10 Total
0 High severity
7 Medium severity
3 Low severity
Summary

This is Signal's combined Terms of Service and Privacy Policy, covering how the company handles your messages, calls, phone number, and account data when you use the Signal app. The most important thing to know is that Signal cannot read your messages or listen to your calls because everything is end-to-end encrypted — and Signal explicitly states it will never sell or monetize your personal data. Your phone number is required to create an account and is shared with third-party providers for verification purposes, so be aware that some minimal account data does leave Signal's systems.

Technical Summary

This document governs use of Signal Messenger LLC's private messaging and calling services, establishing contractual terms and data practices under California law with no explicit GDPR or CCPA legal basis articulations. The most significant obligations include Signal's categorical commitment to never sell, rent, or monetize personal data, and its technical architecture ensuring end-to-end encryption that prevents even Signal itself from accessing message content. Notably, the document imposes a $100 aggregate liability cap on all claims against Signal — an unusually low ceiling for a communications service — and requires all disputes to be resolved exclusively in California federal or state courts, with no arbitration clause or class action waiver present. The policy engages GDPR, CCPA, COPPA (minimum age 13), and FTC Act Section 5 frameworks, though it lacks explicit GDPR legal basis statements, data subject rights procedures, or a Data Protection Officer designation required for EU compliance. The effective date of May 25, 2018 coincides with GDPR enforcement commencement but the document does not address EU-specific rights such as erasure, portability, or objection, creating material compliance gaps for European user populations.

Evidence Provenance
Captured April 18, 2026 07:55 UTC
Document ID CA-D-000305
Version ID CA-V-000616
Wayback Machine View archived versions →
SHA-256 22835e8785154a2346898a96208f336bedc01925a54a28e8d2128b30ec67cc1e
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Institutional Analysis

🔒 Institutional analysis locked

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Upgrade to Professional — $149/mo
Change Timeline
View full version history (0 captures) →
Medium Severity — 7 provisions
Low Severity — 3 provisions

Cross-platform context

See how other platforms handle $100 Aggregate Liability Cap and similar clauses.

Compare across platforms →

Applicable Regulations

CFAA
United States Federal
GDPR
European Union