Telegram Privacy Settings: What Each One Actually Blocks

Telegram Privacy Settings: What Each One Actually Blocks

Someone cannot add you to a group. Someone else says your messages never arrive. A third person can see when you were last online and a fourth swears you have been invisible for weeks. None of this is a bug, and none of it is one setting. It is fourteen separate switches, each with its own list of people, sitting behind one screen that makes them look like a single preference.

The screen is Settings, then Privacy and Security. Most people open it once, set the obvious things to their contacts only, and never look again. That is exactly how you end up unreachable to the people you want and reachable to the ones you do not, because several of the switches control things you would never guess from their names, two of them quietly change what you can see about other people, and three of them are not per person at all.

This article walks every switch, in the order the protocol itself lists them, and says plainly what each one blocks and what it leaves open. It also covers the part almost nobody documents: what the person on the other side actually sees when a setting stops them, because the platform does not fail silently and the error it returns tells you which switch you hit.

Every key, rule, field and default below was read from Telegram's own protocol documentation and public help pages on 10 August 2026, not remembered. Where the platform does not publish a number, that is said rather than filled in with a guess.

The Screen Is Not One Setting, It Is Fourteen

The first correction is structural. Privacy on this platform is not a level you pick, it is a set of independent keys, and each key carries its own audience list.

Fourteen keys, not one preference

The protocol names them individually: last seen timestamp, group invites, phone calls, peer to peer during calls, forwarded message attribution, profile photo, phone number, being added to contacts by phone number, voice messages, bio, birthday, automatic display of received gifts, who can message you without paying, and the songs pinned to your profile. Fourteen keys, fourteen separate answers. Nothing about setting one of them touches another, with two documented exceptions covered further down.

The app groups them, the platform does not

Your client arranges these into sections with friendly headings, which is why they feel like one control panel with a theme. Underneath there is no theme. The read and write operations take exactly one key at a time and return the rules attached to that one key. If you want a coherent posture you have to build it switch by switch, because nothing in the system builds it for you.

Changing one pushes to every device you are signed in on

When you change a rule, the platform emits an update to every session currently signed into that account. This is worth knowing if you run an account from more than one place, because a change made on a phone lands on the desktop client within seconds without anyone touching it. It also means a setting that appears to have changed itself is usually another session of yours, not an intrusion.

Every Switch Takes the Same Five Answers

The keys differ, the vocabulary of answers does not. Once you know the six allow values and the five deny values, every screen in this section reads the same way.

Allow everybody, allow contacts, allow named people

The three ordinary permissions are everybody, the people in your contact list, and a specific list of individual accounts you name. The third one is the interesting one, because it is a list of accounts rather than a category, which is what lets you keep a switch closed to the world and still open it for six people.

The mirror image, and why order matters

Each of those has a deny counterpart: deny everybody, deny contacts, deny named people. Rules are supplied as a list, so a working configuration is usually a permissive rule plus a narrow denial on top of it. Allow contacts, then deny four named accounts, is a normal and supported shape.

Three special values most people never see

Three more values exist that do not appear as ordinary options. One allows the members of specific group chats, addressed by the chat rather than by person, which means a switch can follow a room instead of a roster and quietly widens as that room grows. One allows accounts with a Premium subscription, which turns a switch into a filter on account type rather than on identity. One allows bots as a class, with a matching denial, so automated accounts can be admitted or refused without naming any of them.

There is also a close friends value, and it has two restrictions worth knowing. It works only when posting stories, so it is useless on every other key. And the list it draws from accepts only accounts already in your contact list, edited through its own operation by submitting the entire list at once rather than adding people one at a time. Whether a given contact is on it is readable as a flag on that contact's record, which is the usual pattern here: the platform keeps the value private and publishes the fact that a value exists.

Who Can Add You to Groups

This is the switch people search for most often, usually after being dropped into a group they never asked to join, and it is also the switch that decides whether anyone else can build an audience out of you.

What the switch actually says

The protocol description is one line: whether people will be able to invite you to chats. That is the whole scope. It governs being pulled into a group or channel by another account, and it does not govern anything about links. If your setting is contacts only, an account that is not in your contact list cannot put you into a chat.

