As of mid-2026, an interim EU rule ("Chat Control 1.0") lets platforms voluntarily scan unencrypted messages, reinstated July 2026 and running until 2028 — end-to-end encrypted traffic like this app's is explicitly outside that scope. A separate, permanent regulation ("Chat Control 2.0", formally the CSAR) is still being negotiated, not adopted, with talks resuming in September 2026. This section is about that second, unresolved one, since it's the one that could someday touch encryption.
It would very likely not mean automatic, blanket scanning. The European Parliament's negotiating position centers on targeted, judicially-authorized "detection orders" against specific, identified providers — not a rule that every app must silently build in scanning. Whether Cherry2Cherry could ever realistically be targeted by such an order is a separate, open question — but a global "must scan everything" mandate is not what's currently on the table.
A copy you already have can't be changed by a future law. Any copy of this file that already exists — downloaded, burned to a CD, wherever — is just static bytes. No regulation can reach back and alter code that's already sitting on your device; a legal requirement, if one ever applied, could only affect future versions someone chooses to build and distribute.
A tool with no ongoing operator is an odd fit for this kind of order. Detection orders target a "provider" actively running a service. Once you've downloaded this file, there's no server, account, or ongoing operation left for anyone to compel — the developer's involvement effectively ends at the point you got the file. That doesn't guarantee anything, since the final legal text (and how broadly "provider" ends up defined) isn't settled, but it's a real structural difference from a hosted platform.
None of this is legal advice — it's a factual summary of where things stand as of this writing, on a topic that's still actively moving. If it matters for your specific situation, check current sources or talk to a lawyer.