Telegram: encrypted messaging app with voice calls, groups, and channels. Strong privacy focus with zero third-party tracking or ads. Contacts sync to cloud servers for address book features.
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
3 totalCode Security
4 totalPrivacy
3 totalPermission Usage
1 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
ph.telegra.Telegraph
Version
12.6.3 (Build 32738)
Analysis Date
Apr 17, 2026
Classes Analyzed
353,108
Feedback helps us improve our analysis
Excellent privacy with zero tracking and encrypted chats. Two medium-risk issues with Vimeo and YouTube CDN dependencies and server-side contact storage require awareness. Generally secure for privacy-conscious users.
Data Security - 2 findings (1 low, 1 info)
Network Security - 3 findings (2 medium, 1 info)
Code Safety - 4 findings (2 low, 2 info)
Privacy - 3 findings (3 info)
The following third parties may receive your data:
Security: 90/100
Privacy: 88/100
The app's privacy practices could be strengthened by:
Contact Sync Transparency
Users should be clearly informed before contact upload begins that their full address book - including contacts who are not Telegram users and have not consented - will be stored on Telegram's servers. A granular opt-in per sync event would give users meaningful control.
Third-Party Script Integrity
The Vimeo and YouTube embedded players load code from those companies' servers each time a video plays. Users sharing sensitive video links in chats should be aware that playback creates a connection to those external servers.
Embedded Video Player Scripts
Adding integrity verification for the Vimeo and YouTube player scripts would ensure that the code loaded from those CDNs has not been altered in transit, reducing the risk of tampered scripts running inside the app.
Custom URL Scheme Validation
The tonsite:// URL scheme, used for TON-based website links, should include explicit input validation to prevent maliciously crafted links from opening unintended content in the in-app browser.
App Type: Encrypted messaging, voice/video calls, channels and groups - high privacy sensitivity
Classes Analyzed: 353,108
Third-Party Services: 2 (Firebase Phone Verification, Stripe Payments)
Context Tags: social, contacts, voip, payments
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on iOS applications to help users make informed decisions about app security and privacy.
Developer: Telegram FZ-LLC
Version: 12.6.3 (Build 32738)
Analysis Date: 2026-04-17
Package: ph.telegra.Telegraph
Developer not yet contacted