Edition 28: The Indian govt's crackdown on Bluetooth-enabled messaging apps that wasn't?
The Indian Cyber Crime Coordination Centre had sought the removal of not just BitChat, and GitHub was not the only intermediary to get the takedown notice.
By now, there is about a 110% chance (give or take 5%) that the readers of The Tech Trace are already aware that late night on July 23, the Ministry of Home Affairs’ Indian Cyber Crime Coordination Centre (I4C) notified GitHub to remove the code repository for Bluetooth-enabled messaging app BitChat within three hours of receiving the notice, citing Section 79(3)(b) of the Information Technology Act read along with Rule 3(1)(d) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules (henceforth called the Theseus Rules).
But there is about a 5% chance (give or take 2%) that the readers know that BitChat was not the only Bluetooth-enabled messaging app that was targeted, or that GitHub was not the only intermediary to receive the notice. Or that the following day on July 24, the government orally told the intermediaries that they did not need to comply with the July 23 takedown notice.
Who got the notice? Which other apps were affected?
On July 23, before sending the takedown notice to GitHub at 11:16 pm, I4C sent a similar takedown notice to Google, notifying the company to remove three apps from its Play Store — BitChat, Briar, and Bridgefy — by disabling the relevant URLs within three hours. Apple was sent a similar notice that listed only BitChat and Bridgefy; Briar is not available for iOS.
The notices to the two companies were signed by Manoj Kumar Meena, the director of I4C’s National Cybercrime Threat Analytics Unit (NCTAU) and the Section 79(3)(b) nodal officer for I4C, according to documents reviewed by The Tech Trace.
Separately, as per one telco executive, late on July 23, the telecom operators were also directed to “block” access to Bluetooth-enabled messaging apps/URLs but were told to “unblock” them on July 24. The Tech Trace could not ascertain the ministry/law enforcement agency that directed telcos to do so or the legal provisions cited in such directions.
A technology executive told The Tech Trace that on July 24, less than a day after issuing the takedown notice, the tech companies were also told to not pull down the apps.
Both executives in the story requested anonymity citing the sensitivity around blocking/takedown directions and the students’ protests.
All three apps were available on Google’s Play Store on July 24, July 26 and the wee hours of July 27. Both BitChat and Bridgefy were similarly available on Apple’s App Store.
BitChat’s code repository remained available on GitHub throughout.
In response to a detailed questionnaire from The Tech Trace, GitHub said that it had not taken down cited URLs for BitChat because as per the company policy, it first notifies the affected account owners to give them a chance to appeal.
“When GitHub receives a complete government takedown request, we notify the affected account owners and give them an opportunity to appeal. We are currently in this phase. So, no take down has been done so far!” the statement said.
GitHub’s response explains how Jack Dorsey, the developer of BitChat and the former CEO of X (when it was still Twitter), had a copy of the takedown notice that he had tweeted on July 24. “the government of india does not like technologies like bitchat and wants it taken down [sic],” his tweet had said.
GitHub’s statement said that the company publicly shares every government takedown request that it acts on (more on that below).
In its response to The Tech Trace, GitHub did not answer whether the company had received any communication from I4C, or any other representative of the Indian government, to not take down the links cited in the July 23 notice.
The Tech Trace could not establish the reason for this volte-face in the takedown instructions and has reached out to MHA (which houses I4C), Google and Apple for more information. This article will be updated on receiving a response.
I4C’s problem with Bluetooth-enabled messaging apps
All three messaging services in question are peer-to-peer messaging services that use Bluetooth for communication. This means that the companies in questions do not have a central server to route messages and the apps do not rely on internet services provided by telcos to send messages. This makes them resilient to internet shutdowns such as the ones that hit central Delhi during the students’ protests last week.
No registration, KYC, phone numbers are required but some of them require location data to locate other users in close proximity to act as nodes so that the message can hop from device-to-device until it reaches the intended recipient.
And these are precisely the problems for I4C: authorities cannot intercept them, they cannot get user data from companies, and they can be used to render internet shutdowns moot.
“… establishing decentralized peer-to-peer messaging over Bluetooth mesh networks without relying on mobile networks, internet connectivity, or centralized servers. The application enables anonymous communication without mandatory user registration, phone number verification, or centralized logging of communications,” the notices sent to Google and GitHub said.
This technical architecture, as per the I4C, “significantly impedes lawful interception, attribution, and investigation by law enforcement agencies [emphasis mine]”.
Peer-to-peer communication between “nearby devices through a decentralized mesh network” means that “the platform can be misused to evade lawful surveillance, facilitate anonymous coordination, and circumvent lawful restrictions imposed by competent authorities during situations involving public disorder, riots, terrorism, organized crime, or internet shutdowns [emphasis mine]”.
By allowing people communicate “even during network restrictions”, the applications’ design “creates a substantial risk of misuse by anti-national elements, terrorist organizations, organized criminal groups, and cybercriminals seeking to evade lawful detection and continue communication despite legally imposed restrictions [emphasis mine]”.
The notices cite “intelligence inputs” that such decentralised messaging services can be “exploited for coordinating unlawful assemblies, violent protests, dissemination of misinformation, radicalization, criminal conspiracies, and other activities prejudicial to the sovereignty and integrity of India, defence of India, security of the State, public order, and for facilitating the commission of cognizable offences [emphasis mine]”.
