← all articles

Metadata explained: what encryption does not hide

Metadata is data about your data. When you send a message, the message is the content. Who sent it, who received it, what time, from which device and roughly where, how big it was, how often the two of you talk: that is metadata. Encryption scrambles the content so outsiders cannot read it. It usually does nothing for the rest.

I run a few small sites and a lot of infrastructure out of Singapore, and most of the privacy questions I get start with “but it’s end to end encrypted, so it’s private, right?” Sometimes that is mostly true. Often it is only half true, and the missing half is metadata. If you have ever felt safe because a padlock appeared in your browser or an app advertised encryption, this article is for you.

what it is

Metadata is the envelope, not the letter. A paper letter shows the same thing. The postal service cannot read what is inside a sealed envelope, but it can see the sender address, the destination, the postmark date and the weight. Hold enough envelopes and you can work out a lot without opening one.

Digital metadata works the same way, with more fields. Some common examples:

  • email: sender, recipients, timestamps, subject line, and the path the message took between servers
  • phone calls: numbers involved, call start time, duration, and the cell tower your phone was attached to
  • messaging apps: your account identifier, your contact list, when you were last online, and sometimes your IP address
  • web browsing: the domain you visited, when, and how much data moved, even when the page itself is encrypted
  • files and photos: author name, device model, edit dates and often GPS coordinates stored inside the file

None of these fields contain what you actually said. That is exactly why they get collected so easily, and why people underrate them.

how it works

Encryption protects a specific thing: the content of data while it travels or sits somewhere. The systems that move that data still need to know where to send it. Routers need a destination address. A mail server needs a recipient. A phone network needs to know which tower to ring you through. Those pieces have to be readable by someone, or nothing would be delivered.

Here is how that plays out in a few everyday cases.

web browsing over https

When you visit a site over HTTPS, the page content and the exact URL path are encrypted between your browser and the site. But your device first has to look up the domain, usually through DNS, and the connection setup has historically exposed the domain name in a field called the server name indication. Your internet provider, your employer’s network or the owner of a cafe router can often see “this device connected to example.com at 14:02 and moved this much data.” They cannot see which page you read. The domain alone is frequently enough to say a lot. A visit to a clinic’s site, a debt counselling site or a specific news outlet is a fact about you.

I cover the on-network side of this in public wifi: what the risk actually is, which gets into what a shared network can and cannot see.

messaging apps

End to end encrypted messengers such as Signal and WhatsApp encrypt message content so that the company running the servers cannot read it. The servers still know which accounts are talking, because they have to route the message. Signal has worked to shrink this. Its 2018 “sealed sender” feature, described on Signal’s own blog, hides the sender’s identity from Signal’s servers for messages between contacts. That is unusual. Most mainstream apps hold far more metadata, and what they keep is a policy choice, not a technical limit.

Signal has also published the legal requests it has received. On its bigger picture page, the responses show that when served with a subpoena the company could only hand over an account’s creation time and last connection time. That is what deliberately minimising metadata looks like in practice, and it is rare.

email

Even with PGP or an encrypted provider, the standard email format leaves the subject line, sender, recipients and timestamps readable by the servers that pass your mail along. Some providers encrypt subjects within their own ecosystem, but the moment you email someone on a different service the old envelope rules apply again. Encrypted email protects the body. The headers are how the network delivers it.

files you create

Photos and documents carry metadata in the file itself. A phone photo can include the exact latitude and longitude, the phone model and the time. A Word document can include the author’s name and editing history. Encrypting the file in transit does not remove any of that once the recipient opens it. I wrote about how often this trips people up in what your photos share without you.

why it matters

Fair question: if nobody reads my messages, who cares about the envelope? Four reasons.

  1. patterns reveal more than single messages. One call to a number means little. Calls at 2am to an oncologist, then to a pharmacy, then to an insurer tell a story. Researchers at Stanford showed in a 2016 PNAS study on telephone metadata that call records alone could be used to infer sensitive things like health conditions, and you can find it by searching “Evaluating the privacy properties of telephone metadata” on pnas.org. You do not need the content to draw the conclusion.

  2. it is cheap to collect and easy to keep. Content is big, private and legally awkward. Metadata is small, structured and searchable. That makes it the default product for ad networks, data brokers and some governments. The EFF’s Surveillance Self-Defense guide is a solid primary source on how this kind of collection works and what to do about it.

  3. location is the loudest field. Your phone tells towers where it is whenever it is on. Apps add GPS on top. Stitched together over weeks, this reconstructs where you live, where you work and who you meet. I went through that in location history is the most sensitive file you own.

  4. it links your identities. A masked email, a burner account and a real account are all separate on paper. If they log in from the same IP address, the same device, at the same times of day, metadata joins them back together. This is also how browser fingerprinting works, where the combination of your screen size, fonts and settings becomes an identifier. The team at antidetectreview.org covers that side of the topic in depth from the tooling angle.

common misconceptions

“it’s encrypted, so nobody knows anything”

Encrypted content and exposed metadata usually sit side by side. A message the provider cannot read can still be a message the provider can log. Always ask two questions: what is protected, and what is still visible to the service, my network and the other party.

“metadata is harmless because it is not the real content”

For many purposes metadata is better than content. It is structured, so software can analyse millions of records without a human reading anything. Who you talk to, how often, at what hour and from where is frequently more revealing than the words, because people are careful with words and careless with patterns.

“a vpn hides all my metadata”

A VPN moves trust, it does not remove it. Your internet provider stops seeing which sites you visit, and the VPN company starts seeing them. The VPN also does not scrub the metadata inside your photos, stop an app from reading your contact list, or change the account you are logged into. It is useful for one layer, your local network and your IP address, and nothing else. Pick one based on its audited no-log claims, not its ad budget.

“deleting the message deletes the metadata”

Deleting a chat on your phone removes your local copy. The service may keep delivery logs, backups may hold older copies, and the other person still has theirs. I explain the gap between “gone from my screen” and “gone” in what actually gets deleted when you delete it.

where to go from here

You cannot reduce metadata to zero and still use a phone, so the useful goal is to cut the easy leaks. Start with the ones that cost nothing.

If you want to browse everything in one place, the full list is at the blog index. And if you are curious how the same idea plays out in marketing and automation tooling, aitoolgazette.com reviews a lot of tools that ingest exactly this kind of data.

One last thought from the operator side. When I evaluate any app or service I now read the privacy policy for what it logs, not for what it encrypts. “We cannot read your messages” and “we do not know who you talk to” are two very different promises, and only one of them is usually on the marketing page.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-10-01.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →