Ontaym Open the app

Why Privacy-Minded Signal Groups Still Struggle to Meet in Person

Two groups, both on Signal for good reasons, both hit the same wall trying to get people to an actual room on an actual day. One can't easily bring a new member in without a phone number changing hands. The other watched its meeting point disappear for half the group before the other half ever saw it.

A blurred silhouette of two hands pressed against frosted glass from the other side, faint outlines of fingers visible
Signal is built to leave exactly this much of a group visible to anyone outside it: an outline, nothing sharp enough to act on.

Quick answer

Signal usernames let someone be added without handing over a phone number, but Signal's own documentation confirms there is no searchable directory, so the exact username still has to be shared somewhere outside the app first.

Disappearing messages count down differently for each person, starting only once they've actually read a message, which means the same fact can vanish for an early reader while it's still visible to someone who checks in days later.

Neither is a flaw in Signal. Both point to the same fix: give the handful of facts a group actually needs, an address, a time, a headcount, a home outside the thread's own privacy rules.

The book club that couldn't add its own new member

A book club of seven, three years running, all on Signal because one member works in a field where that matters. A friend of a friend wants to join for the next meeting, a Tuesday, someone's living room.

Normally that's nothing. Except nobody in the group has this person's number, and asking for it feels like a bigger ask than it should be.

Not because anyone's precious about it. Because the whole reason the group is on Signal in the first place is to stop treating phone numbers as the default way people get known to each other.

Signal is careful about exactly the thing you now need

Signal's own group link feature solves part of this well. A group can generate a shareable link, and EFF's Surveillance Self-Defense guide to Signal groups describes turning on "Require Admin Approval" for that link so new joiners are vetted before they land in the chat.

That's the right tool for a public-ish group. A seven-person book club isn't that, and generating a link, sending it somewhere, and having someone tap "request to join" is a lot of ceremony for one guest at one meeting.

The other option is a username, and Signal's own blog post on the feature is clear about what it does and doesn't do. It lets someone initiate contact on Signal without sharing your phone number, which is exactly the gap.

The same post is just as clear about the catch. Signal states plainly that it does not run a searchable directory of usernames, and that "someone will need to know your exact unique username in order to start a chat with you."

So the new member still needs to be handed something specific, in a channel outside Signal, before any of this works. The privacy feature removes the phone number and quietly reinstates a different kind of handoff in its place.

Signal removed the phone number from the handshake. It didn't remove the handshake.

What actually has to happen before Tuesday

Walk through what onboarding one new person to that book club actually takes, and the steps are small but they're real. None of them happen inside the app on their own.

  1. Someone has to get the new member's exact username. Not a name, not a guess, the precise string, because there's nothing to search.
  2. That exchange happens somewhere else entirely. A text, an email, a message on a different app, which is its own small irony for a group that chose Signal to avoid exactly that kind of exchange.
  3. An existing member sends the request and waits for it to be accepted. A short wait, but a wait, and it has to happen before the meeting starts, not during it.
  4. Once they're in, they still need the actual details. The address, the time, whether to bring anything, none of which a fresh member can find by scrolling a week of chat about last month's book.

Every one of those steps is small. Add them up and a book club ends up spending more coordination effort on one new guest than most groups spend on the entire meeting.

Two men laughing with a small group of friends gathered outside a house on a sunny day
The part that's supposed to be easy: someone new, shown in, in time for the actual conversation.

The mutual aid group whose plan disappeared on schedule

A different group, a mutual aid network coordinating a Saturday supply drop, twenty-two people, most of whom don't know each other well. The group has a two-day disappearing timer set, for good reason: nobody wants a permanent, searchable log of who showed up to what.

The drop-off address gets posted Thursday evening. Half the group reads it Thursday night. The other half doesn't open Signal again until Saturday morning, on their way there.

Signal's own documentation on the feature explains why that matters here specifically. A disappearing timer doesn't start the same way for everyone, because a received message only begins its countdown once the recipient has actually read it, while a message someone sent starts counting the moment it left their phone.

For an active pair chatting in real time, that distinction barely registers. For a loose, twenty-two person network where half the members check in once a day, it means the same message is simultaneously alive for a slow reader and already gone for the person who opened it Thursday night and forgot to write it down.

Why the same disappearing message doesn't disappear for everyone at once
Who they areWhen their copy starts counting downWhat that looks like Saturday morning
Person who read it Thursday nightThursday night, the moment they opened itMessage is long gone, and they're relying on memory alone
Person who opens the app Saturday morningSaturday morning, the moment they finally read itMessage is still there, showing the correct address
Person who never opens the thread againNever startsMessage technically still exists, but they never see it

Nobody in that group did anything careless. The timer worked precisely as Signal designed it, on a feature built for exactly this kind of privacy, and it still left the group with three different realities on the same Saturday morning.

