Telegram Encryption Explained in Plain Words
"Encrypted" is printed on almost every messaging app, and it tells you very little on its own. Encryption always protects something specific: a message on its way across a network, a file sitting on a server, or a conversation that only two devices can read. Which of those you have decides who can and cannot see your messages.
Step 002 sorted Telegram's chats into cloud chats and Secret Chats. This step explains what the encryption behind each one actually does, in plain words and without mathematics. The single idea to take away is that encryption protects the line between places, never the places themselves. Your unlocked phone, the other person's screen and anything saved outside the app are where messages are read, and no kind of encryption reaches there.
What you will be able to do after this step
- check_circle Explain encryption in transit, at rest and end to end, and what each one keeps out.
- check_circle Name the places where your messages are readable no matter what encryption is used.
- check_circle Judge claims like "fully encrypted" or "unhackable" by asking which layer they mean.
lock Three kinds of encryption, three different promises
Encryption scrambles data so that it is useless without a key. The important question is never whether something is encrypted, but who holds the key. There are three common answers.
- In transit. The message is scrambled on its way between your device and the server. People on the same network, such as a cafe's Wi-Fi, a hotel router or your internet provider, see traffic going to Telegram but cannot read it. The server, which holds the key for its end of the connection, can.
- At rest. The message is scrambled while it is stored. Someone who walked off with a server's disks would find unreadable data. Telegram's cloud chats are stored this way, and Telegram keeps the keys in data centres in other jurisdictions from the data, so that staff or intruders at one site cannot reach both. The service itself can still decrypt, which is how your history appears on a new device.
- End to end. The message is scrambled on your device and unscrambled only on the recipient's. The server passes along data it has no key for. On Telegram, Secret Chats and calls work this way.
Cloud chats use the first two layers; Secret Chats and calls add the third. None of them is "the real encryption". Each answers a different question about who could see a message along the way.
Where a message lives, and what protects it there
Follow one message from your fingers to someone else's screen. Pick a place.
Where you type it, readable by anyone holding the phone
On your own screen, a message is plain text, as it has to be for you to read it. Anyone who picks up your unlocked phone, or looks over your shoulder, sees what you see. Message previews can also show it on the lock screen without unlocking anything.
What helps here is not message encryption but device protection: a screen lock, your phone's own storage encryption, which modern phones switch on with the screen lock, and Telegram's app passcode. On Telegram Desktop, the local passcode also protects the copy of your account stored on the computer.
On your device, the lock screen and the app passcode are the encryption that matters.
On its way, covered by encryption in transit
Between your device and Telegram, every chat is encrypted in transit, cloud or secret. A stranger on the same public Wi-Fi, or your internet provider, can see that your device is talking to Telegram, roughly when and how much, but not what is being said.
That "roughly when and how much" is worth noticing. Encryption hides content, not the fact that traffic exists. Step 006 covers what this kind of information reveals on its own.
On the network, your words are hidden; the fact that you are talking is not.
Stored or relayed, depending on the kind of chat
A cloud chat is stored on Telegram's servers, encrypted at rest, and Telegram can decrypt it. That is the trade that makes your history available on every device and searchable from anywhere. A Secret Chat is only relayed: the servers pass along scrambled data they cannot open and do not keep it as history.
So "can the service read it?" has two answers on Telegram, and the chat header tells you which one applies. A padlock next to the name means a Secret Chat; no padlock means a cloud chat.
Cloud chat: Telegram holds the key. Secret Chat: only the two devices do.
Where it is read, beyond every kind of encryption
When the message arrives, it is decrypted so the other person can read it. From that moment, they can screenshot it, forward it, copy it into another app, or show it to someone in the room. End-to-end encryption guarantees that only their device could decrypt the message. It says nothing about what they do next.
This is the most important limit on the page, because in real life the person on the other end is the most common way private messages become public. Step 051 is about exactly that case.
Encryption delivers the message safely. What happens after delivery is up to a person.
verified_user End to end is only as good as the check
End-to-end encryption has one weak point: making sure the key really belongs to the person you think it does. If someone could slip their own key into the middle of a conversation, they could read it and pass it on, and both sides would see an encrypted chat.
