← back to blog

What a telegram data export actually contains

People ask for an “export” when they mean something else

We run hosting and proxy infrastructure for Telegram accounts, and the request that comes up most often is some version of “can you export my account so I have a backup.” Almost every time, what the person actually wants is different from what Telegram’s export tool gives them. So it’s worth going through, plainly, what that button in the settings menu actually produces, because the gap between expectation and reality is where people get into trouble.

Telegram’s built-in export lives in Settings, under Advanced, as “Export Telegram data.” It’s a client-side feature: you run it from the Desktop app, on a device that’s already logged into your account, and it pulls a copy of what’s synced to that account’s cloud chats. That last part matters more than it sounds like it should.

What’s actually inside the file

When you run the export, you pick what to include. The options are broadly:

  • Personal chats and group chats, as text
  • Your contact list
  • Basic account info (name, username, bio, phone number as registered)
  • Profile pictures
  • Media: photos, videos, voice messages, video messages, files, and GIFs, each with its own toggle
  • Stickers you’ve used or saved

You can also set a date range and a per-file size cap, which matters if you’re exporting an account that’s been active for years and has gigabytes of media sitting in it.

The output comes as either HTML or JSON. HTML gives you a set of linked pages you can open in a browser and click through like a static archive of the app. JSON gives you the same data in a machine-readable structure, which is what you’d want if you’re writing a script to parse it rather than reading it by eye. Media files sit in their own folders alongside either format, referenced by path.

That’s the whole thing. It’s a snapshot of content, not a copy of the account.

What never makes it into the file

This is the part that trips people up. The export does not include:

  • Your two-factor authentication password
  • Any session tokens or the auth key tied to your logged-in devices
  • The ability to log in as the account on a new device
  • Your list of active sessions
  • Anything from secret chats

That last point deserves its own explanation, because it’s the one that surprises people who assume an export is a full backup. Secret chats in Telegram aren’t stored on Telegram’s servers at all. They’re end-to-end encrypted and tied to the specific pair of devices that started the conversation. Since the export tool pulls from your cloud data, and secret chats were never in the cloud to begin with, they don’t show up in the file no matter what you check or uncheck in the export options.

So if someone hands you an export and says “here’s my whole account,” what you actually have is the cloud-chat history, your contacts, and whatever media you selected. You do not have a way to log in as that account, and you do not have anything from any secret chat that account was part of.

Export and session are two different problems

We draw a hard line between these two things because they get confused constantly, and the consequences of mixing them up are not symmetrical.

A data export is a copy of content. If it leaks, someone can read your old messages and see your media. That’s a real privacy problem, and depending on what’s in the chats, it can be a serious one. But it doesn’t let anyone act as you. They can’t send messages from your account, they can’t change your settings, and they can’t use it to pass Telegram’s login flow.

A session, on the other hand, whether that’s a tdata folder from Telegram Desktop, a session string used by an API client, or an authorized device listed under Settings > Devices, is a live credential. Anyone with that session can act as the account, in real time, without needing your phone number, your 2FA password, or an SMS code. This is why, when we set up hosted instances for people, the session file gets the same handling as an API key: encrypted at rest, never emailed, never dropped into a shared folder next to other project files.

The practical rule we give people: treat an export like a document, and treat a session like a password. If your export leaks, you have a disclosure problem. If your session leaks, you have an account-takeover problem, and it happens faster than most people expect, because there’s no login prompt standing in the way.

Where the phone number and account info actually sit

The export includes the phone number as registered on the account, plus name, username, and bio, because those are part of your cloud profile, the same way they’d show up to anyone who opens a chat with you. It does not include anything about the SIM or number itself, like carrier details or the ability to receive future verification codes, because that lives with whoever controls the phone number, not with Telegram.

This is a distinction we deal with constantly on the hosting side, since a lot of the accounts we manage sit behind a proxy on infrastructure that has nothing to do with the phone that originally registered the number. The export reflects the account as Telegram’s servers know it. It says nothing about the network path the account is currently using, what IP it logs in from, or what proxy configuration is in front of it. If you’re trying to document your setup for your own records, the export is the wrong tool for that; it’s a chat archive, not an infrastructure log.

Why the date range and size limit matter more than they look

For accounts that have been running a while, especially ones used for groups or channels with a lot of media, the export can get large fast. The size limit per file exists so the export doesn’t hand you one unmanageable blob; it splits output into chunks at whatever threshold you set. If you’re archiving for compliance or just want a manageable local copy, setting a reasonable per-file cap before you start saves you from ending up with a single file that’s painful to open or move around.

The date range works the same way in principle. If you only need the last six months of a chat for a specific reason, restricting the range means less data leaves the account and less data sits on whatever drive you’re exporting to. Given that none of this data includes login credentials but all of it includes real message content, narrower is usually better unless you have a specific reason to pull everything.

What we actually tell people

When someone managing a hosted account with us asks for a backup, we ask what they’re trying to protect against. If it’s “I want a record of what was said in these chats,” the built-in export is the right tool, and it’s straightforward to run. If it’s “I want to be able to get back into this account if something goes wrong,” that’s a session and access question, and it needs to be handled with the same care as any other credential, not bundled in with a chat archive. Knowing which one you actually need before you start is most of the job.

If you’re setting up managed hosting or proxy configuration for a Telegram account and want the access side handled properly, take a look at what we run.

Get new guides and videos first — join the Telegram channel.

need infra for this today?