Why loose, privacy-minded groups get hit hardest

A tight friend group checks Signal constantly, so a disappearing timer barely creates a gap between when a fact is posted and when everyone's actually seen it. A mutual aid network, an activist working group, a support meetup for people who'd rather not be findable, none of those groups behave that way.

Membership is looser. People check in on their own schedule, sometimes daily, sometimes only when something's actually happening.

That's precisely the kind of group that has the strongest reason to want Signal's privacy, and precisely the kind of group where a read-triggered countdown creates the widest spread between who's seen a fact and who hasn't. The feature and the use case are pulling in opposite directions at once.

Three fixes people reach for, and where each one runs out

"We'll just say the address twice"

Repeating it helps the people who happened to be online both times. It does nothing for anyone who checks in once, on their own schedule, and it adds a second message that starts its own separate countdown.

"We'll make someone the designated rememberer"

This works until it doesn't. One person holding the current facts in their head, or in a private notes app nobody else can see, is a single point of failure with no backup and no way for anyone else to check their own memory against it.

"We'll turn the timer off for logistics messages"

Signal doesn't offer a message-by-message exception. The timer applies to the conversation, not to a category of message within it, so turning it off for "the important ones" means turning it off for everything, which reopens the exact privacy question the group set the timer to answer.

The same twenty-two people, one week later

The following Saturday the network runs a second drop, same rough size, same two-day timer. This time the organizer tries something different: post the address, then post it again eighteen hours later as a plain reminder, no new information in it.

It helps, a little. Anyone who read the first message and still had it live sees a second copy that agrees with the first, which is at least reassuring.

It does nothing for the person who hasn't opened Signal since Thursday morning, because both messages are sitting unread in the same place, both on the same countdown, both destined to vanish the moment that person finally checks in. Repetition inside a disappearing thread only reaches people who were already going to see the first one.

What a private group actually needs against what a public one needs

It's worth being precise about what's different here, because "Signal is private" undersells what's actually happening. A public community forum optimizes for being found. A private Signal group optimizes for the opposite, and that choice has real, specific costs once the group needs to coordinate something offline.

What a discoverable public group gets by default, against what a private Signal group has to build by hand
What's neededA public, searchable communityA private Signal group
A stranger finding the groupBuilt in, that's the pointDeliberately blocked, by design
Onboarding a specific new memberAn open link, done in secondsAn exact username, handed over elsewhere first
A fact surviving a weekSits in a searchable history indefinitelyDepends entirely on the disappearing timer and who's read it
Proving who's actually comingOften a public RSVP listScattered replies inside a thread nobody outside it can see

Every column on the right is a deliberate trade, not an oversight. A group that wants the left column back, in full, has picked the wrong app on purpose, because the left column is what a public forum's own openness is built to expose.

What a book club and a mutual aid group actually have in common

These look like different problems. A slow social handshake on one side, a vanishing address on the other.

They're the same problem from two directions. Signal was built to make sure nothing sticks around, and nothing gets exposed, that doesn't strictly need to.

Onboarding a new member and keeping a shared fact alive both require exactly the kind of stickiness Signal is designed to avoid by default. Neither group is using the app wrong. They're both running into the edge of what a privacy-first messenger was ever meant to hold onto.

What actually closes the gap without giving anything up

The fix isn't turning off any of Signal's protections. It's giving the handful of facts that need to survive a home that doesn't run on the chat's own rules.

A book club invite that lives at one link tells a new guest the address and the time without anyone handing over a phone number to get there. A mutual aid drop-off point that lives somewhere outside the disappearing thread stays true whether someone reads it Thursday or Saturday morning.

The chat keeps doing what it's good at and was built for: talking, arguing about the book, coordinating who's bringing what, all of it exactly as private as the group chose it to be. The one thing that changes is where the load-bearing facts live.

Where Ontaym fits

Ontaym holds the specific things a privacy-first chat won't hold for you: one time, one place, one current answer per person, all reachable at a single link that anyone can open without an account.

Drop that link into a Signal thread and a new member gets the details without anyone trading numbers, and a mutual aid volunteer gets the correct address whether they check in Thursday or three minutes before the drop. The thread keeps its timer, its privacy, and its actual conversation, untouched.

That's a narrow job on purpose. A public rally with open sign-ups needs a different kind of page entirely, and a two-person coffee catch-up needs nothing more than Signal already gives it.

What "just be more organized" actually asks of people

The advice a lot of these groups get is some version of "just be more disciplined about it." Set the timer longer, pin more carefully, remind people more often.

That advice isn't wrong exactly, and it isn't free either. Every one of those fixes asks a volunteer, an organizer, or a book club host to personally absorb the gap between what Signal is built to do and what the group actually needs.

That's a real cost, paid by one person, over and over, for as long as the group keeps meeting. It's also the kind of cost that's invisible until the person paying it quietly stops volunteering to organize anything.

None of that is a criticism of anyone who's tried the discipline route. It genuinely helps, right up until the week that person is busy, sick, or just tired, and then the group finds out how much weight one person had quietly been carrying.

