To use Zangi vs Telegram vs Signal vs Skred from a security perspective

To use Zangi vs Telegram vs Signal vs Skred from a security perspective

Messaging App Privacy & Security Comparison

Zangi and Telegram are not secure in comparison with Skred and Signal. Since they can work more as hotbeds for scammers and data collectors for governments. This is the radical conclusion of this report.

While Zangi allows registration without a phone number or SIM card, it is heavily targeted by scammers, impersonators, and blackmailers. If an online acquaintance or a stranger on social media insists on moving your conversation to Zangi, see it as a massive red flag. 

This red flag goes for Telegram too, but here because standard chats are stored on the cloud. Telegram can be forced by governments to hand over user data or chats if they choose to comply or are pressured to, as seen during legal pressure on its founder. If a government can do this, anybody can. Furthermore, Telegram basically has a non-encrypted architecture on a central server, which makes it a severe security risk for hacks. Besides that they can in theory (and in practice) hand over all data including from the encrypted Secret Chat feature (since they have decryption keys) to anybody. This should be seen in the light of that the company has an obvious Russian connection. 

While Zangi claims they use a serverless, decentralized, peer-to-peer system and claim to collect zero metadata, do not require a phone number or email to sign up, and store your chat history only on your physical device, they technically have no data to hand over to authorities even if subpoenaed. However, because of the closed-source nature of the app, this zero-retention claim cannot be independently verified.

To use Zangi vs Telegram vs Signal vs Skred from a security perspective

The recommendation from the analysis below is:
  1. If you want maximum, audited anonymity with no phone number: Skred is a stronger, open-source alternative to Zangi. Skred is also working under EU/France jurisdiction.
  2. If you want the absolute most secure, heavily-tested encryption with friends and family: Signal remains the undisputed industry leader.
  3. If you want social features and massive groups, but don’t mind sacrificing default privacy: Telegram is convenient, but should not be trusted for highly sensitive communications. This goes for Zangi too, but for different reasons (see above).

🎯 Comparison focused on security, encryption, and legal compliance to determine which app offers the best privacy protection.

 

Rank App Best For Privacy Score Key Strength Key Weakness
1 Skred Maximum privacy & anonymity ⭐⭐⭐⭐⭐ Zero data collection, P2P, EU jurisdiction Smaller user base, some call quality issues
2 Signal Balanced security & usability ⭐⭐⭐⭐½ E2EE default, open source, audited Requires phone number, US jurisdiction
3 Zangi Enterprise/secure calls ⭐⭐⭐⭐ No phone required, military-grade encryption Closed source, limited scrutiny
4 Telegram General use with cloud features ⭐⭐½ Secret Chats E2EE, large user base Default chats NOT E2EE, UAE jurisdiction

🏆 Recommendation: Skred offers the best privacy protection for users prioritizing absolute anonymity, zero data collection, and strong legal protections under EU/GDPR. Signal is a close second for those wanting a balance of security, usability, and transparency.

 

📊 Detailed Comparison Table

Feature Skred Signal Zangi Telegram
End-to-End Encryption ✅ Yes (device-to-device) ✅ Yes (all chats/calls by default) ✅ Yes (AES-GCM 256) ❌ No (only in Secret Chats)
Encryption Protocol Open source (Guardian Project) Signal Protocol (open, audited) Proprietary (RSA-2048, AES-GCM) MTProto 2.0 (proprietary)
Open Source ✅ Yes ✅ Yes (client & server) ❌ No (closed source) ⚠️ Partial (clients only)
Architecture Peer-to-peer Centralized (minimal data) Decentralized/P2P Centralized (cloud)
Data Collection ❌ Zero personal data ⚠️ Phone number only ❌ Zero (claimed) ⚠️ Phone, contacts, IP, metadata
Message Storage ❌ None (P2P, no servers) ⚠️ Temporary (offline delivery) ❌ None (device-only) ✅ Server-side (cloud chats)
Metadata Collection ❌ Minimal/none ⚠️ Minimal (phone #, random tokens) ❌ Minimal/none ⚠️ Extensive (contacts, groups, etc.)
Phone Number Required ❌ No ✅ Yes ❌ No (assigns private number) ✅ Yes
Jurisdiction 🇫🇷 France (EU/GDPR) 🇺🇸 USA (California) 🇦🇲 Armenia 🇦🇪 UAE (Dubai)
GDPR Compliance ✅ Full compliance ✅ For EU users ✅ Claims compliance ⚠️ Partial (for EU users)
Independent Audits ✅ CNIL, ANSSI standards ✅ Extensively audited ❌ Limited public scrutiny ⚠️ Limited cryptanalysis
Forward Secrecy ✅ Yes ✅ Yes (Double Ratchet) ⚠️ Yes (dynamic channels) ✅ Yes (MTProto 2.0)
Perfect Forward Secrecy ✅ Yes ✅ Yes ✅ Yes ✅ Yes
Multi-device Sync ❌ No ✅ Yes ❌ No (one device = one account) ✅ Yes
Group Chats E2EE ✅ Yes ✅ Yes ✅ Yes ❌ No (only Secret Chats 1:1)
File Sharing E2EE ✅ Yes ✅ Yes ✅ Yes ❌ Only in Secret Chats
Voice/Video Call E2EE ✅ Yes ✅ Yes ✅ Yes ✅ Yes (in Secret Chats)
User Base Size ~21M+ Large (exact undisclosed) Smaller Very large (700M+ monthly)

