Are Instagram messages encrypted? As of May 8, 2026, not anymore. Instagram is removing end-to-end encryption (E2EE) for direct messages, prompting many privacy-conscious users to deactivate their accounts, and raising a series of questions for those who have decided to stay (at least for the time being), including:
- Are Instagram DMs private without E2EE?
- How much control does Meta have over sensitive data once this protection is removed?
- How does this affect past conversations in Instagram DMs?
- What are some privacy-focused alternatives to Instagram messages?
This guide explains how Instagram DM encryption works and outlines the potential consequences of its removal for the trust model, focusing on user privacy and security when using these messaging features.
Are Instagram DMs Encrypted?
As of May 2026, Instagram no longer provides end-to-end encryption (E2EE) for direct messages. Previously, E2EE ensured that no third party, including Meta, could access message or call content, and that messages could only be decrypted by the participants in a conversation.
Before E2EE was removed, devices involved in encrypted conversations generated and used cryptographic keys to protect message content. Messages were encrypted when sent and remained inaccessible until they reached the recipient’s device, where they could be decrypted only with the recipient's device-specific key for that conversation.
The same mechanism previously applied to voice messages and video calls on Instagram. While some message-related features, such as chat themes or reporting tools, were never part of the end-to-end encrypted content itself, message and call contents were protected by E2EE until its removal.
By announcing the end of E2EE support after previously defining it as a key mechanism for Instagram DM privacy, the company is indirectly but unambiguously admitting that messages are no longer private and are accessible to Meta. This change means that E2EE is no longer an opt-in option and will be removed altogether.
In response to this shift, the Meta spokesperson has indicated that users who want E2EE messaging can use WhatsApp instead, highlighting the difference between Instagram DMs and platforms built for encrypted, private communication. However, this change also raises the question of whether social media messaging features can ever truly be considered safe in the first place.
Why Will Instagram DMs No Longer Be Encrypted?
According to a Meta spokesperson, the initial reasoning behind this decision was the reported low user engagement with the option for encrypted DMs.
Another potential factor may be the criticism Meta faced when E2EE was first introduced across Facebook Messenger and Instagram, particularly regarding underage user safety.
The Virtual Global Taskforce (VGT), including Europol, raised concerns that Meta’s encryption model could pose a threat to child safety on its platforms, as potential evidence regarding child abuse would be more difficult to access within an E2EE framework.
In response to these concerns raised in 2023, Antigone Davis, Meta’s Head of Safety, stated that even with E2EE, Meta could still rely on user reports, account information, and other available signals to identify potential abuse. However, even after child safety concerns were highlighted in the New Mexico trials, Mark Zuckerberg, Meta’s CEO, concluded that strong encryption represents a positive change more than a risk.
While the removal of Instagram end-to-end encryption may be perceived as a shift toward a more security-focused rather than privacy-centric environment, the long-term consequences of this decision for both aspects of the user experience could be significant.
Will Old Instagram Messages Remain Encrypted?
As announced in Instagram’s Help Center, users whose chats are affected by this change will receive instructions on how to preserve messages and media before encryption is discontinued. Instagram has also noted that users may need to update their app to the latest version in order to download this content.
Currently, downloading encrypted chats from Instagram is only possible on desktop and only if secure storage has been enabled. The downloaded data can include both sent and received messages, as well as media attachments such as images and files.
To download your data from secure storage, you need to:
- Select Menu in the bottom left corner, then click Your Activity
- Click Download End-to-End Encrypted Data at the bottom of the page, then click Next (PIN may be required at this step)
- Type in your Instagram account password and select Request download
While the contents may not be automatically deleted if they’re not downloaded, it appears that older chats will lose their E2EE status, making them more susceptible to Meta’s access. It remains unclear whether encrypted chats and data that haven’t been backed up will still be accessible via Instagram, particularly given Meta’s guidance to download them in advance.
The fact that Meta can eliminate the option of E2EE after it was once available highlights how privacy and security on social media apps and mainstream platforms can change abruptly and ultimately remain outside of user control.
The Risks of Instagram End-to-End Encryption Being Removed
Privacy in messaging apps concerns more than sensitive conversations, and it doesn’t imply that users have something to hide. Instead, it is about abuse prevention as message content can be exposed and potentially used in harmful contexts, such as:
- Targeted ads based on message content: Unprotected information in Instagram DMs could, in theory, be processed and used to deliver targeted ads based on specific keywords.
- Legal demands: Instagram messages no longer being encrypted means their contents can now be subject to legal processes, allowing government bodies to request access to private conversations.
- Data leaks: In a multibillion-dollar legal case that resulted in billions in settlement-related costs, Meta shareholders accused Mark Zuckerberg of mishandling the personal data of millions of Facebook users, some of which was accessed by Cambridge Analytica and used without consent in a political campaign.
- AI training: Meta has publicly discussed logging its employees’ keystrokes and mouse clicks to train AI; without E2EE, this raises questions about whether messaging data could be included in such processes.
The removal of Instagram's private message encryption represents a major shift in the trust model. Without E2EE, message content is no longer protected from platform-side or third-party access in the same absolute way, affecting mechanisms such as retention, internal processing, and potential future use of that data. Without E2EE, the trust boundary moves from conversation participants to the messaging platform, requiring users to trust it with their messages.
The Reaction of Privacy Advocates to Instagram Removing Encrypted Messages
On April 8, 2026, in response to Meta's decision to eliminate E2EE, the Steering Committee of the Global Encryption Coalition, comprising the Center for Democracy & Technology, Global Partners Digital, the Internet Freedom Foundation, the Internet Society, and Mozilla, expressed concern about this Instagram DM privacy risk.
