Since its inception. The founder worked for Twitter (a company that has little worries about user privacy) and the first group placing money on Signal was Radio Free Asia (literally an CIA-front). The founder was a surfer, so when writing the algorithm he figured that it would be a great idea to invite a bunch of skinny geeks to Hawaii and develop an algorithm there while they surf. Do you know what else is based in Hawaii, the NSA HQ for code breaking algorithms. btw, also the place where Snowden worked for quite a while. Want to know what happened in Hawaii, good luck. Those attending had to sign NDA and won't be specific about their stay there. The algorithm is ready, this is a virtually unknown algorithm from what is little more than a startup with about zero outside users. Do you know who liked it? Whatapp (another company notorious for sharing data with govs) that adopted it immediately for 1 billion users worldwide, an algorithm fresh out of the forge without much real world validation (kind of sus, right). Don't worry, over the years enough employees leaked that the company can indeed read those "encrypted" messages with the Signal algorithm after all. When that is not enough, Signal itself costs tens of million USD to run per year. Guess who is still banking those costs? Yeah, tax payer money. This is verifiable online, just take your time to research by yourself. Then there are years of battles against other messengers but strangely Signal is rarely (never) attacked and yet promoted by usage from both government officials, leftist groups and enough Hollywood movies to make you think why anyone ever recommend a messenger tied to a phone number. The better question is: "What part from signal is NOT compromised?"