Telegram Security & Privacy Scorecard
Android
Messages are delivered through Google's Firebase infrastructure, and the device interacts with Google Play Services and SafetyNet. Payments processed through Stripe follow standard financial data handling. Usage data touches several Google-operated services, though no advertising or behavioral tracking SDKs are present.
Best for
Everyday messaging with standard Google integrations
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- OAuth Client ID Remote Override Vulnerability
- Regular Messages Stored in Unencrypted Database
- Unencrypted Credentials in SharedPreferences
Top privacy issues
- Auth Tokens Backed Up to Google Drive
- External Storage Media Unencrypted
- WebView Third-Party Cookies Enabled
Full analysis
Telegram
Version: 12.3.1 (Build 63852)
Scan Date: January 31, 2026
What This Means for You
Messages are delivered through Google's Firebase infrastructure, and the device interacts with Google Play Services and SafetyNet. Payments processed through Stripe follow standard financial data handling. Usage data touches several Google-operated services, though no advertising or behavioral tracking SDKs are present.
Recommendation: Use With Caution
Best For: Everyday messaging with standard Google integrations
Key Findings
Data Security - 9 findings (1 critical, 1 high, 4 medium, 3 low)
Network Security - 2 findings (1 medium, 1 low)
Code Safety - 0 findings
Privacy - 1 finding (1 medium)
Privacy Concerns
What Data is Collected
Telegram collects device identifiers and usage information through Google Play Services and Firebase. Payment details are handled by Stripe when users make in-app purchases. User location may be accessed through Google Maps when location-sharing features are used.
Third-Party Data Sharing
User data is shared with the following third-party services:
- Google (Firebase Cloud Messaging, Firebase Remote Config, Google Play Services, Google Play Billing, Google Maps, ML Kit, SafetyNet): Message delivery, app configuration, device security checks, and billing.
- Stripe: Processing of any payments made within the app.
- ZXing: QR code reading, processed locally on the device.
- NanoHTTPD: Local network functionality within the app.
No advertising networks or behavioral profiling services are embedded in this build.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 60/100 |
| Privacy | 75/100 |
| Data Security | 50/100 |
| Network Security | 85/100 |
| Code Safety | 70/100 |
| Data Collection | 100/100 |
| Data Sharing | 90/100 |
| User Control | 100/100 |
Positive Security Features
- Data collection exposure is minimal: the app scores 100/100 for Data Collection, reflecting that it requests only what is needed for core functionality.
- Users retain strong control over their data, reflected in a perfect User Control score of 100/100.
- No advertising or behavioral tracking services are included in this version of the app.
Areas for Improvement
- Local data stored on the device is not fully protected, meaning sensitive information could be exposed if someone gained physical access to the device.
- Some network communications could be made more robust to better protect user data while it travels between the device and Telegram's servers.
- Certain internal operations could be handled more securely to reduce risk if the app is running on a rooted or compromised device.
About This Analysis
This scorecard is generated through automated static analysis of the Android application binary. It reflects the security and privacy posture of this specific version and build.
App Details
| Field | Value |
|---|---|
| App Name | Telegram |
| Package ID | org.telegram.messenger |
| Version | 12.3.1 (Build 63852) |
| Scan Date | January 31, 2026 |
| Platform | Android |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 68/100 |