All posts
March 15, 2026 · 11 min read

Is NGL Really Anonymous? What That Word Actually Means

Anonymous means three different things, and apps in this category quietly rely on you meaning the weakest one. Here is what actually gets stored, who can see it, and how to judge any anonymous app.

Written and reviewed in-house by the Secret Message editorial team at Birim Ajans, Maltepe, İstanbul, Türkiye.How we write these

When someone asks whether NGL is really anonymous, they are almost never asking a technical question. They are asking a social one: can the person I am about to message find out it was me? The answer to that narrow question is basically yes, you are safe, on NGL and on every serious app in this category including this one. The answer to the broader question of whether you are anonymous in any absolute sense is no, and no consumer app in this space can honestly tell you otherwise.

The gap between those two answers is where all the trouble in this category lives. It is where paid "reveal the sender" features come from, it is what regulators went after, and it is the thing most apps are careful never to spell out. So let us spell it out.

Anonymous means three different things

Almost every argument about anonymity is really two people using the same word for different ideas. There are three distinct levels, and they are worth separating before anything else.

  1. Anonymous to the recipient. The person reading your message cannot work out who you are from anything the app shows them. No name, no handle, no IP, no country, no device, no timestamp pattern they can cross-reference. Every credible app in this category delivers this, and it is what people actually mean when they use the word.
  2. Anonymous to the operator. The company running the service does not know who sent the message either. This is rare and it is very hard to build, because the same information that would identify you is the information that stops floods of abuse. Almost no anonymous-messaging product offers this, and the ones that imply they do are usually being loose with language.
  3. Anonymous to a court. Even with a subpoena, nobody can connect the message back to a person. This effectively does not exist in a consumer product that also has to handle harassment reports. Products that genuinely offer it, like some encrypted relays, pay for it with a total inability to moderate anything.

A teenager asking about anonymity means level one. A regulator asking means levels two and three. An app can therefore say "fully anonymous" with a straight face, be technically describing level one, and let you assume it means level three. That ambiguity is not an accident; it is the marketing.

What level one actually protects you from

It is worth being precise about what you get, because level one is more useful than people give it credit for.

It protects you from the social consequence, which is the consequence that was stopping you from being honest. Your friend cannot see it was you, cannot screenshot your name into a group chat, cannot bring it up at lunch. That is the entire reason the format works: strip the name and people say the true thing.

What it does not protect you from is a determined recipient doing deduction. Anonymity in the app is not anonymity in your life. If you reference something only four people know, you have narrowed it to four people. If you write in a distinctive way, people who know you will hear your voice in it. We wrote a whole piece on this from the other side, on whether you can find out who sent an anonymous message, and the short version is that the app never gives you away but your own writing might.

What an app in this category stores

We are describing the category rather than quoting anyone's document, so read the current privacy policy of whichever app you are judging rather than trusting a competitor's summary of it. That includes ours. With that caveat, an inbound anonymous message in this category typically leaves behind:

  • The sender's IP address.
  • An approximate location derived from that IP, usually country and sometimes city.
  • Device type, operating system, browser or app version.
  • Timestamps, the message text itself, and the recipient's account or board identifier.
  • Where the app has sender accounts, everything attached to that account.

That set is enough to identify a specific person if a court ever asks and the account or connection can be traced. It is nowhere near enough for a recipient to identify you, because the recipient never sees any of it.

Why operators store it at all

This is the part that gets skipped, and skipping it makes every operator look worse than the situation warrants. The honest reason is that a service which knows nothing about senders cannot defend anyone from them.

Consider what an anonymous inbox looks like with zero sender metadata. Someone decides to target a person. They send a hundred messages. You cannot rate limit, because rate limiting requires recognising that the hundred messages came from one place. You cannot block, because blocking requires something to block. The person on the receiving end has no recourse except closing the inbox entirely. In practice, total sender anonymity does not produce a free-speech utopia, it produces a harassment tool with no brakes.

So every operator that takes abuse seriously keeps some sender signal. The meaningful questions are not whether they keep it, but: how much, for how long, who inside the company can see it, what it gets used for, and whether they tell you plainly. An app that claims to store nothing is either wrong, or has no working abuse controls, and neither is reassuring.

What the NGL enforcement action actually turned on

NGL drew regulator attention in the United States, and the substance of the complaint is genuinely instructive because it was not really about metadata at all. Two threads mattered.

