← Messaging Apps
F

Telegram (Privacy Claims)

Fail
Telegram FZ-LLC · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: Telegram
Manufacturer: Telegram FZ-LLC

⚠️ The bottom line

Telegram is not encrypted by default. Most users don't know this. Regular messages sit in plaintext on Telegram's cloud servers. Only "Secret Chats" — which require manual activation and don't work for groups — are end-to-end encrypted. 950 million people think they're using a secure messenger. They're using a cloud chat app with a privacy reputation it hasn't earned. Signal uses the Signal Protocol. WhatsApp uses the Signal Protocol. Telegram invented its own. Cryptographers call it unvetted. And the only encrypted mode — Secret Chats — doesn't work in groups, doesn't sync across devices, and requires manual activation. The feature exists so Telegram can say it exists. Almost nobody uses it.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
0/4 N/A
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
2/4 MODERATE
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
2Contradictions
1Critical
1High
0Medium
2Sources
Findings by concern
Security 3/4 HIGH 2 findings
⚠️ criticalmarketing vs regulatory
Telegram is not encrypted by default. Most users don't know this. Regular messages sit in plaintext on Telegram's cloud servers. Only "Secret Chats" — which require manual activation and don't work for groups — are end-to-end encrypted. 950 million people think they're using a secure messenger. They're using a cloud chat app with a privacy reputation it hasn't earned.

What they claim: Telegram markets itself as a private, secure messaging platform

What we found: Telegram CEO Pavel Durov was arrested in France in August 2024 on charges including complicity in drug trafficking, CSAM distribution, and fraud facilitated through the platform. Telegram's default chats are NOT end-to-end encrypted — only "Secret Chats" (which few users enable) use E2EE. Regular messages, group chats, and channels are stored in plaintext on Telegram's cloud servers, accessible to Telegram staff and potentially to law enforcement.

⚡ highprivacy policy vs third party research
Signal uses the Signal Protocol. WhatsApp uses the Signal Protocol. Telegram invented its own. Cryptographers call it unvetted. And the only encrypted mode — Secret Chats — doesn't work in groups, doesn't sync across devices, and requires manual activation. The feature exists so Telegram can say it exists. Almost nobody uses it.

What they claim: Telegram promotes Secret Chats with end-to-end encryption

What we found: Telegram uses a proprietary encryption protocol called MTProto, developed in-house rather than using established protocols like Signal Protocol. Cryptographers have repeatedly criticised MTProto as unvetted and potentially vulnerable. Secret Chats — the only E2EE feature — do not sync across devices, do not work in group chats, and must be manually initiated. The vast majority of Telegram users never use them.

Sources