Is Telegram Safe? A Full Guide to User Privacy and Security

Is telegram safe featured image

Click here for a summary of the article Bookmark small
Bookmark smallIs Telegram Safe? A Full Guide to User Privacy and Security – A Quick Guide

Telegram is considered a safe alternative to WhatsApp. Based on our research and testing, it is generally safe to use. Here’s why:

  • All data on the app is encrypted
  • It uses the proprietary MTProto 2.0 protocol which is fully verified
  • You can use secret chats to add end-to-end encryption
  • They use a distributed infrastructure to ensure governments can’t easily access user data

Fortunately, you can take some measures yourself to further improve your privacy on Telegram:

  • Start a secret chat to send messages with end-to-end encryption.
  • Take a critical look at your privacy settings and tweak them if necessary.
  • Use a separate phone number with Telegram instead of your personal number.
  • Use a VPN for more online privacy. We recommend NordVPN.

It’s user-friendly, fast, and secure. The VPN is also suitable for unblocking Telegram if you are in a country where Telegram is blocked or censored.

Nordvpn logo square svg

Want to know more about Telegram security? Then read the full article below.

X mark small purple

Telegram is an encrypted messaging service that was first released in 2013. Unlike most other apps, Telegram’s user base jumps significantly every time there’s a privacy scandal. Since 2019, it’s grown by over 350 million users!

Telegram has enjoyed a constant presence in lists of the most downloaded apps throughout 2022, and it’s widely used by people who wish to communicate without revealing their identity.

However, is Telegram really safe? In this article, we take a critical look at Telegram’s privacy. We also delve into Telegram’s privacy settings and offer tips on how you can make the app as secure and as private as possible.

What is Telegram?

Telegram logoTelegram is a free chat service with a focus on security and speed. You can use the cloud-based chat app on your smartphone, tablet, or computer.

Telegram was founded by Russian brothers Nikolai and Pavel Durov in August 2013. Like other instant messaging apps, you can send text messages, images, and videos via Telegram. You can also share stickers, emojis, your location, and voice messages.

Video calling is also possible via Telegram and you can have group chats just like in WhatsApp. In Telegram, however, you can create groups of up to 200,000 people. For comparison, WhatsApp only supports up to 200 users in a group.

Telegram has become a haven for people who wish to hide their identities, and has been used by terrorists, neo-Nazis, and criminals in the past, which only lends credence to the strong encryption and security policies that it uses.

Is Telegram Safe?

Question mark over padlock iconIn a nutshell, yes. Based on our research and testing, Telegram is a pretty safe messaging app, provided you tweak your privacy settings (more on that in the next section!). Here’s why we think that.

Standard chats aren’t end-to-end encrypted

The standard chats in Telegram, also known as cloud chats, aren’t end-to-end encrypted. End-to-end encryption is important for your privacy.

It ensures that only the sender and receiver can read the message. Without end-to-end encryption, Telegram also has access to the chats. However, this doesn’t mean that Telegram doesn’t use any encryption.

As per clause 3.3.1. of Telegram’s privacy policy, all data on Telegram is heavily encrypted. They use what’s called a secret-splitting scheme, relying on a distributed infrastructure to protect data that isn’t end-to-end encrypted.

The data is stored in data centers throughout the globe (all controlled by Telegram), but in different legal jurisdictions. All decryption keys are also split and never kept in the same place.

Thus, if anyone needed access to your data, they’d have to jump through a whole bunch of legal hoops, including in jurisdictions that are not quite receptive to such requests. This means a single government or even a bloc can’t just force Telegram to give up user data.

Secret chats are end-to-end encrypted

On the other hand, for those who are really serious about their privacy, Telegram offers secret chats. All messages, photos, videos, and other files sent through secret chats are end-to-end encrypted.

Only the recipient with the relevant decryption keys have access to this data. The content of these secret chats is not stored on Telegram’s servers. These are localized, so they’ll only be accessible on the device you send them from, unlike cloud chats.

Cloud chats

At its core, Telegram is a cloud service. Messages, photos, videos, and documents from the cloud chats are stored on Telegram’s servers via the cloud. Cloud storage has the advantage of allowing the content to be accessed from multiple devices.

Cloud chats use server-client encryption, so your data’s still relatively safe. And, if you always want that extra layer of security, you can just start a secret chat without any limitations.

MTProto protocol

Telegram uses a self-developed cryptographic protocol called MTProto. Security experts have criticized this encryption in the past, especially version 1.0, which was using the archaic hashing SHA-1. That was corrected with MTProto 2.0, which released in 2017.

In 2021, after a team of researchers unearthed vulnerabilities in its encryption protocol, Telegram wrote that they had made changes to incorporate those observations.

