Want to know more about Telegram security? Then read the full article below.
Telegram is an encrypted messaging service that was first released in 2013. Unlike most other apps, Telegram’s user base jumps significantly every time there’s a privacy scandal. Since 2019, it’s grown by over 350 million users!
Telegram has enjoyed a constant presence in lists of the most downloaded apps throughout 2022, and it’s widely used by people who wish to communicate without revealing their identity.
However, is Telegram really safe? In this article, we take a critical look at Telegram’s privacy. We also delve into Telegram’s privacy settings and offer tips on how you can make the app as secure and as private as possible.
What is Telegram?
Telegram is a free chat service with a focus on security and speed. You can use the cloud-based chat app on your smartphone, tablet, or computer.
Telegram was founded by Russian brothers Nikolai and Pavel Durov in August 2013. Like other instant messaging apps, you can send text messages, images, and videos via Telegram. You can also share stickers, emojis, your location, and voice messages.
Video calling is also possible via Telegram and you can have group chats just like in WhatsApp. In Telegram, however, you can create groups of up to 200,000 people. For comparison, WhatsApp only supports up to 200 users in a group.
Telegram has become a haven for people who wish to hide their identities, and has been used by terrorists, neo-Nazis, and criminals in the past, which only lends credence to the strong encryption and security policies that it uses.
Is Telegram Safe?
In a nutshell, yes. Based on our research and testing, Telegram is a pretty safe messaging app, provided you tweak your privacy settings (more on that in the next section!). Here’s why we think that.
Standard chats aren’t end-to-end encrypted
The standard chats in Telegram, also known as cloud chats, aren’t end-to-end encrypted. End-to-end encryption is important for your privacy.
It ensures that only the sender and receiver can read the message. Without end-to-end encryption, Telegram also has access to the chats. However, this doesn’t mean that Telegram doesn’t use any encryption.
As per clause 3.3.1. of Telegram’s privacy policy, all data on Telegram is heavily encrypted. They use what’s called a secret-splitting scheme, relying on a distributed infrastructure to protect data that isn’t end-to-end encrypted.
The data is stored in data centers throughout the globe (all controlled by Telegram), but in different legal jurisdictions. All decryption keys are also split and never kept in the same place.
Thus, if anyone needed access to your data, they’d have to jump through a whole bunch of legal hoops, including in jurisdictions that are not quite receptive to such requests. This means a single government or even a bloc can’t just force Telegram to give up user data.
Secret chats are end-to-end encrypted
On the other hand, for those who are really serious about their privacy, Telegram offers secret chats. All messages, photos, videos, and other files sent through secret chats are end-to-end encrypted.
Only the recipient with the relevant decryption keys have access to this data. The content of these secret chats is not stored on Telegram’s servers. These are localized, so they’ll only be accessible on the device you send them from, unlike cloud chats.
Cloud chats
At its core, Telegram is a cloud service. Messages, photos, videos, and documents from the cloud chats are stored on Telegram’s servers via the cloud. Cloud storage has the advantage of allowing the content to be accessed from multiple devices.
Cloud chats use server-client encryption, so your data’s still relatively safe. And, if you always want that extra layer of security, you can just start a secret chat without any limitations.
MTProto protocol
Telegram uses a self-developed cryptographic protocol called MTProto. Security experts have criticized this encryption in the past, especially version 1.0, which was using the archaic hashing SHA-1. That was corrected with MTProto 2.0, which released in 2017.
In 2021, after a team of researchers unearthed vulnerabilities in its encryption protocol, Telegram wrote that they had made changes to incorporate those observations.
Privacy principles
When it comes to privacy, Telegram has two fundamental principles:
User data is not used to display advertisements.
Only essential user data must be stored.
It is of course nice that Telegram does not show personalized advertisements. However, Telegram does store some user data.
What Information Does Telegram Collect?
Telegram indicates that they only store necessary information for the service to function properly. Here’s a quick glance at the data Telegram collects about users:
IP address
Username
Contact list
Phone number
Device used
Here’s what you need to know about all the data that Telegram collects.
Telegram collects user metadata
Telegram states in its privacy policy that it protects users from spam and abuse. To enforce these protections, the app does collect some metadata about its users.
For example, it collects privacy-sensitive information such as your IP address, which device you use, all usernames that you have used on the platform, your phone number, contact list, and devices you access Telegram on. This metadata can be stored for up to 12 months.
Moderators can also view flagged messages on Telegram. This is important for detecting spam and abuse. However, it also shows that the conversations are less private than you might expect.
