# TG Drive Official Documentation **Version:** 3.5.0 Stable Release (Build 2700) **URL:** [https://tgdriveo.pages.dev/docs](https://tgdriveo.pages.dev/docs) **Live Application:** [https://tgdriveo.pages.dev/](https://tgdriveo.pages.dev/) **Android APK:** [Download Native APK](https://github.com/Saini920/DevKit-Manager-v4.0.7/releases/download/tg-drive-2.0.0/TG_Drive_2.0.0.apk) --- ## Table of Contents 1. [About TG Drive](#1-about-tg-drive) 2. [What's New in Version 3.5.0](#2-whats-new-in-version-350) 3. [Premium Features](#3-premium-features) 4. [Android Native App](#4-android-native-app) 5. [System Policies & Limits](#5-system-policies--limits) 6. [Setup Guide](#6-setup-guide) 7. [Storage System: Smart Hybrid Architecture](#7-storage-system-smart-hybrid-architecture) 8. [How It Works: Virtual File System (VFS)](#8-how-it-works-virtual-file-system-vfs) 9. [Storage Logic & Quota Breakdown](#9-storage-logic--quota-breakdown) 10. [Transfers Manager & Concurrency Queue](#10-transfers-manager--concurrency-queue) 11. [Real-Time Cloud Synchronization](#11-real-time-cloud-synchronization) 12. [Frequently Asked Questions (FAQ)](#12-frequently-asked-questions-faq) 13. [Secure Vault & Zero-Knowledge E2EE Architecture](#13-secure-vault--zero-knowledge-e2ee-architecture) 14. [Desktop Experience & Keyboard Shortcuts](#14-desktop-experience--keyboard-shortcuts) 15. [Privacy, Stealth Shield & Security](#15-privacy-stealth-shield--security) --- ## 1. About TG Drive TG Drive is a premium cloud storage interface designed to transform your Telegram experience into a professional file management system. It utilizes your personal Cloud Storage space to host and organize files of any type. By connecting directly to the official Telegram servers, the app ensures that your data is always available across all your devices without the typical subscription costs associated with traditional cloud providers. - **Direct MTProto 2.0:** All communication occurs directly between your client (browser or native app) and Telegram's data centers via GramJS MTProto 2.0. - **Zero Third-Party Storage:** No user files, tokens, or encryption keys are ever transmitted to or stored on TG Drive servers. - **Client-Side Virtual File System:** Folder hierarchies, tags, and file metadata are stored right inside your private Telegram Saved Messages. --- ## 2. What's New in Version 3.5.0 Version 3.5.0 (Build 2700) is the latest stable release featuring major cryptographic enhancements, disaster recovery protocols, and performance upgrades: - **Zero-Knowledge End-to-End Vault (E2EE):** Military-grade client-side encryption using AES-GCM 256-bit and memory-hard Argon2id key derivation (64 MB, 3 passes). Credentials and files are encrypted before leaving your browser. - **Dual-Channel OTP Password Recovery:** User-selectable choice between personal Telegram Saved Messages (direct MTProto, 0% bot ban risk) and Telegram Bot for 6-digit recovery codes with session-preserving PIN reset. - **Automatic Multi-Device Cloud Sync:** Zero-touch background synchronization of cryptographic salt and canary tokens via Telegram Saved Messages (`#TG_DRIVE_VAULT_CONFIG#`) with real-time active status indicators across all devices. - **Android Native Biometric Unlock:** Native fingerprint and facial recognition integrated directly with the Android Hardware Keystore for lightning-fast, secure vault access on mobile. - **Responsive Modular Profile Interface:** Streamlined preferences, modular vault controls, and stealth blur protection. - **Background Legacy File Migration:** One-tap background engine to scan and encrypt older unencrypted files into the AES-256 vault, with optional Wi-Fi only restriction to preserve mobile data. - **Hardened Multi-Salt Session Recovery:** Dual-tier encrypted session storage in IndexedDB with automated fallback resolution across legacy salt structures, preventing accidental logouts. - **Smart Pause & Resume & SW Streaming:** High-speed MTProto streaming pipeline with chunk-level persistence, enabling pause, resume, and direct streaming to the browser's native download manager. --- ## 3. Premium Features - **Multipart Architecture:** Upload and download massive files efficiently by splitting them into safe, high-speed MTProto chunks (512 KB slices). - **Pause & Resume:** Interrupt and continue downloads seamlessly with chunk-level persistence, saving data and time on large transfers. - **Deep Nesting:** Unlimited folder depth with lightning-fast smart indexing stored directly in your Telegram cloud. - **Local Persistence:** Utilizes IndexedDB (`idb-keyval`) for high-speed local caching and instant app responsiveness. - **Zero Server Storage:** Pure peer-to-peer communication via GramJS MTProto. No middleman servers. - **Bank-Grade Privacy:** Leverages Telegram's native encryption and your personal API credentials for absolute security. --- ## 4. Android Native App TG Drive is available as a native Android application built with Capacitor: - **Direct APK Download:** `https://github.com/Saini920/DevKit-Manager-v4.0.7/releases/download/tg-drive-2.0.0/TG_Drive_2.0.0.apk` - **Native Performance:** Buttery-smooth transitions, zero browser address bar interference. - **Background Transfers:** Uploads and downloads continue reliably when minimized. - **Hardware Biometric Keystore:** Secure single-touch fingerprint and face authentication. - **Push Alerts:** Real-time native alerts for transfer completions and system events. - **Privacy Shield:** Independent stealth blur toggles for username, phone number, and thumbnails. --- ## 5. System Policies & Limits To ensure maximum stability and real-time performance across Telegram's MTProto API, TG Drive enforces clear system limits: - **Upload File Size Limit:** Strict 2.0 GB maximum file size policy per file (aligned with standard Telegram file size ceilings). - **Batch Uploading Limit:** Up to 100 files can be selected and queued at once in a single batch. - **Concurrent Download Limit:** Maximum of 3 simultaneous downloads. Additional files wait in a smart priority queue and start automatically as active transfers finish, preventing Telegram API `FLOOD_WAIT` rate limiting and browser memory exhaustion. --- ## 6. Setup Guide Connecting your Telegram account to TG Drive takes less than 2 minutes: 1. **Obtain API Credentials:** Visit [https://my.telegram.org](https://my.telegram.org), log in with your phone number, navigate to "API development tools", and create an application to obtain your `API ID` and `API Hash`. 2. **Create a Bot Token:** Message `@BotFather` on Telegram, create a new bot using `/newbot`, and copy the provided `Bot Token`. (Used for profile photos and optional OTP recovery). 3. **Authorize Account:** Open TG Drive, enter your phone number, API ID, API Hash, and Bot Token. Enter the official Telegram verification code sent to your Telegram app. 4. **Start Organizing:** Your Telegram "Saved Messages" chat is now your unlimited cloud drive! --- ## 7. Storage System: Smart Hybrid Architecture TG Drive uses a Smart Hybrid Storage engine optimizing for speed, privacy, and file size: - **MTProto Direct:** - Files up to 2.0 GB. - High E2E Encryption (Direct P2P GramJS connection). - Encrypted chunks sent straight to your Telegram Saved Messages chat. - **Bot API Gateway:** - Fast metadata indexing and profile photo caching. - Fallback channel for small files (< 20 MB). - Secondary notification channel for OTP recovery codes. --- ## 8. How It Works: Virtual File System (VFS) TG Drive creates a Virtual File System (VFS) on top of Telegram Saved Messages by embedding structured JSON metadata tags: ```json // VFS Message Tagging Structure { "prefix": "#TG_DRIVE_FILE#", "meta": { "fileName": "Project_Archive.zip", "parentId": "root_vault", "totalSize": 2147483648, "isMultipart": true, "parts": 4, "encrypted": true } } ``` When you request a file, TG Drive fetches the corresponding MTProto message chunks, verifies cryptographic integrity, and streams the decrypted bytes directly to disk via a Service Worker. --- ## 9. Storage Logic & Quota Breakdown - **9999 TB Quota:** Visual representation reflecting Telegram's virtually unlimited Saved Messages capacity. - **Categorization Donut Chart:** - **Images:** JPG, PNG, GIF, WEBP, SVG, RAW. - **Videos:** MP4, MKV, MOV, AVI, WEBM. - **Apps & Zips:** ZIP, RAR, 7Z, TAR, GZ, APK, EXE, DMG. - **Documents:** PDF, DOCX, XLSX, PPTX, TXT, CSV, EPUB. - **Others:** Audio, code files, unknown formats. - **Critical Notice:** Never manually delete `#TG_DRIVE_FILE#` or `#TG_DRIVE_VAULT_CONFIG#` messages in your official Telegram "Saved Messages" chat, as this breaks cloud indexing. --- ## 10. Transfers Manager & Concurrency Queue - **Aggregate Progress Bar:** Sleek floating progress pill at the bottom of the viewport showing aggregate percentage, total transferred bytes, and active transfer count. - **Granular Transfers View:** Tabbed panels for "Uploaded" and "Downloaded" items with real-time speed (MB/s), ETA calculation, chunk-level progress, and pause/resume/cancel controls. - **100-File Batch Upload:** Queue entire folders or up to 100 individual files at once with automated chunk scheduling. - **3 Concurrent Transfers:** Strict 3-file concurrency queue prevents browser out-of-memory errors and Telegram network throttling. --- ## 11. Real-Time Cloud Synchronization - **MTProto Update Listeners:** Instant synchronization across all devices. Adding, renaming, moving, or deleting files triggers real-time indexing. - **Auto-Recovery:** TG Drive is completely stateless. Clearing your browser cache or switching devices requires only a login—all folders, files, and tags auto-recover within seconds. - **Favorites & Trash:** Full lifecycle virtual containers for starred files and soft-deleted items with instant restore capability (`Alt + R`). --- ## 12. Frequently Asked Questions (FAQ) ### Is TG Drive safe? Yes. TG Drive operates entirely client-side using official MTProto 2.0 protocols. Your API ID, API Hash, phone session strings, and Master PIN never touch any external server. ### What is the maximum file size? A strict limit of 2.0 GB per file is enforced for all uploads, adhering to Telegram's standard document size limit. ### Why do I need a Bot Token? The Bot Token acts as a lightweight metadata gateway for profile photos, fast thumbnail indexing, and optional OTP delivery without burdening your personal MTProto session. ### How does Master PIN / Password Recovery work? If you forget your Master PIN: 1. Tap **Forgot Password** on the lock screen. 2. Select your delivery channel: - **Saved Messages (Recommended):** Directly to your Telegram Saved Messages via MTProto with **0% risk of bot bans**. - **Telegram Bot:** Delivered via your configured Bot Token. 3. Enter the 6-digit OTP code to verify and reset your PIN while **preserving your active Telegram login session**. ### How does Multi-Device Sync work? Multi-Device Sync is 100% automated and zero-touch. When you configure the Vault, TG Drive securely anchors your cryptographic salt and verification canary into a tagged message (`#TG_DRIVE_VAULT_CONFIG#`) in your Telegram Saved Messages. Secondary devices discover this config automatically upon login—entering your Master PIN unlocks the vault without manual import/export. ### What is the concurrent download and batch upload limit? Up to **100 files per upload batch** and **3 simultaneous concurrent downloads** to prevent Telegram `FLOOD_WAIT` rate limits. ### What is Privacy & Stealth Shield? Stealth Shield provides independent client-side frosted glass blur toggles for: - Telegram Username (`@username`) - Telegram Phone Number - Media Gallery & File Manager Thumbnails Hovering or tapping temporarily reveals blurred items. ### Does Privacy Shield affect file quality or download speed? No. Privacy Shield is a cosmetic CSS visual filter. Uploads, downloads, and stored files remain 100% full-resolution and uncompressed. ### How do Desktop Right-Click Menus and Drag-and-Drop work? Right-clicking any file card opens a desktop context menu (Download, Star, Rename, Info, Trash). Right-clicking blank space opens folder actions (Upload, New Folder, Select 100, Refresh). Dragging files into the window activates a frosted glass drop zone for instant batch uploading. ### How do I open the Keyboard Shortcuts Cheat Sheet? Press `?` (or `Shift + /`) anywhere in the application to open the interactive, searchable Keyboard Shortcuts modal. ### Why does TG Drive ask for my Old PIN immediately after logging out and re-logging in instead of prompting to create a New PIN? When you log out from TG Drive and subsequently log back in to the same Telegram account, the application immediately prompts for your existing (old) Master PIN rather than allowing a new PIN to be created. This happens due to TG Drive's **decentralized zero-knowledge cryptographic architecture**: 1. **Decentralized Cloud State Anchor (`#TG_DRIVE_VAULT_CONFIG#`):** TG Drive does not store your account or vault settings in an external centralized database. Instead, your vault's public KDF salt, canary verification token, and device slots are anchored directly in your personal Telegram **Saved Messages** under the tagged message `#TG_DRIVE_VAULT_CONFIG#`. 2. **Logout Purges Local Storage, NOT Your Cloud Data:** When you click Logout, TG Drive performs a local 8-tier cache wipe (IndexedDB, Dexie VFS DB, browser cache, and memory keys). It explicitly terminates that single MTProto session. However, TG Drive does **NOT** delete your Telegram account, your uploaded files, or the `#TG_DRIVE_VAULT_CONFIG#` message in your Telegram Saved Messages. 3. **Preventing Catastrophic Data Loss (Key Continuity):** All your previously uploaded files were encrypted with a 256-bit AES-GCM Master Key derived from your **Old PIN + Cloud Salt**. If TG Drive allowed an unverified "New PIN" upon re-login, the key derivation function would generate a completely different cryptographic key. With that new key, **all your previously uploaded photos, videos, and documents would become permanently unreadable and corrupted**! 4. **Instant Vault Discovery Upon Re-Login:** When you log back into the same Telegram account, TG Drive scans your Saved Messages, instantly discovers `#TG_DRIVE_VAULT_CONFIG#`, and recognizes that an existing vault already protects your files. It therefore prompts you for your **Old Master PIN** so it can derive the correct master key and unlock your existing data. 5. **What If You Forgot Your Old PIN?** If you no longer remember your Old PIN: - On the PIN Lock screen, click **"Forgot PIN / Recover Vault"**. - Enter your **12-Word BIP-39 Recovery Phrase**. - Enter a new Master PIN (4-8 digits). - TG Drive uses the 12-word root seed to re-derive the master file key, updates the `#TG_DRIVE_VAULT_CONFIG#` anchor in your Saved Messages with your new PIN verifier, and safely unlocks 100% of your existing encrypted files without losing any data. ### What is the difference between High E2E Encryption and Extreme E2E Encryption? - **High E2E Encryption (Standard E2EE):** Client-side AES-256-GCM envelope encryption using a per-device key derived from your Master PIN via memory-hard Argon2id (64 MB, 3 passes; PBKDF2 100,000-round fallback for legacy vaults). Offers flexible recovery options (12-word BIP-39 recovery phrase OR dual-channel 6-digit OTP via Saved Messages/Bot). Coexists seamlessly with standard features. Visualized by a **blue "Encrypted" badge with Lock icon**. - **Extreme E2E Encryption (Strict Zero-Knowledge Protocol):** Strict zero-knowledge mode with **100% client-side keys and zero escrow**. Eliminates all OTP-based cloud recovery channels. Turning on Extreme E2EE automatically disables High E2E Encryption mode to avoid conflicting transport metadata gateways. Requires a 2-notice confirmation ("Agree" → "Confirm") warning that if you lose your Master PIN and 12-word phrase, your files are mathematically unrecoverable. Visualized by a **purple "Extreme E2E" badge with Zap icon**. ### Do High E2E Encryption and Extreme E2E Encryption use the same 12-word recovery phrase? **Yes, absolutely.** Both High E2EE and Extreme E2EE derive from the exact same 12-word BIP-39 cryptographic root seed. The 12-word phrase acts as the root master seed capable of unlocking and recovering your files under both tiers. The difference lies in operational policy: Extreme E2EE disables secondary recovery escrows (like OTP resets) and enforces strict zero-escrow execution. ### How does Device Sharing work in High E2E Encryption across my phone and laptop? High E2E Encryption enables seamless, zero-touch device sharing across all your devices (Android phone, laptop, desktop browser, tablet): - **Decentralized Cloud Anchor:** When you enable High E2E Encryption, TG Drive stores your public salt and verification canary inside your Telegram Saved Messages under `#TG_DRIVE_VAULT_CONFIG#`. No private keys or PINs are ever saved in Telegram or sent to any central server. - **Cross-Device Unlock:** When you log into TG Drive on your second device using your Telegram account, the app automatically detects the vault config and prompts for your Master PIN. - **Instant Decryption:** Entering your Master PIN on the new device derives the identical 256-bit AES-GCM master key client-side. All files uploaded from your phone immediately unlock, preview, and download on your laptop without requiring manual key exports or config transfers. - **Two-Way Sync:** Files uploaded and encrypted on your laptop are immediately accessible and decryptable on your phone. ### What are the critical warnings when using High E2E vs Extreme E2E Encryption? - **Extreme E2E Zero-Escrow Warning:** Extreme E2E disables all OTP resets and bot recovery channels. If you forget your Master PIN and lose your 12-word recovery phrase, **your files are permanently lost and mathematically impossible to decrypt**. No one (including TG Drive developers) can restore your data. - **Telegram Saved Messages Warning:** Never delete `#TG_DRIVE_FILE#` or `#TG_DRIVE_VAULT_CONFIG#` messages in your Telegram Saved Messages chat. Deleting them disrupts file metadata and vault synchronization. - **Re-Login Old PIN Warning:** When you log out and log back in to the same Telegram account, TG Drive will ask for your **Old PIN** to decrypt existing files. Setting an unlinked new PIN on login is blocked because it would derive a mismatched key and corrupt all existing files. - **Recovery Phrase Security:** Keep your 12-word recovery seed written down safely offline. Never share it with anyone. --- ## 13. Secure Vault & Zero-Knowledge E2EE Architecture ### Cryptographic Specifications | Parameter | Standard / Value | Security Benefit | | :--- | :--- | :--- | | **Cipher & Mode** | AES-256-GCM | Authenticated symmetric encryption with 128-bit authentication tags; prevents tampering and bit-flipping. | | **Key Derivation (KDF)** | Argon2id (PBKDF2 legacy fallback) | Memory-hard key derivation that starves GPU/ASIC cracking; older vaults keep PBKDF2 for byte-identical key continuity. | | **KDF Cost Parameters** | 64 MB memory / 3 passes | Every guess must allocate 64 MB of RAM, multiplying the cost of offline brute-force attacks. Scales down on low-RAM devices instead of weakening the algorithm. | | **Entropy Salt** | 128 bits (16 bytes CSPRNG) | Unique per vault; generated via `crypto.getRandomValues`. Prevents pre-computed rainbow tables. | | **Initialization