# Signal messages retrieved from iOS notification

**URL:** https://discuss.privacyguides.net/t/signal-messages-retrieved-from-ios-notification/36475
**Category:** General
**Tags:** software
**Created:** 2026-03-22T14:34:58Z
**Posts:** 21

## Post 1 by @KathyM — 2026-03-22T14:34:58Z

TLDR: signal content in Apple notification can be retrieved even after signal app deletion.

I saw from this reddit thread: [Signal messages retrieved from iPhone after uninstalling app. : signal](https://old.reddit.com/r/signal/comments/1rr8gse/signal_messages_retrieved_from_iphone_after)

Referencing this news article: [Pretti Killing May Affect ICE Prairieland "Antifa Cell" Terrorism Trial](https://theintercept.com/2026/02/11/prairieland-antifa-trial-pretty-ice-protest/)

The mention of signal is in court documents here: [March 10: Federal Trial Day 12 - Support the Prairieland Defendants](https://prairielanddefendants.com/court-notes/march-10-federal-trial-day-12/)

> **Signal chat evidence from Sharp’s device (Exhibit 158):**  
> Messages were recovered from Sharp’s phone through Apple’s internal notification storage — Signal had been removed, but incoming notifications were preserved in internal memory. Only incoming messages were captured (no outgoing).

---

## Post 2 by @anon25722375 — 2026-03-22T15:19:32Z

Isn’t this more an iOS issue than Signal’s?

Also, this is only an issue if one has message preview in notification enabled. That’s why for the longest time Tuta did not have this option.

---

## Post 3 by @iHateKYC2 — 2026-03-23T03:44:40Z

Yes this most likely comes from Biome/KnowledgeC data which can persist for 30 days. This is not unique to signal but a bunch of [apps](https://blog.digital-forensics.it/2023/11/ios-15-image-forensics-analysis-and.html).

iMessage, Instagram, Facebook, Discord are good examples as they rely on “iOS-level” notification hiding which does **nothing** in reality.

Signal, Telegram, and WhatsApp have options to sanitize the notification in-app which is the “real protection” against this.

Only way to wipe notification remnants is to factory reset the phone and **NOT** restore from a iCloud Backup. Your iCloud backup can reintroduce old forensic artifacts. If you have iCloud+ then using iCloud backups would be silly. Most of your important stuff is saved as synced data

- Photos (iCloud Photos)

- Messages (if Messages in iCloud enabled)

- Contacts, Notes, Calendars

- iCloud Drive files

- Keychain (passwords)

Extra Note: It is also important for everyone you communicate with to be just as educated as you or all of this is for nothing. The FBI used one persons phone (who deleted the app) to access the messages of **other** people. This serves as a reminder to not blindly use these secure platforms without understanding at least some digital forensics. People bash the cloud for being insecure yet are harvesting a gold mine of data on local devices that could be accessed depending on their security posture.

---

## Post 4 by @XamL — 2026-03-30T02:22:16Z

> [@iHateKYC2](#):
>
> iMessage, Instagram, Facebook, Discord are good examples as they rely on “iOS-level” notification hiding which does **nothing** in reality.
> 
> Signal, Telegram, and WhatsApp have options to sanitize the notification in-app which is the “real protection” against this.

Could you explain the difference between apps relaying on “iOS-level” notification hiding and other apps sanitizing notifications in-app please?

Might misunderstand you - just not allowing notifications when you set up the app and Apple asks to - that’s not enough? Rather you should not allow notifications within the app (too), especially notification content (so instead of Name and Content changing it to no Name and Content).

---

## Post 5 by @Novelrom — 2026-04-09T01:43:40Z

I believe your understanding is correct - apps that can hide notifications from in app settings while still allowing notifications to come through, ie “Signal name only notifications” for example is the notification sanitation. At least thats how i understand it.

I presume even if you out an app like imessage behind the face ID lock which “hides” the notification, it’s still part of the OS level notification logging.

---

## Post 6 by @PurpleDime — 2026-04-11T05:59:30Z

> **[FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification...](https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/)**
>
> The case was the first time authorities charged people for alleged “Antifa” activities after President Trump designated the umbrella term a terrorist organization.

[Archive link (No Paywall).](https://archive.ph/teJlF#selection-607.0-607.218)

**TL;DR:**

> _**The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database […]**_

@henry-fisher from [Techlore](https://techlore.tech/) also provided some useful contextualization on his socials:

[Mastodon](https://social.lol/@techlore/116375100832088259)  
[BlueSky](https://bsky.app/profile/techlore.tech/post/3mj2xosgjmr2l)  
[Twitter](https://x.com/TechloreInc/status/2042240764785422755?s=20)

> _When Signal messages arrive, iOS stores push notification previews locally on the device. Those previews stayed behind even after Signal was uninstalled._
> 
> _Two things:_
> 
> - _Only incoming messages were captured this way_
> - _Disappearing messages that had already vanished inside Signal were still recoverable from the notification cache_
> 
> _This is iOS behavior, not a Signal vulnerability. And likely impacts other apps._
> 
> _This is a very high threat model concern, though the fix is straightforward:_  
> _Signal → Settings → Notifications → Show → set to “No Name or Content”_
> 
> _You’ll still get a notification ping, but iOS just won’t cache anything useful._

---

## Post 7 by @bitsondatadev — 2026-04-11T03:43:52Z

> **[FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification...](https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/)**
>
> The case was the first time authorities charged people for alleged “Antifa” activities after President Trump designated the umbrella term a terrorist organization.

