On August 10, 2026, Privacy Guides reported on a development buried in Signal’s source code: the encrypted messaging app is actively working on allowing users to register an account without providing a phone number. References in the codebase point to a registration flow that could use a one-time payment in place of phone number verification.
Signal is not alone in moving this direction. The broader privacy community has been pushing back against phone numbers as account identifiers for years, and in 2026, the conversation has shifted from “wouldn’t it be nice” to “this is actually happening.”
To understand why this matters, you first have to understand what a phone number actually reveals about you.
Your Phone Number Is a Privacy Liability
Most people think of their phone number as a communication tool — a way for friends, family, and businesses to reach them. In practice, it’s much more than that. Your phone number is one of the most effective keys to your digital identity.
Consider what your phone number links to:
Data brokers: Phone numbers are routinely sold by data brokers and appear in people-search sites like BeenVerified, Spokeo, and Whitepages. Someone with your number can often find your name, address, associated email addresses, and more within minutes.
Account recovery: Most major online services — Google, Apple, Facebook, banks — use your phone number for account recovery. A criminal who can convince your carrier to transfer your number to a new SIM card (a “SIM swap”) can reset passwords and take over accounts in minutes. SIM swap attacks have been used to steal millions of dollars in cryptocurrency and access highly sensitive personal accounts.
Identity linkage: Because so many services use your phone number as a unique identifier, it becomes a thread that ties together your activity across apps, websites, and companies that might otherwise appear unrelated. Data brokers specialize in stitching these threads together.
Government requests: In most jurisdictions, law enforcement can subpoena phone records from carriers. The carrier knows which number registered which account, when, and from which location.
When Signal requires a phone number to register, it means that even if your messages are end-to-end encrypted and Signal itself cannot read them, your account is still tethered to an identifier that can be traced back to you.
What Signal Already Does to Reduce This Risk
Signal has been aware of the phone number problem for years. In early 2024, the app introduced usernames — a significant step toward separating Signal identity from phone identity.
With Signal usernames, you can:
- Contact other people using their username instead of their phone number
- Hide your phone number from people you message
- Control whether people can find you by searching your phone number
Signal handles usernames with care: they’re not stored in plaintext on Signal’s servers, which limits Signal’s ability to produce them in response to legal requests.
This is a meaningful improvement. If you’re careful about your settings, someone who contacts you on Signal doesn’t necessarily need to know your phone number.
But there’s a ceiling to what usernames alone accomplish. Signal still requires a phone number to create an account. That number is verified via SMS at signup. Even if no one you message ever sees it, Signal’s infrastructure is aware of the number associated with your account. The registration step is the leak.
What Phone-Number-Free Signup Would Mean
If Signal implements registration without a phone number, the architecture changes significantly.
Instead of verifying a phone number (which requires Signal to interact with a carrier network and store some association between your account and a real-world identifier), users would likely pay a one-time fee to create an account. The payment would serve as an anti-spam mechanism — the role phone numbers currently play — without requiring a personally identifiable piece of information.
A well-implemented system could give you a Signal account with no permanent identifier that connects to your real-world identity. Your device’s keypair would be the only thing tying your Signal account to any physical object.
This would meaningfully improve anonymity for:
- Journalists, activists, and whistleblowers who communicate with sources
- People in countries where government access to telecom records is common
- Domestic abuse survivors who can’t share their phone number safely
- Anyone who simply doesn’t want their communications infrastructure to include a chain back to their mobile carrier
The Remaining Gap: File Storage
Signal’s evolution toward stronger anonymity is genuinely significant for secure communications. But it’s worth noting what Signal is and what it isn’t.
Signal is a messaging app. It’s designed to transmit messages between people securely. It has a “Note to Self” feature that lets you send files and messages to yourself, and those messages are end-to-end encrypted. But Signal is not a personal file vault.
The difference matters in practice:
Retention: Signal messages can be set to auto-delete. Many Signal users enable disappearing messages as a privacy feature. This is correct behavior for a communication tool, but it’s the wrong behavior for a file you need to keep.
Storage capacity: Signal is not built to store thousands of photos, documents, and files across years of use. The app isn’t indexed for file retrieval, and there’s no meaningful way to organize a growing personal archive in a messaging thread.
Cross-device access: Signal’s linked devices feature is limited. It’s designed to keep your messages in sync across a small number of personal devices, not to give you reliable, organized access to your personal files across every context.
Backup risk: If you back up a device that has Signal installed, those backups may not preserve Signal data (Signal intentionally excludes itself from device backups in many configurations), which means files you “stored” in Signal Note to Self could be lost.
A phone-number-free Signal is a better communication tool with better anonymity properties. It doesn’t become a private personal cloud.
Why Identity and Storage Are Separate Problems
The discussion around Signal’s phone-number-free accounts is part of a larger shift in how people think about digital identity and privacy. In 2026, more users understand that your “account” on a platform and what that platform does with your data are two different problems.
Identity is about who knows who you are. Even in a perfectly anonymous account setup, the data you create and store can still be visible to the platform operating it. An anonymous account at Google does not make your Google Photos private.
Storage is about who holds your data and what they can do with it. A service that holds your files under server-side encryption can be compelled to produce those files. A service that has no way to read your files cannot produce what it cannot read. A service that doesn’t hold your files at all — because you haven’t entrusted them to it — cannot be reached by subpoena.
Signal’s encrypted messaging handles the communication security problem well. Phone-number-free accounts would handle the identity problem for communications. Neither addresses the question of where you store your personal files, photos, and documents for long-term access.
What This Looks Like in Practice
A realistic privacy-conscious approach in 2026 looks like this:
- Use Signal (or a similar E2EE messaging app) for communication — and if phone-number-free registration becomes available, consider taking advantage of it
- Keep files you’re actively working with in environments where you understand the access model
- Store personal photos, documents, and files that you need to keep privately in a service that is built for that purpose, with clearly documented encryption and access policies
The emergence of phone-number-free Signal doesn’t eliminate the need to think carefully about where your data lives. It solves one problem — anonymous communication — while the problem of private, persistent personal storage remains exactly where it was.
The Broader Shift in Privacy Architecture
What’s interesting about Signal’s direction is what it signals (no pun intended) about where privacy-conscious technology is heading.
The pressure to move away from phone numbers as identity anchors is real and growing. Data breaches, SIM swap attacks, and the growing sophistication of data broker operations have made the phone number an obvious weak link. Regulators in the EU and several US states are beginning to take a harder look at how personal identifiers are used.
Signal moving toward phone-number-free accounts is part of a broader architectural shift: an acknowledgment that strong privacy requires rethinking the foundational assumptions of how digital accounts are created and maintained.
The same reasoning applies to personal file storage. The architectural question isn’t just “is my data encrypted?” — it’s “what identifiers link my data to me, who holds those identifiers, and under what conditions can they be disclosed?”
Signal is asking these questions about messaging. The same questions deserve the same scrutiny for every service where you store personal information.