Privacy principles

When it comes to privacy, Telegram has two fundamental principles:

  • User data is not used to display advertisements
  • Only essential user data must be stored

It is of course nice that Telegram does not show personalized advertisements. However, Telegram does store some user data.

What Information Does Telegram Collect?

Telegram indicates that they only store necessary information for the service to function properly. Here’s a quick glance at the data Telegram collects about users:

  • IP address
  • username
  • contact list
  • phone number
  • device used

Here’s what you need to know about all the data that Telegram collects.

Telegram collects user metadata

Telegram states in its privacy policy that it protects users from spam and abuse. To enforce these protections, the app does collect some metadata about its users.

For example, it collects privacy-sensitive information such as your IP address, which device you use, all usernames that you have used on the platform, your phone number, contact list, and devices you access Telegram on. This metadata can be stored for up to 12 months.

Moderators can also view flagged messages on Telegram. This is important for detecting spam and abuse. However, it also shows that the conversations are less private than you might expect.

Telegram collects your contact information

If you want to use Telegram, you must give the messaging app access to your contact list. All your contacts are copied and saved by Telegram. They use this information to notify you if a contact joins Telegram. The data would also be needed to be able to properly display the names in the app.

Telegram stores phone numbers, first, and last names of all contacts in your list. For a service that says it finds privacy very important, this is a bit disturbing. Additionally, this presents an opportunity for Telegram to collect data from people who haven’t signed up for the app yet.

How to Request Your Telegram Data Report

Telegram must comply with GDPR privacy laws. This means, among other things, that Telegram must give you insight into the data that the service has collected about you. Here’s how to do that.

  1. Open Telegram.
  2. In the search bar, type: “@GDPRbot” without quotes.
  3. Search showing "@gdprbot" in the telegram app
  4. This bot can help you request a copy of all your data that Telegram stores.
  5. Click on “start” at the bottom and follow the steps. Type /access to export telegram data.
  6. A chat with the gdpr bot on telegram
  7. To download the data you will be redirected to Telegram Desktop.
  8. Make sure you have Telegram desktop installed and log in.
  9. Click on the three lines in the corner to open the menu.
  10. Telegram desktop app with the menu highlighted
  11. Go to “Settings.
  12. Menu on telegram desktop app with "settings" highlighted
  13. In the settings menu, click on “Advanced.
  14. Telegram desktop app screen "settings" with "advanced" highlighted
  15. After that, scroll down and click on “Export Telegram data.
  16. Telegram settings on desktop with "export telegram data" highlighted
  17. Choose which data you want to export and click “Export.
  18. "export personal data" screen on telegram desktop app

For security reasons, you can only start the download after 24 hours. Telegram first notifies all your devices of the export request to make sure it is authorized.

Illegal Activities on Telegram

Telegram is unfortunately also increasingly used by criminals and other nefarious groups. They use the messaging app, among other things, to distribute malware, copyrighted software, and even child pornography, content that you’d usually find on the dark web.

On Telegram, you can easily join groups in which criminal matters take place. In addition, large groups can be created on Telegram with up to 200,000 participants. Moreover, the end-to-end encrypted messages sent via secret chats cannot be monitored by, for example, the police.

Telegram also allows people to share illegal computer software that allows scammers to find out their victims’ banking details. They can also use this data for phishing.

Group chats on Telegram are also used to incite riots and protests. The Rotterdam rioters, for example, found each other via Telegram. In Telegram group chats on the messaging service, the out-of-control demonstration was announced more than a day in advance.

Fearing protests, Telegram has been blocked in countries such as Iran, Pakistan, and China. From 2018 to 2020, the popular chat app was also blocked in Russia. Access to the app was blocked because Telegram refused to allow Russian security services access to encrypted Telegram chats.

How does Telegram make money?

Telegram itself indicates that they believe that sending messages should be fast and 100% free. Telegram does not show ads in the app, unless it’s in public group chats. Founder Pavel Durov has largely financed Telegram himself, along with a group of qualified investors.

To be able to continue the rapidly growing chat app, the company considered new revenue models and introduced a “Premium” version of their app.

What is Telegram Premium?

Telegram introduced Telegram Premium as a subscription that lets users support Telegram’s continued development and gives them access to exclusive additional features.

By subscribing to Telegram Premium, users unlock doubled limits, 4 GB file uploads, faster downloads, exclusive stickers and reactions, improved chat management and a bunch of other features. Needless to say, this is geared towards power users.

Telegram screen "about telegram premium" in the app

Up until this point, Durov has largely been paying the cost of keeping Telegram running out of his pocket. He says in his statement that Telegram will not sell the company, like the founders of WhatsApp.

Telegram must continue to serve the world as an example of a tech company that strives for perfection and integrity. And, as the sad examples of our predecessor’s show, that is impossible when you become part of a corporation,” said Durov, referring to WhatsApp’s acquisition.

