07.06.26 · The Cape Team

Are Instagram Messages Encrypted? A Clear Breakdown of Privacy in Instagram DMs

Are Instagram messages encrypted? , not anymore. Instagram is removing end-to-end encryption (E2EE) for direct messages, prompting many privacy-conscious users to deactivate their accounts, and raising a series of questions for those who have decided to stay (at least for the time being), including:

  • Are Instagram DMs private without E2EE?
  • How much control does Meta have over sensitive data once this protection is removed?
  • How does this affect past conversations in Instagram DMs?
  • What are some privacy-focused alternatives to Instagram messages?

This guide explains how Instagram DM encryption works and outlines the potential consequences of its removal for the trust model, focusing on user privacy and security when using these messaging features.

Are Instagram DMs Encrypted?

As of May 2026, Instagram no longer provides end-to-end encryption (E2EE) for direct messages. Previously, E2EE ensured that no third party, including Meta, could access message or call content, and that messages could only be decrypted by the participants in a conversation.

Before E2EE was removed, devices involved in encrypted conversations generated and used cryptographic keys to protect message content. Messages were encrypted when sent and remained inaccessible until they reached the recipient’s device, where they could be decrypted only with the recipient's device-specific key for that conversation.

The same mechanism previously applied to voice messages and video calls on Instagram. While some message-related features, such as chat themes or reporting tools, were never part of the end-to-end encrypted content itself, message and call contents were protected by E2EE until its removal.

By announcing the end of E2EE support after previously defining it as a key mechanism for Instagram DM privacy, the company is indirectly but unambiguously admitting that messages are no longer private and are accessible to Meta. This change means that E2EE is no longer an opt-in option and will be removed altogether.

In response to this shift, the Meta spokesperson has indicated that users who want E2EE messaging can , highlighting the difference between Instagram DMs and platforms built for encrypted, private communication. However, this change also raises the question of whether social media messaging features can ever truly be considered safe in the first place.

Why Will Instagram DMs No Longer Be Encrypted?

According to a Meta spokesperson, the initial reasoning behind this decision was the reported low user engagement with the option for encrypted DMs.

Another potential factor may be the criticism Meta faced when E2EE was first introduced across Facebook Messenger and Instagram, particularly regarding underage user safety.

The Virtual Global Taskforce (VGT), including Europol, raised concerns that Meta’s encryption model could pose a threat to child safety on its platforms, as potential evidence regarding child abuse would be more difficult to access within an E2EE framework.

In response to these concerns raised in 2023, Antigone Davis, Meta’s Head of Safety, stated that even with E2EE, Meta could still rely on user reports, account information, and other available signals to identify potential abuse. However, even after child safety concerns were highlighted in the New Mexico trials, Mark Zuckerberg, Meta’s CEO, concluded that strong encryption represents a positive change more than a risk.

While the removal of Instagram end-to-end encryption may be perceived as a shift toward a more security-focused rather than privacy-centric environment, the long-term consequences of this decision for both aspects of the user experience could be significant.

Will Old Instagram Messages Remain Encrypted?

As announced in Instagram’s Help Center, users whose chats are affected by this change will receive instructions on how to preserve messages and media before encryption is discontinued. Instagram has also noted that users may need to update their app to the latest version in order to download this content.

Currently, downloading encrypted chats from Instagram is only possible on desktop and only if secure storage has been enabled. The downloaded data can include both sent and received messages, as well as media attachments such as images and files.

To download your data from secure storage, you need to:

  1. Select Menu in the bottom left corner, then click Your Activity
  2. Click Download End-to-End Encrypted Data at the bottom of the page, then click Next (PIN may be required at this step)
  3. Type in your Instagram account password and select Request download

While the contents may not be automatically deleted if they’re not downloaded, it appears that older chats will lose their E2EE status, making them more susceptible to Meta’s access. It remains unclear whether encrypted chats and data that haven’t been backed up will still be accessible via Instagram, particularly given Meta’s guidance to download them in advance.

