Skip to main content
Safety guideReviewed: 2026-07-19

Is Telegram Safe? An Evidence-Based Security Review

Telegram is used by more than a billion people, yet its most important safety property is the one most users misunderstand. This evidence-based review explains what Telegram's encryption really covers, what the company stores and shares, and exactly how to configure the app for your risk level.

The Short Answer: Safe for Most Uses, With Important Conditions

Telegram is one of the world's most widely used messaging apps, passing one billion monthly active users in March 2025. For everyday conversations, joining public communities, and following channels, it is reasonably safe when you understand one crucial fact: unlike Signal or WhatsApp, Telegram does not protect your messages with end-to-end encryption by default. Regular chats, every group, and every channel use client-server encryption, which shields your traffic from Wi-Fi snoopers but still lets the content reach Telegram's servers in a form the company can technically access.

That single architectural choice drives almost every serious safety debate about the platform. Security researchers at Royal Holloway and ETH Zurich, cryptographer Matthew Green, and the Electronic Frontier Foundation all converge on the same point: only manually started one-on-one Secret Chats and voice or video calls are end-to-end encrypted, and as of the EFF's January 2026 Encrypt It Already campaign, Telegram still has not made end-to-end encryption the default for direct messages. So the honest verdict is conditional. If you are an ordinary user who hardens a few settings, Telegram is acceptably safe. If you are an activist, journalist, or anyone whose messages could put them in danger, independent experts advise against relying on Telegram's defaults.

How Telegram's Encryption Actually Works

Telegram runs two different encryption schemes side by side. Cloud chats, the default for every private conversation, group, and channel, are encrypted between your device and Telegram's servers using the company's MTProto protocol, then stored in Telegram's cloud so your history syncs across devices. Telegram says this stored data is heavily encrypted, with decryption keys split across data centers in different jurisdictions, and that it does not use your data for advertising. Secret Chats work differently: they are end-to-end encrypted with keys generated on your devices through a Diffie-Hellman exchange, exist only on the two devices that started them, never touch Telegram's cloud backups, and support self-destruct timers.

The catch is what Secret Chats do not cover. They are only available for one-on-one conversations, never for groups or channels, and you must start one deliberately for each contact. Cryptographer Matthew Green documented that activating the feature takes multiple taps through non-obvious menus and requires the other person to be online, which means the vast majority of Telegram conversations, and literally every group chat, remain readable on Telegram's servers. A community answer on Security StackExchange captures the everyday confusion well: normal chats are encrypted in transit, so a network administrator cannot read them, but Telegram itself technically can. If default end-to-end encryption matters to you, see our Telegram vs Signal comparison.

Note

Independent cryptographic review has also tested MTProto itself. A 2022 peer-reviewed analysis by researchers at Royal Holloway, University of London and ETH Zurich found several protocol weaknesses, including message-reordering and timing issues. Telegram fixed the reported issues in client updates released in 2021 and the researchers judged the immediate practical risk to most users as low, but they also noted the protocol falls short of the guarantees offered by standard TLS-based designs.

Inside a Secret Chat you also get screenshot alerts and self-destructing messages, although Telegram itself cautions that screenshot detection cannot be guaranteed on every operating system and that nothing prevents someone photographing a screen with another device. You can read more about whether Telegram notifies screenshots in our dedicated explainer.

What Data Telegram Collects and When It Shares It

Safety is not only about message content. Telegram's privacy policy allows the company to collect metadata such as your IP address, the devices and apps you use, and your history of username changes, and to keep that metadata for up to 12 months for anti-abuse purposes. Signing up requires a phone number, although Telegram hides it from non-contacts by default and provides a dedicated Who Can See My Number setting introduced with its granular privacy controls.

