theSHFT ← Back to Home

Law Enforcement Guidelines

Last Updated: October 5, 2026

Effective Date: October 5, 2026

Version: 2.0

These guidelines explain, for law enforcement officers, prosecutors, courts and other government authorities, what information theSHFT LLC holds, what it cannot provide, and how to send legal process. They describe our practices on the Last Updated date; they are not legal advice, do not create rights for anyone, and may change. We respond to valid legal process under applicable U.S. law and we do not voluntarily disclose user information except as described here and in our Privacy Policy.

1. CONTACT AND SERVICE OF PROCESS

Email: support@theshft.app

Mail: theSHFT LLC, Attn: Legal, 212 W. Troy St., Ste B, Dothan, AL 36303, United States

Please send legal process by email from an official government email address, with the subject line beginning "LEGAL PROCESS," "PRESERVATION REQUEST" or "EMERGENCY DISCLOSURE REQUEST" as the case may be. We accept service of law enforcement legal process by email at the address above as a courtesy; accepting it does not waive any objection, including to jurisdiction. We aim to acknowledge requests within five (5) business days. This is a goal, not a guarantee.

Please identify each account by its exact username. Usernames cannot be changed, but when an account is deleted its username is released and may later be used by a different account, so please also give the date or period of the activity you are asking about.

2. END-TO-END ENCRYPTION: WHAT WE CANNOT PRODUCE

theSHFT direct messages (1-on-1 and group) are end-to-end encrypted using the NaCl cryptographic library and the Signal Double Ratchet protocol, with an ML-KEM-768 post-quantum hybrid layer whenever the recipient's device has published a post-quantum key. In group chats the layer applies only when every member has published one, and a group key issued after a member leaves or is removed is not protected by it. Group chats also use Sender Keys. Photos, videos, voice notes and files sent in those conversations, and voice and video calls, are also end-to-end encrypted. Which accounts reacted to a message is not end-to-end encrypted; the emoji is, except for reactions sent from versions before 9.5.

The keys needed to decrypt this content are created and stored only on users' devices. We do not have them, and we have not built any means to obtain them. We therefore cannot produce the content of direct or group messages, their attachments, or calls, whether or not a message has expired.

We also cannot produce: a user's PIN, recovery phrase or private keys; content deleted by a disappearing message timer, by "delete for everyone," by an account deletion or by a contact removal (a preservation request does not currently stop deletions a user starts; see Section 5); the contents of a user's device address book (the application never reads it); or GPS or other precise location data (the application does not collect it; since version 9.5 it removes embedded location from photos and videos before they are sent, although media posted from older versions, and some kinds of files, may carry location the device embedded in them).

3. WHAT WE MAY HOLD

What follows is what our systems may contain for an account. Whether a given record exists depends on how the account was used and on when we receive your request, because much of it is deleted automatically.

3.1 Account records

  • Internal account identifier and username; bio, profile photo and chosen SHFT look (outfit, color and pose), if set
  • Account creation time
  • Public encryption keys and safety number inputs
  • The account's recovery key, a public key computed from the recovery phrase that our servers use to find the account when the user restores it on a new device (an account that has not opened version 9.5 or later may still have a one-way hash of the phrase instead, and a keyed fingerprint of a replaced hash is kept for one year); neither can be turned back into the phrase. Because the hash works like a password for restoring the account, we will not produce it without a court order and will ask the court to protect it
  • The age confirmation record: the minimum age shown, the region reported by the device, the country associated with the network connection at sign up, and the time
  • Subscription status and product (from Apple through our subscription provider); we do not have payment card or billing details
  • Records of acceptance of our terms (versions and times)
  • Moderation records: warnings, suspensions, bans, reports about or by the account, and appeals, and device restriction records after a ban
  • Purchase records: App Store transactions, promotion code redemptions, state code records and sales representative commission records
  • A referral code, if the user entered one
  • Push notification tokens, while notifications are enabled, and the random installation identifier of the device used with the account
  • Current online status and last seen time, where the user's settings let the application write them