The lack of centralised service provider “limits the ability of law enforcement agencies to obtain subscriber information, communication records, or timely assistance during investigations”, as per the notice.
In the notices to GitHub and the two app stores, I4C cites Sections 43, 84B and 84C of the IT Act and Sections 61, 196 and 197 of the Bharatiya Nyaya Sanhita, 2023, to hold the information unlawful.
Section 43 of the IT Act deals with “penalty and compensation for damage to computer, computer system, etc.”, essentially describing hacking, planting malware/virus, stealing of data, incidents like denial-of-service attacks, ransomware attacks, etc. in legalese. And it then says that whoever does it will be liable to compensate the person affected.
My commentary:
The only way this section applies is if we very, very expansively read Section 43(g) to argue that someone has provided “assistance” to a person “to facilitate access” to a computer network” (where computer network is defined as “inter-connection of one or more computers or computer systems or communication device” through “the use of … wireless or other communication media”) in violation of the IT Act or its rules. I have given up trying to explain the contradiction here because it is so convoluted that my brain started hurting.Moving on.
Who is the person affected? And who will be liable to compensate? Will the people ‘using’ these apps compensate the government? Will the people ‘downloading’ these apps afresh compensate the government? Will the companies compensate the government? If it is a banal use case of a boo communicating with their bae at a burger joint near the protest site (and thus no internet), who is the affected party?
Section 84B of the IT Act deals with punishment for abetment of offences while Section 84C deals with punishment for attempt to commit offences.
Section 61 of the BNS defines criminal conspiracy which requires to or more people to cause or commit an illegal act, or a legal act by illegal means.
Section 196 of BNS prescribes imprisonment of up to three years and/or fine for promoting enmity between different groups on the basis of religion, race, place of birth, language, etc. and doing acts prejudicial to maintenance of harmony.
Section 197 prescribes imprisonment of up to three years and/or fine for imputations, assertions prejudicial to national integration (and includes publication of false/misleading information that jeopardises national security).
Not I4C’s first rodeo (against Briar at least)
This is not the first time that the I4C has acted against messaging apps.
In April 2023, the I4C had requested the Ministry of Electronics and Information Technology (MeitY) to block 14 applications, including Briar, in Jammu and Kashmir citing their use by terrorists and supporters. These apps were subsequently blocked in the union territory in May 2023 under Section 69A of the IT Act, making it the first known instance of regional blocking under the provision.
Not all of the 14 applications that were blocked used Bluetooth-enabled, peer-to-peer communication.
While Briar had challenged the blocking order in Delhi High Court, in July 2024, Justice Subramonium Prasad had dismissed the company’s challenge, saying that principles of natural justice (including the right to a fair hearing) “can be given a go-by” in national security-related matters.
GitHub’s takedown history under Section 79(3)(b)
As per GitHub’s public repository of government takedown requests that it has acted on, the company has taken down only one URL on communication from an Indian agency — in response to a notice sent by the nodal officer for the Tamil Nadu Government on April 7, 2026.
The removal of the GitHub link in question — https://rkoots.github.io/election2026/#google_vignette — was requested by the Tamil Nadu superintendent of police (social media cell). It had posted “Projections on Vote Share and anticipated Seat winning of Tamil Nadu Legislative assembly elections”.
The notice said that the posted surveys did not include the sample size, methodology, margin of error and the details of agency that conducted the survey.
“Thus, the posts are made without disclosing the methodology and are in violation of the Model Code of Conduct and have the potential to adversely impact the conduct of free and fair elections in Tamil Nadu,” the Section 79(3)(b) notice read.
This takedown notice cited “Decency or Morality” as the reasons for “holding the information unlawful” and cited Section 353 of the BNS. To be sure, as per the BNS, Section 353 is related to “statements conducing to public mischief” and deals with false information and rumour-mongering, not decency or morality.
Tamil Nadu assembly elections were announced on March 15 along with assembly elections for Assam, Kerala, West Bengal and Puducherry. While polls were held in Tamil Nadu on April 23, polls in Assam, Kerala, and Puducherry were held on April 9, and in West Bengal in two phases on April 23 and April 29. The votes were counted for all five elections on May 4.
As per Section 126A of the Representation of People Act, 1951, read along with FAQ 68 on the Election Commission’s website, no opinion or exit polls could have been published from April 7 evening (48 hours before the closing of the poll in the first phase on April 9) until the evening of April 29 (conclusion of the last phase of election in all states).
Separately, as per an April 2 press release from the ECI dated April 2, exit polls were prohibited between 7 am on April 9 and 6:30 pm on April 29 while opinion polls for the Tamil Nadu elections were prohibited during the 48-hour silence period lasting from 6 pm on April 21 to 6 pm on April 23.
The takedown notice in question was issued at 10:07 am on April 7.
Notably, the April 7 takedown notice gave GitHub 36 hours to disable access to the URL in question. The MeitY had amended the Theseus Rules on February 10 to reduce this timeline to 3 hours, and brought it into effect on February 20. The reduced timeline of three hours is reflected in the July 23 takedown notices to GitHub and the two app stores.
“The End”


