with post-quantum algorithms.Yes (ML-DSA-87)No (classical XEdDSA)NoNoNoNo (planned in v2)NoNo
Forward secrecy Each message gets a fresh key, so one break does not leak the rest.Yes (Double Ratchet with ML-KEM-1024)Yes (Double Ratchet + SPQR)Yes (Double Ratchet)YesSecret chats onlyNo (planned in v2)YesYes
Sealed sender Hides who sent a message from the server routing it.Yes (blind-RSA)YesNoNoNoYes (onion routing)Yes (no central server)No
Server-side message storage What the server can read if it wants to.Encrypted blobs onlyEncrypted blobs onlyEncrypted blobs onlyEncrypted (Apple; ADP encrypts iCloud too)Plaintext by default (cloud chats)Encrypted (onion nodes)No central storage (deleted after delivery)Encrypted, deleted after delivery
Analytics / trackers / ad SDKs Code in the app that reports on you.None in-app; push via Google FCM (no content)NoneNone in-app, but shares data with MetaApple telemetryNoneNoneNoneNone
Metadata shared with parent / authorities What the operator hands over or can be compelled to share.PIN + device fingerprint only; no contact list, no locationMinimal; last connection dayContact list, location, address book to law enforcement on warrantSubject to US CLOUD Act; ADP limits Apple accessHas disclosed data to governments on legal requestNo central logs (onion network)No identifiers to hand overSwiss law; won court case to avoid telecom ID requirements
Source code & independent audit Can anyone read the code, and has it been audited?Closed (beta); audit plannedOpen source (AGPL); formally verified (ProVerif, F*)Closed; uses Signal ProtocolClosedClients open (GPL); server closedOpen source; audited (Quarkslab)Open source (AGPL); audited (Trail of Bits)Clients open (AGPL); server closed; audited (cnlab)
Hosting & jurisdiction Where the servers live and which law applies.Independent European provider (Belgian law)US (Signal Foundation)US (Meta)US (Apple)Dubai (centralized)Distributed onion networkSelf-hostable relaysSwitzerland (Swiss law)
Platform availability Which devices can run it.Android beta onlyAndroid, iOS, desktopAndroid, iOS, desktop, webApple devices onlyAndroid, iOS, desktop, webAndroid, iOS, desktopAndroid, iOS, desktopAndroid, iOS, desktop, web
Groups, voice, video Richer messaging features.Groups + 1:1 voice/video (no group calls yet)YesYesYes (within Apple)YesVoice notes onlyYes (voice and video)Yes (1:1 video; no group calls)
In plain English

The table is the quick scan. The cards below give the honest version for each competitor, including where beChat loses. The comparison is about privacy and security, not about which app is "best overall." Different people need different trade-offs.

Competitor notes

Signal

The closest spiritual cousin to beChat. Signal pioneered the Double Ratchet and sealed sender, both of which beChat builds on. Since September 2023, Signal uses PQXDH (post-quantum key exchange with Kyber-1024). Since October 2025, Signal goes further: the Triple Ratchet (SPQR) adds a continuous post-quantum ratchet that re-keys throughout a session with ML-KEM-768, giving post-quantum forward secrecy and post-compromise security, formally verified with ProVerif and F*. beChat also has continuous post-quantum ratcheting: its Double Ratchet uses ML-KEM-1024 for every ratchet step, not just the initial handshake. Both beChat and Signal re-key with post-quantum secrets throughout a session. The remaining differences are identity (Signal needs your phone number, beChat does not), signatures (beChat uses ML-DSA-87, Signal uses classical XEdDSA), and formal verification (Signal's protocol is machine-verified, beChat's is not yet).

Honest take

If you want a polished, audited, multi-platform, formally verified messenger today and do not mind sharing your phone number, Signal is the safer choice. Both Signal and beChat have continuous post-quantum ratcheting. beChat's edges are anonymous accounts, post-quantum signatures, and European hosting. beChat trades polish, network size, and formal verification for them.

WhatsApp

WhatsApp uses the Signal Protocol for message content, so 1:1 chat encryption is technically comparable to beChat on the wire. The real gap is everything around the messages. WhatsApp is owned by Meta, an advertising company. In 2016 it began sharing user data (including phone numbers) with Facebook for targeted ads. In 2017 the European Commission fined Facebook €110 million for misleading regulators during the 2014 merger review about whether it could combine WhatsApp and Facebook data. In 2021 WhatsApp forced a new privacy policy that removed the opt-out of data sharing with Meta. Co-founder Brian Acton left in September 2017, later telling Forbes he was coached by Facebook executives to mislead European regulators and that he felt he had sold his users' privacy. An FBI document obtained by Rolling Stone in 2021 showed WhatsApp hands over metadata (contacts, address book, location) to law enforcement within minutes of a warrant. WhatsApp Channels are not end-to-end encrypted at all. Chat backups were plaintext on Google Drive and iCloud until October 2021, and E2EE backups are still opt-in. The Swiss army banned WhatsApp over CLOUD Act concerns. beChat collects no contact list, no location, no behavioral data, has no advertising parent, and is hosted in Europe under Belgian law, outside US CLOUD Act reach.

