Metadata explained: what encryption does not hide
Metadata is data about your data. When you send a message, the message is the content. Who sent it, who received it, what time, from which device and roughly where, how big it was, how often the two of you talk: that is metadata. Encryption scrambles the content so outsiders cannot read it. It usually does nothing for the rest.
I run a few small sites and a lot of infrastructure out of Singapore, and most of the privacy questions I get start with “but it’s end to end encrypted, so it’s private, right?” Sometimes that is mostly true. Often it is only half true, and the missing half is metadata. If you have ever felt safe because a padlock appeared in your browser or an app advertised encryption, this article is for you.
what it is
Metadata is the envelope, not the letter. A paper letter shows the same thing. The postal service cannot read what is inside a sealed envelope, but it can see the sender address, the destination, the postmark date and the weight. Hold enough envelopes and you can work out a lot without opening one.
Digital metadata works the same way, with more fields. Some common examples:
- email: sender, recipients, timestamps, subject line, and the path the message took between servers
- phone calls: numbers involved, call start time, duration, and the cell tower your phone was attached to
- messaging apps: your account identifier, your contact list, when you were last online, and sometimes your IP address
- web browsing: the domain you visited, when, and how much data moved, even when the page itself is encrypted
- files and photos: author name, device model, edit dates and often GPS coordinates stored inside the file
None of these fields contain what you actually said. That is exactly why they get collected so easily, and why people underrate them.
how it works
Encryption protects a specific thing: the content of data while it travels or sits somewhere. The systems that move that data still need to know where to send it. Routers need a destination address. A mail server needs a recipient. A phone network needs to know which tower to ring you through. Those pieces have to be readable by someone, or nothing would be delivered.
Here is how that plays out in a few everyday cases.
web browsing over https
When you visit a site over HTTPS, the page content and the exact URL path are encrypted between your browser and the site. But your device first has to look up the domain, usually through DNS, and the connection setup has historically exposed the domain name in a field called the server name indication. Your internet provider, your employer’s network or the owner of a cafe router can often see “this device connected to example.com at 14:02 and moved this much data.” They cannot see which page you read. The domain alone is frequently enough to say a lot. A visit to a clinic’s site, a debt counselling site or a specific news outlet is a fact about you.
I cover the on-network side of this in public wifi: what the risk actually is, which gets into what a shared network can and cannot see.
messaging apps
End to end encrypted messengers such as Signal and WhatsApp encrypt message content so that the company running the servers cannot read it. The servers still know which accounts are talking, because they have to route the message. Signal has worked to shrink this. Its 2018 “sealed sender” feature, described on Signal’s own blog, hides the sender’s identity from Signal’s servers for messages between contacts. That is unusual. Most mainstream apps hold far more metadata, and what they keep is a policy choice, not a technical limit.
Signal has also published the legal requests it has received. On its bigger picture page, the responses show that when served with a subpoena the company could only hand over an account’s creation time and last connection time. That is what deliberately minimising metadata looks like in practice, and it is rare.
Even with PGP or an encrypted provider, the standard email format leaves the subject line, sender, recipients and timestamps readable by the servers that pass your mail along. Some providers encrypt subjects within their own ecosystem, but the moment you email someone on a different service the old envelope rules apply again. Encrypted email protects the body. The headers are how the network delivers it.
files you create
Photos and documents carry metadata in the file itself. A phone photo can include the exact latitude and longitude, the phone model and the time. A Word document can include the author’s name and editing history. Encrypting the file in transit does not remove any of that once the recipient opens it. I wrote about how often this trips people up in what your photos share without you.
why it matters
Fair question: if nobody reads my messages, who cares about the envelope? Four reasons.
-
patterns reveal more than single messages. One call to a number means little. Calls at 2am to an oncologist, then to a pharmacy, then to an insurer tell a story. Researchers at Stanford showed in a 2016 PNAS study on telephone metadata that call records alone could be used to infer sensitive things like health conditions, and you can find it by searching “Evaluating the privacy properties of telephone metadata” on pnas.org. You do not need the content to draw the conclusion.
-
it is cheap to collect and easy to keep. Content is big, private and legally awkward. Metadata is small, structured and searchable. That makes it the default product for ad networks, data brokers and some governments. The EFF’s Surveillance Self-Defense guide is a solid primary source on how this kind of collection works and what to do about it.
-
location is the loudest field. Your phone tells towers where it is whenever it is on. Apps add GPS on top. Stitched together over weeks, this reconstructs where you live, where you work and who you meet. I went through that in location history is the most sensitive file you own.
-
it links your identities. A masked email, a burner account and a real account are all separate on paper. If they log in from the same IP address, the same device, at the same times of day, metadata joins them back together. This is also how browser fingerprinting works, where the combination of your screen size, fonts and settings becomes an identifier. The team at antidetectreview.org covers that side of the topic in depth from the tooling angle.
common misconceptions
“it’s encrypted, so nobody knows anything”
Encrypted content and exposed metadata usually sit side by side. A message the provider cannot read can still be a message the provider can log. Always ask two questions: what is protected, and what is still visible to the service, my network and the other party.
“metadata is harmless because it is not the real content”
For many purposes metadata is better than content. It is structured, so software can analyse millions of records without a human reading anything. Who you talk to, how often, at what hour and from where is frequently more revealing than the words, because people are careful with words and careless with patterns.
“a vpn hides all my metadata”
A VPN moves trust, it does not remove it. Your internet provider stops seeing which sites you visit, and the VPN company starts seeing them. The VPN also does not scrub the metadata inside your photos, stop an app from reading your contact list, or change the account you are logged into. It is useful for one layer, your local network and your IP address, and nothing else. Pick one based on its audited no-log claims, not its ad budget.
“deleting the message deletes the metadata”
Deleting a chat on your phone removes your local copy. The service may keep delivery logs, backups may hold older copies, and the other person still has theirs. I explain the gap between “gone from my screen” and “gone” in what actually gets deleted when you delete it.
where to go from here
You cannot reduce metadata to zero and still use a phone, so the useful goal is to cut the easy leaks. Start with the ones that cost nothing.
- strip location and author data from photos and documents before sharing them. Start with what your photos share without you and turn off camera geotagging.
- audit the extensions in your browser, since they can see every domain you visit. What browser extensions can see walks through what to check and what to remove.
- reduce what data brokers hold on you, since they sell metadata at scale. The steps are in how to opt out of data broker listings yourself.
- understand where encryption stops on your own devices. Disk encryption and the moment it stops protecting you covers that boundary for laptops and phones.
If you want to browse everything in one place, the full list is at the blog index. And if you are curious how the same idea plays out in marketing and automation tooling, aitoolgazette.com reviews a lot of tools that ingest exactly this kind of data.
One last thought from the operator side. When I evaluate any app or service I now read the privacy policy for what it logs, not for what it encrypts. “We cannot read your messages” and “we do not know who you talk to” are two very different promises, and only one of them is usually on the marketing page.
Written by Xavier Fok
disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-10-01.