The fact that Meta can eliminate the option of E2EE after it was once available highlights how privacy and security on social media apps and mainstream platforms can change abruptly and ultimately remain outside of user control.

The Risks of Instagram End-to-End Encryption Being Removed

Privacy in messaging apps concerns more than sensitive conversations, and it doesn’t imply that users have something to hide. Instead, it is about abuse prevention as message content can be exposed and potentially used in harmful contexts, such as:

  • Targeted ads based on message content: Unprotected information in Instagram DMs could, in theory, be processed and used to deliver targeted ads based on specific keywords.
  • Legal demands: Instagram messages no longer being encrypted means their contents can now be subject to legal processes, allowing government bodies to request access to private conversations.
  • Data leaks: In a that resulted in billions in settlement-related costs, Meta shareholders accused Mark Zuckerberg of mishandling the personal data of millions of Facebook users, some of which was accessed by Cambridge Analytica and used without consent in a political campaign.
  • AI training: logging its employees’ keystrokes and mouse clicks to train AI; without E2EE, this raises questions about whether messaging data could be included in such processes.

The removal of Instagram's private message encryption represents a major shift in the trust model. Without E2EE, message content is no longer protected from platform-side or third-party access in the same absolute way, affecting mechanisms such as retention, internal processing, and potential future use of that data. Without E2EE, the trust boundary moves from conversation participants to the messaging platform, requiring users to trust it with their messages.

The Reaction of Privacy Advocates to Instagram Removing Encrypted Messages

On April 8, 2026, in response to Meta's decision to eliminate E2EE, the Steering Committee of the Global Encryption Coalition, comprising the Center for Democracy & Technology, Global Partners Digital, the Internet Freedom Foundation, the Internet Society, and Mozilla, about this Instagram DM privacy risk.

The Coalition called on Meta to reverse this decision, urging the company to maintain E2EE as the default for Instagram messages, as it already does on WhatsApp and Messenger. In its official statement, the Coalition described encryption as a key mechanism for protecting users’ security, privacy, and fundamental human rights.

The statement also points to Meta’s prior advocacy for encryption, including efforts to defend it against government pushbacks, as well as Mark Zuckerberg’s 2019 position that private communication would increasingly move toward encrypted services.

The key privacy risks identified by the Committee in light of this decision include:

  • Increased risk of surveillance and interception
  • Safety concerns for vulnerable groups, such as the LGBTQ+ community
  • A precedent that could extend to other forms of communication

The statement concludes with a clear message:

Unknown block type "blogQuote", please specify a serializer for it in the `serializers.types` prop

Private Messaging Alternatives to Instagram

To be able to fully understand how privacy functions in messaging apps, it is important to distinguish between three categories:

  1. Direct messages (DMs) within social media platforms
  2. Private chats with encryption enabled
  3. Secure messaging solutions as a security model

Social media messaging platforms are product features within an ad-driven social network, not secure messaging systems. Private messages on these platforms are only private until the platform decides otherwise, which is why Instagram DMs were never the right place for sensitive conversations, and the removal of E2EE makes this distinction more apparent.

The following table outlines the to Instagram DMs:

Platform

Key Security Features

Availability and Pricing

Threema

  • Full anonymity—no email address or phone number required
  • Unique Threema ID assigned to each user
  • Chats and contacts are stored on user devices rather than Threema servers
  • E2EE for all communication, data, and even status messages

No free version; one-time payment plan for individuals (Private, $6), and three business plans (annual payment):

  1. Core ($3/month per user)
  2. Professional ($5/month per user)
  3. OnPrem (custom pricing)

Session

  • Signing up with Session IDs; no email address or phone number required
  • Uses onion routing to encrypt data in multiple layers across distributed nodes
  • Open-source for transparency

Completely free; no ads

Briar

  • No personal information required; users create a unique nickname and password
  • Peer-to-peer encrypted messaging (no central servers)
  • Screenshots or screen recordings are restricted
  • No video or voice chat

Free; available on Android only

GhostPost

  • No personal information required; users create a unique screen name
  • Anonymous social media app with a zero data collection approach

Completely free

Why App-Level Encryption Isn’t Enough Without Network Protection

Encryption represents the core of messaging privacy and, according to privacy organizations and advocates, should be non-negotiable in online spaces. The risks of trusting a messaging platform, especially one that can remove key privacy protections and move away from encryption, are far-reaching and potentially detrimental to privacy and security.

Choosing a secure messaging service in place of Instagram DMs is the key step toward safer communication. However, app-level encryption is only one part of a broader privacy puzzle, the integrity of which largely your data travels through.

Even the most secure messaging app still relies on built on interconnected, often implicit trust, where networks and each other. This model leaves room for surveillance, data exposure, and further exploitation at the carrier level—often outside the app's control.

Rather than relying on networks and platforms, you can reduce your exposure by choosing a such as , which minimizes both the amount of data collected and the in the first place.

Cape: The Carrier Built for Security and Privacy

Cape is a privacy-first mobile carrier designed to keep your communications safe from surveillance and misuse. Unlike traditional cell phone plan providers, our business model centers around providing you with premium and secure call, text, and data, rather than harvesting and selling your information.

Our service is built from the ground up with privacy and security at its core, offering unique features like:

Privacy & Security Feature

Description

Cape doesn’t ask for your name, address, or Social Security number. We only collect the information necessary to provide service, and we retain that information for the minimum amount of time possible.

Traditional carriers rely on a fixed International Mobile Subscriber ID (IMSI) to connect your device to cellular networks. This is a vulnerability that lets carriers, advertisers, and bad actors identify and track your device. Cape lets subscribers automatically rotate their IMSI every 24 hours, making it infinitely more difficult to track you or your device.

Many services ask for your phone number, but sharing it exposes you to spam, scammers, data brokers, and a variety of other risks. VoIPs, on the other hand, don’t work with 2FA, cost extra, and aren’t encrypted. With Cape, you get two free additional SMS/MMS lines that are middle-to-end encrypted.

Most U.S. carriers store your call and text metadata for years, sometimes indefinitely. Cape is built to forget, so call data records (CDRs) are deleted after just 24 hours.

Cape nullifies the threat of SIM swapping by completely removing humans from the loop. During signup, you receive a 24-word phrase that generates a private key tied to your number. This effectively means that no one (but you) can move your number to a new carrier or device, not even Cape.

Legacy network protocols, like SS7, leave you vulnerable to hackers that can track your location, intercept your calls and texts, and steal sensitive information. Cape’s Network Lock relies on a proprietary signaling proxy to verify that your device’s physical location matches the network it’s trying to attach to.

If we detect anything out of the ordinary, Cape automatically blocks the connection, nullifying the potential threat.

Traditional voicemail systems are outdated, unencrypted, and another security hole bad actors can exploit to gain access to your sensitive information. Cape encrypts all voicemails, ensuring only you can access them.

While roaming, your phone connects to local telecom providers to enable service. But, who knows who might be listening on the other end. Cape provides you with peace of mind by routing your traffic through our U.S.-based mobile core, ensuring your identity, data, and communications remain private and secure.

Ditch Legacy Carriers: Get Cape Today

Cape is a “Heavy” Mobile Virtual Network Operator (MVNO), meaning we and provision our own SIMs. This gives us full control over how accounts are authenticated and what data is collected (and for how long), and is how we are able to provide privacy and security features no other carrier on the market can offer.

and enjoy the peace of mind, knowing you are fully protected against scammers, hackers, bad actors, and other mobile threats.

To help protect more than just your phone, we’ve partnered with Proton. As a new Cape subscriber, you can choose between for just $1 for six months.

Share it

Signup Callout

Switch to Cape,
America's privacy-first mobile carrier.

Protect yourself with premium, secure cell service.

Sign up now