← Back to Pollis

Legal requests

Every legal or government demand for user data Pollis has received, what was handed over, and a warrant canary. Last updated 1 October 2026.

This is a conventional transparency report: legal process served on the operator, and what came of it. The transparency log is something else, a signed record of keys and builds.

Message content is end-to-end encrypted, so the operator has no messages to hand over. The most a request could obtain is the metadata listed in the privacy policy and on the retention page.

Transparency report

Covers every request received from the launch of the open preview through 30 September 2026. Published every six months; the next one covers October 2026 through March 2027.

CategoryReceivedComplied withAccounts affected
Subpoenas and court orders for user data000
Search warrants000
Emergency disclosure requests000
National security requests (NSLs, FISA orders)000
Foreign government requests000
Requests to remove content or accounts000
Requests to modify the software or keys000

How requests are handled

  • Users are notified before anything is disclosed, unless a court order legally prohibits it. When a gag order expires, notice is sent then.
  • Only valid legal process is honoured, scoped to named accounts. Informal or bulk requests are refused, and overbroad ones are challenged.
  • What can be disclosed is limited to account email, public keys, device list, group and channel membership, and timestamps, for as long as the retention rules keep them. With sealed sender the server does not record who sent a given message, so that cannot be produced.
  • Nothing is built on demand. A request to ship a modified build, add a key or weaken encryption would be refused. Such a build would also be visible: every release is recorded in the signed binaries tree, and the Linux build is independently rebuilt from source (see assurance).

Legal process goes to dankral01@gmail.com. Pollis is currently operated by an individual, not a company; see who runs Pollis.

Warrant canary

As of 1 October 2026, the operator of Pollis states that:

  1. No warrant, subpoena or court order for user data has been received.
  2. No National Security Letter, FISA order, or other secret legal process has been received.
  3. No gag order preventing disclosure of any of the above is in effect.
  4. No request has been received, or complied with, to modify the software, insert a backdoor, or disclose or change any signing key.
  5. No user data has been disclosed to any government, law enforcement agency or other third party. The infrastructure providers that host the service store and carry its encrypted traffic without being given access to it; what each one can observe is listed on the subprocessors page.

This statement is renewed at least every three months. The next renewal is due by 1 January 2027.

How to read it. A canary works by absence: if this page is not renewed by its due date, or a numbered statement disappears without explanation, assume the worst about that statement. Its history is in the repository's commit log, so a quiet edit is visible too.

Where this ends

The canary is one person's statement, published through the GitHub account and website it describes. It is not anchored in the signed transparency log, so it rests on that person's word and the public edit history, not a cryptographic signature. The legal effect of canaries varies by jurisdiction and has never been tested in court.