engineering notes
online · end-to-end explained

How WhatsApp scales to civilization level.

Three billion people. Over 100 billion messages a day. And the machine in the middle is built to forget almost every single one. Scroll one message's commute and see why a system this big stays this light. read

AUG 2026 ~9 MIN 5 SCENES MODE: CHAT
today

01The server that forgets

The instinct is a warehouse: if three billion people's conversations pass through WhatsApp, rooms of disks must be holding them. The reality is the opposite. Your messages live on your phone; the servers in the middle see only sealed envelopes — and hold each one just long enough to hand it over.

Two worlds, then. A light one, where people and phones and chat bubbles live. And a dark one, the network, where envelopes travel between machines that cannot open them. Since April 5, 2016, every message type — text, photos, voice, calls — has been end-to-end encrypted with the Signal Protocol. The rest of this article lives on the border, following messages across it.

Quick check before we descend: a message leaves your phone, crosses the dark, and lands on another phone. How much does the machine in the middle get to know? read

Nothing travels until your phone seals it. End-to-end encryption — complete since April 5, 2016 — locks every message with keys that never leave either device.

What to watch — the wax seal. It closes at your phone and never opens until the far one.

To the relay, your message is an envelope it cannot open. It reads only the address on the outside — inside stays scrambled all the way across.

The double tick is the handover moment: the envelope reaches the right phone, opens — and the server's copy is deleted. Store-and-forward, with the emphasis on forward.

Friend offline? The sealed envelope waits in an encrypted queue for at most 30 days — then it is deleted whether or not it was ever collected.

Every online user gets their own tiny Erlang process — about 2.7 kilobytes when it starts. Not a thread, not a container: a worker so small one server can hold a small country of them.

In January 2012, one FreeBSD box held 2,277,845 simultaneous connections — with 41.9% of its CPU still idle.

What to watch — the counter. It stops on a real number from a real night, not a round one.

2,277,845 processes × 2.7 KB ≈ 6.2 GB of a 103 GB machine (computed live). This density is how ~550 servers and ~11,000 cores served ~465 million users — run by ~32 engineers.

By 2014 they deliberately backed off to about a million per box. Photos and video had made each connection heavier — headroom for spikes beat bragging rights.

Delivered means deleted.
The server is a relay, not an archive.

You type once. A family group of eight — our demo group — means eight sealed envelopes leave your phone, each locked for exactly one reader.

What to watch — the fan. One bubble in, eight envelopes out.

Measured in 2014, the asymmetry was already huge: 19 billion messages in per day, 40 billion out — every send more than doubling on average (the ratio is computed beside the counters).

Since 2021 your phone does the multiplying itself: multi-device encrypts one copy per recipient device, and the server just routes sealed envelopes it can never open.

The server's whole memory of a conversation is whatever is in flight right now. Delivered means deleted — the copy evaporates on confirmation.

What to watch — envelopes dissolving at the phone. The kept counter never moves.

Undelivered envelopes wait encrypted, at most 30 days. Then they are gone too — no archive, no backlog, no history.

The queue stays shallow because people read fast: in 2014, more than half of queued messages were read within 60 seconds, and 98% of reads came straight from the hot cache.

The counters track this scene's own envelopes — every poof you can count was rendered. Kept after delivery: 0. That zero is the design.

New Year's Eve is the biggest day, every year — and a regular day is already over 100 billion messages and 2 billion calls.

What to watch — the strip. Each bar is a timezone; each strike is its midnight.

The storm arrives as a wave: midnight strikes first at UTC+14 and rolls westward for more than a day until UTC−12. Every crest is a region's worth of simultaneous greetings.

Measured on the 2014 fleet: 342,000 messages in per second, 712,000 out — fan-out again — plus 230,000 logins per second. NYE 2019 alone topped 100 billion messages.

A relay that forgets never grows with its history — only with its storm. That is the whole trick.

07The whole conversation, exported

chat exporthow-whatsapp-scales.txtend-to-end
today
So how does WhatsApp hold civilization's chats? read
By refusing to hold them. Each message is a sealed envelope, owned by a ~2.7 KB process, deleted the instant the double tick lands. read
The machine's size tracks who is online right now — never everything humanity has ever said. read

WhatsApp scales to civilization level because it never tries to keep civilization's conversations. Sealed on your phone, relayed unread, deleted on delivery — the system's cost grows with presence and fan-out, not with history. The storm it must survive is New Year's Eve, and the reason it survives is that there is almost nothing to carry between storms. The same relay-versus-store tension, pushed to seven trillion messages a day, is Kafka's story.

3B+
users · may 2025
>100B
messages / day
2B
calls / day
32 : 465M
engineers : users · 2014
Nothing here is faked or undated. 2,277,845 connections on one server (WhatsApp engineering, January 2012) · 19B in / 40B out per day, 342K/712K messages per second, 230K logins per second, ~550 servers / ~11,000 cores / ~32 engineers (Rick Reed, Erlang Factory 2014) · delete-on-delivery and the 30-day retention bound (WhatsApp privacy policy) · Signal Protocol complete April 5, 2016 (Open Whisper Systems) · multi-device client-fanout (Meta engineering, 2021) · 3B+ users (Meta, May 2025) · over 100 billion messages and 2 billion calls a day (WhatsApp blog, December 2025). The family group of eight and the wave curve are illustrative. Every counter on this page is computed or carries its date.
· end of chat ·