Comparisons
Is Signal or Telegram a Safe Place for Private Photos?
Sending photos to yourself in a messaging app is one of the most common improvised vaults there is. Signal's version holds up better than most people expect. Telegram's works differently from what most people assume.
Signal is a reasonable place, because Note to Self is end-to-end encrypted like any other Signal chat. Telegram’s Saved Messages is a different thing entirely, encrypted in transit and on Telegram’s servers with keys Telegram holds. Neither removes the original from your camera roll, which is the part that usually matters most.
The short answer
Messaging yourself is probably the most widely used improvised vault in the world. It costs nothing, it needs no new app, and the photo is instantly on every device you own.
The instinct isn’t wrong. Two of the three big options really are end-to-end encrypted, and for a lot of people that’s genuinely enough.
What trips people up is assuming all messengers work the same way. They don’t, and the differences are structural rather than cosmetic. One of them is a private channel only you can read. Another is a cloud drive with a chat interface, run by a company that can read what’s in it if compelled.
Why people do this in the first place
Worth being fair to the habit before picking it apart, because the reasoning behind it is sound.
You want a photo out of the main camera roll, where anyone handing back your phone might swipe one frame too far. You want it somewhere that survives losing the device. You want it on your laptop too. And you’d rather not install and trust another app.
A message to yourself does all four. That’s a real solution to a real problem, and dismissing it would be silly. The question is only what it does and doesn’t cover.
Signal’s Note to Self, accurately
Note to Self is a conversation with yourself, and it inherits everything Signal does for ordinary chats.
The content is end-to-end encrypted, so Signal cannot read it. It syncs to your linked devices, still encrypted, so the photo shows up on your iPad or desktop without ever being readable by the service in between. Disappearing messages work there too, which gives you an automatic expiry if you want one.
Signal has also added an encrypted backup, with a small free allowance and an optional paid tier for more space, protected by a long recovery key that you hold. That closes the traditional gap in Signal’s model, which was that losing your phone meant losing your history.
As a place to park a handful of sensitive photos, this holds up better than most improvised methods. The honest limits are the ordinary ones: it’s protected while the app is locked, not while it’s open in your hand, and anyone who can unlock your phone can usually open Signal.
There’s a second limit that comes directly from the feature people like most. Syncing means the photo is readable on every device you’ve linked, so a desktop at work with Signal open, or an iPad the family shares, is another screen where that conversation can be scrolled. The encryption is doing its job perfectly at each of those endpoints. It just can’t help you if one of the endpoints is a laptop someone else walks past. If you use Note to Self this way, it’s worth reviewing your linked devices occasionally and removing the ones you’ve forgotten about.
Telegram’s Saved Messages, accurately
This is the one worth reading carefully, because the assumption people carry into it is usually wrong.
Telegram has two kinds of chat. Cloud chats are the default, and they’re encrypted between your device and Telegram’s servers, with Telegram holding the keys. Secret Chats are end-to-end encrypted, tied to a single device, and have to be started deliberately.
Saved Messages is a cloud chat. It is not end-to-end encrypted, and there’s no Secret Chat version of it.
That isn’t a scandal, and it isn’t a flaw so much as a trade. Holding the keys is exactly what lets Telegram sync your entire history to a new phone after you’ve lost the old one, which Secret Chats can’t do. It’s the same bargain as ordinary iCloud without Advanced Data Protection, and plenty of people would take it knowingly.
The problem is that most people take it unknowingly. They see a messaging app with a strong privacy reputation and assume the private-looking folder inside it is private in the strongest sense. For photos you’d be upset to see disclosed, that gap between assumption and architecture is the whole issue.
WhatsApp sits closer to Signal here. Its message-yourself feature runs over the same end-to-end encryption as every other WhatsApp chat, though what lands in your backup depends on whether you’ve turned on the encrypted backup option.
The camera roll problem all of them share
Here’s the failure that has nothing to do with encryption, and it undoes all three equally.
Sending a photo to yourself copies it. It doesn’t move it. The original is still sitting in Photos unless you go back and delete it, including from Recently Deleted, where it lingers for thirty days.
Worse, if the messaging app is set to save incoming media to your photo library, you now have two copies in the camera roll instead of none. People do this, check the message thread, see the photo safely there, and never notice the library got busier rather than cleaner.
So whatever you choose, the sequence matters more than the tool:
- Put the photo somewhere protected.
- Confirm it’s actually there and opens correctly.
- Delete the original from Photos.
- Empty Recently Deleted.
- Check the app isn’t auto-saving media back into your library.
Skip step three and the rest is decoration. We covered the related version of this problem, where photos resurface through Memories and widgets, in why your iPhone keeps resurfacing private photos.
Side by side
| Signal Note to Self | Telegram Saved Messages | Dedicated photo vault | |
|---|---|---|---|
| End-to-end encrypted | Yes | No, keys held by Telegram | Yes, on device |
| Provider can be compelled to disclose | No, it can’t read it | Yes, in principle | No server involved |
| Syncs across your devices | Yes, encrypted | Yes | Usually not |
| Survives losing your phone | With encrypted backup on | Yes | Only if you back up yourself |
| Separate lock from your phone | No | No | Yes, its own PIN |
| Hides that content exists | No, it’s a visible chat | No | Varies, some offer a decoy |
| Removes the camera roll original | No | No | No, you delete it |
The row that usually decides it is the second-to-last one. A chat thread is visible. Anyone scrolling your messenger sees a conversation called Saved Messages or Note to Self, and its existence is not a secret.
