Privacy · version 0.1.0 · effective: DRAFT

Government and Law Enforcement Requests

DRAFT — requires review by qualified counsel in each jurisdiction. Not in force.

In one line

We hand over customer data only when the law truly requires it, we push back on overbroad requests, and we tell you unless we are legally barred.

The short version

This short version helps you understand the full text. Read the full text for the complete terms.

  • We require valid legal process, such as a court order or warrant, before we disclose customer data. (Full text, section 1)
  • We check every request and challenge ones that are unclear, overbroad, or from the wrong place. (Section 2)
  • We tell the customer before we disclose, unless the law forbids it or someone's life is at risk. (Section 3)
  • We will publish a yearly count of requests. So far we have received none. (Section 4)

Full text

Read the full text (about 1 minute)

1. Valid process only

We disclose customer data to a government body only if the request is in writing, is legally valid and binding on us, and is limited to specific data. Emergency requests involving an imminent risk of death or serious injury are considered case by case.

2. Review and challenge

We review each request with counsel. We seek to narrow or challenge requests that are overbroad, lack a legal basis, or conflict with the law of the country where the person is protected (for example, GDPR Article 48 on foreign court orders).

3. Notice

We notify the affected customer before disclosure, so it can seek a remedy, unless the law forbids notice or notice would create a risk of harm. If a ban on notice ends, we notify then.

4. Transparency

We will publish the number and type of requests received each year on the trust change log. As of 10 October 2026 we have received no requests.

Change log

  • 2026-10-10 · 0.1.0 · First draft.

Open questions for counsel

We publish these while the page is a draft, so you can see what is not settled yet.

  • US CLOUD Act exposure depends on the entity and providers; review with transfer impact assessments.
  • Confirm the "no requests" statement is true at publication.

Useful for: Business owners, IT and security reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.