

They could always do that, and basically anything you can read on your phone, they can access if they need.
Encryption is a math thing: generate a pair of keys: one te encde, one to decode. I broadcast the one to encode (“public key”), and the whole world is tu use it to send me encrypted messages. I keep the decoding (“private key”) only for myself.
In client to erver encryption, we exchange keys with the server through which go all the comms: it decodes my messages and re-encodes them for my contact.
In e2e, the key exchange is between contacts: the server does not have the private keys.
In Meta, the proprietary app can send your private key to the server and then they know what you wrote. You have no way to know it doesn’t do so!
Opensource audited software is the only way to make sure.



Metadata. They would still know where you were, for how long, who you talk to, when and from where. Then they combine these info. ex: you call your pop and mom, théir fridge broke down, and you start receiving ads for fridges. Was Meta listening?? No: pop and mom hinted the fridge was down (Google search or other), Meta has established your family links a long time ago, and you usually visit them after a longer than usual conversation (as they have an issue and yuu go help). Here: you fridge’s ads.