Vector (IV)** | 96 bits (12 bytes unique/chunk) | Unique IV per encrypted chunk; absolute zero-IV-reuse guarantee. | | **Authentication Tag** | 128 bits (16 bytes) | Validates cryptographic authenticity before ciphertext is decrypted. | | **Canary Token** | `TG_DRIVE_VAULT_TEST` | Instant PIN validation without risking state corruption or partial decryption. | | **Cloud Sync Anchor** | Telegram Saved Messages | Zero external database; config stored as `#TG_DRIVE_VAULT_CONFIG#`. | | **Session Credentials at Rest** | AES-256-GCM (`VAULT_DATA_KEY`) | MTProto session string, API ID, API Hash, and Bot Token are stored encrypted; zero plaintext credentials in storage. | | **BIP-39 Mnemonic at Rest** | AES-256-GCM (`tg_vault_encrypted_recovery_phrase`) | 12-word phrase is encrypted at rest; decrypted strictly in volatile RAM when vault is unlocked; zero plaintext in localStorage/IDB. | | **Remote Session Revocation** | MTProto `Api.auth.LogOut` | Server-side authorization termination on Telegram core servers upon user logout prior to local cache purge. | | **Android Native Hardening** | `webContentsDebuggingEnabled: false`, Keystore Decoupled | Prevents USB/ADB DevTools memory inspection, blocks mixed-content injection, forbids ADB backup, and isolates release signing keys in CI/CD secrets. | ### The 11 Cryptographic Lifecycle Phases 1. **Phase 1: Entropy & Salt Generation:** Generates a 16-byte cryptographically secure random salt using `crypto.getRandomValues(new Uint8Array(16))`. 2. **Phase 2: Argon2id Key Derivation:** Derives a 256-bit AES-GCM `CryptoKey` from your Master PIN using memory-hard Argon2id (64 MB memory, 3 passes). Because every guess must allocate 64 MB of RAM, GPU/ASIC brute-force farms lose their parallelism advantage. Vaults created before this hardening have no `kdf` tag and keep deriving with PBKDF2-HMAC-SHA256 (100,000 rounds), so existing PINs and files work unchanged. 3. **Phase 3: Canary Verification Token:** Encrypts `TG_DRIVE_VAULT_TEST` with a unique 12-byte IV. The ciphertext hex is stored in vault config to reliably verify PIN correctness. 4. **Phase 4: Session Credentials Hardening:** MTProto session string, API credentials, and bot tokens are encrypted with AES-256-GCM and stored in IndexedDB under `tg_vault_data`. Plain-text credentials are actively purged from storage to prevent local exfiltration. 5. **Phase 5: Automatic Cloud Sync via Saved Messages:** Dispatches `#TG_DRIVE_VAULT_CONFIG#` to Telegram Saved Messages containing the salt, canary ciphertext, and timestamp. Master keys and PINs are NEVER sent. 6. **Phase 6: Zero-Touch Multi-Device Cross-Unlock:** Secondary devices discover `#TG_DRIVE_VAULT_CONFIG#` automatically. Entering your Master PIN derives the matching key and unlocks your vault with zero manual configuration. 7. **Phase 7: Filename Obfuscation & Envelope:** Files uploaded in High Security mode have their file names and MIME metadata encrypted into an envelope format (`enc__`). 8. **Phase 8: Streaming Chunk-Level Encryption & Decryption:** Files are split into 512 KB chunks, each encrypted with AES-GCM and its own tag. Downloads stream through the Service Worker directly to disk with RAM usage below 50 MB. 9. **Phase 9: Android Hardware Biometric Keystore & Native Container Hardening:** Interfaces with Android BiometricPrompt and Secure Hardware Keystore for fingerprint and facial authentication. The native Capacitor Android container enforces strict production hardening: Chrome DevTools remote debugging is disabled (`webContentsDebuggingEnabled: false`), mixed HTTP content is blocked (`allowMixedContent: false`, `MIXED_CONTENT_NEVER_ALLOW`), arbitrary top-level navigation is disabled (`allowNavigation: []`), ADB backups are forbidden (`android:allowBackup="false"`), and release signing keystores are decoupled from Git and secured via encrypted CI/CD secrets (`KEYSTORE_BASE64`). 10. **Phase 10: 12-Word BIP39 Root Seed & Disaster Recovery:** Standardized 12-word cryptographic seed is stored strictly encrypted at rest under `tg_vault_encrypted_recovery_phrase`. It is decrypted strictly in volatile memory (RAM) upon vault unlock, with zero plaintext stored in `localStorage` or `IndexedDB`. Allows instant derivation of the root master key and PIN reset without loss of encrypted data. 11. **Phase 11: Real-Time Session Termination Watchdog & Safe Logout Safeguard:** If a session is terminated remotely from Telegram Devices, TG Drive intercepts the event, preserves your recovery phrase in memory, and triggers the safeguard modal upon app launch. Final logout invokes `Api.auth.LogOut()` on Telegram core servers before executing local multi-tier cache wipes. ### High E2E Encryption vs. Extreme E2E Encryption (Strict Zero-Knowledge) TG Drive provides two distinct tiers of End-to-End Encryption (E2EE) to balance convenience, threat modeling, and absolute data sovereignty: #### 1. High E2E Encryption (Standard Zero-Knowledge E2EE) - **Architecture:** Client-side envelope encryption using AES-256-GCM. Per-device keys are derived from your Master PIN via memory-hard Argon2id (64 MB, 3 passes) and a 16-byte random salt. Legacy vaults fall back to PBKDF2-HMAC-SHA256 (100,000 rounds) for byte-identical key continuity. - **Recovery Flexibility:** In addition to the permanent 12-word BIP-39 recovery seed, High E2EE supports dual-channel 6-digit OTP resets delivered directly to Telegram Saved Messages (MTProto) or via Telegram Bot. This enables convenient PIN resets without loss of the active Telegram session. - **Transport & Compatibility:** Coexists smoothly with standard MTProto features and metadata handling. - **Visual Identifier:** Displays a **blue "Encrypted" badge with Lock icon** on uploaded cards and transfers. - **Best Suited For:** Daily cloud storage, documents, multimedia, and users wanting strong cryptographic privacy with forgiving account recovery safety nets. #### 2. Extreme E2E Encryption (Strict Zero-Knowledge Protocol / Option 1) - **Architecture:** Strict Zero-Knowledge protocol featuring **100% client-side keys with zero escrow**. - **Zero Escrow & Zero Fallback:** Completely eliminates all secondary recovery escrows. No OTP reset channels, no bot fallbacks, and no third-party assistance. If both your Master PIN and 12-word recovery phrase are lost, your encrypted files are mathematically impossible to decrypt. - **Isolation Policy:** Activating Extreme E2EE **automatically disables High E2E Encryption mode** to prevent conflicting