 

🔍 Deep Dive: Security Analysis

🥇 Skred – The Privacy Champion

Encryption & Security:

  • Protocol: Open-source encryption based on Guardian Project’s work
  • Architecture: True peer-to-peer (device-to-device) – no intermediate servers
  • E2EE: All communications (messages, calls, files) are end-to-end encrypted
  • Data Storage: No server storage – messages exist only on devices
  • Anonymity: No phone number, email, or any personal identifier required
  • Deletion: Messages deleted from both ends when either user deletes them

Legal & Compliance:

  • Jurisdiction: France (FRANCE EN LIGNE company)
  • GDPR: Explicitly designed for full GDPR compliance
  • Data Protection: Governed by French and European law
  • Audits: CNIL declarations, ANSSI standards, independent technical reviews
  • Hosting: Servers located exclusively in Europe under French jurisdiction
  • Data Transfer: No data transferred to non-European territories

Privacy Features:

  • Multiple profiles for different social groups
  • Secret Spaces for compartmentalized communication
  • Biometric app lock
  • Revocable relationships (stop being reachable)
  • Click-to-call for anonymous web calls

Trade-offs:

  • Smaller user base compared to mainstream apps
  • Call quality can be inconsistent (P2P dependency)
  • No multi-device sync

 

🥈 Signal – The Gold Standard

Encryption & Security:

  • Protocol: Signal Protocol (open source, industry gold standard)
  • E2EE: All messages, calls, group chats, files by default
  • Forward Secrecy: Double Ratchet algorithm + X3DH key agreement
  • Post-Quantum: PQXDH protocol for quantum-resistant encryption
  • Open Source: Client apps and server code fully open source
  • Audits: Extensively audited by independent security researchers

Legal & Compliance:

  • Jurisdiction: USA (Signal Messenger LLC, California)
  • GDPR: Compliant for EU users
  • Data Collection: Phone number only (required for registration)
  • Data Retention: Minimal – only what’s necessary for delivery
  • No Ads: Non-profit, no monetization of user data

Privacy Features:

  • Disappearing messages
  • Screen security (prevents screenshots in some cases)
  • Registration Lock PIN
  • Sealed sender (hides sender/receiver metadata from Signal servers)
  • Private contact discovery

Trade-offs:

  • Requires phone number for registration
  • US jurisdiction (potential for government requests, though minimal data available)
  • Server infrastructure (though minimal data stored)

 

🥉 Zangi – The Enterprise Contender

Encryption & Security:

  • Protocol: Proprietary multi-layer encryption
    • Encrypted proprietary handshaking mechanism
    • Dynamic channel encryption (RSA-2048, AES-GCM)
    • End-to-end encryption
  • E2EE: All messages, calls, files encrypted with AES-GCM 256
  • Architecture: Decentralized model – no central servers
  • Data Storage: No data stored on servers (device-only)
  • No Phone Required: Assigns private number upon registration

Legal & Compliance:

  • Jurisdiction: Armenia (Secret Phone, Inc.)
  • GDPR: Claims full compliance
  • Data Collection: Claims to collect zero user information
  • Business Model: Sells platform to businesses (not ad-based)

Privacy Features:

  • Works in low-bandwidth conditions
  • Military-grade encryption
  • No ads, no tracking
  • Zero-data retention policy

Trade-offs:

  • Closed source – cannot be independently audited
  • Limited public scrutiny and community review
  • Smaller user base
  • Company based in Armenia (less established legal framework)

 

🏺 Telegram – The Crowd Favorite

Encryption & Security:

