How to Back Up an Encrypted Messenger Without the Cloud
Back up your messenger without cloud accounts: learn the 12-word recovery phrase model, why offline backups matter most, and how to store your keys safely.
By The PrivacyPortal Team
To back up a messenger without the cloud, you stop relying on a provider's servers to hold your account and instead keep your own identity keys offline. On a modern encrypted messenger, that identity is often a short recovery phrase — commonly 12 words — that you write down and store somewhere only you control.
This guide explains why cloud backups and end-to-end encryption pull in opposite directions, what you are actually backing up, and how the recovery-phrase model lets you own your identity without a single account in the cloud.
Why cloud backups and encryption pull apart
End-to-end encryption (E2EE) means only you and the person you are messaging can read the contents. The trouble starts when a backup copies those messages somewhere the provider — or its cloud partner — can read them.
A few real-world examples:
- WhatsApp encrypts message content end-to-end by default, but its standard cloud backups are not end-to-end encrypted unless you turn on the separate encrypted-backups option. Left off, a backup can be far less protected than the chats themselves.
- Telegram stores ordinary "cloud chats" on its own servers and can access them; only opt-in one-to-one Secret Chats are end-to-end encrypted, and those live on a single device with no cloud copy.
- Signal is built to minimize what its servers hold and keeps your message history primarily on your device rather than in a provider cloud.
The pattern is clear: the moment a readable backup lands in someone else's cloud, your encryption is only as strong as that backup's weakest setting.
What you're actually backing up
"Backing up a messenger" bundles two very different things:
- Your identity (the keys). This is what proves you are you and lets you decrypt messages. Lose it and you cannot recover the account.
- Your message history. The actual conversations, media, and files.
Cloud services blur these together and often tie both to a phone number or email. A no-cloud approach separates them: you protect the identity yourself, and you decide whether — and where — to keep message history, usually on-device.
The recovery-phrase model
How it works
Instead of a username-and-password account stored on a server, many privacy-first tools generate a recovery phrase: a list of ordinary words (frequently 12) that encodes your private key in a form a human can copy down. The phrase is your identity. Whoever holds it can restore the account; whoever doesn't, can't.
Because the phrase is generated on your device, there is no account record sitting on a server waiting to be breached, subpoenaed, or reset by anyone who captures your SMS.
Why it's more private
- Nothing to leak server-side. If there's no stored account, a server breach exposes no login to steal.
- No phone number or email as a handle. Your identity isn't tied to your SIM card.
- You are the single point of recovery. That is a responsibility as much as a benefit — which is exactly why storing the words well matters.
How to store 12 words safely
The recovery phrase trades convenience for control. Treat those words like the only key to a safe, because that is what they are.
| Do | Avoid |
|---|---|
| Write the words on paper or stamp them into metal | Screenshotting them into a cloud photo library |
| Keep at least two copies in separate physical places | Storing them in cloud notes, email drafts, or a chat-to-self |
| Consider a fireproof or waterproof container | Reading them aloud near smart speakers or on video |
| Store copies somewhere only you can access | Splitting the words in a way you will never reassemble |
Two principles cover most mistakes:
- Offline beats online. Anything typed into a synced app can end up in a cloud you don't control.
- Redundancy beats over-secrecy. One copy that burns in a house fire is as lost as no copy. Aim for two durable, separated copies.
If you use a password manager, keep the phrase only in a vault that stays local or is itself end-to-end encrypted — never in plain cloud storage.
How messengers compare on backup and identity
| Messenger | Identity handle | Where history lives | Cloud-backup dependency |
|---|---|---|---|
| Signal | Phone number | Primarily on your device | Minimizes server-stored data |
| Phone number | Device + optional cloud backup | Backup not E2E unless you enable encrypted backups | |
| Telegram | Phone number | Cloud chats on Telegram's servers; Secret Chats device-only | Cloud chats stored server-side, not E2EE |
| Graphite | 12-word recovery phrase (no account) | On your device | No cloud account to depend on |
The differences aren't about which app is "good" — they're about how much of your identity and history you keep versus hand to a provider.
How Graphite handles no-cloud backup
Graphite is an end-to-end-encrypted messenger by PrivacyPortal built around exactly this model. It uses no phone number and no email. Your identity is a 12-word recovery phrase generated on your device, and there is no account on the server to back up in the first place.
That design changes what a "backup" even means:
- You hold the only key. The recovery phrase is created locally and never leaves your device unless you write it down. Restore Graphite on a new device by entering your 12 words.
- The relay isn't a backup. Graphite's no-logs relay stores only sealed ciphertext, keeps it for a maximum of 7 days, and deletes it once delivered. It never sees your plaintext, your keys, or your recovery phrase — so there is nothing readable in the cloud to protect.
- Your history stays on your device. Messages, encrypted group chats, and shared files live locally, and Graphite's AI message search runs on-device with nothing uploaded.
- It runs where you need it. Windows (a portable .exe with bundled Tor), Android — including GrapheneOS and de-Googled phones with no Google Play Services — and the web app.
Encryption itself is handled with NaCl/libsodium sealed boxes plus a hybrid post-quantum layer (ML-KEM-768) and Signal-style forward secrecy, and traffic is routed over Tor by default to hide your IP. But for backups, the headline is simpler: because your identity is 12 words you control and the server holds nothing readable, backing up means protecting those words — not trusting a cloud.
A simple no-cloud backup routine
- When you set up the messenger, immediately write down your recovery phrase — on paper or metal, never a screenshot.
- Make a second copy and store the two in different secure locations.
- Verify you copied the words correctly before relying on them.
- If you want history preserved, keep your device itself backed up locally using device-level encrypted backups you control.
- Test recovery on a spare device or after a reinstall so you know the process works.
Do this once and your messenger survives a lost, broken, or stolen phone — with no cloud account anywhere in the chain.
Want the bigger picture? See our guide to how an encrypted messenger works, and if you're leaving a number-based app, read messaging without a phone number and choosing a Signal alternative without a phone number.
Try it yourself
Graphite is free and in public beta (v1.13.25) on Windows, Android, and the web — no phone number, no email, and a no-logs relay that stores nothing readable. Your identity is 12 words you keep offline. Download it and set up your recovery phrase at graphite.chat.