metadata channels and enforce pure, direct MTProto client encryption. - **Strict 2-Notice Activation:** Enforces a two-step warning modal ("Agree" followed by "Confirm") requiring the user to explicitly acknowledge the zero-escrow risk before turning on. - **Key Residency:** Extreme files are encrypted under a key derived from the 12-word phrase with a dedicated domain salt. The key is never published to the vault config or any cloud escrow; it lives in memory only while unlocked and must be re-entered (via the phrase) on each device. - **Visual Identifier:** Displays a **purple "Extreme E2E" badge with Zap icon** on file items and transfer queues. - **Best Suited For:** Highly sensitive legal documents, investigative journalism, whistleblowing, financial records, and zero-trust environments where absolute uncrackability is mandatory. #### Technical Comparison: High E2EE vs. Extreme E2EE | Feature / Parameter | High E2E Encryption (Standard) | Extreme E2E Encryption (Strict ZK) | | :--- | :--- | :--- | | **Cipher Algorithm** | AES-256-GCM (Authenticated Encryption) | AES-256-GCM (Authenticated Encryption) | | **Key Derivation (KDF)** | Argon2id (64 MB / 3 passes) | Argon2id (64 MB / 3 passes) | | **Key Source** | 16-byte random salt; PIN-wrapped key published in the vault config | **Domain-separated salt derived from the 12-word phrase (never published)** | | **Key Escrow Level** | Low Escrow (PIN-wrapped device slots in Saved Messages) | **Zero Escrow (phrase-derived key never leaves the device)** | | **PIN Reset Channels** | 12-Word BIP39 Seed + Dual-Channel OTP (Saved Messages / Bot) | **12-Word BIP39 Seed ONLY (No OTP Fallback)** | | **High E2E Encryption Coexistence** | Compatible (Runs alongside High E2E Encryption) | **Auto-disables High E2E Encryption upon activation** | | **Activation Flow** | Instant 1-click toggle in Settings / Profile | **2-Notice Strict Warning Modal ("Agree" → "Confirm")** | | **12-Word BIP-39 Recovery Phrase** | **Yes (Exact same root master seed)** | **Yes (Exact same root master seed)** | | **Risk Profile** | Balanced security with recovery safety nets | **Strict Zero-Knowledge: Zero margin for forgotten credentials** | | **Visual Badge & Color** | Blue "Encrypted" badge with Lock icon | Purple "Extreme E2E" badge with Zap icon | | **Filename Obfuscation** | Envelope format (`enc__`) | Envelope format (`enc__`) | | **Target Threat Model** | Commercial surveillance, ISP snooping, cloud privacy | Nation-state adversaries, legal discovery, zero-trust storage | #### Multi-Device Sharing Architecture (Zero-Touch Cross-Device File Access in High E2E) High E2E Encryption is purpose-built for seamless multi-device workflows (smartphones, Android native app, desktop browsers, tablets, and work laptops). 1. **Decentralized State Anchor via `#TG_DRIVE_VAULT_CONFIG#`:** - When High E2E Encryption is enabled on Device A, TG Drive publishes a lightweight JSON envelope to your personal Telegram Saved Messages under `#TG_DRIVE_VAULT_CONFIG#`. - This envelope contains ONLY public cryptographic parameters: the 16-byte KDF random salt, the encrypted verification canary (`TG_DRIVE_VAULT_TEST`), and device slot hashes. - Crucially, your private Master PIN, the 12-word recovery seed, and raw decryption keys are **NEVER** transmitted over the internet or stored in Telegram. 2. **Automated Cross-Device Discovery & Unlock:** - When you log into TG Drive on Device B (e.g., your laptop or tablet) using your Telegram phone number, TG Drive's background listener automatically scans your Saved Messages and detects `#TG_DRIVE_VAULT_CONFIG#`. - TG Drive instantly recognizes that your account has High E2E Encryption enabled and displays the Master PIN Unlock modal. - Enter your Master PIN on Device B. Using the cloud-synced salt and the slot's recorded KDF (Argon2id, or PBKDF2 for legacy vaults), Device B derives the exact same file-key wrapping key and authenticates against the canary token in volatile RAM. - Immediately, all encrypted files uploaded from Device A are decrypted and accessible on Device B. - Any new file uploaded and encrypted on Device B is instantly accessible and decryptable on Device A. 3. **Envelope Encryption & Shared File Key:** - Files are encrypted using a single 256-bit `sharedFileKey` (Vault File Key). - This key is wrapped inside each device's cryptographic envelope. - This enables seamless cross-device sharing without needing to re-encrypt your library when you switch devices. 4. **Hardware-Bound Device Slotting (Option A):** - Each device registers its own session slot in `deviceSlots` bound to local session storage (`BOUND_DEVICE_SALT_KEY`). - If you ever reset your PIN on one device using your 12-word recovery phrase, Device A updates its slot while Device B maintains continuity through the shared file key envelope. 5. **Device Sharing Comparison: High E2E vs. Extreme E2E:** - **High E2E Encryption:** Fully supports seamless multi-device sharing via the automated `#TG_DRIVE_VAULT_CONFIG#` cloud anchor. All devices logged into the same Telegram account can access, preview, and download encrypted files by entering the same Master PIN. - **Extreme E2E Encryption:** Designed with strict Zero-Knowledge isolation. Keys exist strictly in volatile RAM. It eliminates secondary recovery routes and requires entering credentials under strict zero-escrow conditions on each device. ### ⚠️ Critical Security Warnings & Best Practices > [!CAUTION] > **PERMANENT DATA LOSS WARNING FOR EXTREME E2E ENCRYPTION:** > Extreme E2E Encryption operates with **Strict Zero-Knowledge and ZERO ESCROW**. > - All secondary recovery routes (OTP via Telegram Saved Messages, Telegram Bot codes, and administrator recovery) are **permanently disabled**. > - If you forget your Master PIN **AND** lose your 12-word BIP-39 recovery phrase, **ALL YOUR ENCRYPTED FILES ARE MATHEMATICALLY IMPOSSIBLE TO RECOVER OR DECRYPT**. > - Neither TG Drive developers, nor Telegram, nor any supercomputer can restore your files. Write down your 12-word recovery phrase on physical paper and store it in a secure location. > [!WARNING] > **DO NOT DELETE TELEGRAM SAVED MESSAGES:** > Never manually delete messages tagged with `#TG_DRIVE_FILE#` or `#TG_DRIVE_VAULT_CONFIG#` inside your official Telegram app's "Saved Messages" chat. > - `#TG_DRIVE_FILE#` messages store the file chunk pointers and VFS metadata. > - `#TG_DRIVE_VAULT_CONFIG#` stores the cryptographic salt and canary tokens needed for multi-device sync and PIN