Telegram gives you a way to check. In a Secret Chat, both people can open the encryption key screen and compare the image shown there. In a call, both sides see the same four emoji at the top. If what you see matches what the other person sees, reading them out over the call or comparing in person, no one is sitting in the middle. Comparing through a screenshot sent in the same chat proves nothing, because that is the channel you are trying to check.
Most conversations never need this step. For the few that do, it is the difference between "encrypted" and "encrypted to the right person".
rule Reading security claims
With the three layers in mind, most marketing language becomes easy to decode. "Military-grade encryption" usually describes the strength of the scrambling, not who holds the key. "Fully encrypted" often means encrypted in transit and at rest, which is standard and good, but is not end to end. And "unhackable" is never true of any app, because no encryption protects an unlocked phone, a person who is tricked into sharing a login code, or a screenshot.
The question that cuts through all of it is the one from the start of this step: who holds the key, and what happens on the screens at either end?
quiz Check your instincts
You send a message in an ordinary group over a cafe's public Wi-Fi. Who can read it?
Groups are cloud chats: encrypted in transit, so the cafe's network sees only scrambled traffic, and stored encrypted with keys Telegram holds. They are not end to end encrypted, but they are not open to the network either.
You use a Secret Chat for something sensitive. The other person takes a photo of their screen with a second phone. What did the encryption protect?
End-to-end encryption did its job completely: the message reached only their device. What they do with their own screen is outside what any encryption can control. When the risk is the other person, the answer is to not send it, not a different kind of chat.
An app advertises "military-grade encryption". What is the most useful question to ask?
Strong scrambling is standard; the difference between services is who can unscramble. A key held by the service means the service can read; a key held only by the two devices means it cannot. Key length rarely changes the answer for ordinary people.
task_alt
touch_app Try it now — five minutes
- Check your phone's screen lock If your phone has no screen lock, every other protection on this page stops at the first person who picks it up. Set one in the phone's own settings.
- Look at the headers of your private chats A padlock next to the name means a Secret Chat. No padlock means a cloud chat, readable by Telegram and synced to your devices.
- Hide message previews on the lock screen In Telegram's Notifications and Sounds settings, turn off message previews, so a locked phone does not display what it is protecting.
- Compare the four emoji on your next important call Read them out to each other. It takes five seconds and confirms nobody is in between.
How to start a Secret Chat, how its self-destruct timer works, how to compare its encryption key, and why most conversations are better left as cloud chats.
help Questions
Is Telegram end-to-end encrypted?
Partly. Secret Chats and calls are end to end encrypted. Ordinary chats, groups and channels are cloud chats: encrypted in transit and when stored, with the keys held by Telegram so your history can follow you to every device.
Does a VPN add more encryption?
A VPN encrypts the connection between you and the VPN provider, which hides from your local network that you are using Telegram at all. It does not change who can read your messages: Telegram's own encryption in transit already hides their content, and the VPN company now sees your traffic's metadata instead of your internet provider.
Are voice messages and files encrypted too?
They follow the chat they are sent in. In a cloud chat, they are encrypted in transit and stored encrypted with keys Telegram holds. In a Secret Chat, they are end to end encrypted like the messages around them. Once downloaded and saved to your phone's gallery or folders, they are ordinary files on your device.
If my messages are encrypted, why do I still need Two-Step Verification?
Because the most common attack does not break encryption at all; it signs in as you. Someone who gets your login code opens a new session and reads your cloud chats the way you do. Encryption protects messages on the way, and Two-Step Verification protects the door. Step 004 covers the code.
Can encryption be broken?
In practice, attacks go around encryption rather than through it: a stolen login code, an unlocked phone, a malicious app, or a screenshot. That is why this track spends far more time on those than on mathematics.
Encryption protects the line
Encryption in transit, at rest and end to end, what each one keeps out, and why none of them protects the screens at either end. Tap to open it at full resolution.