Law Enforcement Requests
We cooperate with the justice system within the law, verify every request and disclose only what it covers.
Versjon 2026-09-21 · Versjonshistorikk
Kun mal — få alle juridiske tekster gjennomgått av en fagperson.
This page is not yet available in your language; showing English.
Submitting a request
Requests from authorities (court order, police request, warrant) must be sent to [email protected]. They must state the authority and its legal basis, the case or order number, the account or accounts concerned and the specific data requested.
If there is an imminent threat to someone's life or safety, say so in the subject line; such requests are handled first.
Data that exists
| Data | Does it exist? | Retention |
|---|---|---|
| Account and profile information | Yes | While the account is active |
| Public and private media | Yes | As long as the member keeps them |
| Messages | Yes | While the account is active |
| Phone number | Only if the member provided it | While the account is active |
| Login logs | Yes | Limited period needed for security |
| Payment history | Yes, without card numbers | As long as accounting obligations require |
| Verification template | Yes, non-reversible | Until its purpose is fulfilled, no later than 3 years after the last interaction |
Verifying the request
We verify the authenticity of each request and the jurisdiction of the issuing authority. A request from one country does not automatically bind us: we examine the law that applies to the situation.
Challenges
We challenge requests that are excessive, overly broad or unfounded. We extract only what the request covers: an order about one incident does not justify exporting an entire account.
Preservation (legal hold)
On a valid request, we can freeze the data of an account subject to proceedings so that it is not automatically deleted while the proceedings are ongoing.
Notifying the member
We tell the member that their data has been accessed, unless the law or a non-disclosure order prohibits it.
Controlled access
- No staff member has standing access to private data.
- Every exceptional access requires a reason and a case reference, is limited to the accounts concerned and expires automatically.
- Private conversations and verification data require approval from two senior administrators.
- Every access is written to a log that can be neither altered nor deleted.
What we can never provide
- Passwords: they are irreversibly hashed.
- Payment card numbers: we never store them.
- An image of a member's face from their verification template: the template is non-reversible by design, and the captured image is deleted immediately.
Transparency
Every request received and how it was handled is recorded, and the totals are published in our transparency report.