PrivacyPick
Session logo

Session

Open Source
6.5
out of 10
Visit Session →
Independent Security Audit
QuarkslabApril 29, 2021
Read the audit report →
Show audit details

Android, iOS and Desktop clients, including the onion routing and the messaging protocol, ten days of work per platform between March 2020 and spring 2021. The protocol was redesigned during the audit, and the work predates the current Session Protocol being attacked in academic research.

Group Chat E2EESome groups
ProtocolOther
Sign-up NeedsRandom ID
Metadata ProtectionOnion routing
Server ModelRelay network
Multi-DeviceIndependent devices
FundingDonations
Operated byFoundation
JurisdictionSwitzerland
Established—
WindowsmacOSLinuxAndroidiOS

Published October 9, 2026By Juan Martinez

In This Article

Session is a free app for text messages and voice and video calls on Android, iPhone, Windows, Mac and Linux. It needs no phone number or email to sign up: each account is identified by a random Account ID. The Session Technology Foundation, a Swiss foundation, manages the apps and the website, and independent operators run the network of nodes that carries messages.

Messaging is free, and the project runs on donations. In April 2026 the foundation laid off all paid staff, and a donation campaign later let development continue with a smaller team.

Session’s strength is how little it learns about you: messages travel through onion routing, and the app never asks for your phone number. The weak point is the encryption itself, because the current protocol version has no forward secrecy and a 2026 research paper describes attacks on it.

Cryptography & Protocol

Session encrypts messages with its own messenger protocol, the Session Protocol, built on the libsodium library. In December 2020 Session replaced the Signal Protocol with it, explaining that the Signal Protocol “was built to operate in a centralised environment”.

Encryption is on by default for private chats. Groups of up to 100 people are end-to-end encrypted as well. Communities are a separate type of chat: their messages are encrypted only in transit to the server that hosts the community, and Session’s FAQ says communities are not as private as private chats or groups.

The current protocol has no forward secrecy and no deniable encryption. Session’s 2020 post about the change describes the effect: if long-term keys for a conversation are compromised, only a small amount of recent messages can be decrypted.

Session Protocol V2 is in development. In December 2025 Session announced that it would add forward secrecy through rotating key pairs for each device and each account, plus post-quantum encryption with ML-KEM. In August 2026 Session wrote that it was exploring a first alpha as a separate invite-only app, with Session Pro users getting access first; the alpha would initially cover direct messages between two people who both use V2. Session has not given a release date.

Metadata Privacy

Session asks for no phone number or email. The sign-up identifier is a random Account ID, and you add a contact by pasting theirs. There is no contact discovery through the phone’s address book.

Messages travel through Onion Requests, Session’s onion-routing protocol for hiding IP addresses. Each layer of a request is removed by a different server, so no single node sees both the sender’s IP address and the message. The nodes belong to a relay network run by independent operators; Session’s FAQ says over 1,500 nodes are on the network.

This metadata protection has limits. A message waits for the recipient in a group of 5 to 7 nodes, and these nodes see the recipient’s Account ID, the message timestamp and its expiry time. By default a message expires after two weeks.

Some features reveal your IP address. Voice and video calls connect peer to peer, so your IP address is visible to the other person and to a relay server run by the foundation. On Android and iOS, push notifications give Google or Apple your device’s IP address and a push token, and give a push server run by the foundation your Account ID.

Session’s privacy policy states that the app does not collect or share your information, which means no telemetry from the app itself. On mobile, Apple or Google may record their own data, such as when the app is opened, crash logs and the device model.

Transparency & Verifiability

The Android, iOS and Desktop apps are open source under the GPL-3.0 license. The foundation also publishes the storage server that network nodes run, the onion-routing code and the server software for communities.

Session’s Android repository does not describe reproducible builds, so there is no documented way to confirm that the installed app was built from the public code.

Quarkslab audited the Android, iOS and Desktop apps, including the onion routing and the messaging protocol, from March 2020 to about April 2021. One engineer spent ten days on each platform, 42 days in total. Midway through, Session’s developers completely redesigned the cryptographic protocol, so the project changed while the audit was under way.

Quarkslab found 16 issues: 2 in the Desktop app, 7 in the iOS app and 7 in the Android app. Session’s announcement says most were already patched; the one severe issue, a TLS verification flaw in the Android app affecting the list of network nodes, has since been fixed. Quarkslab concluded: “The overall security level of this application is good and makes it usable for privacy-concerned people.” Session announced the result in April 2021, and the audit covers the apps as they were in 2020 and 2021.