Telegram collects your contact information
If you want to use Telegram, you must give the messaging app access to your contact list. All your contacts are copied and saved by Telegram. They use this information to notify you if a contact joins Telegram. The data would also be needed to be able to properly display the names in the app.
Telegram stores phone numbers, first, and last names of all contacts in your list. For a service that says it finds privacy very important, this is a bit disturbing. Additionally, this presents an opportunity for Telegram to collect data from people who haven’t signed up for the app yet.
How to Request Your Telegram Data Report
Telegram must comply with GDPR privacy laws. This means, among other things, that Telegram must give you insight into the data that the service has collected about you. Here’s how to do that.
Open Telegram.
In the search bar, type “@GDPRbot” without quotes.
This bot can help you request a copy of all your data that Telegram stores.
Click on “start” at the bottom and follow the steps. Type “/access” to export telegram data.
To download the data, you will be redirected to “Telegram Desktop.”
Make sure you have Telegram Desktop installed and log in.
Click on the three lines in the corner to open the menu.
Go to “Settings.”
In the settings menu, click on “Advanced.”
After that, scroll down and click on “Export Telegram data.”
Choose which data you want to export and click “Export.”
For security reasons, you can only start the download after 24 hours. Telegram first notifies all your devices of the export request to make sure it is authorized.
Illegal Activities on Telegram
Telegram is unfortunately also increasingly used by criminals and other nefarious groups. They use the messaging app, among other things, to distribute malware, copyrighted software, and even child pornography, content that you’d usually find on the dark web.
On Telegram, you can easily join groups in which criminal matters take place. In addition, large groups can be created on Telegram with up to 200,000 participants. Moreover, the end-to-end encrypted messages sent via secret chats cannot be monitored by, for example, the police.
Telegram also allows people to share illegal computer software that allows scammers to find out their victims’ banking details. They can also use this data for phishing.
Group chats on Telegram are also used to incite riots and protests. The Rotterdam rioters, for example, found each other via Telegram. In Telegram group chats on the messaging service, the out-of-control demonstration was announced more than a day in advance.
Fearing protests, Telegram has been blocked in countries such as Iran, Pakistan, and China. From 2018 to 2020, the popular chat app was also blocked in Russia. Access to the app was blocked because Telegram refused to allow Russian security services access to encrypted Telegram chats.
How Does Telegram Make Money?
Telegram itself indicates that they believe that sending messages should be fast and 100% free. Telegram does not show ads in the app, unless it’s in public group chats. Founder Pavel Durov has largely financed Telegram himself, along with a group of qualified investors.
To be able to continue the rapidly growing chat app, the company considered new revenue models and introduced a “Premium” version of their app.
What is Telegram Premium?
Telegram introduced Telegram Premium as a subscription that lets users support Telegram’s continued development and gives them access to exclusive additional features.
By subscribing to Telegram Premium, users unlock doubled limits, 4 GB file uploads, faster downloads, exclusive stickers and reactions, improved chat management and a bunch of other features. Needless to say, this is geared towards power users.
Up until this point, Durov has largely been paying the cost of keeping Telegram running out of his pocket. He says in his statement that Telegram will not sell the company, like the founders of WhatsApp.
“Telegram must continue to serve the world as an example of a tech company that strives for perfection and integrity. And, as the sad examples of our predecessor’s show, that is impossible when you become part of a corporation,” said Durov, referring to WhatsApp’s acquisition.
How to Make Telegram More Private
You can take several measures yourself to improve your privacy and security on Telegram:
Send end-to-end encrypted chats via the secret chat option.
Use a separate mobile phone number to log in to Telegram.
Use a VPN to hide your IP address.
Let’s break these down one by one.
Use the secret chat feature in Telegram
The secret chat is not immediately accessible in Telegram. Here’s how to start one:
Open the Telegram app on your iPhone or Android phone.
Open the profile of the person you want to chat with by clicking their profile picture on Telegram’s interface.
Then click on the three dots at the top right of the screen and choose “Start secret chat.”
A chat opens in which chats are end-to-end encrypted. At the beginning of the chat you will receive a notification in which the secret chat functions are listed.
In the overview with chats, you can recognize the secret chat by the green padlock in front of the name of the chat partner. It’s also important to note that iPhone users can still take screenshots. However, the chat will display a message showing that someone has taken a screenshot.
Enable two-factor authentication
Two-factor authentication is a fantastic way to keep your Telegram chats from people with access to your phone. Despite secret chats being end-to-end encrypted, for example, someone with access to your phone can access these chats.
To activate two-factor authentication on Telegram follow the steps below:
Open the Telegram app on your phone.
Click the three lines on the top-left side of the screen.