The first was the paid "hint" feature. Users understood they were buying a step toward learning who sent a message. What the purchase produced did not identify anyone. The problem there is not cryptography, it is a promise the product could not keep and was charging for anyway.

The second was children. An app that in practice has a large under-13 audience carries specific legal obligations about what it may collect from them, and effective age gating is the mechanism regulators expect to see. You can read the underlying rules directly in the FTC's guidance on children's privacy, which is short and readable and is a better checklist for judging any app than anything we could write.

We are deliberately not quoting a penalty figure or a filing date. We would be doing it from memory, the numbers get repeated wrongly across the internet, and being approximately right about a specific number is a form of being wrong. The filings are public. If you are evaluating an app seriously, read them at the source.

Why the "reveal the sender" upsell keeps coming back

Understand the business logic and you will spot the pattern in the next app too. An anonymous inbox generates a very specific emotional state: someone said something about you and you cannot know who. That is not idle curiosity, it is an itch, and it peaks in the first minutes after a message lands.

A product sitting on that moment has an obvious monetisation path, and it does not require the reveal to work. It only requires the purchase to feel like progress. A hint that narrows nothing, a partial clue, a blurred first letter, a "this person is nearby" that is true of half the country. The user pays, learns nothing, and often blames themselves for expecting more.

That is why we treat any reveal feature as disqualifying rather than as a feature we happen to lack. There is real money in it. Refusing it is the whole point, and we say so on the safety page so that it is a commitment we can be held to rather than a mood.

What honest anonymity looks like, including ours

Here is our own position stated at the same level of detail we just demanded of everyone else, limits included.

  • Senders are anonymous to recipients, completely and permanently. No name, no IP, no country, no device, no hint, no paid unlock, not now and not as a future feature.
  • Senders are not anonymous to us. We store the sender's IP address with the message. It is used for rate limiting, for the block feature, and for responding to lawful requests. Message content is kept for 90 days and sender metadata for 180 days, as set out in the privacy policy.
  • We do not build device fingerprints. This is a real limitation and not a boast: it means blocking works at the network level, so somebody who switches from wifi to mobile data looks like a new sender.
  • Moderation runs locally on our own servers, with no external AI service involved. It catches patterns somebody wrote down in advance, which means it misses coded language, misspellings, and cruelty phrased politely. The safety page describes exactly what it does and does not catch.
  • We are a small independent operation, and the about page says who runs it. An anonymity product run by an anonymous company is not a good look, so we put a name and an address on it.

How to judge any anonymous app in five minutes

Apply this to us as readily as to anyone else. Open the privacy policy and the safety or help pages, then check:

  1. Does it say plainly what happens to sender metadata? Look for the specific words: IP address, retention period, who it is shared with. A policy that talks at length about "your privacy" without ever saying what is stored is dodging.
  2. Is there a paid reveal, hint or unlock?If yes, close the tab. Either it does not work, or the recipient's protection from senders is being sold off piece by piece.
  3. Is there a named operator? A company, a jurisdiction, a working address that a lawyer or a parent could actually write to. Anonymous operators are a bad sign in every industry and a worse one in this industry.
  4. Does it admit to a limitation anywhere? Every real system has failure modes. A page that lists only strengths was written by marketing and reviewed by nobody.
  5. Is there a working report route? Not a form that goes nowhere: a stated response time and a named address. Test it if you want; send a question and see whether a human replies.

If you need real anonymity

Worth saying clearly, because someone reading this has a serious reason to ask. If you are a whistleblower, if you are reporting abuse by someone with resources, if being identified would put you in physical danger, then a consumer anonymous-messaging app is the wrong tool. Not ours, not NGL, not any of them. We are built for honest feedback between people who know each other, and our threat model assumes the worst outcome is hurt feelings rather than retaliation.

For genuinely high-stakes situations you want purpose-built channels: an organisation's formal whistleblower process, a journalist's published secure-contact instructions, or a legal professional. Those exist because the risk is real and a fun web product is not equipped for it.

The bottom line

Is NGL really anonymous? To the person receiving your message, yes. To the company, no. To a court, no. That is also true of Secret Message, and any app telling you otherwise is either confused or selling something.

So the question worth asking is not which app is anonymous. It is which operator tells you the truth about what anonymous means before you need to find out the hard way. If you want to see how we compare head to head, the NGL alternative page lays out both sides, and the roundup of anonymous messaging apps covers the wider field.

Get your free anonymous link

Type your name on the homepage and you have a shareable link in ten seconds. No signup, no email, no password.

Get my link

Read next