3.2 Contact lists and relationships

  • The account's contacts list (account identifiers and usernames), contact relationship records and pending contact requests
  • Invitation records (who created an invitation and who redeemed it)
  • Accounts the user has blocked

3.3 Conversation records (not content)

  • Participants of each conversation, group names, group photos and member roles, and the conversation creation time
  • For messages we still store: the sender and recipient account identifiers and usernames, when each was sent, delivered and read, the message type, the disappearing message timer and expiry time, and reactions (the account identifiers of the people who added them; the emoji only for reactions sent from versions before 9.5). We store an end-to-end encrypted message only until it is read and its timer runs out; a timed message nobody opens is deleted three (3) days after it was sent, or three (3) days plus the timer for a seven (7) or thirty (30) day timer; a message with no timer that has had no expiry is deleted after one (1) year. The encrypted payload itself cannot be decrypted by us.
  • Push routing references, when used, which point to a sender and a conversation and are kept for seven (7) days
  • Contact removal signals (thirty (30) days) and removal records on accounts
  • Streak records (two account identifiers and times) and invitation records
  • Call setup records (caller, callee, whether video, and times), which exist while a call is ringing or in progress; one to one records are deleted when the call ends or within about twelve (12) hours, and a group call record is deleted when its last participant leaves, or by our servers within about seven (7) hours after the call started

3.4 Content we can read

  • Community posts, replies, polls and images, and Community names, descriptions, rules, member lists and moderation logs. Community content remains until it is deleted; posts removed by moderators are hidden, not always deleted.
  • Community votes (the voter's account identifier and the direction of the vote; an upvote is shared with the post's author only, a downvote is stored in a record only the voter's own account can read and is never shared with anyone, including that post's author); votes on replies are stored on the reply with the voter's account identifier
  • Stories, their captions, reactions and viewer lists, until the Story is deleted. Stories expire twenty four (24) hours after posting and are deleted by a job that runs every thirty (30) minutes.
  • Profile photos and group photos (encrypted at rest with keys our servers hold)
  • Reports filed by users, including any text or copy of server-readable content saved with the report, and appeal text
  • Voice room listings (not the audio)
  • Bug reports, data export files requested by the user, and records of Keep requests where that feature is on

3.5 Logs and network information

  • Our hosting provider's logs of our server functions and our real time relay are kept under its default settings for about thirty (30) days. They record operations and can include account identifiers, conversation identifiers and, for relay connections, network (IP) addresses. We do not store IP addresses in our databases in readable form.
  • Short lived rate limit records keyed to a shortened hash of a network address, kept for hours to a few days. Because such a hash could be matched back to the address, we treat it as a network address.

4. REQUIRED LEGAL PROCESS

4.1. Subpoena. A valid subpoena may compel basic subscriber records under 18 U.S.C. 2703(c)(2), such as the username, account creation time, subscription status and the records in Section 3.1 that fall within that provision.

4.2. Court Order Under 18 U.S.C. 2703(d). A 2703(d) order may compel other non-content records, such as those in Sections 3.2, 3.3 and 3.5.

4.3. Search Warrant. A search warrant issued under the Federal Rules of Criminal Procedure or equivalent state procedure is required for content we can read (Section 3.4). No warrant can compel end-to-end encrypted content, because we do not have the keys.

4.4. Real Time Orders. Orders under the Wiretap Act or the Pen Register statute will be evaluated case by case. We cannot intercept end-to-end encrypted content in readable form.

4.5. National Security Process. We respond to National Security Letters and orders under the Foreign Intelligence Surveillance Act as the law requires.

4.6. Civil Litigants. The Stored Communications Act generally prohibits us from disclosing the contents of communications in response to a civil subpoena. Parties to civil cases should seek information from the account holder, who may be able to export some of their own account information in the application.

4.7. Records Authentication. On request we can provide a declaration of authenticity for records we produce. We do not provide live testimony without a subpoena and a reasonable opportunity to respond.