The invite link is the hole in the wall

This is the part that surprises people. Closing the switch stops other accounts from adding you; it does not stop you from joining. An invite link is you performing the join, so a link works no matter how the switch is set. That is why the same person who cannot add you directly can still get you into the group by sending you a link you tap. If you want to understand the mechanics of that from the other side, our write up on how many members you can add and how fast covers where the ceilings actually sit.

Why this matters if you run an account list

Anyone building a group by adding people is filtered by this switch on every single target, one at a time, and the failures are not evenly distributed: they cluster in the people who have been on the platform long enough to have changed something. That is the honest reason an adding run never converts a source list at anything close to a hundred per cent, and it is a platform behaviour, not a tool defect. Our group member sourcing tool reports these refusals per account rather than hiding them in an average, because the refused ones tell you what the source group is made of.

Your Phone Number Has Two Separate Switches

The number is the one field where people consistently believe they are covered and are not, because there are two keys and closing one does nothing for the other.

Visibility is one key

The first key controls whether people will be able to see your phone number. The published default in Telegram's own help is that your number is visible only to people you have added to your address book as contacts, and the same page states the exception that matters: people will always see your number if they already know it and saved it in their address book. The setting governs the platform's disclosure, not other people's memory.

Discovery is a different key

The second key controls whether people can add you to their contact list by your phone number. This is a separate switch with a separate list, and it is the one that decides whether someone holding a list of numbers can turn those numbers into accounts. Hiding the number does not close this door, and closing this door does not hide the number.

What that means for a number you paid for

If an account matters to you, both keys need an answer, and the second one usually needs the stricter answer. This is doubly true for accounts built on real numbers you intend to keep for a long time, which is the whole point of our approach to buying established Telegram accounts rather than minting throwaways.

Last Seen, and the Rule That Cuts Both Ways

Last seen is the only privacy key in the set that charges you for using it, and the charge is paid in visibility rather than money.

The reciprocity clause, stated by the platform

The documentation is unusually direct here. If you decide to hide your exact last online timestamp from someone, and you do not have a Premium subscription, you will not be able to see the exact last online timestamp of those users either, even if they do share it with you. Hiding is not free. Without a subscription it is a trade, and the trade is symmetric.

The flag that tells you it happened

When those people do share their status with you but you cannot see it for the reason above, the status you receive carries a marker indicating the restriction is caused by your own setting. Recently, last week and last month statuses all carry it. So the vague status you see on someone's profile may be describing your configuration rather than theirs, which is worth remembering before concluding that a contact is hiding from you.

Online is not fully controllable

Telegram's help page lists the exceptions plainly. Regardless of your last seen setting, people will see you online for roughly thirty seconds if you send them a message in a one to one chat or in a group you share, if you read a message they sent you in a one to one chat, or if your client broadcasts a typing indicator into a chat you share. If you do none of those things, they never see you online. We covered the wider behaviour of this field in our piece on what last seen really reports.

Read Receipts Ride on the Last Seen Switch

The second documented exception to the one switch, one effect rule is read receipts, and it is easy to miss because it lives in the global settings rather than next to the key it modifies.

One global flag borrows another key's audience

There is a global flag that makes the last seen key also govern the ability to look up exactly when a message was read. With it enabled, anyone who cannot see your exact last online date gets an explicit privacy error when their client asks for the read date of a message they sent you. You do not configure a separate audience for read receipts. You inherit the one you already set for last seen.

The other side can detect the state

Accounts that enable this expose a flag in their full profile record saying read dates are private. This is deliberate, so that a client can present the situation as a setting rather than as a failure. It also means the state is discoverable rather than secret, which is the pattern across this entire subsystem: the platform hides the value and publishes the fact that a value is hidden.

Forwarded Messages and the Name That Disappears

The forwarding key is small, widely misunderstood, and produces one of the most visible artefacts on the platform.

What it controls, exactly

The description is whether messages forwarded from you will be anonymous. It does not prevent forwarding. Anyone can still forward what you wrote. What changes is the attribution: instead of a clickable link back to your account, the forwarded copy carries your name as plain text with no link, so a reader can see who said it but cannot reach you from there.

