10 Total
0 High severity
8 Medium severity
2 Low severity
Summary

Signal's combined Terms of Service and Privacy Policy establish the operational parameters for the Signal messaging platform, specifying data collection practices and service usage rules. The policy establishes that Signal collects phone numbers for account creation and implements end-to-end encryption for message and call content, which renders message content and call audio inaccessible to Signal's systems. The agreement authorizes users to contact Signal at privacy@signal.org to manage account data and exercise data access or deletion rights.

Technical / Legal Breakdown

This document governs use of Signal Messenger LLC's messaging and calling services, combining Terms of Service and a Privacy Policy under California law, with the stated purpose of operating end-to-end encrypted communications. The terms assert that Signal does not sell, rent, or monetize personal data or content in any way, that message content cannot be decrypted or accessed by Signal, and that minimal technical metadata (authentication tokens, push tokens, keys) is retained only as required to operate the service. Notably, the document's data minimization posture is substantially narrower than typical consumer messaging platforms, reflecting Signal's architectural commitment to collecting only a phone number for registration and hashing contact data for discovery; however, the policy's compelled disclosure provision permits sharing data in response to applicable law, regulation, or enforceable governmental requests without explicit notice to users, which is standard but operationally significant given Signal's user base. The policy engages GDPR, CCPA, COPPA (minimum age 13), and FTC Act consumer protection frameworks; GDPR applicability is not explicitly addressed in the document, though the effective date of May 25, 2018 coincides with GDPR enforcement commencement, suggesting awareness of that framework. The absence of explicit EU/EEA data transfer mechanisms, a Data Protection Officer designation, or a dedicated GDPR lawful basis statement represents a material gap for EU-facing compliance review.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 8 provisions
Low — 2 provisions

Monitoring

Signal has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle $100 Aggregate Liability Cap and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 18, 2026 07:55 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000305
Version ID CA-V-000616
SHA-256 22835e8785154a2346898a96208f336bedc01925a54a28e8d2128b30ec67cc1e
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans