You have probably read that WhatsApp is end-to-end encrypted, and that is true. So the backup must be encrypted too, right?
No. They are two different systems, protected in two different ways, and only one of them is on by default.
This is not a technicality. It is the single most common gap between what people believe about their message history and what is actually true of it.

Where the protection stops
End-to-end encryption protects a message on its journey. It is locked on your phone, it stays locked as it crosses WhatsApp's servers, and it is unlocked on your friend's phone. During that trip, WhatsApp cannot read it.
The backup is a different event entirely. Your phone takes the messages that are already decrypted and sitting in your app, packages them up, and sends the package to Google Drive or iCloud.
The trip was protected. The copy at the destination is a separate question, governed by a separate setting.
This is why "WhatsApp is end-to-end encrypted" and "my WhatsApp backup is end-to-end encrypted" can both be sentences about the same account, with one true and the other false.
The two kinds of encryption people confuse
Ask whether a backup is encrypted and you get a yes, which is technically accurate and answers the wrong question.
Google Drive and iCloud do encrypt what they store. The question that matters is not is it encrypted but who holds the key.
- Encrypted at rest by the provider. The data is scrambled on disk. The provider holds a key that unscrambles it. This defeats someone who steals a hard drive. It does not defeat a legal request served on the provider, because the provider can comply.
- End-to-end encrypted. The key is derived from your password or a 64-digit code, and stays with you. WhatsApp does not have it. Google and Apple do not have it. A legal request produces a blob nobody can open.
Both get called "encrypted". Only the second means what most people assume when they hear the word.
If you want the same guarantee for your files, not just your chats
Encryption happens on your device before anything is uploaded, so the provider stores a blob it cannot read. The property you are switching on for your WhatsApp backup, applied to everything else you keep in the cloud.
Turning it on, and the price of doing so
The setting lives in WhatsApp itself, not in Google Drive or iCloud, which is where a lot of people go looking for it. Follow Settings, then Chats, then Chat backup, then End-to-end encrypted backup.
You choose between a password you invent and a 64-digit key the app generates. The 64-digit key is stronger, since it cannot be guessed the way a chosen password can, but it is also something you must genuinely store rather than intend to remember.
And here is the part that deserves a full stop before you tap through:
If you lose that password or key, the backup is gone. Permanently. There is no support ticket for this.
That is not WhatsApp being unhelpful. It is the whole point. A recovery path that WhatsApp could operate on your behalf would be a key WhatsApp holds, and then the backup would not be end-to-end encrypted at all. You cannot have both properties, and any service claiming to offer both is doing one of them badly.
Where to keep the key
The failure mode is almost comic in how reliably it happens: someone enables encrypted backup, saves the 64-digit key in a note on their phone, then loses the phone. The key was only ever needed in the one situation where it is now unreachable.
Store it somewhere that survives the loss of the device:
- A password manager that syncs, so the key exists on more than one device.
- Written on paper and kept where you keep documents. Old-fashioned, and it does not break when a phone does.
- Not in the WhatsApp chat you use for notes to yourself, since restoring that chat is exactly what the key is for.
If you already use a password manager for logins, this is the same habit applied to one more secret. If you do not, this is a reasonable moment to start, because the consequence of losing this particular string is unusually final.
What the backup still reveals
Even with end-to-end encrypted backup enabled, the contents are unreadable but the existence of the backup is not hidden. Your cloud provider can see that a WhatsApp backup exists in your account, roughly how large it is, and when it was last written.
Size and timing are not nothing. A backup that grows steadily says something about how much you message, and one that stops growing says something too. This is the same metadata problem that runs through every encrypted system: the content is sealed, the shape of the envelope is not.
For most people this is an acceptable residue. It is worth knowing about rather than being surprised by, particularly if your reason for caring about the backup was never really about advertising.
The honest summary
Your messages in transit: protected by default. Nothing to do.
Your backup: protected only if you switched it on. Go and look, because the answer is stored in a setting rather than in your memory of having read that WhatsApp is encrypted.
The check takes under a minute, and unlike most privacy advice, the outcome is binary and you can verify it yourself right now. If the toggle is off, you have learned something true about where your message history currently lives. If it is on, confirm you can still find the key, which is the half of the job people skip.
Frequently asked questions
- Is my WhatsApp backup encrypted by default?
- Your messages are end-to-end encrypted in transit by default, but that protection stops when the backup is written. WhatsApp offers an end-to-end encrypted backup option, and it is something you switch on yourself. If you have never opened that setting, your backup is stored under the ordinary protections of Google Drive or iCloud rather than under a key only you hold.
- What is the difference between an encrypted backup and an end-to-end encrypted backup?
- Almost everything, from a privacy point of view. Google Drive and iCloud both encrypt what they store, but they hold keys that can decrypt it, which means the contents can be handed over in response to a legal request. An end-to-end encrypted backup is locked with a key derived from your password or a 64-digit code, and neither WhatsApp nor the cloud provider holds it.
- What happens if I forget my WhatsApp backup password?
- The backup becomes permanently unreadable. This is not a policy that support can override, it is the direct consequence of nobody else holding the key. If you enable end-to-end encrypted backup, save the password or the 64-digit key somewhere you will still have access to after losing your phone, which rules out saving it only on that phone.
- Does the backup count against my Google Drive or iCloud storage?
- This has changed over time and differs between the two platforms, so check the current behaviour in your own account rather than trusting an article. The privacy question and the storage question are separate: whether the backup consumes quota has no bearing on who can read it.
- Should I just turn the backup off instead?
- That is a real option, and for some people the right one, but understand what you are choosing. With no backup, a lost or broken phone means your message history is gone, because WhatsApp does not keep a copy on its servers for you to restore from. Turning on end-to-end encrypted backup usually gets you the privacy you wanted without accepting that loss.
Switch to encrypted email → Proton Mail
Swiss · end-to-end encrypted · open-source · free tier