Restricting forwarding is a different feature entirely

Preventing forwarding at all is a content restriction applied to a chat or channel, not a personal privacy key, and it produces its own error when someone tries. If your question is about copying content out of a locked channel rather than about attribution, that is a separate mechanism and we treated it separately in our guide to channels with content protection turned on.

Profile Photo, Bio and Birthday

Three keys that look cosmetic and are not, because together they are most of what a stranger can learn about an account before writing to it.

The photo key and the fallback nobody mentions

The photo key controls whether people will be able to see your profile picture. The part that is not on the settings screen is that the profile record supports a fallback photo, a public placeholder shown to people who are outside your audience for the real one, alongside a personal photo that only certain people see. So closing this switch does not necessarily produce an empty circle; it can produce a different picture, which is a meaningfully better posture for a business account than a grey placeholder that reads as abandoned.

The bio key

One line: whether people can see your bio. This is the field most often used to carry a link or a contact route, so an account that has closed it to non contacts has quietly closed its own funnel. If you are using the bio as a call to action, that switch needs to stay open even when the instinct is to close everything.

Birthday, gifts and the profile rating

Birthday has its own key. So does whether gifts you receive are automatically displayed on your profile, which matters more than it sounds now that Telegram's help page confirms profiles carry a numerical rating derived from the total volume of successful Star transactions, rising with gifts and paid messages and falling with refunds. That is a spending signal on public display, not a trust score, and it is worth deciding deliberately whether your account shows it.

Voice Messages and Calls

Two of the fourteen keys are gated behind a subscription, and one of them is the only key in the set that blocks an entire message type.

Voice messages are a Premium only switch

The key controls whether people can send you voice messages or round videos, and the documentation marks it Premium users only. Without a subscription you cannot close it. When it is closed, the sender's client is told the recipient forbids voice messages through a flag on your profile record rather than by letting them record and fail.

Calls are two keys, not one

Whether you accept calls at all is one key. Whether peer to peer connection is allowed during a call is a second, and it is a network setting wearing a privacy label: with peer to peer disallowed the call is relayed rather than direct, which hides your address from the other party at the cost of some latency. People who close the first key by mistake usually meant to close the second.

The Global Switches That Are Not Per Person

Alongside the fourteen keys there is a separate set of settings that apply to everyone at once. They are read and written through their own operations, and they are the ones that change how your inbox behaves rather than who can see what.

Archive and mute new chats from non contacts

One flag archives and mutes new chats started by people who are not in your contacts. Messages still arrive. They simply arrive out of sight. This is the single most useful setting for an account that gets unsolicited contact, and also the single most common reason a business account appears to have missed a real customer.

Two flags that decide what stays in the archive

A second flag keeps unmuted chats in the archive when they get a new message instead of pulling them back out. A third does the same for chats that are always included or pinned in a folder, and it is ignored if the second one is set. These decide whether the archive is a filing cabinet or a waiting room.

The gift button and the gift blocklist

Two further flags control whether a gift button appears in the message field in private chats, and which categories of gift you refuse to receive at all. Neither is a privacy setting in the ordinary sense, but both live in the same record and both are visible to the other side, which is the pattern to expect here.

Requiring Premium From Strangers

This is the strongest wall the platform offers against unsolicited contact, and it is worth understanding precisely because it produces a specific, readable failure on the sender's side.

What it does

Enabling it means only accounts that hold a Premium subscription, are already in your contact list, or already have an existing private chat with you can write to you privately. Everyone else is refused. The refusal is an explicit permission error, not a message that vanishes, so the sender knows.

Three conditions, checked separately

The documentation is careful about this, and it matters if you are reasoning about a list of accounts rather than one. The flag showing that a user requires Premium is set even for people who can still write to them, because the other two conditions are checked independently. A mutual contact sees the flag and can still send. Reading the flag alone and concluding a person is unreachable is a mistake the protocol explicitly warns against, and there is a dedicated operation that answers the real question for a batch of accounts in one call.

Who is allowed to switch it on

Ordinarily only Premium accounts can enable it. There is a client configuration value that, when true, lets non Premium accounts enable it too. When that value is false, a non Premium account attempting to set it gets an account level error. So whether this wall is even available to you is a server side decision that can change without any announcement.

