These guidelines explain, for law enforcement officers, prosecutors, courts and other government authorities, what information theSHFT LLC holds, what it cannot provide, and how to send legal process. They describe our practices on the Last Updated date; they are not legal advice, do not create rights for anyone, and may change. We respond to valid legal process under applicable U.S. law and we do not voluntarily disclose user information except as described here and in our Privacy Policy.
Email: support@theshft.app
Mail: theSHFT LLC, Attn: Legal, 212 W. Troy St., Ste B, Dothan, AL 36303, United States
Please send legal process by email from an official government email address, with the subject line beginning "LEGAL PROCESS," "PRESERVATION REQUEST" or "EMERGENCY DISCLOSURE REQUEST" as the case may be. We accept service of law enforcement legal process by email at the address above as a courtesy; accepting it does not waive any objection, including to jurisdiction. We aim to acknowledge requests within five (5) business days. This is a goal, not a guarantee.
Please identify each account by its exact username. Usernames cannot be changed, but when an account is deleted its username is released and may later be used by a different account, so please also give the date or period of the activity you are asking about.
theSHFT direct messages (1-on-1 and group) are end-to-end encrypted using the NaCl cryptographic library and the Signal Double Ratchet protocol, with an ML-KEM-768 post-quantum hybrid layer whenever the recipient's device has published a post-quantum key. In group chats the layer applies only when every member has published one, and a group key issued after a member leaves or is removed is not protected by it. Group chats also use Sender Keys. Photos, videos, voice notes and files sent in those conversations, and voice and video calls, are also end-to-end encrypted. Which accounts reacted to a message is not end-to-end encrypted; the emoji is, except for reactions sent from versions before 9.5.
The keys needed to decrypt this content are created and stored only on users' devices. We do not have them, and we have not built any means to obtain them. We therefore cannot produce the content of direct or group messages, their attachments, or calls, whether or not a message has expired.
We also cannot produce: a user's PIN, recovery phrase or private keys; content deleted by a disappearing message timer, by "delete for everyone," by an account deletion or by a contact removal (a preservation request does not currently stop deletions a user starts; see Section 5); the contents of a user's device address book (the application never reads it); or GPS or other precise location data (the application does not collect it; since version 9.5 it removes embedded location from photos and videos before they are sent, although media posted from older versions, and some kinds of files, may carry location the device embedded in them).
What follows is what our systems may contain for an account. Whether a given record exists depends on how the account was used and on when we receive your request, because much of it is deleted automatically.
4.1. Subpoena. A valid subpoena may compel basic subscriber records under 18 U.S.C. 2703(c)(2), such as the username, account creation time, subscription status and the records in Section 3.1 that fall within that provision.
4.2. Court Order Under 18 U.S.C. 2703(d). A 2703(d) order may compel other non-content records, such as those in Sections 3.2, 3.3 and 3.5.
4.3. Search Warrant. A search warrant issued under the Federal Rules of Criminal Procedure or equivalent state procedure is required for content we can read (Section 3.4). No warrant can compel end-to-end encrypted content, because we do not have the keys.
4.4. Real Time Orders. Orders under the Wiretap Act or the Pen Register statute will be evaluated case by case. We cannot intercept end-to-end encrypted content in readable form.
4.5. National Security Process. We respond to National Security Letters and orders under the Foreign Intelligence Surveillance Act as the law requires.
4.6. Civil Litigants. The Stored Communications Act generally prohibits us from disclosing the contents of communications in response to a civil subpoena. Parties to civil cases should seek information from the account holder, who may be able to export some of their own account information in the application.
4.7. Records Authentication. On request we can provide a declaration of authenticity for records we produce. We do not provide live testimony without a subpoena and a reasonable opportunity to respond.
4.8. Costs. Where the law allows, we may seek reimbursement of costs reasonably incurred in responding.
Send preservation requests under 18 U.S.C. 2703(f) to support@theshft.app with the subject line beginning "PRESERVATION REQUEST." Include the usernames, the time period and the categories of records to be preserved. On a valid request we will take reasonable steps to preserve the records we hold for the named accounts on the date we receive it, for ninety (90) days, and for a further ninety (90) days on a renewed request.
What preservation does in our systems: it stops our scheduled deletion jobs from deleting server copies of messages the named accounts sent and of one-to-one messages sent to them (still encrypted), their Stories and related server-readable records while the preservation is in place. In a group conversation it preserves the messages the named account sent, not those other members sent. It does not stop short lived records, such as call setup records and rate limit counters, from expiring, and it does not stop the removal of suspected child sexual abuse material from view. It does not allow us to decrypt anything, and it cannot recover anything already deleted. Preservation does not currently stop every deletion a user starts, such as deleting the account, deleting a message for everyone or removing a contact, from removing server copies; if you need an account frozen against user action, say so in your request and we will tell you what we can do.
theSHFT LLC is a U.S. company. Foreign authorities should use a Mutual Legal Assistance Treaty request, letters rogatory or, where one applies, an agreement under the U.S. CLOUD Act. We may respond to an emergency request from a foreign authority as Section 7 describes.
Under 18 U.S.C. 2702(b)(8) and (c)(4), we may disclose information to a government entity if we believe in good faith that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay. Send emergency requests to support@theshft.app with the subject line beginning "EMERGENCY DISCLOSURE REQUEST" and include: the nature of the emergency; the accounts involved; the information requested and how it would help prevent the harm; and the name, agency, badge or identification number and contact details of the requesting officer. We review emergency requests as quickly as we can. We may require legal process after the emergency has passed.
theSHFT LLC reports apparent, planned, or imminent violations that 18 U.S.C. 2258A covers, including child sexual abuse material and the enticement or sex trafficking of a minor, to the CyberTipline of the National Center for Missing and Exploited Children (NCMEC) when we become aware of them, and preserves reported material as that law requires. We learn of such material through user reports and through automated checks of community posts; we do not and cannot scan end-to-end encrypted messages. We cooperate with law enforcement investigations arising from CyberTipline reports. We preserve what we report, including the reported content and the reported account's identifying information, for one year from the date of the report, as 18 U.S.C. § 2258A(h) requires, except under a time-limited legal hold. See Privacy Policy Section 24 for the full retention schedule.
Our policy is to tell users about legal process that seeks their information before we disclose it, where we are permitted to by law and able to reach them. Because we do not have users' email addresses or phone numbers, notice is given inside the application, which the user may not see if they no longer use it. We do not give notice where a court order or statute prohibits it (for example an order under 18 U.S.C. 2705(b)), where notice would risk harm to a person, in an emergency, or for preservation requests. If your process is accompanied by a non-disclosure order, please attach it. We may give notice after a non-disclosure period ends.
To protect users from fraudulent requests, we verify legal process before responding. We may require that a request come from an official government email domain, may contact the issuing agency through publicly listed contact details, and may decline requests we cannot verify.
We do not currently publish a transparency report. If we begin to publish one, it will be on our website.
Legal process and preservation: support@theshft.app
Mail: theSHFT LLC, Attn: Legal, 212 W. Troy St., Ste B, Dothan, AL 36303, United States
Website: https://theshft.app