Is RCS as Private as Signal or WhatsApp?

Short answer

Not quite, and the difference is structural rather than a matter of one being better built. Signal and WhatsApp encrypt every conversation by default on every platform, because both ends run the same app. RCS encryption is conditional — it depends on both phones and on whether both carriers have shipped it — so it is something you have to check rather than something you can assume.

The structural difference

The important distinction is not how strong the encryption is. All three use well-regarded modern cryptography, and the mathematics is not where they differ.

The difference is in what has to be true for it to apply.

Signal and WhatsApp are apps. Both ends run the same software written by the same organisation. That organisation decides that every conversation is encrypted, ships it, and it is true — on every platform, on every carrier, in every country, from the day you install it. There is no condition to check.

RCS is a carrier service built from an industry specification. For an encrypted conversation between an iPhone and an Android phone, the encryption has to be implemented by Apple, implemented by Google, defined compatibly in the shared specification, and enabled by both carriers on both lines. Any one of those missing and you have RCS without encryption — which still looks and behaves like modern messaging.

So the honest comparison is: with Signal you can assume, with RCS you have to check. That is the whole difference, and it is a big one in practice even when the underlying cryptography is comparable.

Between two Android phones both on Google Messages, incidentally, RCS is on much stronger ground — both ends are the same app, which is structurally the Signal situation rather than the cross-platform one. The difficulty is specific to bridging two ecosystems.

Three things worth comparing separately

“Private” bundles together at least three questions, and the three systems rank differently on each.

Content in transit

Signal: encrypted, always. WhatsApp: encrypted, always. RCS: conditional, as above.

For this question alone, RCS with encryption active is genuinely comparable. The problem is the word “with”.

Backups

This is where more real-world exposure lives than in transit, and where the picture gets messier for everyone.

Signal: backups are local and encrypted with a key you hold. Strongest position, at the cost of being easy to lose your history.

WhatsApp: offers end-to-end encrypted backups, but you have to switch it on, and by default your history may sit in a cloud backup the provider can open.

RCS: depends on your phone’s backup arrangement, not on RCS itself. On an iPhone, the interaction between iCloud Backup and Advanced Data Protection is the thing that matters. On Android it depends on your backup settings.

For all three, the same warning applies and it is the one people miss: it takes both of you. Your messages are in the other person’s backup as well.

Metadata

Who you talked to, when, how often. Frequently more revealing than content.

Signal: designed to minimise what it holds. The strongest position of the three by a clear margin, and the main reason people who need privacy choose it.

WhatsApp: encrypts content but retains substantial metadata, and is part of a larger commercial group.

RCS: metadata necessarily passes through your carrier and, on most networks, through a messaging back end. Structurally, RCS cannot hide this — routing a message through the phone network requires the network to know where it is going.

What RCS is actually better at

It would be easy to read the above as “RCS loses”, and for a privacy comparison alone it does. But privacy is not the only axis, and RCS has one enormous structural advantage.

It requires nothing of the other person. No install, no account, no persuading your family to switch. It is simply how texting works now. That means it protects the vast majority of ordinary conversations that would otherwise be plain SMS — which has no encryption at all — and it does so without anyone deciding to care about it.

That is a real and underrated win. The realistic alternative to RCS is not Signal; it is SMS. Measured that way, conditional encryption applied automatically to everyone beats excellent encryption applied only to the small number of people who install something.

RCS also does not require an account, does not have your contact list on a company’s servers by design, and does not depend on one company continuing to exist and behave well.

Which conversations belong where

A practical division rather than a maximalist one.

Ordinary conversation — logistics, chat, photos, plans. RCS is fine. It is a substantial improvement on SMS and it costs you nothing to use.

Things you would rather were private but are not dangerous — health details, money, family matters. Use Signal or WhatsApp. Not because RCS will necessarily fail, but because “check the padlock every time” is not a habit anyone sustains, and unconditional beats conditional for anything you would rather not have to think about.

Things where exposure would cause real harm — journalism, legal matters, safety. Signal, with disappearing messages, verified safety numbers and careful backup settings. Do not rely on a prediction from a website — including this one — for that category.

Anything you send to a business, or a business sends to you. Assume it is readable by the messaging provider handling it. That is a different track entirely.

The honest summary

RCS is a large improvement on SMS and a genuine step forward for ordinary messaging, made more valuable by the fact that it happens automatically. It is not a replacement for a dedicated encrypted messenger, and it was never designed to be.

The specific gap is not the cryptography. It is that RCS gives you an answer that depends on your phone, their phone and two carriers, while Signal gives you the same answer every time. If you want to know which answer you personally have right now, that is exactly what our checker is for — and if you find yourself needing to check often, that is itself a signal about which tool to use for that conversation.

Check your own setup

Before comparing RCS to anything, find out whether your own RCS conversations are actually encrypted right now.

Run the checker

Version facts on this page: not verified yet — the site-wide verification pass has not been completed. See the update log

Related guides

Published 1 September 2026. Last reviewed 1 September 2026. This guide depends on facts F2, F3, F11, F15, F25, F27 in our verification table — if one of those changes, this page gets rewritten and the change is logged in the update log.