Yandex's Alice neural network, integrated into the Max messenger, is advising users in chats to install alternative messengers — Telegram, Signal, or WhatsApp — instead. The outlet Verstka drew attention to this.

When asked about Max's security, the neural network, created by Yandex, lists the messenger's vulnerabilities, including the lack of end-to-end encryption and the transfer of data to VK servers.

"The messenger collects IP addresses, activity times, contacts, device and browser type, provider information, and other metadata. This data may be transferred to third parties, including government agencies, upon lawful request (for example, a court order or a reasoned request from authorized bodies)," the neural network warns.

Alice recommends using a separate smartphone (a "maxphone") for Max and not installing the messenger on a primary device that contains banking apps, confidential chats, and other personal data the user wants to protect from the state. If Max must be used on a personal phone, Alice suggests using the browser version and denying the app constant access to geolocation, contacts, microphone, and camera.

Alice also reminded that Max was found to have a forced update system bypassing app stores, a neural network for analyzing voice calls, and a vulnerability allowing third parties to edit correspondence on the user's device. "Although developers deny some accusations, such findings raise questions about the system's transparency," the neural network emphasized.

Experts and researchers have repeatedly called Max spyware. Mikhail Klimarev, head of the Internet Protection Society, noted that the privacy policy explicitly states data transfer upon request to the FSB, the Interior Ministry, the Federal Tax Service, and the Bank of Russia. Researchers on GitHub, after analyzing the app's APK file, found that it tracks processes on the device, collects geolocation, a full list of installed programs, and can record audio, video, and typed text. The messenger can also determine the real IP address when a VPN is enabled and uses a built-in device identifier that cannot be reset even after deleting the app or restoring the phone to factory settings.