Transparency
We respond to legally binding requests, and we can only produce what we actually hold. Because message content is end-to-end encrypted, the answer to most requests is that we do not have it.
How to serve a request
Send legal process to xiaosan9288@gmail.com with "Legal request" in the subject line. Requests must identify the account by the exact identifier you already hold, state the legal authority relied on, and be signed by the issuing authority.
What we can provide
- Whether an account exists for a given identifier.
- The date the account was created, and the date it last connected, at day-level precision.
- The email address on file for the account.
What we cannot provide
- Message content, past or future.
- Voice or video call content.
- Attachments, in readable form.
- Group names, group membership, or profile names and photos.
- Contact lists. We never receive them.
- A list of who a given account has communicated with.
We will not build a capability to intercept or decrypt content in order to satisfy a request. If a demand cannot be met without doing so, we will say that it cannot be met.
Notifying users
Where the law allows it, we notify the affected user before disclosing anything, so that they have an opportunity to respond. Where a valid order forbids notification, we comply with the order and notify once the restriction lapses.
Reporting period
We publish the number of requests received and the number complied with. Vutalk is newly launched and no reporting period has closed yet; the first report will appear on this page.