End-to-end encryption protects message contents, but typing indicators, read receipts, and precise timestamps still expose a surprising amount of behavioral metadata: when someone is awake, who answers quickly, and whether an exchange feels urgent. I’ve caught myself checking the gap between “read” and a reply and assigning meaning to it, even when I knew that was probably unfair.
Signal at least makes typing indicators and read receipts optional, with both sides involved, and shows timing details locally. I wonder whether the safer default is coarser time buckets, local-only indicators, configurable disclosure delays, or privacy-preserving batching. Real-time presence can still matter for accessibility and coordination, so disabling everything universally seems too blunt. Should metadata controls be granular user settings, privacy-safe defaults, or both? I’d like to hear about implementations and strong counterarguments.