What a messenger genuinely does better
Two things, and they’re not trivial.
Sync is the obvious one. Your photo is on your phone, your laptop and your tablet within seconds, encrypted the whole way if you’re on Signal or WhatsApp. Most on-device vaults deliberately don’t do this, because not having a server is the point, and that means moving photos between devices is a manual job.
Recovery is the other. If your phone goes into a river, a synced messenger gets your content back. A vault with no server can’t help you, and if you’ve forgotten the PIN nobody can. That asymmetry is real and it cuts against the vault.
If you’d rather stay with a messenger, a few adjustments make it meaningfully better:
- Pick one that’s end-to-end encrypted for this purpose. Signal and WhatsApp qualify for messages to yourself. Telegram’s Saved Messages doesn’t.
- Turn off saving media to your photo library, so incoming pictures stop being copied back into the camera roll you were trying to keep clean.
- Set disappearing messages on that conversation if the photos have a natural expiry. It’s the one thing a messenger does that a vault typically doesn’t.
- Check what’s attached to the file. Photos carry metadata including, often, the location where they were taken, and how much survives depends on the app. Strip location from anything sensitive before it leaves your phone.
- Review your linked devices, and drop any you no longer use.
- Turn on the app’s own lock where one exists, so opening the messenger needs Face ID even on an unlocked phone.
That last point closes most of the practical gap. It doesn’t close the visibility gap, because the conversation is still plainly there.
Where a vault is the better fit
The case for a vault is narrower and sharper.
It’s a separate lock. Handing someone your unlocked phone doesn’t hand them the vault, because the vault has its own PIN. A messenger you’re already signed into offers nothing at that moment, and that moment — phone unlocked, in someone else’s hands — is the realistic risk for most people rather than a sophisticated remote attack.
It helps to be specific about who you’re actually protecting against, because the three options rank differently depending on the answer. Against someone with physical access to your unlocked phone, a partner, a friend, a repair technician, a vault with its own PIN wins clearly and the messengers offer nothing. Against a company being compelled to produce records, Signal and a vault both hold up and Telegram’s Saved Messages doesn’t. Against losing the phone entirely, the synced messengers win and the vault loses unless you kept your own backup. Most people are worried about the first case and buy for the third.
It also keeps nothing anywhere else. No account, no server, no copy in a company’s infrastructure to be requested, subpoenaed or breached. Whether that matters depends on what you’re protecting against, which is the question we worked through in on-device vs cloud encryption for photos.
And some vaults can address the visibility problem, where the issue isn’t whether a file can be decrypted but whether anyone can tell it exists.
Where Arca fits
Arca is built for the narrow case above. Photos you move in are encrypted individually with AES-256-GCM, and the key comes from your PIN through Argon2id, a deliberately slow derivation function that makes guessing that PIN expensive rather than instant.
Everything stays in the app’s container on your device. No server, no account, so there’s no synced copy in anyone’s infrastructure, nothing on our side to breach, and nothing for us to hand over. If you might ever be pressured to unlock, there’s a decoy vault. The full model is on our security page.
The limits, plainly. Arca protects the photos you actually move into it, not the ones still in your camera roll. It protects them at rest, not while the vault is open in front of someone. And because there’s no server, we can’t recover anything if you forget your PIN, so keep your own backup of what’s irreplaceable.
Messaging yourself isn’t a mistake. Just know which of the three you’re using, and remember that the copy still sitting in Photos is the one doing the damage.
Get Arca on the App Store to keep your private photos encrypted with AES-256-GCM on your device, with no server in the loop.
Frequently asked questions
Are Telegram Saved Messages end-to-end encrypted? +
No. Saved Messages live in a regular cloud chat, which Telegram encrypts between your device and its servers while holding the keys itself. Only Secret Chats are end-to-end encrypted, and Secret Chats are tied to one device and don't cover Saved Messages. That's a reasonable design for syncing across devices, but it's a different trust model from end-to-end encryption, and worth knowing before you use it as a photo store.
Is Signal's Note to Self actually encrypted? +
Yes. Note to Self is a normal Signal conversation with yourself, so it carries the same end-to-end encryption as any other Signal chat, syncs to your linked devices in encrypted form, and supports disappearing messages. Signal can't read what you put there. The practical limits are about the app being unlocked in your hand and about photos also sitting in your camera roll.
Do photos I send myself also stay in my camera roll? +
Usually yes, and this is the step people forget. Sending a picture doesn't remove the original, and if the app saves incoming media to Photos, you can end up with two copies rather than none. Whatever you use as a private store, the original in the camera roll is the copy that actually determines how exposed you are.
Keep reading
Comparisons
Google Photos Locked Folder vs a Photo Vault: Which Is Safer?
Google Photos Locked Folder hides sensitive photos behind Face ID, which is genuinely handy. But it isn't end-to-end encrypted, and backed-up photos sit on Google's servers. Here's how it compares to an on-device vault.
Comparisons
Where Should You Store Private Photos? iCloud vs a Vault App vs Offline
iCloud is convenient, a vault app adds a separate lock, and offline storage is the most private. The right home for a private photo depends on what you are protecting it from. Here is how the four options really compare.
Comparisons
iCloud Advanced Data Protection vs a Photo Vault
Both make your photos more private, but they defend against different threats. Advanced Data Protection encrypts your whole iCloud library in the cloud; a vault seals specific photos on your unlocked device. Here's what each does, and why they work best together.
Your photos. Truly private.
Download Arca and lock your first photos away in under a minute. No account, no cloud, no one but you.
Free to download · iPhone · iOS 18+