What tools to use to avoid Chat Control?

This article is a draft. It is not finished yet and might never be.

Back to articles

Created on 2026/07/18

Chat Control 1.0 is here, but I hear and read many tool suggestions that I find just incorrect.

You can read the full text here.

French government already tried tried to pass a similar censoring law in 2020, called Avia law, which would have forced companies (social networks, search engines) to delete hateful content within 24 hours.

Messengers

Useful to communicate with your relatives, friends and stranger.

SMS/MMS

Not encrypted. Requires a phone service plan, which may limit your messages count.

Whatsapp

Remember that end-to-end encryption means that your message cannot be intercepted during its transmission, but the emitter and the receiver can still be compromised, which is exactly what Chat Control exploits here. Oh and Whatsapp is closed-source, so 1

Telegram

I never understood why everyone was and still is promoting it as a private messenger. It has encryption disabled by default. Oh and you might have to pay fees to confirm your identity when creating your account (happens in France and countries in North Africa such as Cameroun).

Signal

Seems to be linked to Chat Control as well?

Session

A fork of Signal. Last time I used it messages were slow as hell to send. I wanted to try it out again to see if it changed, but it’s an 18+ app in the Play Store, so I cannot download it. This seems to apply to some regions only.

Briar

It is Android-only and in maintenance mode. But it has interesting features such as Bluetooth communication, ideal for people living in countries spying their users via their ISP.

Element

Still has metadata issues?

XMPP

Limited.

E-mails

Mails aren’t encrypted by default. You would have to use tools like PGP, associate your key with your mail account, and make sure your recipient does the same. It varies among OS and mail clients, so yeah, complex.

Protonmail

It doesn’t support external mail clients or custom signature unless you pay. Previous audits found huge vulnerabilities. Web client is open source but not the server code, which would be then trusted if it’s audited. Even if it would respect your privacy, it still bothers you with choosing a subscription.

When reading the privacy policy, we get this:

Account Activity: Due to limitations of the SMTP protocol, we have access to the following email metadata: sender and recipient email addresses, the IP address incoming messages originated from, attachment name, message subject, and message sent and received times.

Ah yes, metadata collection.

[…] unencrypted messages sent from external providers to your Account, or from Proton Mail to external unencrypted email services, are scanned for spam and viruses to pursue the legitimate interest of protecting the integrity of our Services and users.

Not so private then.

Such inbound messages are scanned for spam in memory, and then encrypted and written to disk. We do not possess the technical ability to scan the content of the messages after they have been encrypted.

What does prevent them from reading inbound messages before the encryption?

Tuta mail

It doesn’t support external mail clients and its last audit happenned more than a DECADE ago. And I mean an external security audit lead, not internal ones. It’s like thinking Windows doesn’t have a vulnerability because Microsoft haven’t found it.

“I’m creating my own encrypted platform”

Great! I’d use it gladly, but not regularly if its code isn’t audited.

So what?

The truth is that there is no single solution. The tools you will have to use depends on your threat model, and how much you’re ready to put aside as comfort to protect more your privacy. See privacy guide.

“But I have nothing to hide”