Honest take

WhatsApp has 3 billion users, group voice and video calls, full platform support, and your contacts are almost certainly already on it. That network effect is real and beChat cannot match it today. If you need to reach people who are only on WhatsApp, use WhatsApp for them. But for conversations where you do not want Meta, law enforcement, or cloud providers in the chain, beChat is built for exactly that.

iMessage

iMessage is end-to-end encrypted between Apple devices. Since iOS 17.4 (2024), iMessage uses a post-quantum protocol called PQ3 with ongoing key rekeying throughout a session, making it one of the few messengers with continuous post-quantum protection. With Advanced Data Protection enabled, iCloud backups and photos are end-to-end encrypted too; without it, Apple holds the keys. Your identity is your Apple ID (an email or phone number registered with Apple). beChat works on Android, uses anonymous accounts, and uses NIST-standardized post-quantum algorithms rather than a custom protocol.

Honest take

iMessage is seamless if everyone you know is on Apple. The moment an Android contact is involved, messages fall back to SMS or RCS, which lack end-to-end encryption. beChat runs on Android today. iMessage is locked to Apple devices and its code is closed source, so it cannot be independently audited.

Telegram

Telegram is fast and feature-rich, but its default chat mode stores messages on Telegram servers in a way Telegram can read. End-to-end encryption only exists in "secret chats," which must be enabled per conversation and are limited to two devices. Telegram has disclosed user data to governments on legal request (6,992 requests to India in 2024 alone, per Pavel Durov). beChat is end-to-end encrypted by default, always.

Honest take

Telegram beats beChat on features, speed, and network size by a wide margin. If default-on encryption and anonymous accounts are not your priority, Telegram is more capable today.

Session

Session is the closest competitor on anonymity: it uses auto-generated Session IDs (66-character numbers) and needs no phone number, like beChat. The difference is the cryptography. Session uses its own protocol over a decentralized onion network (the Session Network, formerly Loki blockchain). It does not yet implement forward secrecy, though it is planned in protocol v2 along with post-quantum cryptography. beChat uses the Double Ratchet (which provides forward secrecy) extended with NIST-standardized post-quantum algorithms (ML-KEM-1024, ML-DSA-87).

Honest take

Session is more mature, supports more platforms (Android, iOS, desktop), and has been independently audited. beChat has forward secrecy today and adds post-quantum signatures. Both are anonymous; neither has the network size of Signal or WhatsApp. Note: on 19 March 2026 the Session Technology Foundation warned it would shut down by 8 July without funding; paid staff finished on 9 April. In June 2026 the foundation confirmed it had raised enough via community donations to continue with a smaller team.

SimpleX

SimpleX goes further than any other messenger on anonymity: it uses no user identifiers at all, not even a random ID. Connections are made via one-time invitation links. SimpleX uses a double-ratchet protocol similar to Signal, and since v5.6 (March 2024) it has had post-quantum cryptography in the ratchet itself using Streamlined NTRU Prime (sntrup761), not just at the handshake. SimpleX chose sntrup761 over ML-KEM citing no known patent claims and a lower perceived risk of compromise, and explicitly criticised Signal's PQXDH for only hardening the initial key exchange without improving the ratchet. beChat also has continuous post-quantum ratcheting, using ML-KEM-1024 (NIST-standardized) in every ratchet step. Both beChat and SimpleX re-key with post-quantum secrets throughout a session. beChat uses an anonymous PIN (less radical than no identifiers, but lets you recover contacts by sharing the PIN). SimpleX relay servers can be self-hosted; beChat runs on a single independent European server.

Honest take

SimpleX has a stronger anonymity story in principle, supports more platforms, has voice and video calls, has been independently audited (Trail of Bits cryptographic design review), and had continuous PQ ratcheting before either beChat or Signal. beChat is simpler to set up (one PIN, one server), uses NIST-standardized post-quantum algorithms (ML-KEM-1024, ML-DSA-87) including post-quantum signatures which SimpleX does not have, and is hosted in Europe under Belgian law.