Tap on “Settings.”
Tap on “Privacy and Security.”
Under Security, click “Two-Step Verification.”
Tap “Set Password.”
Enter the password you would like to use.
Re-enter your new password.
Enter a hint to remind you of your password in case you forget it (optional).
Enter a recovery email in case you forget your password (optional).
If you choose to skip providing an email, you’ll get the following Telegram warning.
Self-destructing chats and media
You can also use self-destructing messages if you have to send something really sensitive. The messages will disappear after a defined time period once it’s opened.
In a private chat, you can set the self-destruct timer by clicking on the three dots in the top right of the chat window. Then click on “Auto-Delete.”
Set the time after which messages will be deleted.
Telegram’s auto-delete feature offers a range of pre-set time ranges to choose from too.
Customize Telegram privacy settings
By adjusting your privacy settings, you can double down on what information is shared with other users on the platform. Here’s how:
Open Telegram.
Click the three dashes in the upper-left corner.
Go to “Settings” and click on “Privacy & Security.”
Indicate what you want others to see. You have the option to hide your telephone number, last seen and online, profile pictures, forwarded messages, and Telegram groups.
Hiding your phone number on Telegram
To use Telegram, you need a phone number. This phone number is shown to everyone you interact with (unless you hide it in privacy settings) through the messaging app.
The phone number can also be used to search for you on Telegram. If you want to chat anonymously, you may prefer to keep your phone number hidden.
Here’s how to hide your mobile number on Telegram:
Open the Telegram app on your phone.
Click the three lines on the top-left side of the screen.
Tap on “Settings.”
Tap on “Privacy and Security.”
Under “Privacy,” tap on “Phone Number.”
Under “Who can see my phone number?” choose “Nobody.”
Telegram’s desktop and tablet app allow you to log in with a separate number. This phone number does not need to be linked to your smartphone. So you can also use a different phone number for this.
The Best Way to Improve Your Privacy on Telegram: Use a VPN
Using a virtual private network (VPN) can provide more online anonymity and privacy. A VPN also hides your IP address. For example, Telegram collects and stores your IP address for undisclosed reasons. Using a VPN will protect your real IP address from Telegram.
You can also use a VPN to bypass geo-blocks abroad. In countries where Telegram is blocked due to censorship, you can use a VPN to change your IP address and use the app.
NordVPN is an excellent VPN provider that we recommend for use with apps like Telegram. It is not for nothing that this VPN has been at the top of our list of best VPNs for years.
NordVPN
Our choice
Deal
Save big with 69% off a two-year subscription + three months free!
The popular chat app WhatsApp lost many loyal users after the service was acquired by Facebook. Users were afraid that WhatsApp would share private messages from users with parent company Meta (formerly Facebook).
Facebook’s revenue model is based on advertising, hence the platform is known to collect information about users. Many users therefore switched to Telegram, which is considered to be a safer alternative.
In a Telegram vs. WhatsApp comparison, the latter collects a lot more metadata. What most people don’t realize is that Telegram, unlike WhatsApp, only offers end-to-end encryption for the “secret chats” while all chats in WhatsApp are end-to-end encrypted by default.
Is There a Safer Alternative to Telegram?
If you find privacy very important, Telegram is not the perfect solution. Others, like Signal, have proven to be far more private and secure. But, with a VPN, you can essentially hide your identity entirely from Telegram, making it just as safe (unless you start revealing details yourself!).
While it’s safe to use, we understand that it might not be for everyone. If you want, you can also delete your Telegram account permanently. Interested in learning about privacy and security of other popular social media and messaging apps? Check out some of our other articles:
Telegram Privacy and Security: Frequently Asked Questions
Here are some frequently asked questions about Telegram’s privacy and security settings.
What data does Telegram collect?
In addition to your phone number, Telegram also collects your IP address, which device you use and all the usernames you have used on the platform. The chat app also collects information about your contacts. However, Telegram is safe to use.
How can I better protect my privacy on Telegram?
While Telegram is safe to use, there are some additional steps you can take to improve your privacy on this messaging app:
Send encrypted messages via the “secret chat.”
Adjust Telegram’s privacy settings.
Use a VPN to hide your IP address.
Use a different phone number to sign in.
Will Telegram stay free?
Telegram is working on a new revenue model that is needed to keep the chat app running. The features that are now free will remain free. For business users, paid features will be added. They also have a Telegram Premium for power users.
Ian is a former VPNOverview content writer with expertise in researching and writing about cybersecurity, internet privacy, and online freedom. He’s a marketer and cybersecurity enthusiast who aims to educate others through his writing.