Your IP:Unknown

·

Your Status: Unknown

Skip to main content

Is Telegram safe? What to know before using it

Telegram is a popular global messaging and social media app. It is fairly safe to use, but it has some privacy concerns to be aware of. With the right settings and practices, you can make your Telegram experience much more secure. Let’s break down Telegram’s security features, privacy concerns, and how to use the app safely. 

Aug 3, 2025

9 min read

How to delete Telegram

How safe is Telegram?

Telegram is generally safe to use because it offers encryption options and customizable privacy settings, which help you keep your messages away from prying eyes. However, end-to-end encryption isn’t automatically turned on.

Additionally, Telegram allegedly doesn’t follow the same strict content moderation standards that other social media platforms do. This lack of moderation has made Telegram an attractive platform for cybercriminals. While Telegram has tried to deter malicious actors and extremist groups, users still need to watch out for scam messages. 

Telegram's privacy and security features

Telegram offers users several customizable privacy and security features. Let’s take a look at how they work. 

End-to-end encryption for secret chats only

Telegram only offers end-to-end encryption (E2EE) when using its secret chat feature. This means that only the message's sender and recipient can see its content, and even Telegram can’t see the content of messages sent using this feature. 

E2EE also keeps your messages safe from other third parties, such as your internet service provider or your Wi-Fi network routers. It uses cryptographic keys stored on the user’s device, rather than on Telegram’s servers. 

Since secret chats are not stored in Telegram’s cloud servers, they are only accessible on the device where the chat took place. This feature is helpful for sensitive or secure conversations. 

How does encryption work?

Two-factor verification (2FA)

Telegram offers 2FA options to protect your account from cybercriminals. With 2FA, you’ll need to enter both a password and a one-time SMS code to access your account. 

2FA adds an extra layer of security to your account. Even if a cybercriminal stole your password, they wouldn’t have the SMS code needed to log in. In Telegram, 2FA needs to be turned on manually.

MTProto security protocol

Telegram uses a proprietary encryption protocol called MTProto. It contains a mix of cryptographic algorithms, including AES-256 encryption for standard messages, RSA 2048-bit encryption for cryptographic key exchanges, and Diffie-Hellman key exchange protocols for secret chats. 

MTProto was built to handle Telegram’s mobile messaging needs. However, this protocol is not open-source, which means that independent security experts have not been able to evaluate its effectiveness. 

Custom privacy settings

Telegram allows users to customize privacy settings according to personal preferences. For example, you can decide which aspects of your profile you want to make public and which you want to hide from strangers. These features give you more control over who can find you and the information they can access. 

Self-destructing messages and media

Telegram users can set up self-destructing messages and photos in Secret Chat mode. Users set a timer that indicates how long they want the message to be accessible. This timer can last anywhere from one second to one week. 

When the recipient opens the message or photo, the timer starts. The recipient can’t take screenshots of the message or photo. Additionally, the data won’t be stored in Telegram’s cloud servers or backed up on the recipient’s device. These features add an extra layer of security when sending sensitive content. 

Telegram's main privacy and security issues

Although Telegram has some built-in security features, users should also be aware of some significant concerns. 

Not all messages are encrypted end-to-end

Telegram’s encryption options vary depending on the type of message you’re sending. Regular messages and posts only use client-server encryption, meaning Telegram can see the messages you’re sending. 

Secret chats are the only type of Telegram message that uses end-to-end encryption. If you want to keep your communications completely private between you and the recipient, you’ll need to use secret chats every time. 

Lack of transparency

As an organization, Telegram has not been very transparent about its operations and security practices. For example, it uses the closed MTProto encryption protocols, and its server-side code is also completely private. 

Additionally, Telegram does not disclose its content moderation practices. The app is known for having relatively lenient content standards when compared to other social media platforms.

In 2024, Telegram said it would strengthen its content moderation practices to prevent extremism on the platform. This step included adding moderation features to private chats. However, the app hasn’t been forthcoming about exactly how it’s moderating content.  

Telegram collects and stores metadata

Telegram stores user metadata such as usernames, IP addresses, and message timestamps. This information is collected from public and private conversations and stored for up to 12 months. 

If Telegram experiences a data breach, your metadata could be exposed to cybercriminals. Telegram is also obligated to share your data with authorities if they have a legal reason to request it. 

Telegram bots target users for phishing attacks and scams

Cybercriminals often use Telegram to launch complex phishing schemes and other frustrating scams. Users need to stay vigilant and be extremely cautious when responding to messages from unknown contacts. 

The latest Telegram scams include elaborate cryptocurrency scams, fake job offers, and dating scams. These scams can be extremely stressful and financially devastating for victims. Avoid sharing sensitive information like your bank details, address, or Social Security number with anyone on Telegram. 

How to use Telegram securely

While Telegram has some privacy and safety concerns to be aware of, that doesn’t mean you need to avoid it completely. Use the following security measures to stay safe while messaging on Telegram:

  • Use two-factor authentication. Use this feature to add an extra layer of security to your Telegram account. With 2FA, you’ll need both a password and a one-time SMS code to log in. 
  • Use a strong password. Make sure each password contains at least eight characters with a mix of upper- and lowercase letters, numbers, and symbols. Create a unique password for each account, and avoid combinations that are easy to guess, such as your birthday. 
  • Customize your privacy settings. Instead of making your account completely public, limit who can view your profile in Telegram’s app settings. 
  • Update Telegram regularly. When your phone prompts you to update Telegram, install the new version as soon as possible. Outdated apps are more vulnerable to cyberattacks. 
  • Use secret chats. If you’re just talking to one other person, use a secret chat instead of a regular chat. Since this feature has end-to-end encryption, it’s far more secure and private. 
  • Use a VPN for Telegram. A VPN encrypts your web traffic and hides your IP address, so even if your Telegram account is compromised, hackers won’t know your location.

Comparing Telegram with alternative secure messaging apps

Telegram is one of several messaging apps currently available. If you’re concerned about Telegram’s security limitations, you have plenty of other options to choose from. 

Other popular secure messaging apps include Signal and WhatsApp. Signal is widely considered to be the most secure messaging app on the market, with a number of advanced features to protect your privacy. It has end-to-end encryption using an open-source protocol, as well as disappearing messages and a “sealed sender” option. 

WhatsApp is also a very secure choice because it has default end-to-end encryption for all messages. You can also back up your WhatsApp history to Google Drive or iCloud and adjust your privacy settings to see who can access your profile. However, it’s important to note that WhatsApp is owned by Meta, which has a history of harvesting data from its users. 

To help you decide which app fits your needs, we’ve broken down the main privacy and security differences between Telegram, Signal, and WhatsApp.

Telegram

Signal

WhatsApp

End-to-end encryption

Only in secret chats

Default for all messages

Default for all messages

Encryption protocol

Proprietary

Open source

Open source

Data collection

Moderate

Minimal

Extensive

Self-destructing messages

Only in secret chats

Possible for all messages

Possible for all messages

Online security starts with a click.

Stay safe with the world’s leading VPN

FAQ

Also available in: Español,Français,Bahasa Indonesia,Italiano,Nederlands,Português,Svenska,Türkçe,繁體中文 (香港),繁體中文 (台灣).

NordVPN experts

NordVPN experts

Our NordVPN experts know the ins and outs of cybersecurity solutions and strive to make the internet safer for everyone. With a finger on the pulse of online threats, they share their expertise and practical tips on how to avoid them. Whether you're a tech newbie or a seasoned user, you'll find valuable insights in their blog posts. Cybersecurity should be accessible to everyone — and we're making that happen, one blog post at a time.