Law Enforcement Requests
Effective September 7, 2026 · version lawenforcement-v3
The short version
The short version: we respond to valid legal process from authorities with jurisdiction over us, and to nothing less. We cannot read your messages, we do not keep your IP addresses beyond our hosting provider’s short-lived logs, and we hold no history of how you use the app — so those are not ours to hand over, whoever asks. Where the law allows it, we tell you before we disclose anything about your account. We publish the number of requests we receive, and how many we complied with.
1. What This Policy Covers
This policy explains how Enso handles requests from law enforcement, courts, and government authorities for user information. It applies to every such request, wherever it comes from.
We are based in Canada and our data is hosted in Canada. We respond to valid legal process issued by authorities with jurisdiction over us. A request from an authority without that jurisdiction is not something we are obliged to act on, and we will not act on it voluntarily.
2. What We Cannot Produce
Some things are not withheld by policy — they do not exist to be handed over:
- The content of your direct and group messages. These are end-to-end encrypted. Our servers hold ciphertext, and the keys are on your device. We cannot decrypt them, for anyone, under any order.
- Your IP addresses. We do not store them in our own records. Our hosting provider keeps short-lived infrastructure logs that may contain them for no more than 28 days, after which they are gone.
- A history of how you use the app. Usage analytics are recorded against a pseudonymous identifier that rotates every 30 days and is never linked to your account, and the underlying records are deleted after 30 days.
- Continuous or historical location tracking. We never collect it. We hold the location of events you chose to create, and which events you joined — nothing else.
We designed it this way on purpose. A platform that holds less can be compelled to disclose less.
3. What We May Hold
Depending on the account and how it has been used, we may hold:
- Account basics: the phone number or email used to sign in, profile details you entered, and the date the account was created.
- Verification record, if the account completed ID verification: that it passed, when, Stripe’s reference number, and two one-way fingerprints. We do not hold the name, date of birth or document details; under valid legal process those would have to be obtained from Stripe, and any retrieval by us is logged.
- Connection and event activity: who an account connected with and when, and events created or joined, including the location of those events.
- Message metadata: who messaged whom and when — but never what was said.
- Recent session records: device name and model, operating system, and an approximate city derived from the network address at sign-in, kept for up to 90 days.
- Content posted to the app: posts, stories, comments, and reports.
4. What We Require
We require valid legal process appropriate to what is being sought, and we will say no to requests that do not meet it.
- Basic subscriber information requires a production order or equivalent court order.
- Content and detailed records require a warrant or equivalent judicial authorization.
- Preservation requests are accepted and honoured for a limited period, but a preservation request alone does not produce anything — it only pauses deletion pending valid process.
Requests must be specific. We reject requests that are overly broad, that seek information about groups of users rather than identified accounts, or that ask us to conduct ongoing monitoring.
We do not provide bulk or direct access to our systems, and there is no interface by which any authority can query our data independently.
5. Emergency Requests
Where we receive a credible request indicating a risk of death or serious physical harm to a person, we may disclose the limited information needed to address that risk without waiting for legal process. We assess each such request on its facts, we disclose only what is necessary, and we record it. These are counted separately in our transparency reporting.
6. Telling You About It
Our default is to notify you before we disclose information about your account, so that you have the opportunity to object.
We will not notify you in advance where we are legally prohibited from doing so, or where we believe notice would create a risk of death or serious harm, or of destruction of evidence. Where a prohibition on notice expires, our practice is to notify you then.
7. Transparency Report
Reporting period: since launch, to 7 September 2026.
- Requests received from law enforcement or government: 0
- Accounts affected: 0
- Requests where we produced information: 0
- Emergency disclosures: 0
- Preservation requests received: 0
We update these figures periodically. Where a figure is zero, it is zero because nothing was received — not because we are unable to say.
8. Warrant Canary
As of 7 September 2026, Enso has never:
- received a national security letter or equivalent secret demand;
- received an order compelling us to weaken, backdoor, or otherwise undermine the encryption of user messages;
- received a gag order preventing us from disclosing the existence of a request;
- handed over user data to any government or law enforcement body.
We intend to restate this periodically. If this section is removed, stops being updated, or changes, readers should draw their own conclusions — that is the point of it.
9. How to Submit a Request
Law enforcement requests should be sent to legal@ensosocial.app from an official government email address, and must identify the requesting agency, the officer responsible, the accounts at issue, and the legal authority relied on.
This address is for legal process only. If you are a user with a question about your own data, use Settings → Support, or the data export and deletion tools in Settings, which give you your information directly and without needing to ask us.
Enso is operated by Ashish, an individual carrying on business as a sole proprietor in Ontario, Canada. Service by email to legal@ensosocial.app is accepted; a postal address for formal service is available on request from the same address.