Legal
Transparency
Last updated: September 2026 · reviewed quarterly
What we hold
"Designed to forget" is a claim, so here is the auditable inventory behind it. If this table ever drifts from reality, this page is wrong and we fix the page or the architecture — not the other way around.
| Data | Held? | Lifetime | Notes |
|---|---|---|---|
| File contents | No | Ciphertext only (End-to-end mode) | In End-to-end mode the relay forwards ciphertext only; Transport-only mode is relay-carried by design |
| Keys / room secrets | No | — | Derived in your browser; never transmitted to us |
| Accounts, emails, address books | No | — | No registration exists |
| IP addresses | No | — | Stripped before any log write; invariant is automated |
| Room / transfer state | Ephemeral | In-memory only; gone on disconnect or restart | Never persisted, never backed up |
| Operational logs | Yes | Rotating (~150 MiB window) | Timestamp, method, path, status, latency, bytes — no addresses |
| Metrics | Yes | Prometheus retention | Counters/gauges only; no per-user dimension |
| TURN credentials | Ephemeral | Minutes | Minted per session, never retained |
Join identifiers are not recorded in access logs: short-link paths
(/s/<token>) are skipped at the server, a room code
is never part of a URL, and logged request lines carry the request path with timing and
status fields only — no code, no token.
When we are asked
Four honest answers to the four things authorities can ask for:
- Content or plaintext: we cannot produce it — in End-to-end mode it never exists on our infrastructure in recoverable form. (Transport-only mode is relay-carried by design: those bytes stream through the relay — pick End-to-end when confidentiality from the relay matters.)
- Metadata or traffic data: we do not retain IP addresses or per-user identifiers; there is no historical set to hand over.
- Live interception: a state could in principle compel infrastructure-level interference with a live session. We do not architect for it, and if we are ever compelled we will say so on this page to the maximum extent the law allows.
- Preservation orders (e.g. EU e-evidence, in force since 18 August 2026): an order can only freeze data that exists. We hold no content and no persistent identifiers, so the producible set is empty — and we confirm that in writing, per request.
Standing counters
Published every quarter, even when flat. Zeros are stated positively — never left blank.
Period: 2026-Q3 Government / law-enforcement content requests received: 0 ... of which produced any user content: 0 Preservation orders received: 0 Takedown / content-removal demands honoured: 0 Account-termination demands (no accounts exist): 0 Warrant canaries / gag orders restricting disclosure: 0 National-security letters / orders: 0 Third-party (non-government) data requests: 0
Independent review
Status: none yet — no third-party security audit has been completed to date. A review is scheduled for 2027-Q1; the dated status lives at /security/audit and is updated when its state changes. Stating the gap is deliberate: a trust surface that only reports good news is a marketing page, not a trust surface.
Canary
A signed statement covering the categories above will appear monthly once our offline signing-key ceremony is complete. The point of a fixed cadence: omission of a scheduled statement is itself the signal. The statement format, the signing-key fingerprint slot and the last-signed / next-due fields live at /canary.
Jurisdiction & legal basis
Operated from Helsinki, Finland (EU); infrastructure is EU-only (single EU provider —
Hetzner, Helsinki). Both relay hostnames,
relay.sendtallow.com and
relay-us.sendtallow.com, are aliases of that same relay
process: relay-us is a legacy name kept alive for older
clients, not separate (or US-based) infrastructure.
We rely on data minimisation as a design property under the GDPR, and on the DSA's
no-general-monitoring rule (Art. 8) as an intermediary. We do not claim to be in
scope of NIS2 (below the size cap, non-listed sector). If any of this ever changes,
this page changes first, with the change named.
What would change this page
Adding accounts, retention, analytics, a CDN, or a non-EU subprocessor. Each of those is a page-triggering event, and the review checklist for any new dependency starts with one question: does this change the inventory above?
In short
- We hold nothing to produce: no files, no keys, no IPs, no accounts
- Requests are answered in writing, narrowly, and logged on this page
- Counters published quarterly; a signed canary follows the key ceremony