How to Make Telegram More Private

You can take several measures yourself to improve your privacy and security on Telegram:

  • Send end-to-end encrypted chats via the secret chat option
  • Enable two-factor authentication
  • Activate disappearing messages
  • Tweak your privacy settings
  • Use a separate mobile phone number to log in to Telegram
  • Use a VPN to hide your IP address

Let’s break these down one by one.

Use the secret chat feature in Telegram

The secret chat is not immediately accessible in Telegram. Here’s how to start one:

  1. Open Telegram app on your iPhone or Android phone.
  2. Open the profile of the person you want to chat with by clicking their profile picture on Telegram’s interface.
  3. Telegram chat with a profile picture highlighted
  4. Then click on the three dots at the top right of the screen and choose ‘Start secret chat‘.
  5. Telegram profile with "more" and "start secret chat" highlighted
  6. A chat opens in which chats are end-to-end encrypted. At the beginning of the chat you will receive a notification in which the secret chat functions are listed:

Telegram's information on secret chats

In the overview with chats, you recognize the secret chat because there is a green padlock in front of the name of the chat partner. It’s also important to note that iPhone users can still take screenshots. However, the chat will display a message showing that someone has taken a screenshot:

A message on telegram showing someone took a screenshot of a secret chat

Enable two-factor authentication

Two-factor authentication is a fantastic way to keep your Telegram chats from people with access to your phone. Despite secret chats being end-to-end encrypted, for example, someone with access to your phone can access these chats.

To activate two-factor authentication on Telegram follow the steps below:

  1. Open the Telegram app on your phone.
  2. Click the three lines on the top-left side of the screen.
  3. Tap on “Settings.”
  4. Tap on “Privacy and Security.”
  5. Under Security, click “Two-step verification.”
  6. Screenshot of telegram app, privacy and security menu, two-step verification option highlighted
  7. Tap “Set Password.”
  8. Screenshot of telegram app, set password
  9. Enter the password you would like to use.
  10. Re-enter your new password.
  11. Enter a hint to remind you of your password in case you forget it (optional).
  12. Enter a recovery email in case you forget your password (optional).
  13. If you choose to skip providing an email, you’ll get the following Telegram warning.

Screenshot of telegram app, warning message about skipping password backup email

Self-destructing chats/ media

You can also use self-destructing messages if you have to send something really sensitive. The messages will disappear after a defined time period once it’s opened.

  1. In a private chat, you can set the self-destruct timer by clicking on the three dots in the top right of the chat window. Then click on Auto-Delete.
  2. Screenshot of telegram, private chat menu
  3. Set the time after which messages will be deleted.

Telegram’s auto-delete feature offers a range of pre-set time ranges to choose from too.

Customize Telegram privacy settings

By adjusting your privacy settings, you can double down on what information is shared with other users on the platform. Here’s how:

  1. Open Telegram.
  2. Click the three dashes in the upper-left corner.
  3. Go to Settings > Privacy & Security.
  4. Telegram settings with "privacy and security" highlighted
  5. Here you can indicate what you want others to see: telephone number, last seen & online, profile pictures, forwarded messages, Telegram groups.

Hiding your phone number on Telegram

To use Telegram, you need a phone number. This phone number is shown to everyone you interact with (unless you hide it in privacy settings) through the messaging app.

The phone number can also be used to search for you on Telegram. If you want to chat anonymously, you may prefer to keep your phone number hidden.

Here’s how to hide your mobile number on Telegram:

  1. Open the Telegram app on your phone.
  2. Click the three lines on the top-left side of the screen.
  3. Tap on “Settings.”
  4. Tap on “Privacy and Security.”
  5. Under Privacy, tap on “Phone Number.”
  6. Screenshot of telegram app, privacy and security menu, phone number option highlighted
  7. Under “Who can see my phone number?” choose “Nobody.”
  8. Screenshot of telegram app, phone number settings with focus on who can see my number

Telegram’s desktop and tablet app allow you to log in with a separate number. This phone number does not need to be linked to your smartphone. So you can also use a different phone number for this.

The Best Way to Improve Your Privacy on Telegram: Use a VPN

Reputable vpn shield iconUsing a virtual private network (VPN) can provide more online anonymity and privacy. A VPN also hides your IP address. For example, Telegram collects and stores your IP address for undisclosed reasons. Using a VPN will protect your real IP address from Telegram.

You can also use a VPN to bypass geo-blocks abroad. In countries where Telegram is blocked due to censorship, you can use a VPN to change your IP address and use the app.

NordVPN is an excellent VPN provider that we recommend for use with apps like Telegram. It is not for nothing that this VPN has been at the top of our list of best VPNs for years.