For years, the privacy debate around messaging apps has focused almost entirely on end-to-end encryption. From a professional cyberintelligence perspective, that view is incomplete.
The right question is not only whether a platform can read our messages, but also what it can learn without accessing the content at all.
That is where metadata becomes strategically important. Metadata describes a communication: who communicates with whom, when, how often, for how long and from which technical environment. It does not contain the message itself, but it can reveal very precise behavioural patterns.
The value of metadata in the digital age
Many users believe that if messages are encrypted, privacy is guaranteed. Reality is more complex.
In intelligence work, digital investigation and social network analysis, metadata can be as valuable as the content of a conversation, and sometimes more valuable.
A single message saying “See you tomorrow” may reveal little. A map of identities, schedules, frequency of contact, call duration, shared groups, location changes and periods of activity or inactivity can reveal far more.
WhatsApp: content privacy, metadata collection
WhatsApp uses end-to-end encryption to protect messages, calls and shared files between users. However, its privacy model still allows a broad range of platform usage information to be collected.
Time-related information
Registration date, connection times, last seen status, online status, frequency of use and session duration can be used to build detailed time-based profiles.
Relationship information
WhatsApp can know which users interact with each other, how often and through which features. Even when content remains encrypted, communication patterns are still visible to the platform.
Groups, profile and technical information
Group names, group images, descriptions, profile pictures, status information, device model, operating system and diagnostic logs can all provide contextual information about a person or an organisation.
Threema: architecture focused on data minimisation
Threema follows a significantly different design philosophy. While WhatsApp starts from the user’s phone identity, Threema works with random identifiers that do not have to be linked to a phone number or email address.
The phone number is optional, the email address is optional and the user can operate only with a randomly generated ID. This greatly reduces the ability to correlate a digital identity with a physical identity.
Metadata minimisation
One of Threema’s core principles is to store as little information as possible: deleting messages from the server after delivery, avoiding permanent content storage and reducing dependence on identifying information.
The role of a VPN: what it can and cannot protect
A common mistake is to think that a VPN removes every possibility of tracking. It does not.
A trusted VPN can hide the real IP address, make IP-based geolocation harder, prevent the internet provider from seeing some destinations and protect traffic on unsafe networks. But it cannot prevent an application from knowing what happens inside its own ecosystem.
WhatsApp with a VPN
WhatsApp will still know contacts, groups, usage times, communication patterns and frequency of interaction. The VPN only hides the original IP address.
Threema with a VPN
The combination is considerably more effective: there is no obligation to provide a phone number, no obligation to provide an email address, the IP address is protected by the VPN and the user ID is not directly tied to a real identity.
Conclusions
The digital privacy debate should not stop at end-to-end encryption. Encryption protects the content of a communication, but metadata can still provide a large amount of information about people.
WhatsApp offers strong content protection, but it still has considerable capacity to collect information related to platform usage. Threema, by contrast, focuses on data minimisation and reducing identifying metadata.
From a cyberintelligence perspective, the main difference between the two platforms is not only the strength of encryption, but the amount of auxiliary information they generate and retain.

