We’ve already talked more than once about the dangers of the MAX messenger. One of the main complaints about this government-backed app is: MAX lacks end-to-end encryption. That’s exactly what today’s article is about — I’ll explain what it is, why it matters, and what it means in practice when using the national messenger.

Unlike Telegram and other messengers, MAX does not have end-to-end encryption

End-to-End Encryption of Messages — What Is It

Let me explain with a simple example. Imagine you write a letter, lock it in a safe, and send it to the recipient. Only you and the recipient have the key to the safe. The courier carrying the safe physically cannot read the letter — they don’t have the key. This is exactly how end-to-end message encryption works.

Technically, the chain looks like this: the message is encrypted right on the sender’s smartphone before it’s even sent. What travels over the network is already an encrypted data set. Only the recipient’s device can decrypt it, because the key is stored there. The messenger’s server acts as a postman: it passes along the encrypted package but doesn’t know what’s inside. Even if the server is hacked or the messenger’s owner wants to read your correspondence — it’s technically impossible without the recipient’s key.

How end-to-end encryption works

End-to-end data encryption is used by Telegram in secret chats, as well as other messengers blocked in Russia. And this isn’t just a marketing term — it’s a specific cryptographic architecture.

How End-to-End Encryption Differs from Regular Encryption

This is a key point that many people confuse. There are two different levels of protection, and they’re easy to mix up, especially when the manufacturer writes “your data is protected”:

  • Encryption in transit — this is HTTPS, TLS, a secure connection. The message is encrypted on the way from your phone to the server. On the server, it is decrypted. This is protection against interception en route — a hacker in a café won’t catch your traffic. But the service itself sees the message in plain text.
  • End-to-end encryption — this is different. The message is encrypted before it leaves the phone and remains encrypted on the server. The service technically cannot read the content — even if it really wants to.

The difference is fundamental: in the first case, you trust the platform operator. In the second — you trust mathematics. When the MAX messenger or any other service writes “secure connection,” it’s almost certainly the first scenario, not the second. This isn’t deception, but it’s not the same as E2EE either.

How Chats and Calls Are Protected in the MAX Messenger

Security structure in the MAX messenger

MAX security is described in official materials through several tools:

  • secure connection for data transmission (HTTPS/TLS);
  • password to log into the app;
  • control of active sessions (you can terminate suspicious ones);
  • privacy settings (who can see your phone number and last seen time).

These are real security tools. They work and cover some risks. But not a single official document of the MAX app contains a public specification of end-to-end encryption for regular chats. There is no description of a cryptographic protocol. There is no statement that the server is technically unable to read messages.

Why MAX Doesn’t Have End-to-End Encryption

Encryption in MAX is limited to the data transmission level, which is confirmed by analysis of public materials. Here are the specific facts:

  • MAX does not publish a description of an E2EE protocol for regular chats. Telegram publishes one for secret chats — it uses the open MTProto protocol. MAX has no such document publicly available.
  • MAX does not explain where encryption keys are created and stored. If the keys are on the operator’s servers — the server can decrypt messages. If the keys are only on devices — it can’t. This is not publicly disclosed.

The architectural reason is clear: end-to-end encryption in the MAX messenger would create a technical obstacle to complying with Russian legislation requirements. In short: MAX’s privacy policy explicitly states that user data may be shared with third parties at the request of law enforcement agencies. End-to-end encryption would make fulfilling such requests technically impossible — which is exactly why it’s absent.

MAX openly states that it shares data with third parties

This doesn’t mean that “MAX reads all your messages” in real time. It means that the architecture allows such access when a corresponding request is made.

What Messages You Shouldn’t Send Through MAX

A practical takeaway without fearmongering. Chatting in MAX for most everyday tasks (messaging friends, work discussions, news from official sources, memes) is perfectly acceptable. The risks are comparable to any other messenger without E2EE.

But there are categories of information that are better not transmitted through messages in MAX:

  • passwords and confirmation codes (even temporary, even one-time);
  • photos of documents (passport, social security number, driver’s license);
  • bank details and card data;
  • trade secrets and business correspondence with legally significant content;
  • medical data and personal information.

An important caveat: the absence of confirmed E2EE does not mean that some stranger is reading your correspondence right now. It means something else — the trust model changes. By using MAX on Android, you trust not only your conversation partner but also the platform itself, as well as those who may request data from the government messenger. This is a conscious choice that everyone makes for themselves.