India Orders BitChat GitHub Repos Removed, IFF Calls It Unconstitutional
India's I4C issued a three-hour takedown order for Jack Dorsey's BitChat repositories on GitHub, citing the app's anonymous, decentralized architecture. IFF calls it unconstitutional and a procedural bypass. The same legal logic applies to every permissionless protocol.

India's cybercrime agency gave GitHub three hours to erase Jack Dorsey's open-source messaging app. The offense: the app's architecture itself.
Key takeaways
- India's I4C issued Notice No. 11072601011432 at 11:16 p.m. on July 23, 2026, ordering GitHub to disable three BitChat repositories within three hours, citing the Bluetooth mesh app's decentralized design as an impediment to lawful surveillance.
- India's Internet Freedom Foundation called the order "unconstitutional and authoritarian," arguing it weaponized an intermediary liability provision rather than the statutory website-blocking process that carries procedural safeguards.
- The notice names zero illegal content in the repositories. It targets what BitChat is capable of enabling, a legal logic that applies identically to Bitcoin nodes, Lightning channels, and Nostr relays.
India's Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs, ordered GitHub on July 23, 2026, to disable three repositories under the "permissionlesstech" account: the main BitChat project, its Android build, and the Android releases page. The deadline was three hours. The Internet Freedom Foundation (IFF), India's leading digital-rights nonprofit, condemned the move the following morning, calling it a procedural end-run that sacrifices due process to silence a tool protesters have used to communicate through Bluetooth mesh when mobile networks go down.
Jack Dorsey, who launched BitChat in July 2025, posted a copy of the I4C notice on X on July 24, writing: "the government of india does not like technologies like bitchat and wants it taken down."
What the Order Actually Says
The I4C notice states that BitChat "enables anonymous communication without mandatory user registration, phone number verification, or centralized logging of communications," which "significantly impedes lawful interception, attribution, and investigation by law enforcement agencies." The government argued the platform could be exploited for coordinating unlawful assemblies, violent protests, dissemination of misinformation, and criminal conspiracies.
IFF's response was direct: "The blocking of BitChat's code on GitHub is unconstitutional and authoritarian."
The foundation's core legal objection is procedural. I4C issued the order under Section 79(3)(b) of the Information Technology Act, 2000, an intermediary liability provision, rather than under Section 69A, the formal statutory mechanism for website blocking that includes procedural safeguards. IFF demanded withdrawal of the notice and publication of all takedown orders issued under Section 79(3)(b).
The substantive objection is sharper. The notice identifies no specific unlawful content hosted in the repositories. It targets the application's architecture. IFF argued that "the reasons in the order are circular," that the order asserts the repositories contain information "prohibited under any law" without naming any such information, and that it rests instead on what the application is "capable of" enabling.
As of publication, MediaNama reported the repository links had been taken down. GitHub had not issued a public statement confirming compliance. The BitChat app remained available on major app stores.
The Precedent That Travels
This is where the story stops being about a messaging app and starts being about every permissionless protocol.
The I4C notice could be reissued tomorrow with "Bitcoin node" substituted for "BitChat repository" and the logic holds identically. BitChat has no registration, no centralized server, and no lawful interception point, and that framing covers Bitcoin nodes, Lightning channels, and Nostr relays with equal ease.
India's move also demonstrates that states don't need to ban permissionless tools outright. They pressure the choke points: GitHub, app stores, ISPs, telecom infrastructure. Platform intermediary liability does the dirty work.
Removing the repositories won't kill BitChat; open-source code is mirrored widely, and the network continues. But the action establishes that GitHub will comply with a three-hour government deadline carrying no due process, and that precedent travels across jurisdictions and across protocols.
China ordered BitChat pulled from Apple's App Store in April 2026, making India the second large state to move against it. China also banned Dorsey's Nostr-based Damus app in 2023. The pattern is consistent: states move against permissionless communication tools in sequence, testing platform compliance along the way.
BitChat has gained meaningful adoption precisely because it works when states cut connectivity. The Bluetooth mesh design routes encrypted messages between nearby devices with no internet, no servers, and no phone numbers required. That design is the product, and it is exactly what the I4C notice finds threatening.
The falsifiable thesis here is narrow. If I4C amends the notice to cite specific illegal content in the repositories, or if an Indian court upholds the Section 79(3)(b) application as lawful procedure rather than a bypass, that would indicate this is normal content moderation operating within legal guardrails. The notice as written offers no basis for that reading.
What to Watch
IFF has demanded three things: withdrawal of Notice No. 11072601011432, publication of all Section 79(3)(b) takedown orders, and restoration of internet connectivity around Jantar Mantar alongside disclosure of the legal authority for jammer deployment there. Whether GitHub issues a public response and whether any Indian court takes up a challenge to the notice will determine whether this three-hour order sets a repeatable template or gets walked back.
Sources
- IFF statement, @internetfreedom, X, July 24, 2026
- Jack Dorsey (@jack), X, July 24, 2026
- I4C Notice No. 11072601011432, July 23, 2026 (reproduced via Dorsey's X post; no standalone government URL available)
- MediaNama
- First reported in English by Decrypt
Frequently Asked Questions
MediaNama reported the repository links were taken down following the order. GitHub had not publicly confirmed compliance as of July 24, 2026. The BitChat app itself remained available on Google and Apple app stores through Asian afternoon hours that day.
Section 79(3)(b) of India's IT Act is an intermediary liability provision, meaning it governs when platforms lose their safe harbor from prosecution. Section 69A is the statute designed specifically for government-directed website and content blocking, and it carries procedural requirements including oversight and documentation. IFF argues I4C used the liability provision as a content-removal mechanism to avoid those safeguards, making the order procedurally improper regardless of its underlying rationale.
No. Open-source repositories are routinely mirrored across independent hosts. Removing three GitHub repositories eliminates one access point while the underlying codebase remains distributed across forks, archives, and mirrors. The removal tests platform compliance more than it threatens the software's availability.