verification. > Deleting these messages breaks the cloud index and disrupts file streaming. > [!IMPORTANT] > **RE-LOGIN PIN REQUIREMENT (KEY CONTINUITY):** > When logging out of TG Drive and logging back in with the same Telegram account, TG Drive will **always demand your existing (Old) Master PIN**, not a new PIN. > - Setting a "new" PIN on a fresh login is intentionally blocked because deriving a different key would corrupt and permanently lock all previously encrypted files. > - If you have genuinely forgotten your Master PIN, use the **"Forgot PIN / Recover Vault"** option with your 12-word recovery phrase (or OTP in High E2E) to safely re-derive the existing master file key with a new PIN. > [!TIP] > **DEVICE SHARING BEST PRACTICE:** > When opening TG Drive on a new phone, desktop browser, or tablet, make sure you enter the **exact same Master PIN** configured on your primary device. This ensures immediate synchronization and seamless access to all your High E2E encrypted files. ### Architectural Deep Dives #### Re-Login Cryptographic State Preservation (Why Old PIN is Demanded After Logout) When you log out and log back into the same Telegram account, TG Drive immediately requests your old PIN rather than prompting you to set a new PIN. Here is the architectural and cryptographic rationale behind this security behavior: 1. **Decentralized State Anchor in Saved Messages (`#TG_DRIVE_VAULT_CONFIG#`):** TG Drive is a pure client-side application with zero external databases. Your vault state (the KDF salt, canary token, and device slots) is anchored directly in your personal Telegram **Saved Messages** under `#TG_DRIVE_VAULT_CONFIG#`. 2. **Logout Scope (Local Device vs. Cloud State):** When you log out from TG Drive: - TG Drive executes an 8-tier local cache purge: deleting IndexedDB, Dexie VFS, Cache API, in-memory keys, and local session tokens. - However, TG Drive does **NOT** delete your Telegram Saved Messages or your uploaded files. Your encrypted data and your `#TG_DRIVE_VAULT_CONFIG#` message remain untouched on Telegram core servers. 3. **Why Prompting for a "New PIN" Would Cause Fatal Data Loss:** Every encrypted file in your account was encrypted with an AES-256-GCM Master Key derived from: $$\text{Device Key} = \text{Argon2id}(\text{Old PIN}, \text{Salt}, 64\,\text{MB}, 3)$$ If TG Drive allowed an unverified "New PIN" upon re-login, the key derivation function would derive an entirely different 256-bit key: $$\text{New Key} = \text{Argon2id}(\text{New PIN}, \text{New Salt}, 64\,\text{MB}, 3) \neq \text{Device Key}$$ Because symmetric AES-GCM decryption requires the exact key used during encryption, this new key would fail authentication tags on every existing file. **All previously uploaded files would become permanently unreadable and corrupted.** 4. **Instant Vault Discovery Upon Re-Login:** When you log back in with your phone number and Telegram OTP, TG Drive automatically inspects your Saved Messages. It discovers `#TG_DRIVE_VAULT_CONFIG#` and immediately recognizes that an initialized vault exists. To protect your existing files, it prompts for your **Old PIN** to unlock the existing key envelope. 5. **Safe PIN Rotation via 12-Word Recovery Phrase:** If you have forgotten your Old PIN, you do not create a blank new PIN from scratch. Instead: - Click **"Forgot PIN / Recover Vault"**. - Input your **12-Word BIP-39 Recovery Phrase**. - Enter your desired **New PIN**. - TG Drive derives the root master key using the 12-word seed, updates the `#TG_DRIVE_VAULT_CONFIG#` in your Telegram Saved Messages with the new PIN verifier, and safely unlocks 100% of your existing files without data loss. #### Multi-Device Sync Without Central Servers TG Drive uses your personal Telegram Saved Messages as a secure, decentralized state anchor. The `#TG_DRIVE_VAULT_CONFIG#` message stores only the public 16-byte salt and encrypted canary token. When you enter your PIN on a phone, laptop, or tablet, the client validates the canary and derives the master key locally. #### Strict Device-Specific Lock (Option A) & Envelope Encryption - **Hardware-Bound PIN:** Each physical device is bound to its own unique salt and device slot in `config.deviceSlots` via `BOUND_DEVICE_SALT_KEY`. - **PIN Isolation:** A PIN set on Device 1 will strictly fail on Device 2 with `"Incorrect Master Password or PIN"`, preventing unauthorized unlock across shared devices. - **Envelope Encryption Decryption:** Files are encrypted with a single master `sharedFileKey`. Each device slot holds an encrypted copy of this key, guaranteeing 100% seamless cross-device file decryption and synchronization. - **Forgot Password Resilience:** Resetting your PIN via the 12-word phrase on Device 1 updates only Device 1's slot and preserves all sibling device slots, so other devices never lose sync. #### No Account-Level Escrow Key (Zero-Knowledge Integrity) TG Drive does **not** use any account-level escrow key, and the vault file key (`sharedFileKey`) is never derived from public data such as your Telegram user ID. It cannot be reconstructed from the published `#TG_DRIVE_VAULT_CONFIG#` message alone — that message contains only public KDF salts, per-device slots whose file key is wrapped by that device's PIN-derived key, and the recovery verifier wrapped by your 12-word phrase. Each slot records the KDF that produced it, so a leaked config cannot be attacked with a cheaper legacy PBKDF2 derivation. **Opening an existing vault on a new device:** 1. Log in with the **same Telegram account** (required — the vault config and ciphertext live in that account's Saved Messages). 