The 2026 research on Session Protocol V1

In June 2026 four researchers, Urushigaki, Kimura, Tanaka and Isobe, posted a paper titled “Practical Attacks on a Decentralized Secure Messenger Session” to the IACR ePrint archive. It analyses Session Protocol V1, the version Session uses today.

The paper reports two gaps in the design: the two sides of a chat do not authenticate each other’s public keys, and messages are not cryptographically bound to an increasing message counter. According to the authors, these gaps make it possible to impersonate a user, forge message timestamps, and drop or replay messages.

The paper is academic research, not a commissioned audit. It does not say whether the authors reported the issues to Session or whether they have been fixed.

Usability & Reach

Session has apps for Android (also as an APK file and on F-Droid), iPhone, Windows, Mac (Apple Silicon and Intel) and Linux. There is no web version.

Voice and video calls are in beta and work between two people only. Attachments go through the Session File Server and are limited to 10 MB. Disappearing messages are available.

Multi-device use does not depend on a primary phone: you restore the same Account ID on another device with the recovery password. Session has no message backup. You restore an account with its recovery password, and the device then retrieves only messages sent in the last 14 days; contacts come back only if one of your devices was online in the last 30 days.

Funding & Sustainability

Session’s funding model is donations, and its FAQ says Session will always remain free to use. A paid Session Pro tier, from $2.99 a month, adds longer messages and animated profile pictures; core messaging stays free.

The Session Technology Foundation, a Swiss foundation with a non-profit orientation, has looked after Session since October 2024, when the Australian Oxen Privacy Tech Foundation ended its stewardship.

In April 2026, as CyberInsider reported, the foundation said it would stop operating on 8 July 2026 without more funding. 9 April was the last working day for all paid staff and developers. The foundation estimated that it needs about $1 million a year to operate with a small team, and at that point about $65,000 had been raised, enough for 90 days of essential infrastructure.

In June 2026 the foundation wrote that a donation campaign had given it enough resources to continue development “in some capacity”. The team is now 2 to 3 developers, down from more than 12 full-time developers.

Pros and Cons

  • No phone number or email is needed to sign up; contacts are added by Account ID
  • Private chats and groups of up to 100 people are end-to-end encrypted by default
  • Onion routing keeps any single node from seeing both the sender's IP address and the message
  • Messages pass through a network of nodes run by independent operators
  • The apps and the network's server software are open source
  • Quarkslab audited the Android, iOS and Desktop apps and rated their overall security level as good
  • The privacy policy states that the app does not collect or share your information
  • Core messaging is free on Android, iPhone, Windows, Mac and Linux
  • The current Session Protocol has no forward secrecy; Session Protocol V2, which adds it, is still in development
  • Communities are encrypted only in transit to the server that hosts them
  • A 2026 research paper describes impersonation, timestamp forgery and message replay attacks on Session Protocol V1
  • The nodes storing a message see the recipient's Account ID and timestamps
  • Voice and video calls, still in beta, show your IP address to the other person and to a relay server run by the foundation
  • On Android and iOS, push notifications give Google or Apple your device's IP address
  • There is no message backup, and a restored account retrieves only messages from the last 14 days
  • In April 2026 the foundation laid off all paid staff; development continues with 2 to 3 developers

Our Rating

  • Cryptography & Protocol5.5/10

    Private chats and groups of up to 100 people are end-to-end encrypted by default, but the current Session Protocol has no forward secrecy and communities are encrypted only in transit to their server. A 2026 research paper describes impersonation, timestamp forgery and replay attacks on the protocol.

  • Metadata Privacy8.5/10

    Sign-up needs no phone number or email, and onion routing keeps any single node from seeing both the sender's IP address and the message. The nodes storing a message still see the recipient's Account ID and timestamps, and calls and mobile push notifications reveal the IP address.

  • Transparency & Verifiability6.5/10

    The apps and the network's server software are open source, and Quarkslab audited the apps in 2020 and 2021 with ten days of work per platform. The Android repository does not describe reproducible builds.

  • Usability & Reach6.5/10

    Session runs on Android, iPhone, Windows, Mac and Linux without a phone number. It has no message backup, calls are a beta for two people only, and attachments are limited to 10 MB.

  • Funding & Sustainability4.5/10

    Session runs on donations, and in April 2026 the foundation laid off all paid staff, saying it needs about $1 million a year to operate with a small team. Development continued in June 2026 with 2 to 3 developers.

Overall6.5/10

Cryptography & Protocol 30% · Metadata Privacy 25% · Transparency & Verifiability 20% · Usability & Reach 15% · Funding & Sustainability 10%

See our rating methodology →

Ready to try Session?

Visit Session →

Last updated: October 9, 2026By Juan Martinez