Charging Stars for a First Message

The newest layer is not a wall but a toll, and it changes the economics of unsolicited contact rather than the permissions.

How the toll works

A global setting specifies a number of Telegram Stars that anyone wishing to message you must pay. It can be enabled only when a server side availability flag is true and the account holds a Premium subscription. The ceiling on the amount is published as a configuration value rather than a fixed number in the documentation, which means it can move.

Who is exempt, and who is not

After the toll is on, the accounts that do not pay are the ones already in your contact list and the ones you have an existing conversation with. There is also a dedicated privacy key for exactly this, controlling who can message you without paying, so the exemption list is configurable rather than fixed. The same mechanism exists for supergroups and for direct messages to channels.

The part that is a business decision

The amount you receive is the amount sent multiplied by a commission value expressed in parts per thousand, and there is an operation for retrieving the total non refunded Stars people have spent messaging you. In other words the platform treats this as revenue with a take rate, and if you switch it on for an account that customers use to reach you, you have put a price on your own inbox. For accounts whose entire job is to receive first contact, that is usually the wrong trade.

What the Sender Actually Sees

The most useful diagnostic property of this whole system is that it does not fail quietly. Each wall has its own error, and the error names the wall.

The privacy errors

An account requiring Premium from strangers returns an error stating a Premium subscription is needed to message that user. An account charging Stars returns an error saying the peer only accepts paid messages. These are distinct codes with distinct meanings, and a client that understands them can tell a user exactly what happened instead of showing a generic failure.

The blocking errors

Being blocked by the other person and having blocked them yourself are two different errors, which is genuinely useful because they answer two different questions. There is a third for chats you simply cannot write in, and a fourth for accounts that have been deleted.

Why silence is almost never the answer

The recurring belief that a blocked message sits somewhere unseen while the sender is told it was delivered is not how this works. The platform refuses at the point of sending and says why. If you are running any kind of outreach and your reporting shows delivered, that word means the platform accepted it, and the errors above are the reason a well built sender can separate a privacy refusal from a rate limit. Our walkthrough of sending at volume covers how those two look different in practice, and our campaign tool records the refusal reason per recipient rather than collapsing everything into failed.

Blocking Is a Different Mechanism

Blocking sits next to privacy in the interface and works nothing like it, which is why advice that treats them as interchangeable is unreliable.

Privacy is a rule, blocking is a relationship

A privacy key is a rule evaluated against an audience. Blocking is a stored state between two accounts, and it is absolute in both directions rather than scoped to one capability. It also appears as a flag on the full profile record, so a client can show the state rather than discovering it at send time.

The practical difference shows up when you try to undo something. Loosening a privacy key changes the rule for everyone it covers at once and takes effect immediately across every device signed into the account. Unblocking is a single relationship being restored, and it does not restore anything else: a person you unblock is still subject to whatever your fourteen keys say about them, which is why unblocking someone and then finding they still cannot add you to a group is not a glitch. Two systems, two states, and only one of them was ever the reason.

Blocking as the last resort for online status

Telegram's own help page notes that another way to stop a specific person from ever seeing you online is to block them, which is a revealing admission: the platform is telling you that the granular setting has known leaks and the blunt tool does not. If a single person is the actual problem, the blunt tool is the correct one.

The Settings People Forget Until the Account Is Gone

Three things sit in this area that are not about who can see you at all, and each of them has ended accounts.

Inactivity deletes the account

Telegram's help page states it directly: if you stop using Telegram and do not come online for at least eighteen months, the account is deleted along with all messages, media, contacts and everything else stored in the cloud, and the exact period can be changed in Settings. Anyone holding accounts they do not log into every day should treat that as a countdown they are responsible for resetting, not as a distant technicality.

Sessions are the real security boundary

The list of devices signed into an account is the thing that actually controls access, and it is the first place to look when anything strange happens. It is also the thing that should be checked and cleared the moment control of an account changes hands. Running several accounts multiplies this problem, which is the reason we built a single panel for it rather than logging in and out; the details are in our note on running more than one account without losing them and in the multi account panel itself.