  • Protocol: MTProto 2.0 (proprietary, designed by Telegram)
  • E2EE: Only in Secret Chats (1:1, not groups)
  • Cloud Chats: Server-client encryption (Telegram holds keys)
  • Secret Chats: Device-device E2EE with forward secrecy
  • Voice Calls: E2EE available
  • Open Source: Client apps open source, server closed source

Legal & Compliance:

  • Jurisdiction: Dubai, UAE (Telegram FZ-LLC)
  • GDPR: Partial compliance for EU users
  • Data Collection:
    • Phone number (required)
    • Contacts (if synced)
    • IP addresses
    • User IDs, device info
    • Message metadata (timestamps, etc.)
  • Data Storage: All cloud chat data stored on Telegram servers

Privacy Features:

  • Secret Chats with self-destruct timers
  • Two-step verification
  • Passcode lock
  • Large file sharing (up to 2GB)
  • Cross-platform sync

Trade-offs:

  • Default chats are NOT end-to-end encrypted – Telegram can access content
  • Centralized architecture creates single point of failure
  • UAE jurisdiction raises concerns about government access
  • Extensive metadata collection
  • Server holds encryption keys for cloud chats

 

⚖️ Legal Compliance Comparison

GDPR Compliance

App GDPR Compliant Data Minimization User Rights Jurisdiction
Skred ✅ Yes ✅ Zero personal data ✅ Full rights (delete, access) 🇫🇷 France (EU)
Signal ✅ Yes (for EU) ✅ Minimal (phone # only) ✅ Full rights 🇺🇸 USA
Zangi ✅ Claims ✅ Zero (claimed) ✅ Full rights 🇦🇲 Armenia
Telegram ⚠️ Partial ❌ Extensive ⚠️ Limited 🇦🇪 UAE

Jurisdiction Analysis

🇫🇷 Skred (France/EU):

  • Strongest legal protections
  • GDPR provides robust privacy rights
  • CNIL (French data protection authority) oversight
  • ANSSI (French cybersecurity agency) standards
  • No data transfer to non-EU territories
  • Verdict: Excellent legal protection

🇺🇸 Signal (USA):

  • US has weaker privacy laws than EU
  • However, Signal’s architecture minimizes data available
  • California Consumer Privacy Act (CCPA) provides some protections
  • Signal cannot access message content even if compelled
  • Verdict: Good legal protection (architecture compensates for jurisdiction)

🇦🇲 Zangi (Armenia):

  • Armenia has data protection laws
  • GDPR compliance claimed
  • Less established legal framework than EU/US
  • Verdict: Adequate but less certain

🇦🇪 Telegram (UAE):

  • UAE has limited privacy protections
  • Government has broad surveillance powers
  • Telegram has complied with some government requests in the past
  • Verdict: Weakest legal protection

 

🛡️ Security Analysis

Encryption Quality

App Protocol Open Source Audited Forward Secrecy Implementation
Skred Guardian Project-based ✅ Yes ✅ CNIL/ANSSI ✅ Yes P2P, no servers
Signal Signal Protocol ✅ Yes ✅ Extensively ✅ Yes (Double Ratchet) Centralized, minimal data
Zangi Proprietary (RSA-2048, AES-GCM) ❌ No ❌ Limited ✅ Yes Decentralized
Telegram MTProto 2.0 ⚠️ Partial ⚠️ Limited ✅ Yes Centralized

Protocol Strength:

  1. Signal Protocol: Industry gold standard, used by WhatsApp, Facebook Messenger, Skype. Extensively analyzed and proven secure.
  2. Skred’s Protocol: Based on Guardian Project (open source, community-reviewed)
  3. MTProto 2.0: Proprietary but cryptographically sound. Some concerns about lack of formal proof.
  4. Zangi’s Protocol: Proprietary, cannot be independently verified.

Threat Model Protection

Threat Skred Signal Zangi Telegram
Government surveillance ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐ ⭐⭐⭐⭐ ⭐⭐
Corporate data harvesting ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐⭐ ⭐⭐⭐
Hacker interception ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐
Server breach ⭐⭐⭐⭐⭐ (no servers) ⭐⭐⭐⭐ ⭐⭐⭐⭐⭐ (no data) ⭐⭐ (cloud chats at risk)
Metadata collection ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐ ⭐⭐⭐⭐⭐
Insider threats ⭐⭐⭐⭐⭐ ⭐⭐⭐⭐ ⭐⭐⭐⭐⭐ ⭐⭐⭐

📈 Privacy Score Breakdown

Scoring Criteria (out of 100)