Threema

Threema is the closest mature anonymous competitor to beChat. Based in Switzerland, it uses a random Threema ID instead of requiring a phone number or email (both are optional). It is paid (one-time purchase), multi-platform, audited, and open-source on the client side. It won a 2021 Swiss Federal Supreme Court case preventing it from being classified as a telecom provider, so it has no legal requirement to identify users. The Swiss army recommends Threema over WhatsApp, Telegram, and Signal for troops, citing its Swiss jurisdiction and freedom from the US CLOUD Act. Threema does not use post-quantum cryptography.

Honest take

Threema is what beChat wants to be when it grows up: mature, multi-platform, anonymous, audited, and Swiss-based. It has a larger user base (10 million as of 2021) and full platform support. beChat's edges over Threema are post-quantum cryptography (Threema uses classical ECDH only) and sealed sender (Threema does not hide the sender from its server). Threema's edges over beChat are maturity, platforms, audit history, and the fact that it ships today.

Where beChat is ahead

The strongest beChat differentiators are about who knows what about you. beChat uses anonymous accounts (no phone number, no email) and a zero-knowledge Zero-knowledge (server) A design where the server that runs the service cannot read your data. The beChat server stores only scrambled blobs. It has no key to unscramble them. Think of it as a post office that moves sealed envelopes but cannot open them. Click for full glossary → server that stores only your PIN PIN (in beChat) A random 8-character code your phone generates when you install beChat. It is your account identity, like a gym locker number. It is not a password you choose, and it says nothing about who you are. Click for full glossary →, device fingerprint, public keys, and encrypted blobs. It collects no contact list, no location, no behavioral data. It is hosted on an independent European provider under Belgian law, outside US CLOUD Act reach. It has no advertising parent company. WhatsApp, by contrast, shares data with Meta and hands metadata to law enforcement on warrant. iMessage and Signal are subject to US jurisdiction.

On cryptography, beChat uses ML-KEM-1024 ML-KEM The post-quantum key-exchange algorithm beChat uses to let two phones agree on a shared secret that a future quantum computer cannot figure out. Standardized by NIST as FIPS 203. Click for full glossary → (FIPS 203) in every ratchet step, not just the initial handshake. The Double Ratchet re-keys with post-quantum secrets throughout a session, giving post-quantum forward secrecy and post-compromise security against "harvest now, decrypt later" Harvest now, decrypt later An attack where someone records your encrypted traffic today, while it is still unbreakable, and stores it for years until a future quantum computer can crack it. It is why post-quantum encryption matters now, not later. Click for full glossary → attacks. beChat also uses ML-DSA-87 ML-DSA The post-quantum signature algorithm beChat uses to prove who sent a message and that it was not tampered with. Standardized by NIST as FIPS 204. Click for full glossary → (FIPS 204) for post-quantum signatures, both NIST NIST The U.S. National Institute of Standards and Technology. It ran the multi-year public competition that chose the post-quantum algorithms beChat uses (FIPS 203 and 204). It also standardized AES and SHA-3. Click for full glossary →-standardized. beChat is the only messenger on this list using NIST-standardized post-quantum algorithms for both key exchange and signatures. Signal\'s SPQR and SimpleX\'s sntrup761 ratchet also provide continuous post-quantum ratcheting; beChat matches that with ML-KEM-1024 and adds post-quantum signatures on top. Post-quantum signatures protect authenticity at the moment of use. They are not an HNDL surface (a future quantum computer cannot retroactively forge a past signature to unlock a closed session), but they do protect against future quantum key-substitution attacks during active sessions.

Where beChat is behind

beChat is in open beta on Android only. There is no iOS, desktop, or web client yet. Group voice and video calls are not available yet (1:1 calls and group text chats are). The client is closed source and has not been independently audited. Signal\'s protocol is formally verified (ProVerif, F*); beChat\'s is not. The user base is small. beChat depends on Google FCM for Android push delivery (encrypted payloads, no message content, but Google sees delivery metadata and a token tied to your Play Store install). If any of those matter to you today, Signal, Threema, or SimpleX are more capable right now.