The company's legal posture changed sharply in 2024. After CEO Pavel Durov was detained in France in August 2024 and charged with offenses including complicity in illegal content distribution and refusal to assist lawful interception, charges he denies, Telegram updated its terms. Since September 2024, the privacy policy states that Telegram may disclose a user's IP address and phone number to judicial authorities that present a valid legal order, with cases reported through its transparency channels. The BBC and the EFF both documented this shift, and the EFF noted it alarmed communities that had chosen Telegram precisely because it marketed resistance to government demands.

Important

One less-known exposure: by default, Telegram voice calls with people in your contacts use a direct peer-to-peer connection, which reveals each side's IP address to the other. TechCrunch verified this behavior in 2023 and Telegram confirmed it is by design. You can turn it off under Settings, then Privacy and Security, then Calls, by setting Peer-to-Peer to Never, so calls route through Telegram's servers instead.

Telegram also has an inactivity self-destruct feature for accounts, and its FAQ recommends Secret Chats, 2-Step Verification, and an app passcode for anyone with real security concerns. Because public references currently disagree about the exact default self-destruct period, do not rely on any assumed value: open Settings and confirm the period yourself, alongside the metadata retention practices described in the privacy policy.

Scams, Phishing, and Content Risks on Telegram

For most people, the biggest day-to-day danger on Telegram is not cryptography but other people. Groups can hold up to 200,000 members, bots can be created by anyone, and security vendors have documented thriving phishing markets, fraudulent investment schemes, and malware distribution that exploit that openness. Norton's review of the platform reached the same conditional verdict this page does, calling Telegram fairly safe for the average person while cataloguing the scam ecosystem that operates inside it. Our guide to common Telegram scams and how to avoid them covers the specific schemes in depth.

Checklist

  • Apply standard anti-phishing hygiene inside Telegram: treat unsolicited messages, links, and file attachments as untrusted even when they appear to come from known brands
  • never enter credentials or payment details on pages reached from chat links
  • keep your devices and apps updated
  • protect accounts with multi-factor authentication
  • and report fraud both through Telegram's in-app report buttons and to consumer-protection authorities such as the FTC at ReportFraud.ftc.gov.

On the moderation side, Telegram has historically drawn criticism for a lighter touch than rival platforms, a factor in the 2024 French investigation. The company now reports blocking more than 40 million groups and channels during 2025, checking public images against child-abuse hash databases including the Internet Watch Foundation's, and publishing daily transparency reports. Its Terms of Service prohibit spam, scams, promotion of violence, and illegal pornographic content on public parts of the platform, and require users in the EU, UK, and Australia to be at least 18. Those rules matter for families: public discovery surfaces can still expose younger users to inappropriate communities, so the age limits deserve respect.

Nine Settings That Make Telegram Meaningfully Safer

Steps

First, enable 2-Step Verification under Settings, Privacy and Security, so logging in requires a password in addition to the SMS code, and add a recovery email protected by its own strong password. Second, set a passcode lock, or a passkey where supported, so someone holding your unlocked phone cannot open the app. Third, set Peer-to-Peer to Never under Calls to stop IP exposure. Fourth, restrict Who Can See My Number and your last-seen visibility to My Contacts or narrower. Fifth, start Secret Chats for genuinely sensitive one-on-one conversations and use self-destruct timers. Sixth, review active sessions periodically and terminate devices you do not recognize. Seventh, be deliberate about which groups can add you. Eighth, check your account's inactivity self-destruct period. Ninth, keep the app updated so protocol fixes reach you.

Note

Telegram's own FAQ is candid about the limits of any settings checklist: it cannot protect you from someone with physical or root access to your device, and it recommends exactly this combination of Secret Chats, 2-Step Verification, and passcodes for users with real security concerns. Hardening helps ordinary users considerably; it does not convert Telegram into a tool for high-risk threat models.

Are Telegram Browser Extensions Safe? A Case Study in Reading Disclosures

Many people use Telegram in a browser, and using Telegram Web safely raises one more question: what about extensions that add features, such as video downloaders? The honest answer is that an extension is only as trustworthy as its disclosures, and you should read them critically. Take the Telegram Video Downloader extension associated with this site as a worked example. Its Chrome Web Store listing (version 1.3.2, a Manifest V3 extension declaring storage and tabs permissions with host access limited to telegram.org pages) describes saving videos, images, and audio from Telegram Web with original filenames.