4.8. Costs. Where the law allows, we may seek reimbursement of costs reasonably incurred in responding.

5. PRESERVATION REQUESTS

Send preservation requests under 18 U.S.C. 2703(f) to support@theshft.app with the subject line beginning "PRESERVATION REQUEST." Include the usernames, the time period and the categories of records to be preserved. On a valid request we will take reasonable steps to preserve the records we hold for the named accounts on the date we receive it, for ninety (90) days, and for a further ninety (90) days on a renewed request.

What preservation does in our systems: it stops our scheduled deletion jobs from deleting server copies of messages the named accounts sent and of one-to-one messages sent to them (still encrypted), their Stories and related server-readable records while the preservation is in place. In a group conversation it preserves the messages the named account sent, not those other members sent. It does not stop short lived records, such as call setup records and rate limit counters, from expiring, and it does not stop the removal of suspected child sexual abuse material from view. It does not allow us to decrypt anything, and it cannot recover anything already deleted. Preservation does not currently stop every deletion a user starts, such as deleting the account, deleting a message for everyone or removing a contact, from removing server copies; if you need an account frozen against user action, say so in your request and we will tell you what we can do.

6. REQUESTS FROM OUTSIDE THE UNITED STATES

theSHFT LLC is a U.S. company. Foreign authorities should use a Mutual Legal Assistance Treaty request, letters rogatory or, where one applies, an agreement under the U.S. CLOUD Act. We may respond to an emergency request from a foreign authority as Section 7 describes.

7. EMERGENCY DISCLOSURE

Under 18 U.S.C. 2702(b)(8) and (c)(4), we may disclose information to a government entity if we believe in good faith that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay. Send emergency requests to support@theshft.app with the subject line beginning "EMERGENCY DISCLOSURE REQUEST" and include: the nature of the emergency; the accounts involved; the information requested and how it would help prevent the harm; and the name, agency, badge or identification number and contact details of the requesting officer. We review emergency requests as quickly as we can. We may require legal process after the emergency has passed.

8. CHILD SAFETY

theSHFT LLC reports apparent, planned, or imminent violations that 18 U.S.C. 2258A covers, including child sexual abuse material and the enticement or sex trafficking of a minor, to the CyberTipline of the National Center for Missing and Exploited Children (NCMEC) when we become aware of them, and preserves reported material as that law requires. We learn of such material through user reports and through automated checks of community posts; we do not and cannot scan end-to-end encrypted messages. We cooperate with law enforcement investigations arising from CyberTipline reports. We preserve what we report, including the reported content and the reported account's identifying information, for one year from the date of the report, as 18 U.S.C. § 2258A(h) requires, except under a time-limited legal hold. See Privacy Policy Section 24 for the full retention schedule.

9. NOTICE TO USERS

Our policy is to tell users about legal process that seeks their information before we disclose it, where we are permitted to by law and able to reach them. Because we do not have users' email addresses or phone numbers, notice is given inside the application, which the user may not see if they no longer use it. We do not give notice where a court order or statute prohibits it (for example an order under 18 U.S.C. 2705(b)), where notice would risk harm to a person, in an emergency, or for preservation requests. If your process is accompanied by a non-disclosure order, please attach it. We may give notice after a non-disclosure period ends.

10. AUTHENTICATION OF REQUESTS

To protect users from fraudulent requests, we verify legal process before responding. We may require that a request come from an official government email domain, may contact the issuing agency through publicly listed contact details, and may decline requests we cannot verify.

11. TRANSPARENCY

We do not currently publish a transparency report. If we begin to publish one, it will be on our website.

12. CONTACT

Legal process and preservation: support@theshft.app

Mail: theSHFT LLC, Attn: Legal, 212 W. Troy St., Ste B, Dothan, AL 36303, United States

Website: https://theshft.app

© 2026 theSHFT. All rights reserved. | Home | Privacy Policy | EULA | Community Guidelines | Law Enforcement Support