Law Enforcement Guidelines
What process is required for what data, and what we cannot give.
The operator has not yet published: legal entity name, registered address, governing law / jurisdiction, legal contact address, privacy contact address. Each missing item is marked in the text below. Until they are published this service should not be taking money from the public.
For law enforcement and government agencies. Everyone else: this page tells you what we will and will not hand over about you.
Where to send legal process
[not yet published: law-enforcement contact address] — [not yet published: legal entity name], [not yet published: registered address].
Include the legal basis, the specific accounts or records sought, and a return address we can verify. We do not act on requests sent from free email accounts without verification.
What is required
| What you want | What we need |
|---|---|
| Preservation of records | A written preservation request. We preserve for 90 days, renewable once. |
| Basic subscriber information | A subpoena or equivalent legal process |
| Non-content records (login times, signalling records) | A court order or equivalent |
| Message content | A search warrant on probable cause, or the equivalent in the requesting jurisdiction |
What we can and cannot give you
A warrant for message content returns what we actually hold, which is this:
- Ordinary chats, on or after 26 July 2026: readable text. They are not end-to-end encrypted. Earlier versions of these documents said they were; that was wrong, and correcting it means saying plainly that this content is obtainable.
- Private chats: ciphertext only. Either party can make a direct conversation private, after which the two devices encrypt to each other. We hold what we are given, which is ciphertext, and we have no key. We will not build one.
- Messages sent before 26 July 2026: ciphertext only. Those were end-to-end encrypted. We hold the wrapped private key but it is sealed with the user's password, which we do not have, and we will not build a way to open it.
- Call audio and video: nothing. Calls are encrypted between the participants and never pass through us in a readable form. A large meeting passes through LiveKit, which forwards it and does not store it. We can show that a call happened. The one exception is a cloud recording of a meeting, which we hold for two days.
- Media files — photos, videos, voice notes — are held as files and can be produced.
Emergencies
Where we believe in good faith that there is an imminent risk of death or serious physical harm, we may disclose what is necessary to prevent it, without waiting for process. Mark the request URGENT and state the emergency.
Notice to users
Our policy is to tell a user before disclosing their data, so they can object, unless we are legally prohibited from doing so or there is an emergency as above. Where a non-disclosure order expires, we notify then.
Requests we refuse
Requests that are overbroad, that lack a legal basis in a jurisdiction that binds us, or that would require us to break the law somewhere else, are refused or narrowed. We say so in the Transparency Report.
What has changed
24 September 2026 · version 4
- Call audio and video: a large meeting passes through LiveKit, which does not store it; we still hold no copy unless a cloud recording was made.
20 September 2026 · version 3
- Private chats: content is ciphertext we cannot produce.
20 September 2026 · version 2
- CORRECTION. This document said direct messages were end-to-end encrypted. They have not been since 26 July 2026: we can read message text sent on or after that date. Messages sent before it remain ciphertext we cannot open, and calls are still encrypted between the people on them.
- "What we cannot give you" is now "What we can and cannot give you", and says that message content on or after that date is obtainable on a warrant.
12 July 2026 · version 1
- First published.