Introduction
Recently in July 2026, India's Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs quietly tried to do something almost no government has managed before: switch off an app that doesn't need the internet to work. On July 23, 2026, I4C sent takedown notices to Google, Apple and GitHub, ordering them to pull three offline messaging apps – like BitChat, Briar and Bridgefy – from the Play Store, App Store and GitHub's code repository, respectively, giving a three-hour deadline. The notices followed a period of student-led demonstrations at Jantar Mantar, New Delhi, associated with a group "Cockroach Janata Party," a period that also saw a mobile internet shutdown in parts of central Delhi. When Twitter co-founder Jack Dorsey, who built and open-sourced BitChat, publicised the GitHub notice on X, the episode made international news. Google and Apple got near-identical orders the same night, and telecom operators were reportedly told, and then just as quickly untold, to block the apps at the network level. By July 29, all three apps were still live on both app stores, and BitChat's code was still on GitHub. This incident is worth unpacking carefully, because it sits at the intersection of three things most people care about but rarely see explained together: how this technology actually works, what the law actually allows, and why an app can be "banned" on paper while still working perfectly on your phone.
What makes these apps different
Ordinary apps like WhatsApp or Telegram are centralised: your message travels from your phone to a company's server, and then to the recipient's phone. Block or seize the server, and communication stops. BitChat, Briar and Bridgefy are built differently. They use Bluetooth mesh networking, a system where nearby phones talk directly to each other, and each device also relays messages onwards to phones further away, like a bucket brigade. No message ever touches a central server. Briar adds a further layer by routing traffic over Tor, an anonymity network, when internet access is available, and falls back to Bluetooth or Wi-Fi Direct when it isn't. Bridgefy is tuned for larger crowds, useful during concerts, natural disasters, or protests where thousands of phones are packed into a small area and cellular networks buckle under the load. This design, often called decentralised or peer-to-peer communication, is precisely why these apps are useful during disasters and precisely why they worry law enforcement: they keep working when the internet doesn't, whether that's because a cyclone knocked out cell towers or because the government itself ordered a shutdown.
The legal machinery behind a takedown notice
India's power to block online content mainly comes from Section 69A of the Information Technology Act, 2000, which lets the central government order blocking on grounds like sovereignty, public order or preventing incitement to an offence but only through a defined process set out in the IT (Blocking) Rules, 2009: a designated officer, a review committee, and recorded written reasons. The Supreme Court examined this exact provision in its landmark 2015 ruling, Shreya Singhal v. Union of India. While the judgement is best remembered for striking down the vague "offensive speech" law under Section 66A, it separately upheld Section 69A specifically because it came with procedural guardrails, a reasoned order, an opportunity to be heard, and the possibility of judicial review that stopped it from becoming an unchecked censorship tool. The July 23 notices, however, reportedly leaned on a different lever: Section 79(3)(b) of the IT Act, read with Rule 3(1)(d) of the IT Intermediary Guidelines and Digital Media Ethics Code Rules, 2021. That provision governs when an intermediary loses its legal immunity ("safe harbour") for user content if it fails to act on a government or court order, a mechanism built for content takedowns, not necessarily for pulling an entire app off a store shelf within three hours. Legal commentators have flagged this as significant, since Shreya Singhal itself read down Section 79(3)(b) to require action only pursuant to a court order or a properly authorised government direction, not an informal notice. This isn't the first time a mesh-messaging app has run into this machinery. In 2023, following an I4C request, the government blocked Briar and thirteen other apps in Jammu and Kashmir under Section 69A, citing use, the first known instance of Section 69A being used for a regional block. Briar's developers challenged this in the Delhi High Court; in 2024, the court dismissed the challenge, holding that principles of natural justice can give way in matters of national security.
Why you can't easily switch off a mesh network
Here's the technical wrinkle that made the July order largely symbolic: removing an app from the Play Store stops new downloads, but it does nothing to phones that already have it installed, and it does nothing at all to the Bluetooth radios exchanging messages between those phones. Unlike an internet shutdown, which works by controlling the pipes that all traffic must pass through, a mesh network has no chokepoint, no server to seize, no IP address to blacklist, and no single company to compel.
GitHub, for its part, said it followed its standard process of notifying the account holder and offering an appeal before taking any action, which is one reason BitChat's source code stayed publicly accessible throughout. Within a day, officials reportedly told the companies orally that enforcement wasn't necessary after all, though no public clarification or official document has been released explaining why the notices were issued or withdrawn.
Two legitimate, competing interests
None of this means the government's underlying worry is baseless. Law enforcement agencies genuinely lose visibility when communication moves off networks they can lawfully intercept, and coordination of unlawful assembly or violence is a real concern during volatile protests.
The transparency gap
The single biggest problem with how this played out isn't the underlying concern it's the absence of a public, reasoned order. Under the blocking rules, disclosure is restricted, and courts, including the Supreme Court in Anuradha Bhasin v. Union of India, have said that when access is restricted, reasons must be recorded and, where possible, made available. A three-hour notice, issued and then informally withdrawn without explanation, sits uneasily with that standard. A more durable approach, one that CyberPeace and other digital-rights researchers have called for, would combine clearly identified statutory authority; published (even if redacted) reasoning; proportionality review; and investment in lawful digital forensics, rather than blanket app-store takedowns that decentralised technology is, by design, built to survive.
CyberPeace's policy recommendations
Alongside the legal analysis above, CyberPeace puts forward a ten-point framework for how India should approach decentralised communication technologies going forward, instead of defaulting to blanket takedowns:
- Strengthen transparency in blocking decisions
- Ensure statutory clarity
- Apply legality, necessity and proportionality
- Differentiate technology from misuse
- Invest in advanced investigative capabilities
- Establish a multi-stakeholder advisory mechanism
- Develop a framework for emerging decentralised technologies
- Promote responsible innovation
- Enhance public awareness
- Foster international cooperation
Conclusion
The referred incident illustrates that regulating decentralised technologies requires more than swift takedown notices. As communication networks become increasingly resilient and distributed, effective governance must combine legal certainty, technical realism, transparency, and proportionate enforcement. India's challenge is not simply to regulate emerging technologies but to develop a kind of regulatory framework that safeguards national security and the constitutional values of privacy, free expression, and due process.
Sources