Important

Here is the part a safety guide must not gloss over: the extension's public privacy disclosures do not describe data handling in the same way. As reviewed on July 19, 2026, the Chrome Web Store disclosure says the extension handles personally identifiable information, user activity, and website content. The developer policy separately says browser type, operating system, pages accessed, IP address, and device identifiers may be collected automatically. The scope of those statements and the extension's runtime data flow have not been independently verified. Treat the broader store disclosure as operative when deciding whether to install this or any extension.

Rights matter as much as privacy. Telegram's Terms of Service prohibit scraping and the platform's rules protect content owners; saving media is appropriate only for content you created, own, or have explicit permission to keep, and channel owners' restrictions and copyright law apply regardless of what any tool makes technically possible. If that describes your use case, our guide on how to download Telegram videos you are authorized to save explains the process step by step.

Verdict: Match Telegram to Your Threat Model

So, is Telegram safe? For public communities, channels, and everyday chats, yes, provided you harden the settings above and treat strangers' links with suspicion. For sensitive one-on-one conversations, it can be acceptable if you deliberately use Secret Chats on trusted devices. For anyone whose safety depends on their provider being unable to read or hand over their communications, the expert consensus points elsewhere: Telegram's own materials frame the platform as secure, while cryptographers and digital-rights groups counter that without default end-to-end encryption most content remains technically accessible to the company, which since 2024 also discloses IP addresses and phone numbers under valid legal orders. Both positions are documented; which one governs your decision depends on what you have at stake.

Frequently asked questions

Is Telegram end-to-end encrypted by default?

No. Default cloud chats, groups, and channels use client-server encryption, so content is protected in transit but technically accessible on Telegram's servers. End-to-end encryption applies only to voice and video calls and to one-on-one Secret Chats you start manually, and as of early 2026 advocacy groups still list default end-to-end encryption as an unmet demand.

Can Telegram read my messages?

Architecturally, Telegram's servers can access the content of regular cloud chats and all group and channel messages, although the company says stored data is heavily encrypted with keys split across jurisdictions and is not used for advertising. Secret Chats are end-to-end encrypted, so Telegram cannot read those.

Does Telegram share my data with the police?

Since September 2024, Telegram's privacy policy states it may disclose your IP address and phone number to judicial authorities that present a valid legal order confirming you are a criminal suspect, and it reports such cases in transparency updates. It may also retain metadata such as IP address and device information for up to 12 months.

Do Telegram calls expose my IP address?

They can. Calls with contacts default to a peer-to-peer connection that reveals each side's IP address, a behavior TechCrunch verified and Telegram confirmed. Set Peer-to-Peer to Never under Settings, Privacy and Security, Calls to route calls through Telegram's servers instead.

Is Telegram safe for activists or journalists?

Independent security researchers and digital-rights organizations advise against relying on Telegram's defaults for high-risk work, because most content is not end-to-end encrypted and the platform now discloses certain identifiers under legal orders. If provider-inaccessible messaging is a requirement, experts point to messengers with default end-to-end encryption.

Are Telegram video downloader extensions safe to use?

Evaluate each extension's disclosures before installing. For the extension associated with this site, the store listing and developer privacy policy conflict about usage-data collection. Our bounded clean-profile check observed only public login states: the popup rendered on Web K, while Web A focused Web K. It did not exercise an authenticated download or establish the authenticated data flow, so weigh the broader privacy disclosure. Whatever tool you use, save only content you own or have explicit permission to keep, and respect Telegram's terms and copyright law.

Keep Exploring Telegram Safety

Continue with our guides to common Telegram scams, the Telegram vs Signal comparison, and using Telegram Web securely, so every part of your setup matches the level of risk you actually face.