232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Which messaging apps train AI on your data?

Of the 9 messaging apps on file, 6 are graded: 2 train on your data by default and 4 don't. The other 3 have a policy that doesn't say either way. The best graded is Signal (A) and the worst is Loom (F).

9 APPS TRACKED IN THIS CATEGORY · WORST FIRST

Can they read your messages at all, and do they train on them?

Every story about messaging privacy is about encryption. The apps that carry your messages, calls, mail and meeting recordings are graded here on a narrower question: does that content train a model, and how hard is it to stop. Read together, they divide first by reach, because some say they can’t read the content at all. Then by what the document says: training with no way out, training with a form to find, a commitment not to, or a document that leaves the question open.

The ones that say they cannot read it

Signal’s policy says it plainly: “Signal cannot decrypt or otherwise access the content of your messages or calls.” The document has no training, machine-learning or AI language anywhere, and that absence isn’t what earns the grade. The incapacity is. What Signal does hold, the phone number you register and the tokens and keys to route messages, sits outside the question.

Tuta’s statement is about reach, not intent: “Tutao GmbH has no access to the unencrypted data.” Training, machine learning and AI are never mentioned, and as with Signal the grade rests on the incapacity, not the silence. The same document supplies the caveat. Mail arriving from outside Tuta can arrive unencrypted, and is encrypted for the user before it’s stored, so plaintext crosses its servers on the way in. Tuta doesn’t claim to read it.

The ones that say enough to grade

Loom lists “machine learning and artificial intelligence model training” among the ways it develops and improves the Services, without saying which inputs are covered: recordings, transcripts or usage data. The opt-out language the policy does contain covers marketing email, analytics and US state-privacy disclosures, none of which touch training. The one control that reaches it is the objection right, bounded to the EEA and UK. Outside them nothing undoes the clause, which is what an F records.

WhatsApp is graded in tiers and carries the worst of them. For personal messages and calls the European Region policy says “No one else, not even WhatsApp, can read or listen to them”, an A on its own. Chats with AI at Meta inside the app are graded on Meta’s generative-AI page, which names those interactions as a training source. On by default once you use the feature, with an objection request “through your WhatsApp account” as the way out. A form to find, so a D.

Unusually broad for a negative commitment: Zoom doesn’t use “audio, video, chat, screen sharing, attachments or other communications-like Customer Content” to train its own or its third-party AI models. The sentence before it permits use of data “to develop, test, and improve Zoom products and services” where settings authorise it. The intelligent features may process Customer Content by AI, but “solely to provide the intelligent features”. Processing, not training. Off by default is what a B is.

Fastmail’s policy now carries the sentence: “Fastmail does not and has never trained AI on customer data.” It went in after Fastmail said so by email and was asked to put it where a customer could cite it. The reply is printed on the verdict. B and not A because it’s a commitment and not a stated inability, and because it sits under a third-party heading, beside the line that the Anthropic connection runs “with model training switched off”.

The ones that leave the question open

Discord’s policy has no form of the word train and no standalone AI. It bridges content and models once, on moderation. Reported content, rule-breaking content and material already public may be used “to create systems and models that can be automated to more swiftly detect, categorize, and take action against prohibited content or conduct”. Reported content can include private messages. For messages nobody reports, and for anything beyond safety enforcement, the document says nothing. Answered for anti-abuse models, unanswered for the rest.

Telegram’s policy contains no form of train, no machine learning and no artificial intelligence. A documented absence, not an unread document. What it did carry was a sweeping assurance that data wasn’t used for “ad targeting or other commercial purposes”, which a reader could reasonably have read as covering training. That sentence survives narrowed, to the contents of “private chats” and contact lists. Public groups and channels have left it. Nothing was added about training either way.

Both of Threema’s privacy policies govern its website, and say so in their opening lines: the “Detailed Privacy Policy For the Threema Website” and the “General Privacy Policy For the Threema Website”. Neither mentions messages, calls or the app’s data handling. Threema is widely understood to be end-to-end encrypted. That isn’t evidence, and no archivable document says what the messenger can reach.

Every quotation above is the company’s own words, read from a dated, archived copy of its document. The check date and the archived copy are on each verdict, and every grade on this page is the one on the company’s own entry. An A here is a statement of incapacity, not a promise. UNCLEAR is a finding about the document, never an accusation about the company. A policy that comes to answer the question is re-read against it. How grades are set · Right of reply

Side by side

3 pairs of messaging apps people choose between, with both verdicts on one page.