Law Enforcement Guidelines
Last updated: July 9, 2026
These guidelines explain how law-enforcement and government authorities can request data from Telbox, and what Telbox can and cannot produce. This is guidance, not legal advice, and does not waive any right or defense.
Where to send requests
- Legal process (subpoena, court order, warrant): legal@telbox.ai
- Emergency disclosure requests (imminent risk of death or serious physical harm): legal@telbox.ai with
EMERGENCYin the subject line.
Requests must be in English (or accompanied by a certified English translation), issued under valid legal authority, and specify the account with a precise identifier (phone number). We do not act on informal requests.
What Telbox can and cannot produce
Telbox is end-to-end encrypted in transit. That shapes what exists to produce:
- Message, voice-note, and media content: We store ciphertext we cannot read for ordinary delivery; the decryption keys live on users' devices. We cannot produce readable message content from encrypted storage alone, and we cannot build a backdoor to do so.
- AI-derived data: For accounts with AI enabled, AI-derived outputs (e.g. transcripts, summaries) may exist in our systems and can be produced in response to valid legal process for that account.
- Call-segment audio (insights path): When post-call insights capture ran for a call, encrypted call-segment blobs may exist and are erased with account deletion; we cannot read them without the relevant keys.
- Basic subscriber / account records: Account identifiers (e.g. registered phone number, account creation date), subscription tier, and device metadata may be available.
- What we do not have: users' private keys, and data we never collect (see Privacy Policy §2.9).
Our standing practices
- We review each request for validity and scope under the law of the asserting jurisdiction and push back on overbroad requests with counsel.
- We notify the affected user within a reasonable time (target: 24 hours of a valid request) unless legally prohibited by a gag order or the request is a valid emergency. Where prohibited, we re-evaluate the prohibition periodically (target: every 90 days) and notify as soon as we are permitted.
- We log every production to an internal register.
- Preservation requests: we honor valid preservation requests for the period the law requires while a formal legal process is obtained.
- Cross-border conflicts: where the requesting jurisdiction's law conflicts with the user's resident jurisdiction's protections, we route to the stronger user protection where feasible and lawful.
Emergency requests
For requests involving an imminent risk of death or serious physical injury, we may disclose the limited information we hold that is relevant to preventing the harm, consistent with applicable law. Include the nature of the emergency, the specific harm, and why the requested data is needed to prevent it.
Transparency
We publish aggregate transparency figures at telbox.ai/transparency periodically. Until the first annual report is published, this page and our Privacy Policy §4.1 describe our standing practices.
Child-safety reports
Telbox reports apparent child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC) as required by U.S. law where applicable, and cooperates with the resulting legal process. Users can report abuse in-app via Report / Block.
Contact
- Legal / law-enforcement: legal@telbox.ai