A normal text message is not private. When you send an SMS, it leaves your phone unencrypted, passes through your mobile carrier's network, and is stored on their systems for a period of time. Carriers keep records of who you messaged and when, and those records can show up on itemized billing statements or be handed over on request. Anyone with access to that pipeline can read the words you typed.
You cannot stop your carrier from seeing that a message was sent — that is how the network routes it. What you can do is make sure the contents are meaningless to anyone but the person holding the key. That is what CipherPigeon does.
What your carrier can and cannot see
- Can see: the phone numbers involved, the time, and the size of the message. This is metadata, and it usually appears in call and text logs.
- Can see with plain SMS: the full text of the message itself.
- Cannot see with encryption: anything about the actual content — only a block of scrambled characters.
Itemized phone bills typically list numbers and timestamps rather than message bodies, but the message content still exists on carrier infrastructure. Encrypting before you hit send removes that exposure entirely.
How to send a text your carrier cannot read
- Agree on a passphrase with your recipient — in person, over a call, or through a separate channel. Never send it in the same message.
- Open CipherPigeon and type your message.
- Enter the passphrase and tap encrypt. The app produces a block of ciphertext on your device.
- Copy the ciphertext and paste it into your normal Messages app, then send it as usual.
- Your recipient pastes it back into CipherPigeon, enters the same passphrase, and reads the original text.
The message travels over the same SMS network it always did. The difference is that the only readable copy exists on your phone and your recipient's phone.
Why not just use an encrypted messaging app?
Encrypted messengers are a good option, but they come with conditions: an account, a phone number, an internet connection, and trust in the company running the servers. If the app is compromised, subpoenaed, blocked in your country, or simply changes its policies, your protection changes with it.
CipherPigeon works differently. There is no account, no server, and no network requirement. Encryption happens on your device before anything is transmitted, so you can send the result through SMS, email, a note app, or a scanned piece of paper. The channel becomes irrelevant.
It works for photos too
Images are just as revealing as text — often more so, because they carry timestamps and location data. CipherPigeon can turn a photo into an encrypted .cpg file that you send the same way. The carrier or platform handling the transfer sees only an opaque file.
Practical habits that help
- Send the passphrase through a different channel than the message.
- Change passphrases periodically for ongoing conversations.
- Delete plaintext drafts from your notes and clipboard after sending.
- Remember that metadata still exists — encryption hides what you said, not that you said something.
If you want the contents of your texts to stay between you and one other person, encrypt them before they touch the network. Everything after that is just delivery.