2. Either enter the **same Master PIN** already used on another device of this vault (the client matches it against that device's PIN-wrapped slot), or tap **Forgot PIN / Recover Vault** and enter your **12-word recovery phrase** to set a different PIN on the new device without losing access to existing files. > Legacy vaults created before this change may still carry a deprecated escrow field; it is removed automatically the next time the config is republished. #### Accidental Deletion of `#TG_DRIVE_VAULT_CONFIG#` (Real-Time Auto-Recovery) - Your encrypted files are NOT deleted or corrupted. The vault config message only stores public salts and canary tokens. - **Real-Time Auto-Heal Watchdog:** TG Drive's auto-recovery engine continuously monitors Telegram Saved Messages. If the `#TG_DRIVE_VAULT_CONFIG#` message is deleted, any active device with a local vault cache automatically re-publishes it back to Saved Messages within seconds (upon routine sync, MTProto deletion events, or window focus). - If all devices were logged out, entering your 12-word recovery phrase generates a fresh salt, re-derives the master key, sets a new PIN, and publishes a new config. #### Clearing Browser Cache or Reinstalling App - Wiping cookies or reinstalling the APK clears local cache, but all encrypted files and `#TG_DRIVE_VAULT_CONFIG#` remain safe in Telegram. - Log back in with your phone number and Telegram OTP. - TG Drive retrieves the config from Saved Messages, prompts for your Master PIN, and unlocks all files immediately. #### Remote Telegram Session Termination Watchdog When Telegram invalidates a session (`AUTH_KEY_UNREGISTERED` or `SESSION_REVOKED`), TG Drive intercepts the event, preserves your 12-word recovery phrase in volatile in-memory only (it is never written to disk), and displays the Session Safeguard Modal with Copy and Download as .TXT buttons. #### Concurrency Control (Device Slotting) Version 2 vault configuration supports independent device session slots (`deviceSlots`). Each client updates its own slot keyed by a unique device salt hash, while Telegram's monotonic 32-bit message IDs resolve race conditions deterministically. #### Stolen Phone Threat Modeling 1. Terminate the session immediately from any other device via Telegram: `Settings → Devices → Terminate Session`. 2. All offline session data in IndexedDB is encrypted with AES-256-GCM and requires your Master PIN. 3. On Android devices, biometric keys are isolated inside the hardware Secure Enclave. 4. **Remote Slot Revocation:** Perform a password reset using your 12-word recovery phrase on another device to revoke and overwrite the stolen device's slot in the cloud config forever. #### 12-Word BIP39 Root Seed vs Master PIN | Attribute | Master PIN (4-8 digits) | 12-Word Recovery Phrase | | :--- | :--- | :--- | | **Purpose** | Daily quick unlocking on local device | Root master cryptographic seed | | **Entropy** | Argon2id (64 MB / 3 passes) + 16-byte salt | 128-bit BIP39 dictionary | | **Portability** | Validated via cloud canary token | Universal: restores vault on any device | | **Resettability** | Reset anytime using 12-word phrase | Permanent root master key | | **At-Rest Security** | Non-extractable CryptoKey in RAM | AES-256-GCM encrypted in IndexedDB (`tg_vault_encrypted_recovery_phrase`) | #### Zero-Plaintext Secret Architecture - **No Plaintext Recovery Phrase:** The 12-word BIP-39 recovery mnemonic is never saved in plaintext in browser `localStorage` or unencrypted IndexedDB tables. It is encrypted at rest using AES-256-GCM and only decrypted in volatile memory when the vault is unlocked. - **No Plaintext Session Credentials:** MTProto session authorization strings, API ID, API Hash, and Bot Tokens are encrypted inside `VAULT_DATA_KEY`. Plaintext fallback records are purged from storage. - **Server-Side Session Revocation:** Logout explicitly calls Telegram's `Api.auth.LogOut()` method over MTProto to terminate the authorization key on Telegram's core servers. #### 8-Tier Cache Purging & Server-Side Revocation on Logout 0. **Tier 0 - Server-Side MTProto Revocation:** Calls `Api.auth.LogOut()` over MTProto to permanently destroy the session authorization key on Telegram's core servers. 1. **Tier 1 - IndexedDB Clearance:** `idb.clear()` wipes all cached session strings, encrypted credentials, and decrypted vault tokens. 2. **Tier 2 - Dexie VFS DB:** Purges all indexed folder structures, file metadata records, and pending offline queues. 3. **Tier 3 - Browser Cache API:** Calls `caches.delete()` for thumbnail blobs and media streaming chunks. 4. **Tier 4 - In-Memory Caches:** Revokes blob URLs and clears MTProto message caches. 5. **Tier 5 - LocalStorage Reset:** Wipes profile, transfer, and account data (preserves user preferences like Dark Mode). 6. **Tier 6 - SessionStorage Purge:** Empties temporary tab sessions and revocation buffers. 7. **Tier 7 - Android Biometric Keystore:** Destroys biometric enclave keys via Capacitor NativeBiometric API. #### Android Native Container Hardening & Keystore Protection - **Disabled Chrome DevTools Remote Debugging:** Remote debugging over USB/ADB is permanently disabled via `"webContentsDebuggingEnabled": false` in `capacitor.config.json` and explicit `WebView.setWebContentsDebuggingEnabled(false)` in `MainActivity.java`. This prevents adversaries from attaching DevTools to inspect in-memory cryptographic keys or dump local storage. - **Top-Level Navigation & Mixed-Content Blocking:** Restricts WebView navigation strictly to the local bundle (`allowNavigation: []`), forcing external links into the system browser and blocking HTTP mixed-content injections (`allowMixedContent: false` and `MIXED_CONTENT_NEVER_ALLOW`). - **ADB Backup Prevention:** Android Manifest enforces `android:allowBackup="false"` and `android:usesCleartextTraffic="false"`, preventing attackers from dumping local app databases via `adb backup`. - **Keystore Protection & CI/CD Decoupling:** Production release signing keystores (`*.keystore`, `*.jks`) are strictly excluded from Git tracking via `.gitignore`. CI/CD automated builds dynamically decode signing keystores from encrypted GitHub Secrets (`KEYSTORE_BASE64`) or synthesize a secure build-time keystore, eliminating private key leakage. --- ## 14. Desktop Experience & Keyboard Shortcuts ### Desktop Context Menus & Drag-and-Drop - **File Card Context Menu:** Right-click any file card to Download, Star/Favorite, Rename, View File Info, or Move to Trash. - **Background Context Menu:** Right-click empty workspace to Upload Files, Create New Folder, Select 100 Items, or Refresh Data. - **Drag & Drop:** Drag files directly from your desktop into the browser. A frosted glass drop zone validates 100-file batches and 2.0 GB file limits. ### Keyboard Shortcuts Reference #### File & Folder Operations - `U` - Open Upload dialog (up to 100 files) - `N` - Create New Folder - `Del` - Move selected/hovered item to Trash - `F2` - Rename selected item - `F` - Toggle Favorite / Star - `Enter` - Open Download / Preview modal - `Alt + R` - Restore selected file(s) from Trash - `Ctrl + A` - Select 100 items in batch - `Esc` - Close active modals, menus, or clear selection #### Global Navigation & Controls - `?