How to choose

  • If you want the most anonymous messenger: SimpleX (no identifiers at all) or Session. beChat and Threema are close behind, with simpler setup.
  • If you want the strongest post-quantum protection against harvest-now-decrypt-later: beChat (ML-KEM-1024 in every ratchet step), Signal (SPQR continuous ratchet), SimpleX (sntrup761 in ratchet since March 2024), or iMessage (PQ3, Apple only). All four re-key with post-quantum secrets throughout a session.
  • If you want NIST-standardized PQ for both key exchange and signatures: beChat is the only option on this list.
  • If you want open source and independent audit: Signal (formally verified), Session (Quarkslab audit), SimpleX (Trail of Bits audit), or Threema (cnlab audit). beChat is closed beta with an audit planned.
  • If you want to keep Meta and law enforcement out of your contacts and metadata: beChat. WhatsApp shares data with Meta and hands metadata to authorities on warrant.
  • If you want a mature, anonymous, European messenger today: Threema. It ships now, is audited, and is Swiss-based.
  • If your contacts are already on one app: use that one. A messenger is only useful if the person you want to talk to is on it.
  • If you want all of the above at once: no single app offers anonymity, continuous post-quantum ratcheting, open-source audit, voice and video, and a large network today. You have to pick which trade-offs matter most.

FAQ

Is beChat better than Signal?

Not in general. Signal is mature, audited, multi-platform, open source, and formally verified. beChat is in open beta on Android. Both Signal and beChat have continuous post-quantum ratcheting: Signal uses SPQR (Triple Ratchet, ML-KEM-768, since October 2025) and beChat uses ML-KEM-1024 in every ratchet step. Both re-key with post-quantum secrets throughout a session. beChat differs from Signal in three ways: anonymous accounts (no phone number), post-quantum signatures (ML-DSA-87, which Signal does not have), and European hosting under Belgian law. Signal differs from beChat in three ways: formal verification (ProVerif, F*), multi-platform support, and a large user base. If anonymity and European jurisdiction matter more to you than polish, network size, and formal verification, beChat is the stronger fit. Otherwise Signal is the safer choice today.

Does beChat work on iPhone?

Not yet. beChat is in open beta on Android only. iOS is planned but not in public testing. Signal, WhatsApp, Telegram, Session, SimpleX, and Threema all support iOS today.

Which messenger is most anonymous?

SimpleX uses no identifiers at all. Session uses anonymous Session IDs. Threema uses a random ID with optional phone/email. beChat uses an anonymous 8-character PIN and device fingerprint. Signal, WhatsApp, Telegram, and iMessage all require a phone number or Apple ID. beChat, Session, SimpleX, and Threema are the options that never require a phone number. One caveat for beChat: the device fingerprint is hardware-derived and stable, so it is a non-rotating identifier. You can burn a phone number by getting a new SIM; you cannot rotate a device fingerprint without changing hardware.

Which messengers are post-quantum?

beChat, Signal, iMessage, and SimpleX all have post-quantum or quantum-resistant key exchange, and all four have continuous post-quantum ratcheting (re-keying with PQ secrets throughout a session, not just at the start). beChat uses ML-KEM-1024 (FIPS 203) in every ratchet step and ML-DSA-87 (FIPS 204) for signatures, both NIST-standardized. Signal uses PQXDH (Kyber-1024) for key exchange and SPQR (Triple Ratchet, ML-KEM-768) for continuous ratcheting since October 2025. iMessage uses PQ3 with ongoing rekeying. SimpleX uses sntrup761 in its ratchet since v5.6 (March 2024), chosen over ML-KEM for its lack of known patent claims. WhatsApp, Telegram, Session, and Threema use classical cryptography that a future quantum computer could break. beChat is the only one that uses NIST-standardized post-quantum algorithms for both key exchange and signatures, and one of four with continuous post-quantum ratcheting.

Does beChat have voice and video calls?

Yes, beChat supports 1:1 voice and video calls. Group voice and video calls are not available yet. Group text chats are available. Signal, WhatsApp, Telegram, and Threema all support voice and video calls today. If group calls are essential to you, beChat is not ready yet.

Should I switch from WhatsApp to beChat?

It depends on what you are trying to protect. WhatsApp uses the Signal Protocol for message content, so your 1:1 messages are well encrypted on the wire. But WhatsApp is owned by Meta, shares your phone number and usage data with Facebook, and in May 2017 the European Commission fined Facebook (not WhatsApp itself) €110 million for misleading regulators during the 2014 merger review about the technical difficulty of combining WhatsApp and Facebook data. The merger clearance stood. A 2021 FBI document showed WhatsApp hands over contacts, address book, and location data to law enforcement within minutes of a warrant. WhatsApp Channels are not end-to-end encrypted at all. If your concern is just that other people cannot read your messages, WhatsApp is fine. If your concern is that Meta, cloud providers, and law enforcement should not have your contacts, location, and metadata, beChat is built for exactly that. The trade-off is network size: WhatsApp has 3 billion users, beChat does not.

Learn more

Read how beChat works, the guide to post-quantum encryption, the full security model, or the FAQ. Look up any term in the glossary. Ready to try it? Join the Android beta.