Fair questions, straight answers.

Including the ones marketing pages usually skip.

Accounts & privacy

Is my Telegram account at risk?

NoBuf logs you in through Telegram's own official flows: phone + code, QR scan, two-factor password. Your session is stored locally on your machine with restrictive file permissions.

One thing worth knowing: logging into third-party apps can trigger Telegram's own security notifications to your other devices. That's Telegram protecting you. Expected, not a red flag about NoBuf.

What NoBuf never sees: your 2FA "cloud password" stays between you and Telegram even during login.

Do I need a developer account? Why API keys?

Every third-party Telegram client needs an API ID/hash pair from my.telegram.org. That's Telegram's requirement, not ours.

The difference: NoBuf's wizard opens my.telegram.org in a built-in window and fills the app-creation form for you, then hands the keys straight to the app. You log in once yourself; the paperwork automates away. Keys live on your machine.

Does NoBuf phone home?

The complete list of things NoBuf can talk to:

  • Telegram's servers: fetching your files. The whole point.
  • api.opensubtitles.com: only when you search subtitles, using your own free key.
  • GitHub Releases: update checks and downloads.
  • One optional ffmpeg download: only if your system lacks it and a format needs it.

That's it. No analytics, no crash reporters, no accounts with us. The app's own servers bind to 127.0.0.1 and its UI sandbox can't reach anything but localhost.

Will it work offline?

NoBuf is a Telegram client, so new streams need Telegram reachable. What caching does give you:

  • Everything already downloaded in this session replays instantly without re-fetching.
  • The download-ahead keeps working while you watch, so brief dropouts don't interrupt playback.
  • Extracted subtitle tracks persist across restarts even though video cache clears each launch.
Does the cache fill my disk?

The stream cache wipes itself on every launch, so you'll never dig gigabytes out of AppData. Closing a half-watched video offers three honest choices: continue downloading the rest in the background, keep what's cached for instant replay this session, or discard it.

What ports does it open? Is something listening on my LAN?

Nothing listens on your network. All local servers bind strictly to 127.0.0.1: the streaming server on port 14201 and, if you enable it in Settings, the REST API on a port you choose. The REST API requires an API key which is stored hashed and compared in constant time. It's off by default.

Using NoBuf

Why not just use the Telegram app?

For MP4s, Telegram's built-in player is genuinely fine. NoBuf earns its keep on everything else:

  • MKV, TS and HEVC files play by streaming instead of demanding a full download first.
  • A real seek engine: jump anywhere in seconds, frame previews while scrubbing, no index required.
  • Embedded subtitles render properly, OpenSubtitles search is built in.
  • Dual-audio files switch languages mid-scene.
  • Your channels become a browsable library with folders, groups and search.
Which subtitle formats work?

Yes: SRT/SubRip, ASS/SSA (rendered with libass, including fonts embedded in the MKV), WebVTT and mov_text. You get size, position and sync sliders, and per-file track memory.

Not yet: image-based formats like PGS (Blu-ray), VobSub and DVB are detected but can't be extracted or rendered. We'd rather say that than pretend.

What formats play? What about 4K HEVC?
  • H.264/VP9/AAC in MP4/WebM: streams directly.
  • MKV and TS: remuxed live: instant start, no quality change.
  • HEVC your GPU can decode: passed through untouched.
  • HEVC 10-bit / HDR: hardware-transcoded (Intel QuickSync when available): plays everywhere, may take a moment to start.

Old recordings with metadata at the end of the file get virtually faststarted: they play immediately without downloading anything extra.

How do I import my existing channels?

Rename any private channel to include [NB] and it appears as a folder on next launch, no re-upload, and works across devices since the tag lives in the channel title itself. Public channels join via their t.me link and browse as searchable grids. Folders can be grouped with colored, reorderable tabs.

Updates & install

How do updates work? Are installs safe?

NoBuf checks GitHub Releases and verifies every download against a minisign public key pinned inside the app before installing. A tampered package can't pass. Updates apply with one click.

Windows note: SmartScreen may show "unknown publisher" on first run because the installer isn't EV-code-signed. That's a reputation system, not a virus verdict. Use More info → Run anyway. The update channel itself remains signature-verified.

Does it need ffmpeg?

Maybe not at all: a large share of files stream through NoBuf's built-in remuxer with zero external tools. When a format does need ffmpeg, NoBuf finds an existing installation first; otherwise it fetches a minimal build once into its own data folder and validates the binary actually has the encoders it needs. Nothing to configure.

Convinced? It's free.