Which messaging apps train AI on your data?
Of the 9 messaging apps on file, 6 are graded: 2 train on your data by default and 4 don't. The other 3 have a policy that doesn't say either way. The best graded is Signal (A) and the worst is Loom (F).
Can they read your messages at all, and do they train on them?
Every story about messaging privacy is about encryption. The apps that carry your messages, calls, mail and meeting recordings are graded here on a narrower question: does that content train a model, and how hard is it to stop. Read together, they divide first by reach, because some say they can’t read the content at all. Then by what the document says: training with no way out, training with a form to find, a commitment not to, or a document that leaves the question open.
The ones that say they cannot read it
Signal’s policy says it plainly: “Signal cannot decrypt or otherwise access the content of your messages or calls.” The document has no training, machine-learning or AI language anywhere, and that absence isn’t what earns the grade. The incapacity is. What Signal does hold, the phone number you register and the tokens and keys to route messages, sits outside the question.
Tuta’s statement is about reach, not intent: “Tutao GmbH has no access to the unencrypted data.” Training, machine learning and AI are never mentioned, and as with Signal the grade rests on the incapacity, not the silence. The same document supplies the caveat. Mail arriving from outside Tuta can arrive unencrypted, and is encrypted for the user before it’s stored, so plaintext crosses its servers on the way in. Tuta doesn’t claim to read it.
The ones that say enough to grade
Loom lists “machine learning and artificial intelligence model training” among the ways it develops and improves the Services, without saying which inputs are covered: recordings, transcripts or usage data. The opt-out language the policy does contain covers marketing email, analytics and US state-privacy disclosures, none of which touch training. The one control that reaches it is the objection right, bounded to the EEA and UK. Outside them nothing undoes the clause, which is what an F records.
WhatsApp is graded in tiers and carries the worst of them. For personal messages and calls the European Region policy says “No one else, not even WhatsApp, can read or listen to them”, an A on its own. Chats with AI at Meta inside the app are graded on Meta’s generative-AI page, which names those interactions as a training source. On by default once you use the feature, with an objection request “through your WhatsApp account” as the way out. A form to find, so a D.
Unusually broad for a negative commitment: Zoom doesn’t use “audio, video, chat, screen sharing, attachments or other communications-like Customer Content” to train its own or its third-party AI models. The sentence before it permits use of data “to develop, test, and improve Zoom products and services” where settings authorise it. The intelligent features may process Customer Content by AI, but “solely to provide the intelligent features”. Processing, not training. Off by default is what a B is.
Fastmail’s policy now carries the sentence: “Fastmail does not and has never trained AI on customer data.” It went in after Fastmail said so by email and was asked to put it where a customer could cite it. The reply is printed on the verdict. B and not A because it’s a commitment and not a stated inability, and because it sits under a third-party heading, beside the line that the Anthropic connection runs “with model training switched off”.
The ones that leave the question open
Discord’s policy has no form of the word train and no standalone AI. It bridges content and models once, on moderation. Reported content, rule-breaking content and material already public may be used “to create systems and models that can be automated to more swiftly detect, categorize, and take action against prohibited content or conduct”. Reported content can include private messages. For messages nobody reports, and for anything beyond safety enforcement, the document says nothing. Answered for anti-abuse models, unanswered for the rest.
Telegram’s policy contains no form of train, no machine learning and no artificial intelligence. A documented absence, not an unread document. What it did carry was a sweeping assurance that data wasn’t used for “ad targeting or other commercial purposes”, which a reader could reasonably have read as covering training. That sentence survives narrowed, to the contents of “private chats” and contact lists. Public groups and channels have left it. Nothing was added about training either way.
Both of Threema’s privacy policies govern its website, and say so in their opening lines: the “Detailed Privacy Policy For the Threema Website” and the “General Privacy Policy For the Threema Website”. Neither mentions messages, calls or the app’s data handling. Threema is widely understood to be end-to-end encrypted. That isn’t evidence, and no archivable document says what the messenger can reach.
Side by side
3 pairs of messaging apps people choose between, with both verdicts on one page.