The Third Party in the Room
Why talking to an AI agent through a cloud messenger puts a third party in the room, and what changes when you hold the key instead. Measured against Telegram's own disclosure figures and the Marmot protocol.
Why talking to an AI agent through a cloud messenger puts a third party in the room, and what changes when you hold the key instead. Measured against Telegram's own disclosure figures and the Marmot protocol.


Every message you send to an AI agent through Telegram is read by three parties: you, the model, and Telegram. That third one is not a configuration mistake, not a setting you forgot to change. It is how the product is built, and no amount of care on your side will remove it.
Telegram does have end-to-end encryption. It is called Secret Chat, and it does what it claims: a Diffie-Hellman handshake between two devices, keys that never reach the server, forward secrecy on the wire. It also has three properties that make it useless for talking to an agent.
Secret Chat works only between two people. It lives on a single device, so opening the app elsewhere gives you a fresh chat with a new key and none of the history. Most importantly, no bot can be in one. Telegram's architecture keeps bots out of Secret Chats, because a bot needs readable text in order to produce a reply.
Everything else on Telegram runs on server-side encryption: direct messages, groups, channels, and every conversation anyone has ever had with a bot. Encrypted on the wire, decrypted on Telegram's servers, stored there so your history follows you between devices. That convenience and that exposure are the same feature, and Telegram holds the keys.
Add an agent to a Telegram group and you have added a bot. The conversation is now decrypted twice, once by Telegram and again by whatever machine runs the agent.

Telegram publishes how often it hands data to authorities. In the first quarter of 2024 it disclosed IP addresses or phone numbers to France in four cases (Le Monde/AFP, January 2025, citing figures the platform published itself). In the second quarter, six. By the fourth quarter of that year the count had reached 673, and more than 2,000 users were affected by French requests over the twelve months, over half of them in the final three months.
August 2024 is what changed. French police arrested founder Pavel Durov on the tarmac at Le Bourget, and within weeks Telegram rewrote its terms of service. It now hands over the IP addresses and phone numbers of users who violate its rules in response to valid legal requests, and publishes quarterly transparency reports (CNN, September 2024).
The point here is arithmetic rather than blame. A service that holds your messages in readable form is a service that can be asked for them, by a court, by a government, by whoever compromises it next. Privacy that depends on an operator's continued goodwill is not a property of the system. It is a promise, and promises get revised when the pressure arrives.


Marmot, the protocol behind the White Noise app, takes the other road. Identity is a Nostr keypair rather than a phone number. Messages are protected with MLS, the Messaging Layer Security group key agreement standard built at the IETF as RFC 9420, so the group shares a key that rotates as membership changes. Group messages are published under ephemeral keypairs instead of your identity key, which means a relay operator cannot reconstruct a social graph from the traffic it carries. Relays store and forward ciphertext they cannot read.
For agents, the relevant part is that the integration is public and you run it yourself. The connector ships for Hermes, OpenClaw, Codex, Claude Code, OpenCode and Pi. You start it next to your agent, give the agent a White Noise identity, and invite it into a conversation. Nothing in that sentence requires trusting a platform with your messages.
Cypherpunks write code, wrote Eric Hughes in 1993. The practical test of that slogan is whether you can read the thing protecting you, run it on your own machine, and point it at a relay you choose. Here you can do all three.
The strongest case against my own argument is ergonomic, which is exactly why it wins. Telegram works on every device you own, at once, with one history. Adding an agent takes minutes and no key management. Nothing breaks when you switch phones.
White Noise in its current state will not sync a conversation to a second device. Linked-device support is still being built, and importing the same identity elsewhere does not carry the encryption state with it. Lose your identity key and nobody can recover it, because there is no support desk that can restore what was never theirs. That is the price of having no custodian, and anyone who tells you the trade is free has not yet lost a key.
There is a scale limit worth naming plainly as well. A ratcheted protocol like MLS is built for a handful of people discussing something sensitive, not for six hundred members with channels and moderators. If your group is a community, this is the wrong tool, and Concord or a relay-based group is the right one.

Connecting an agent through White Noise encrypts the trip between you and the connector. It does not turn a cloud model into a local one. The message leaves your machine again on its way to whatever answers it, and that provider reads the text.
White Noise states this in its own FAQ, and it is the most important sentence in this article: the privacy you gain sits at the transport layer, not at the model layer. Anyone selling you an encrypted chat with a cloud model has moved the leak rather than closed it.
I could not verify one thing that matters for anyone planning a switch, and it should be said out loud. There is no independent audit of the connector's own socket layer that I was able to find, and the White Noise clients have been reviewed at the protocol level rather than as shipping binaries. Read that as a gap in my research rather than as evidence of a flaw, and check it yourself before you move anything sensitive.
That is why the combination matters more than the app. On a stack that runs the model on its own hardware, the same message never leaves the house: the relay carries ciphertext it cannot read, the model executes locally, and the third party disappears from the room. The messenger was the part that leaked, and it leaked quietly, because nothing in the interface ever told you who else was listening.
If you have been talking to an agent through a bot on a cloud messenger, you have been treating a three-party conversation as a two-party one. The fix is not to trust a different company more, but to stop needing to trust one at all. Hold the key, run the connector, keep the model where it can stay local. Then the room has two chairs in it again.