The awkwardness nobody names out loud

There's a version of this that never gets said in the group, and it's worth saying once, plainly. Asking someone for their phone number, in a lot of contexts, is a small, ordinary thing.

In a group that specifically chose Signal to avoid treating a phone number as a universal ID, asking for one again, even just to route around a search feature that doesn't exist, feels like undoing the group's own decision. Nobody wants to be the person who says "just text me your number" in a thread whose entire premise is that numbers shouldn't be the default currency of trust.

That's not paranoia, and it's not overthinking a book club. It's a completely reasonable reaction to being handed a tool built around one principle and then needing to work around that exact principle to get one new person into a room.

The organizer usually ends up doing it anyway, over text or email, because there's no other way through. It just costs a small, specific bit of discomfort every single time, and that cost never shows up anywhere except in how tired people get of inviting new members at all.

A false start that's worth mentioning: safety numbers

People sometimes reach for Signal's safety number verification, the process for confirming you're actually talking to who you think you are, assuming it might also solve the onboarding problem. It's a genuinely useful security feature for a different job entirely.

Signal's own blog post on the feature describes it as tracking whether an existing contact's encryption key has changed, and requiring manual approval before a message goes through if a verified number suddenly changes. That confirms identity between two people who are already in contact.

It doesn't help a group find or vet a brand new person who isn't in the conversation yet, and it doesn't touch the disappearing message timer at all.

It's a good feature, aimed at a real threat, that simply isn't shaped like the two problems this article is about. Worth knowing it exists, and worth not expecting it to do something it was never built for.

Two groups, one shared shape

Step back and the book club and the mutual aid network turn out to be running the exact same experiment, just at different sizes and different stakes. Both picked Signal for good reasons that have nothing to do with event planning.

Both then discovered that the thing they needed, a new member showing up smoothly, or a fact staying true for everyone regardless of when they checked their phone, sits slightly outside what the app was built to hand them for free. Neither group is unusual, and neither problem is a bug report waiting to be filed.

It's the honest cost of choosing privacy on purpose, and it's worth naming clearly instead of quietly working around it forever. Once it's named, the fix is small and doesn't touch any of the reasons the group chose Signal in the first place.

A quick check for your own group

Not every Signal group needs a separate place for its facts. If everyone checks the app constantly and membership barely changes, the thread is probably handling it fine on its own.

Watch for two things instead. If a new person joining requires more back-and-forth than the actual event does, or if the group has ever wondered whether "everyone" actually saw the update before a disappearing timer took it, that's the sign.

Signal is doing exactly what it was built to do in both cases. The group just needs one small thing living somewhere else.

That's a much smaller ask than it sounds, once you name it. Not a new app to convince nine reluctant friends to install, not a new set of habits to enforce.

Just one address, for the handful of facts that actually need to survive contact with a new member or a slow week, sitting quietly outside the part of Signal that was always going to forget them.

Frequently asked questions

Can you add someone to a Signal group without their phone number?

Yes, using a username instead. Signal's own blog post describes usernames as a way to initiate contact without sharing a number, though the same post confirms there is no searchable directory, so the new member's exact username still has to be shared through some other channel first.

Why does a Signal group link need admin approval?

It lets a group share a join link publicly while still vetting who actually gets in. EFF's guide to managing Signal groups describes turning on admin approval for exactly this reason, so a link can circulate without every recipient automatically becoming a member.

Do disappearing messages vanish at the same time for everyone in a group?

No. Signal's own explanation of the feature confirms a sent message starts counting down the moment it's sent, while a received message only starts counting once the recipient actually reads it, so the same message can be gone for one person and still visible to another.

Why do loose or occasional-use groups struggle more with disappearing messages?

Because the countdown only starts once someone reads a message, a group where people check in daily or weekly creates a wide gap between who's seen a fact and who hasn't. A group that's active constantly barely notices the same mechanic.

Is turning off the disappearing timer a fix?

It stops messages from vanishing, but Signal applies the timer to the whole conversation rather than to specific messages, so there's no way to keep it off only for logistics. Turning it off for one fact means turning it off for everything in that thread.

What's the actual difference between a book club's problem and a mutual aid group's problem?

One is about bringing a new person in without a phone number exchange, the other is about a fact surviving long enough for everyone to see it. Both come from the same source: Signal is built to avoid holding onto things by default, and both onboarding and a stable fact require exactly that.

Does fixing this mean giving up Signal's privacy features?

No. The fix is giving a small number of load-bearing facts, like a time, a place or an address, a home outside the thread's own rules, while the conversation keeps its disappearing timer and its phone number privacy exactly as set.

Ontaym Editorial Team

Ontaym builds tools for organising real-world gatherings, so the team spends its days on the coordination problems this article describes. Articles are researched against primary sources, reviewed before publication, and revised when the underlying facts change rather than on a schedule.

Give your next plan one address instead of one more thread.

Plan it with Ontaym