Some interesting takeaways for iphone + signal users. I don’t have an iphone but curious if the recommended settings in privacy guides accounts for the notification logs.

---

## Post 8 by @WhyRhy — 2026-04-11T13:40:09Z

Why is this only iOS and not Android? I’ve not had an Android before so I don’t know but presume they handle notifications differently and deleted?

For iOS, how long are these ‘notifications’ held for (and WHY!!) and does it contain the WHOLE message, or just a line or two?

---

## Post 9 by @graym — 2026-04-11T13:52:42Z

> [@WhyRhy](#):
>
> For iOS, how long are these ‘notifications’ held for (

I was just thinking about the same question. [This source](https://www.magnetforensics.com/blog/ios-forensics-evidence-sources-to-capture-before-they-expire/) says KnowledgeC DB is 28-30 days.

I also found [this link](https://theforensicscooter.com/2021/10/03/ios-knowledgec-db-notifications/) really interesting. While dated, it has a lot of detail about what was captured in KnowledgeC DB (at least at that point in time).

---

## Post 10 by @WhyRhy — 2026-04-11T14:04:23Z

Yeah, although from what I’ve read it depends how much memory your device has and how heavy a user as and when it needs to rewrite.

---

## Post 11 by @bitsondatadev — 2026-04-11T18:00:52Z

> [@WhyRhy](#):
>
> I don’t know but presume they handle notifications differently and deleted?
> 
> For iOS, how long are these ‘notifications’ held for (and WHY!!) and does it contain the WHOLE message, or just a line or two?

They likely do but it would be worth it to investigate Android as well since… Why not.

This is why I think it’s worth asking someone who knows like @fria or @jonah who use these. Is there any way to account for this leak?

I don’t imagine it’s something nefarious from Apple, likely a convenience thing for both users and developers, but hopefully something you can disable in some way.

---

## Post 12 by @ignoramous — 2026-04-11T20:26:21Z

> [@bitsondatadev](#):
>
> it’s something nefarious from Apple, likely a convenience thing

This is “nefarious” insofar their implementation choice [0] goes against their marketing claim, “Apple. Privacy.”

[0] Why not implement e2ee or similar scheme for sensitive notifications?

---

## Post 13 by @bitsondatadev — 2026-04-11T23:20:39Z

Fair, but misleading marketing is part for thr course. Not that it’s ideal but that is just what one should expect in this age. But as you say, Apple is Privacy Possible versus the consumer expectation of Privacy by Default.

This particular leak was due to them not using their resources to pen test beyond what they might consoder reasonable assumptions. They are doing “good enough" for the public to remain convinced they are privacy by default. If that is actually true is not the company’s true concern.

The only way these days to get that are communities that dogfood their own product and truly care about the outcome like GrapheneOS.

---

## Post 14 by @anon93307265 — 2026-04-12T02:35:33Z

What if you leave notifications turned off?

---

## Post 15 by @Valynor — 2026-04-12T02:44:05Z

From the Signal iOS settings:

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/4/3/43a00ab30f8d32135d3589be35e7aa4c33973f16.png)

---

## Post 16 by @WhyRhy — 2026-04-12T06:39:46Z

Yes, if notifications are turned off then this specific issue would be a non-issue. So, muted groups/1-2-1 chats would also not be an issue.

My settings are now set to “No name or content” in Signal, and I’ve gone into iOS and changed to remove all previews. Apple AI is off in any case, too.

---

## Post 17 by @WhyRhy — 2026-04-12T07:40:16Z

Linking this message:

> [@Pavel Durov on Signal](https://discuss.privacyguides.net/t/pavel-durov-on-signal/37058/21):
>
> I may be wrong here - and very happy to be corrected by those more technically minded - but I think there is a way. In Signal group chats, snippets of your replies to messages are sent to everyone - even if you’ve got them blocked! By this I mean: you can send a message in a group chat, but if someone replies to your message, everyone can see the first line of text (to a degree) even if they’re blocked. So, to rectify this you write something on the first line (emojis, a full stop, any lette…

As I’m not sure if this is a solution (_or at least a viable interim measure_) to prevent the Apple notifications storing your actual message. I don’t know enough about how it’s stored to give any technical assurances. Perhaps others may know of this is viable?

---

## Post 18 by @securitybrahh — 2026-04-12T16:07:39Z

> [@Is there an alternative to FCM and APN?](https://discuss.privacyguides.net/t/is-there-an-alternative-to-fcm-and-apn/36242):
>
> I mean there is unified push but developers need to implement that tbh I don’t use notifications at all for weird reasons I just open apps randomly throughout the day. And I don’t give notification permission

---

## Post 19 by @Quantum — 2026-04-12T17:06:37Z

Another solution would have been to be in lock down mode without biometrics enabled. That would have prevented physical exploitation of the iPhone in question.

---

## Post 20 by @anon93307265 — 2026-04-12T21:29:35Z

kind of what I figured, but I wanted to make sure. I leave notifications off on anything sensitive (just have to remember to check it).

---

## Post 21 by @WhyRhy — 2026-04-12T21:50:12Z

Yes, and also not forgetting if the threat model is to protect anything ‘sensitive’, you’re relying on at least two-way (or multiple for groups). Just because you or I try to minimise the privacy issue, we rely on others to do the same. This is not in our control…
