India's Order to Delete Bitchat Repositories: An Unprecedented Move

India's Ministry of Home Affairs has directed GitHub to restrict access to three code repositories of the offline messaging app Bitchat, founded by Jack Dorsey, arguing that the app's decentralized Bluetooth architecture could facilitate unlawful activity during internet shutdowns. The notice, issued by the Indian Cybercrime Coordination Centre (I4C) on July 23, gives GitHub three hours to comply and claims the app makes it harder for authorities to trace communications.

The demand comes as Bitchat surged in popularity in India amidst ongoing protests in New Delhi against the education minister. According to Sensor Tower data, India accounted for about 85% of the app's global downloads between July 17 and July 23, with over 91,000 downloads in five days and daily active users hitting 330,000. The government's move is unusual because it targets the entire project on the grounds of its technical design, rather than pointing to any specific unlawful posts or content hosted on GitHub.

Digital rights advocates immediately questioned the legal foundation of the order. Mishi Choudhary, founder of SFLC.in, noted that the notice resembles earlier government takedown formats but cites provisions that do not clearly authorise the removal of a whole software project purely based on how it works. GitHub did not confirm receipt of the notice, and the repositories remained accessible from India at the time of reporting.

Legal Experts Question the Basis of the Takedown — and What It Could Mean for Open Source

A Legal Gray Zone: Architecture vs. Content

The takedown demand stands out because it does not identify any specific violating content. Instead, it frames the app's offline, server-less design – specifically the ability to function during network restrictions and without central servers – as a threat to lawful interception and traceability. Legal experts say this approach pushes the boundaries of existing Indian cyber law, especially Section 69A of the IT Act and the 2009 Blocking Rules, which were designed to remove content, not entire software projects.

Raman Chima of the Association for Progressive Communications warned that the notice seeks to suppress open source development itself. “They're not just targeting the designated service provider, but they're trying to say that open source development of this type of product … should not occur,” he said. This signals a potential shift toward pre-emptive blocking of technologies that governments view as tools to circumvent internet shutdowns.

Open Source as a Target

By ordering the removal of repositories from GitHub, the government is attempting to cut off access to the underlying code, not just the end-user app. As digital rights group SFLC.in pointed out, deleting a repository does not uninstall the app from phones that already have it, nor does it stop the peer-to-peer mesh from working. The real effect, they argue, is to prevent public scrutiny of the code and hinder future open source collaboration around offline communication tools.

The incident raises uncomfortable questions for platforms like GitHub, which are increasingly caught between local laws and their own policies on transparency and developer freedom. GitHub’s principal online safety counsel said the company notifies affected account owners of government takedown requests and gives them an opportunity to appeal, but it declined to confirm whether this specific request had been received.

Internet Shutdowns and the Right to Communicate

The surge in Bitchat usage directly correlates with protests in New Delhi and the imposition of restrictions on marches toward parliament. Namrata Maheshwari of Access Now told TechCrunch that blocking an offline messaging platform during such moments risks turning internet shutdowns into a full “communication blackout” that violates fundamental rights. The notice, dated during the protest peak, suggests that authorities are concerned not just about content moderation but about the very possibility of citizens communicating privately when official networks are deliberately turned off.

This case is likely to become a test of how far India’s cybersecurity framework can reach when it comes to infrastructure that is explicitly designed to be censorship-resistant. If the takedown succeeds or sets a precedent, other countries with frequent internet blackouts may follow suit, reshaping the global landscape for mesh networking and privacy-first apps.

What Developers, Platforms, and Users Should Watch For

  • Developers of offline or mesh-networking apps should review India's intermediary guidelines and the legal risks of having code repositories hosted on public platforms. The notice signals that architecture alone can trigger takedown demands, even without any illegal content.
  • Open source projects that could be used to bypass internet restrictions – from Bluetooth messengers to VPNs – should assess their exposure in jurisdictions with active shutdown policies. Hosting alternatives and clear contributor policies may become necessary safeguards.
  • Platforms like GitHub will need to balance legal compliance with transparency commitments. They may face difficult decisions about whether to challenge broad orders or comply, with repercussions for their developer communities.
  • Users in India who rely on Bitchat or similar apps should be aware that the government is actively seeking to disable such tools. The app itself may remain functional on devices already installed, but future updates and security patches could be affected if the repositories are taken down.

Risk & Opportunity Assessment

Commercial RiskLowThe immediate commercial impact on GitHub is limited as the platform has not confirmed compliance and the repositories remain accessible. However, prolonged legal disputes could create uncertainty for developers hosting projects on the platform.
Competitive RiskLowThe order targets a specific open-source project, not the broader competitive landscape. Other messaging apps are not directly affected, though the precedent could influence how governments treat similar technologies.
Regulatory RiskHighThe notice tests the outer limits of India's cyber laws by seeking removal of entire repositories based on architectural design. If upheld, it would grant regulators expansive powers to block any open-source tool that can function during shutdowns, increasing compliance costs for code-hosting platforms and developers.
Reputation RiskMediumGitHub's handling of the request could affect its standing with the open-source community. Transparency and a willingness to challenge overbroad orders are expected, and any perceived heavy-handed compliance could damage its reputation as a neutral developer platform.
Technology DisruptionLowThe underlying technology of Bitchat (Bluetooth mesh) is well established and cannot be easily eliminated. Even if repositories are removed, existing installations continue to work and the code can circulate through other channels. The disruption is more legal and procedural than technological.
Commercial OpportunityLowNo direct commercial benefit emerges from the takedown attempt. The heightened attention could temporarily boost downloads of privacy-focused apps, but the regulatory climate in India likely deters investment in censorship-resistant technologies.