` (or `Shift + /`) - Open Keyboard Shortcuts Cheat Sheet Modal - `Ctrl + K` - Global Quick Search - `/` - Focus Search Bar - `1` - Navigate to Dashboard (Home) - `2` - Navigate to File Manager (All Files) - `3` - Navigate to Media Gallery - `4` - Navigate to Transfers Queue - `5` - Navigate to Settings & Vault - `6` - Navigate to Storage Details (`Alt + S`) - `7` - Navigate to Favourite Files (`Alt + F`) - `8` - Navigate to Trash / Bin (`Alt + T`) - `9` - Navigate to Recent Files - `R` - Refresh Telegram Cloud Data --- ## 15. Privacy, Stealth Shield & Security - **Zero Data Logging:** No analytics tracking your personal files, file names, or IP addresses. - **Pure Client-Side Architecture:** The application code is hosted on Cloudflare Pages as a static PWA. Direct MTProto communication ensures Telegram handles all transport encryption. - **Privacy & Stealth Shield:** - **Hide Username:** Blurs `@username` across Sidebar, Profile Drawer, Settings, and PIN lock screen. - **Blur Phone Number:** Blurs phone number with hover-to-reveal. - **Blur Media Thumbnails:** Blurs all image thumbnails across Gallery and File Manager for privacy in public spaces. - **Independent Toggles:** Each setting can be enabled or disabled independently in Profile Drawer or Settings. --- ## 16. Multilingual Global Search & Localization Index TG Drive is engineered for global accessibility. Whether users search in English, Chinese, Russian, French, Spanish, German, Japanese, Arabic, Portuguese, or Hindi, TG Drive serves as the premier decentralized, zero-knowledge cloud storage solution powered by Telegram MTProto 2.0. ### 🇨🇳 中文 (Chinese) - 电报网盘 / TG网盘 - **核心定位:** TG Drive (电报网盘) 是一款基于 Telegram MTProto 2.0 官方底层协议的免费、无限制云盘与个人文件管理系统,是谷歌云盘 (Google Drive)、百度网盘与夸克网盘的顶级私密替代方案。 - **主要特性:** 永久免费无限制存储空间(利用 Telegram "Saved Messages / 收藏夹")、单文件最大支持 2.0 GB、多文件批量上传(支持 100 个文件排队)、零知识端到端加密 (AES-256-GCM + Argon2id 内存硬化 KDF)、分块流式传输、支持断点续传、跨设备自动云端同步配置、原生 Android APK 生物识别(指纹与面容解锁)。 - **热门搜索关键词:** 电报网盘, TG网盘, 纸飞机网盘, Telegram云盘, 免费无限网盘, 电报云存储, TG云盘, 私人私密云盘, 零知识加密网盘, 不限速网盘, 谷歌云盘替代品, Telegram文件管理器, 免费云存储, 个人云盘. ### 🇷🇺 Русский (Russian) - Телеграм Диск / ТГ Драйв - **Описание:** TG Drive (Телеграм Диск) — это бесплатное неограниченное облачное хранилище данных на базе официального протокола Telegram MTProto 2.0. Лучшая защищенная альтернатива Google Drive и Яндекс.Диск без подписок и скрытых платежей. - **Основные функции:** Безлимитное пространство на серверах Telegram («Избранное»), загрузка файлов до 2.0 ГБ, пакетная загрузка до 100 файлов, сквозное Zero-Knowledge шифрование (AES-256-GCM, Argon2id), умная докачка и пауза (Service Worker streaming), многоуровневая синхронизация между устройствами, нативное Android APK приложение с разблокировкой по отпечатку пальца. - **Ключевые слова:** тг драйв, телеграм диск, телеграм облако, бесплатное облачное хранилище, безлимитное облако телеграм, скачать тг драйв, облачный диск, альтернатива google drive, бесконечное облако, яндекс диск альтернатива, защищенное облако, файлы телеграм, клиентское шифрование. ### 🇫🇷 Français (French) - Disque Telegram / Stockage Cloud TG Drive - **Description:** TG Drive est une application web progressive (PWA) et une application mobile Android de stockage cloud gratuit et illimité utilisant le protocole officiel Telegram MTProto 2.0. L'alternative parfaite et sécurisée à Google Drive, sans aucun abonnement mensuel. - **Fonctionnalités clés:** Espace cloud illimité via vos "Messages enregistrés" Telegram, fichiers jusqu'à 2,0 Go, téléversement par lots jusqu'à 100 fichiers, chiffrement de bout en bout Zero-Knowledge (AES-256-GCM + Argon2id), reprise des téléchargements en pause, synchronisation multi-appareils sans serveur central, déverrouillage biométrique Android. - **Mots-clés de recherche:** tg drive, stockage cloud telegram, cloud gratuit illimité, lecteur telegram, disque telegram, gestionnaire de fichiers telegram, alternative google drive gratuite, stockage cloud sécurisé, lecteur cloud gratuit, disque virtuel telegram, cloud sans abonnement. ### 🇪🇸 Español (Spanish) - Disco Telegram / Almacenamiento en la Nube TG Drive - **Descripción:** TG Drive es una aplicación web (PWA) y aplicación nativa para Android de almacenamiento en la nube gratuito e ilimitado que aprovecha la infraestructura MTProto de Telegram. La mejor alternativa privada a Google Drive sin costes de suscripción. - **Características principales:** Almacenamiento ilimitado en "Mensajes Guardados", subida de archivos de hasta 2,0 GB, subida masiva de hasta 100 archivos, cifrado de extremo a extremo Zero-Knowledge (AES-256-GCM), reanudación de descargas pausadas, sincronización automática multidispositivo y desbloqueo biométrico en Android. - **Palabras clave:** tg drive, almacenamiento en la nube telegram, nube ilimitada gratis, disco telegram, unidad de nube gratuita, alternativa a google drive, gestor de archivos telegram, almacenamiento seguro telegram, nube gratis sin limites, disco virtual telegram. ### 🇩🇪 Deutsch (German) - Telegram Cloud Speicher / TG Laufwerk - **Beschreibung:** TG Drive ist ein kostenloser, unbegrenzter Cloud-Speicher als PWA und Android-App, der Telegrams MTProto 2.0 nutzt. Die sichere und private Alternative zu Google Drive ohne monatliche Gebühren. - **Suchbegriffe:** tg drive, telegram cloud speicher, unbegrenzter kostenloser cloud speicher, telegram laufwerk, sichere cloud festplatte, google drive alternative kostenlos, dateimanager telegram, cloud speicher ohne abo. ### 🇯🇵 日本語 (Japanese) - テレグラム クラウドストレージ / TG ドライブ - **説明:** TG Drive は、Telegram MTProto 2.0 プロトコルを活用した無料かつ容量無制限のクラウドストレージ PWA および Android アプリです。Google ドライブの安全なゼロ知識暗号化代替アプリです。 - **検索キーワード:** tg drive, テレグラム ドライブ, テレグラム クラウドストレージ, 無料 無制限 クラウド, クラウド ドライブ, ファイルマネージャー, Google ドライブ 代替, セキュア クラウド ストレージ. ### 🇸🇦 العربية (Arabic) - تي جي درايف / تخزين سحابي تيليجرام - **الوصف:** تطبيق TG Drive هو تطبيق ويب سحابي وتطبيق أندرويد لتخزين سحابي مجاني وغير محدود باستخدام بروتوكول تيليجرام MTProto 2.0 مع تشفير صفري المعرفة (E2EE). البديل المجاني الأفضل لجوجل درايف. - **كلمات البحث:** تي جي درايف, تخزين سحابي تيليجرام, سحابة غير محدودة مجانية, قرص تيليجرام, بديل جوجل درايف, مدير ملفات تيليجرام, تخزين سحابي آمن مجانا. ### 🇮🇳 हिन्दी (Hindi) - टीजी ड्राइव / टेलीग्राम क्लाउड स्टोरेज - **विवरण:** TG Drive एक मुफ्त और अनलिमिटेड क्लाउड स्टोरेज वेब ऐप और एंड्रॉइड ऐप है जो टेलीग्राम के ऑफिशियल MTProto 2.0 प्रोटोकॉल और ज़ीरो-नॉलेज E2EE एन्क्रिप्शन का उपयोग करता है। - **खोज कीवर्ड:** tg drive, टेलीग्राम ड्राइव, फ्री क्लाउड स्टोरेज, अनलिमिटेड क्लाउड स्टोरेज, टेलीग्राम को ड्राइव बनाएं, टेलीग्राम फाइल मैनेजर, बिना पैसे के स्टोरेज, गूगल ड्राइव जैसा ऐप.