Threema
Official website (opens in a new tab)
Usable without a phone number, name or email thanks to a dedicated identifier (the “Threema ID”), whose key is registered once and for all in a directory: no mechanism allows a user’s identity to be substituted, but key distribution is centralized and a lost key cannot be recovered.
At a glance
• End-to-end encryption — ✅ Good
• End-to-end authentication — ❌ Poor
• End-to-end security — ❌ Poor
• No identity substitution — ✅ Good
• Open source client — ✅ Good
• End-to-end multi-device — ✅ Good
• Minimal personal data — 🟠 Partial
• No contact discovery and spam — 🟠 Partial
• Post-quantum encryption — ❌ Poor
Like Olvid and SimpleX, Threema stands out from other messaging apps in one respect: it requires no personal data from its users. Instead of a phone number, each user is identified by a “Threema ID,” a string of eight characters generated when the account is createdarchived. A phone number and an email address can still be added, but only so that the user’s contacts can find them. It is a result few messaging apps achieve, and it is consistent with Threema’s business model: the app is paid, and therefore does not make its living from exploiting data. Threema does, however, draw from this an argument about anonymity whose limits deserve to be spelled out, which we do below.
No phone number, but not anonymous
Threema solves a real problem: doing without the phone number as an identifier. Not knowing a user’s number or name does not prevent the server from seeing which Threema ID communicates with which other one, how often, and when. This knowledge of the social graph is not specific to Threema, either: as explained in the minimal personal data criterion, any relay server can reconstruct that graph simply by correlating the addresses users connect from. And a user’s exposure does not depend entirely on their own choices. A user who refuses to provide their number or email remains identifiable as soon as their contacts have provided theirs: in a social graph, knowing a node’s neighbors is often enough to recognize it, and when you are the last anonymous person among contacts who are all identified, you are no longer really anonymous. Anonymity with respect to the operator is therefore not a property each person sets for themselves, but a collective matter, and a minority of careful users can do little if most of the people around them have linked their legal identity to their Threema ID. Minimizing identifiers and protecting the social graph are therefore two distinct properties: Threema achieves the first, not the second.
End-to-end encryption ✅ Good
Nothing falls outside end-to-end encryption — not groups, not calls — and no setting lets you turn it off; the implementation relies on the NaCl libraryarchived. The Ibexarchived protocol, rolled out from late 2022 and enabled by default since then, adds continuous key renewal to the end-to-end layer, and with it the forward secrecy set out in the criterion; researchers at ETH Zurich have published a security proofarchived of it.
End-to-end authentication ❌ Poor
To connect with someone, the application fetches the public key associated with a Threema ID from Threema’s central directory, which it trusts: this is the directory scenario described in the criterion. Threema offers in-person verification by scanning a QR code, which raises the contact to the highest of three verification levelsarchived, but it is optional and nothing requires doing it before communicating. On first remote contact, the link between a Threema ID and its key therefore rests solely on the directory.
End-to-end security ❌ Poor
Systematic encryption is achieved; end-to-end authentication, however, is not. This composite criterion is therefore not met.
No identity substitution ✅ Good
The public key associated with a Threema ID is set at creation and can never be replacedarchived. No external mechanism (SMS, email) allows an existing ID to be re-associated with a new key, which sets Threema apart from Signal or WhatsApp, where possession of the number is enough to register a new key. The flip side is that losing the private key is final: you do not “recover” a Threema ID, you create a new one, that is, a new identity. The phone number, when one is linked, can be attached to a new ID, which automatically unlinks the old one; but contacts remain tied to the original ID, now without a number. Olvid and SimpleX remove the association between an identifier and a key, whereas Threema has chosen to freeze it, which is enough to rule out silent substitution without solving the authentication of the initial link.
Open source client ✅ Good
The Threema apps are published under an open source license (AGPLv3)archived, and the cryptographic protocol is documented in a public whitepaperarchived. Reproducible builds, available on Android, make it possible to verify that the distributed application matches the published code.
End-to-end multi-device ✅ Good
We consider here the Threema 2.0 desktop app, in beta, and not the web client or the old desktop app (1.0), which are mere windows onto the phonearchived. Version 2.0 is a genuinely autonomous device: it works even when the phone is off or offlinearchived. Its multi-device architecture ties devices to a “Device Group Key” that is never known to the mediator serverarchived: it is an already legitimate device (the phone) that authorizes a new computer, by scanning a QR code, and the server cannot inject a ghost device into the group. Two minor caveats: as of September 2026, the feature is still in beta (limited features, two computers at most), and the old desktop app, which is still distributed, does not meet this criterion.
Minimal personal data 🟠 Partial
Threema can be used without a name, a phone number or an emailarchived, which few messaging apps allow. Threema gets a 🟠Partial rather than a ✅Good because the application offers to link a phone number or an email to the user’s Threema ID, so that their contacts can find them. Accepting this option means providing the data to the operator, since the hashing applied before sending offers little protection: the space of phone numbers is small enough for an exhaustive search to invert a hash. The criterion reserves the ✅Good for solutions that offer no way at all to provide such data to the operator, even optionally. Note that on Android, Threema Pusharchived makes it possible to do without Google’s notification token, an identification vector described in the criterion.
No contact discovery and spam 🟠 Partial
The verdict depends on what the user exposes. If they link a phone number or an email to their Threema ID, which the application offers so that contacts can find them, they become discoverable through those identifiers. In that case, the criterion is not met. But Threema also makes it possible to expose only a Threema ID: an eight-character string, long enough that it cannot be enumerated. A stranger then has no practical way of linking a user to their identifier, unless the user has shared it themselves. This possibility of being undiscoverable justifies not grouping the solution with those that identify users by their phone number. The protection nevertheless remains incomplete, since there is no contact-request confirmation. Once the ID is known, anyone can send a message immediately, without the target having accepted anything; the only default protection is reactive: blocking after the first message. Threema therefore closes one of the criterion’s two barriers (discovery) but not the other (contact-request confirmation).
Post-quantum encryption ❌ Poor
No post-quantum encryption has been deployed to date. In February 2026, Threema announced a collaboration with IBM Researcharchived to gradually equip the application with new algorithms, with no specific timeline.