Criteria (20 pts each) Skred Signal Zangi Telegram
Encryption Strength 20 20 18 15
Open Source 20 20 0 10
Data Collection 20 18 20 5
Jurisdiction 20 15 12 5
Architecture 20 17 20 5
Total 100 90 70 40

 

🏆 Final Recommendation

For Maximum Privacy: Choose Skred

Skred is the clear winner for privacy-conscious users who want:

  • ✅ Zero personal data collection (no phone, email, or identifiers)
  • ✅ True peer-to-peer architecture (no central servers to breach)
  • ✅ Full GDPR compliance with French/EU legal protections
  • ✅ Open-source encryption based on Guardian Project
  • ✅ Complete anonymity (multiple profiles, no tracking)

Best for: Journalists, activists, whistleblowers, anyone needing absolute privacy and anonymity.

For Best Balance: Choose Signal

Signal is the best all-around choice offering:

  • ✅ End-to-end encryption by default for all communications
  • ✅ Fully open-source (client and server)
  • ✅ Extensively audited security
  • ✅ Strong privacy practices (minimal data collection)
  • ✅ Large, established user base

Best for: Most users who want strong privacy without sacrificing usability.

When to Choose Zangi

Consider Zangi if you need:

  • ✅ No phone number required (assigns private number)
  • ✅ Military-grade encryption for calls
  • ✅ Works in low-bandwidth conditions
  • ✅ Enterprise-grade security

But be aware: Closed-source nature means you must trust Zangi’s claims without independent verification. Unlike widely trusted privacy apps like Signal, Zangi is closed-source and uses proprietary encryption. Because the code is not public, independent cybersecurity researchers cannot review it to verify that Zangi’s “military-grade” encryption is implemented correctly or free of backdoors. You have to take the developers (Secret Phone, Inc.) entirely at their word regarding how secure the app actually is. Because of the closed architecture and anonymous settings, you as a user are not in control, so if you want to use it, use it only with people you know.

 

Avoid Telegram for Privacy

Telegram is not recommended for privacy-focused users because:

  • ❌ Default chats are NOT end-to-end encrypted
  • ❌ Extensive metadata collection
  • ❌ Centralized architecture (single point of failure)
  • ❌ UAE jurisdiction (weak privacy laws)
  • ❌ Server holds encryption keys for cloud chats
  • ❌ Big Red Flag since it is one of the main playgrounds for scammers and other criminals 

Only use Telegram if you:

  • Always use Secret Chats (1:1 only, not groups)
  • Understand the privacy limitations
  • Prioritize features and user base over privacy

Written by

LarsGoran Bostrom

Developer of SOE Wellness Community and Expert of Data Ethics and Developer/Author of the Course: Data Ethics – Navigating the Ethical Landscape of Emerging Technologies and helping businesses and other organisations to Re-Digitalise with European Products and Services

European trends

Need help choosing? Consider your threat model: If you face government-level surveillance, Skred is strongest. For everyday privacy, Signal offers the best balance. For enterprise use with no phone requirement, if you do not like Skred, Zangi is viable, but it is basically the trust you have in Secret Phone Inc that should determine if you should use it or not. Avoid Telegram for sensitive communications.

For a more detailed analysis of your specific requirements, please contact me via the form below for advice about a complete digital solution with focus on privacy or advice on specific apps, tools and features. 

 

📚 Sources & References

Skred

Official Website: https://skred.app/

Privacy Policy: https://skred.app/privacy

Google Play: https://play.google.com/store/apps/details?id=mobi.skred.app

 

Signal

Official Website: https://signal.org/

Privacy Policy & Terms: https://signal.org/legal/

Documentation: https://signal.org/docs/

 

Zangi

Official Security: https://zangi.com/features/security

Privacy & Encryption Guide: https://zangi.com/news/en/all-about-privacy-encryption-zangi-secure-messaging-app/

FAQ: https://delta.zangi.com/faq?url=security-and-privacy

Google Play: https://play.google.com/store/apps/details?id=com.beint.zangi

 

Telegram

MTProto Documentation: https://core.telegram.org/mtproto

End-to-End Encryption: https://core.telegram.org/api/end-to-end

Technical FAQ: https://core.telegram.org/techfaq

 

🔄 Updates & Notes

Last Updated: July 16, 2026

Methodology: Research conducted using official documentation, privacy policies, and reputable third-party analyses

Limitations: Information based on publicly available data as of July 2026. Security landscapes evolve rapidly.

Disclaimer: This comparison is for informational purposes only. Always conduct your own research based on your specific threat model and requirements.

 

.