The Coalition called on Meta to reverse this decision, urging the company to maintain E2EE as the default for Instagram messages, as it already does on WhatsApp and Messenger. In its official statement, the Coalition described encryption as a key mechanism for protecting users’ security, privacy, and fundamental human rights.
The statement also points to Meta’s prior advocacy for encryption, including efforts to defend it against government pushbacks, as well as Mark Zuckerberg’s 2019 position that private communication would increasingly move toward encrypted services.
The key privacy risks identified by the Committee in light of this decision include:
- Increased risk of surveillance and interception
- Safety concerns for vulnerable groups, such as the LGBTQ+ community
- A precedent that could extend to other forms of communication
The statement concludes with a clear message:
Private Messaging Alternatives to Instagram
To be able to fully understand how privacy functions in messaging apps, it is important to distinguish between three categories:
- Direct messages (DMs) within social media platforms
- Private chats with encryption enabled
- Secure messaging solutions as a security model
Social media messaging platforms are product features within an ad-driven social network, not secure messaging systems. Private messages on these platforms are only private until the platform decides otherwise, which is why Instagram DMs were never the right place for sensitive conversations, and the removal of E2EE makes this distinction more apparent.
The following table outlines the privacy-optimized alternatives to Instagram DMs:
Platform | Key Security Features | Availability and Pricing |
Threema |
| No free version; one-time payment plan for individuals (Private, $6), and three business plans (annual payment):
|
Session |
| Completely free; no ads |
Briar |
| Free; available on Android only |
GhostPost |
| Completely free |
Why App-Level Encryption Isn’t Enough Without Network Protection
Encryption represents the core of messaging privacy and, according to privacy organizations and advocates, should be non-negotiable in online spaces. The risks of trusting a messaging platform, especially one that can remove key privacy protections and move away from encryption, are far-reaching and potentially detrimental to privacy and security.
Choosing a secure messaging service in place of Instagram DMs is the key step toward safer communication. However, app-level encryption is only one part of a broader privacy puzzle, the integrity of which largely depends on the network your data travels through.
Even the most secure messaging app still relies on telecom infrastructure built on interconnected, often implicit trust, where networks trust devices and each other. This model leaves room for surveillance, data exposure, and further exploitation at the carrier level—often outside the app's control.
Rather than relying on networks and platforms, you can reduce your exposure by choosing a privacy-focused carrier such as Cape, which minimizes both the amount of data collected and the level of trust required in the first place.
Cape: The Carrier Built for Security and Privacy
Cape is a privacy-first mobile carrier designed to keep your communications safe from surveillance and misuse. Unlike traditional cell phone plan providers, our business model centers around providing you with premium and secure call, text, and data, rather than harvesting and selling your information.
Our service is built from the ground up with privacy and security at its core, offering unique features like:
Privacy & Security Feature | Description |
Cape doesn’t ask for your name, address, or Social Security number. We only collect the information necessary to provide service, and we retain that information for the minimum amount of time possible. | |
Traditional carriers rely on a fixed International Mobile Subscriber ID (IMSI) to connect your device to cellular networks. This is a vulnerability that lets carriers, advertisers, and bad actors identify and track your device. Cape lets subscribers automatically rotate their IMSI every 24 hours, making it infinitely more difficult to track you or your device. | |
Many services ask for your phone number, but sharing it exposes you to spam, scammers, data brokers, and a variety of other risks. VoIPs, on the other hand, don’t work with 2FA, cost extra, and aren’t encrypted. With Cape, you get two free additional SMS/MMS lines that are middle-to-end encrypted. | |
Most U.S. carriers store your call and text metadata for years, sometimes indefinitely. Cape is built to forget, so call data records (CDRs) are deleted after just 24 hours. | |
Cape nullifies the threat of SIM swapping by completely removing humans from the loop. During signup, you receive a 24-word phrase that generates a private key tied to your number. This effectively means that no one (but you) can move your number to a new carrier or device, not even Cape. | |
Legacy network protocols, like SS7, leave you vulnerable to hackers that can track your location, intercept your calls and texts, and steal sensitive information. Cape’s Network Lock relies on a proprietary signaling proxy to verify that your device’s physical location matches the network it’s trying to attach to. If we detect anything out of the ordinary, Cape automatically blocks the connection, nullifying the potential threat. | |
Traditional voicemail systems are outdated, unencrypted, and another security hole bad actors can exploit to gain access to your sensitive information. Cape encrypts all voicemails, ensuring only you can access them. | |
While roaming, your phone connects to local telecom providers to enable service. But, who knows who might be listening on the other end. Cape provides you with peace of mind by routing your traffic through our U.S.-based mobile core, ensuring your identity, data, and communications remain private and secure. |
Ditch Legacy Carriers: Get Cape Today
Cape is a “Heavy” Mobile Virtual Network Operator (MVNO), meaning we own our mobile core and provision our own SIMs. This gives us full control over how accounts are authenticated and what data is collected (and for how long), and is how we are able to provide privacy and security features no other carrier on the market can offer.
Get started with Cape today and enjoy the peace of mind, knowing you are fully protected against scammers, hackers, bad actors, and other mobile threats.
To help protect more than just your phone, we’ve partnered with Proton. As a new Cape subscriber, you can choose between Proton Unlimited and Proton VPN Plus for just $1 for six months.
Share it

