Is Telegram safe? What its encryption actually covers
Published 31 August 2026. Written by the Nyra team.
Telegram is safe from outside hackers, but not private from Telegram itself. Regular chats and every group chat are stored on Telegram's servers in readable form. Only secret chats are end-to-end encrypted, and you have to start them manually. For messaging that is private by default, Telegram is the wrong tool.
Telegram is one of the most used apps on the planet and one of the most misunderstood. Ask ten people whether Telegram is encrypted and most will say yes, it is the private one. The honest answer is more specific: Telegram is a very good cloud messenger with a genuinely strong feature set, and its encryption covers much less than most users assume. Whether it is safe depends entirely on what you use it for.
A disclosure up front: we are building a messaging app ourselves, so we have an interest in this topic. We have kept this page factual, and where Telegram is good we say so plainly.
The short answer
Telegram is safe as a social platform and unremarkable as a private messenger. Regular chats and all group chats are stored on Telegram's servers in a form the service can read. Only secret chats, which you must start manually and which work only one-to-one, are end-to-end encrypted. If you treat Telegram like a fast, feature-rich social network, it serves you well. If you treat every Telegram chat as confidential, you are trusting the company more than you probably realize.
Is Telegram encrypted? Yes, but not the way you think
Telegram has two kinds of chats, and the difference is the whole story.
Cloud chats are the default. Every regular one-to-one conversation and every group chat is a cloud chat. These are encrypted in transit between your device and Telegram's servers, which protects you from someone snooping on your Wi-Fi. But on the servers themselves, your messages are stored in a form Telegram can access. The company describes a distributed encryption scheme with keys split across jurisdictions, and that is a real engineering choice, but the functional fact remains: the service holds your message content and can technically read it. That is precisely what end-to-end encryption prevents, and cloud chats do not have it.
Secret chats are Telegram's genuine end-to-end encrypted mode. You start one manually for a specific contact, and from then on only the two devices in that conversation hold the keys. Telegram's servers relay ciphertext they cannot read. Secret chats support self-destruct timers and screenshot alerts, and they are a real, working privacy feature.
The limits matter as much as the feature. Secret chats work only one-to-one: there is no end-to-end encrypted group chat on Telegram at all. They do not sync across devices, because the keys live on one device by design, and they are not available in every client. And because each one must be started deliberately, per contact, the overwhelming majority of Telegram conversations never get this protection. The private mode exists; almost nobody is in it.
What server-side storage means in practice
Server-side storage is not a bug. It is the reason Telegram feels so good to use. Sign in on a new phone and your entire history appears instantly. Groups scale to two hundred thousand members. Channels broadcast to millions. Bots, file sharing up to gigabytes, seamless multi-device sync: all of it works because the server holds everything. Signal, which stores almost nothing, cannot match that convenience, and it is fair to say so.
The trade is that a readable copy of your conversations exists on infrastructure you do not control. That copy is exposed to whatever reaches the company that holds it: a security breach, an insider, or a legal order from a government with jurisdiction. Telegram is operated from Dubai with servers distributed across several countries, which has historically made legal access slow and inconsistent rather than impossible.
The legal picture shifted in 2024. After its founder was arrested in France that August, Telegram updated its privacy policy in September 2024: it now states that the IP addresses and phone numbers of users who violate its terms can be disclosed to authorities in response to valid legal requests, where previously it had described sharing data only in terror-related cases. Telegram's own transparency reporting since then shows the company fulfilling thousands of such requests. None of this is scandalous by industry standards, and it is roughly how most cloud services operate. It is simply worth knowing that the era of Telegram as a company that handed over nothing is over, stated by Telegram itself. What a service can be compelled to produce is a function of what it stores, which is why metadata and server-side data deserve as much attention as encryption.
MTProto in one paragraph
Telegram's encryption uses MTProto, a protocol the company designed itself rather than adopting an established one. Cryptographers were sharply critical of early versions, and MTProto 2.0 fixed the identified weaknesses. Academic analyses since have found flaws of mostly theoretical impact, which were patched, and no practical break of current secret chats is publicly known. The fair summary: MTProto appears to hold up, but it has received a fraction of the independent scrutiny applied to the Signal Protocol, which has been formally verified and audited for years by many teams. When the stakes are high, the amount of qualified review a protocol has survived is itself a security property.
What Telegram genuinely gets right
- The best large-group and channel experience in messaging. Nothing else combines the scale, speed, and moderation tools.
- Open source clients with reproducible builds, so researchers can verify the app you install matches the published code. The server is closed source.
- Real security options for those who look: two-step verification passwords, active session management, auto-deleting messages, and secret chats.
- It is free, fast, and polished across every platform, which is why over a billion people use it.
So who is Telegram safe for?
Telegram fits you well if you use it as what it is: a social platform. Public communities, hobby groups, channels you follow, chats with friends where the realistic worst case of a leak is embarrassment. For that use, Telegram is excellent, and its safety record is fine.
Telegram is the wrong default if you need conversations that stay unreadable by everyone except the person you sent them to. Journalists and sources, lawyers, activists, medical conversations, anything you would not want stored indefinitely on a company's servers: for those, use an app where end-to-end encryption is the default rather than an option. Signal is the standard recommendation, and it earns it: end-to-end encrypted by default including groups, independently audited many times, run by a nonprofit. Our guide to encrypted messaging apps walks through the options in detail, our ranking of the most secure messaging apps orders them for today, and our side-by-side comparison puts Telegram, Signal, and others in one table.
For completeness: our own app, Nyra, is in development and not yet downloadable. It aims to pair Signal-style end-to-end encryption, on by default for everything including groups, with registration that needs no phone number at all. Until it ships and is independently audited, the released apps above are the ones to judge it against.
Frequently asked questions
Is Telegram end-to-end encrypted?
Not by default. Regular Telegram chats and all group chats are encrypted between your device and Telegram's servers, where they are stored in a form the service can read. Only secret chats are end-to-end encrypted, and they must be started manually, work only one-to-one, and stay on the device where you started them.
Are Telegram secret chats safe?
Secret chats are Telegram's real end-to-end encrypted mode, and no practical break of the current protocol is publicly known. They use MTProto, Telegram's own cryptography, which has received academic analysis but far less independent scrutiny than the Signal Protocol. The bigger risk is practical: secret chats must be started manually for every contact, so most conversations never get their protection.
Can police read Telegram messages?
It depends on the chat type. Regular chats and all group chats are stored on Telegram's servers in a form the company can read, so that content exists to be produced, and since 2024 Telegram's privacy policy states it can share the IP addresses and phone numbers of users who violate its terms in response to valid legal orders. Secret chats are end-to-end encrypted, so Telegram holds no readable copy, though messages can still be read from a seized, unlocked phone.
Want private messaging with nothing to hand over? One email at launch, nothing else.
Join the waitlist