A restricted account is a separate problem

None of these settings will fix an account that has been restricted for unsolicited messaging. That is a different system with a different appeal path, and we wrote the whole route up in how to lift a spam restriction. Treating a restriction as a privacy problem wastes the appeal window.

Three Configurations That Work

Configuration advice is only useful if it starts from what the account is for. These three cover most real cases.

An account that wants to be left alone

Group invites and being added by phone number to contacts only. Phone number visible to nobody. Last seen to nobody, accepting the reciprocity cost. Archive and mute new chats from non contacts turned on, so unsolicited contact still arrives but out of the way. Voice messages closed if a subscription is available. This posture is quiet and it does cost you the ability to read other people's exact last seen.

An account whose job is to be contacted

The reverse on the fields that carry your funnel. Bio open to everybody, profile photo open, last seen left alone so the account looks live, group invites narrowed to contacts because being pulled into random groups is noise. Do not enable the Premium requirement and do not enable paid messages, because both of them charge admission to your own front door. If unsolicited contact is heavy, archive and mute is the right lever rather than a wall, and a first response can be automated with our bot panel without closing anything.

Accounts you are preparing for work

Set the two phone number keys before anything else, set the inactivity period deliberately, and leave the bio and photo open because an empty profile is itself a signal. Then look at the chat bar the platform shows above a first conversation. That bar is not decoration: before a single message is exchanged it publishes the month the account was registered, the country of the number behind it, and the dates the name and the photo were last changed. A profile whose name and photo both changed in the same recent week reads exactly like what it is, and no privacy setting hides those two dates.

The practical order, then, is to finish the profile first and change nothing afterwards, rather than configuring an account and then dressing it. It is the one part of this whole subject where the timing of a change matters more than the change itself. We covered that surface, and how it is used to judge accounts, in our piece on checking an account before you pay, and the wider hygiene in avoiding restrictions during outreach.

Frequently Asked Questions

Why can some people still add me to groups when the setting is closed

Because the setting stops other accounts from adding you, and an invite link is you joining rather than being added. Anyone can send you a link and the link works regardless of the switch. If being added is the problem, the switch is the fix; if links are the problem, nothing in this section addresses it.

Does hiding my last seen stop me from seeing other people's

Yes, unless you have a Premium subscription. The documentation states that hiding your exact last online timestamp from a set of people removes your ability to see theirs, even when those people do share it with you, and the status you receive carries a marker showing your own setting caused it.

I hid my phone number, so why did someone still find me by it

Because visibility and discovery are two different keys. One controls whether the number appears on your profile, the other controls whether people can add you to their contacts using it. Closing the first leaves the second open, and Telegram's own help adds that anyone who already saved your number will always see it.

What does the other person see when a privacy setting blocks a message

An error, not silence. Requiring Premium from strangers returns a specific error naming the subscription requirement. Charging Stars returns a different one saying the peer only accepts paid messages. Being blocked returns another again, distinct from having blocked them yourself.

Can I turn on the Premium requirement without a subscription

Usually no. Ordinarily only a Premium account can enable it, and a non Premium account trying to set it receives an account level error. There is a server side configuration value that, when true, lets any account enable it, so availability can change without notice.

Do read receipts have their own setting

Not their own audience. A global flag makes the last seen key also govern who can look up exactly when a message was read, so the audience is inherited. People outside it receive an explicit privacy error when their client asks for a read date.

Will my account really be deleted if I stop using it

Yes. Telegram's help page states that not coming online for at least eighteen months deletes the account along with all messages, media and contacts, and that the exact period can be changed in Settings. It is a setting, not a rumour.

Does closing my profile photo leave an empty circle

Not necessarily. The profile record supports a fallback photo shown to people outside the audience for the real one, so the switch can produce a different picture rather than nothing. For a business account that is usually the better configuration.

Which single setting stops the most unwanted contact

Archiving and muting new chats from non contacts, because it costs nothing. Messages still arrive, so you never lose a real enquiry, and they arrive out of your main list. The walls that actually refuse contact also refuse customers, which is a different trade and should be made deliberately.

See Which Settings Are Costing You Reach

If you run more than one account, the privacy keys on each of them decide who you can reach and who can reach you. Open a demo and read them from one panel instead of one phone.

Try Free Demo