Law Enforcement Guidelines
This page addresses government authorities and their legal representatives. If you are a user facing danger, this is the wrong page — contact your local emergency services first, then report the account in the app.
1. The principle
User data belongs to users. Sebairo discloses data only in response to a valid, binding, narrowly-scoped legal request, and only the minimum that satisfies it. Every request is reviewed individually. Overbroad requests, requests without a stated legal basis, and requests that do not identify an account precisely are refused or returned for correction.
Sebairo is operated from the United Kingdom and is subject to the law of England and Wales.
2. What data exists at all
A request for data Sebairo does not hold cannot be complied with, so the useful starting point is what exists:
- Basic subscriber information
- The registered phone number or email address, display name, account creation date, and language and profile settings.
- Public content
- Anything the user chose to publish publicly: public posts, business pages, Marketplace listings, job posts. This is visible without any process at all.
- Non-public content
- Messages, private posts, notes, workspace records and stored media. Sebairo is not end-to-end encrypted, so this content exists in a form the service can read, and a valid order can compel its disclosure. We state this plainly rather than let anyone assume otherwise in either direction.
- Transaction records
- Wallet balances, top-ups, purchases, transfers, withdrawals and ad spend, each with a reference and timestamp. Card numbers are not among them — those are held by the payment processor, not by Sebairo.
- AI interaction records
- A user's conversations with the assistant and the actions the agent took on their behalf, together with metering records.
- Moderation records
- Reports made about an account or by it, and the enforcement actions taken, with the reason and the acting reviewer.
- Server records
- The ordinary operational records any hosted service keeps in order to run, diagnose faults and detect abuse. These are retained for operational periods, not indefinitely; a request arriving late may find nothing.
3. What does not exist, and cannot be produced
- No copy of anyone's address book. Contact matching is performed in memory and nothing from a user's contacts is written down. There is no contact graph to produce.
- No card numbers. Card details are collected by the payment processor on its own pages and never reach Sebairo.
- No readable AI provider keys. A user-supplied key is held in a server-side vault and the pointer column is revoked from client roles; it cannot be produced in readable form.
- No location history by default. Map presence is off unless a user switched it on. Where it is off, the database will not release the row to anyone.
- No call recordings. Voice and video calls are carried, not recorded. A live-stream replay exists only where the host deliberately created one.
- No plaintext passwords. Only hashes exist.
Sebairo does not provide bulk access, standing access, direct database access, or any interface allowing an agency to query user data itself. There is no backdoor and none will be built. Requests are answered one at a time, by a person, against a specific account.
4. What process is required
Sebairo requires legal process proportionate to what is being sought. As a general matter:
- Basic subscriber information — a valid request from a UK authority under an applicable statutory power, identifying the account and the investigation.
- Non-public content — a court order, warrant or equivalent instrument that specifically authorises the disclosure of stored content. A police request letter alone is not sufficient for content.
- Non-UK authorities — a request through a mutual legal assistance treaty, letters rogatory, or another route recognised in UK law. A foreign order that has not been given effect in the UK is not by itself binding on Sebairo, though it may be considered where it supports an emergency disclosure under section 6.
- Civil litigants — a court order. Sebairo does not disclose user data to a private party on request, and a solicitor's letter is not process.
This is a description of practice, not legal advice about your powers. Where a specific statutory instrument compels something different, the law governs.
5. How to serve a request
Requests are submitted by email to support@sebairo.com with a subject line beginning [Law Enforcement], sent from an official agency address. There is one published channel and this is it — an address that is monitored, rather than a dedicated one that is not.
A request that can actually be actioned includes:
- The requesting agency, the responsible officer, their official contact details, and a case or reference number.
- The legal basis relied on, and a copy of the order, warrant or instrument itself.
- Precise identification of the account: registered phone number or email address, or a profile link. A display name alone is not enough — display names are not unique.
- The specific categories of data sought. “All data held” is not a category and will be returned for narrowing.
- The time period the request covers.
- Whether a non-disclosure obligation applies, and the legal basis for it (see section 7).
Sebairo is a small operation and does not charge a fee for responding to requests. Responses are sent to the official agency address the request came from, and not to a personal address.
6. Preservation requests
If you need data preserved while you obtain the process required to compel it, send a preservation request to the same address with [Law Enforcement — Preservation] in the subject. Identify the account precisely and state the period.
A preservation request causes data then in existence to be retained; it does not cause anything to be disclosed, and it does not create data that was never held. Preservation is for a defined period and is not open-ended.
7. Emergency disclosure
Where there is an imminent threat to someone's life or physical safety, send the request with [Law Enforcement — Emergency] in the subject line. Describe the danger, who is at risk, and why it cannot await normal legal process.
These are treated with top priority. Sebairo may disclose information in good faith where it reasonably believes doing so is necessary to prevent death or serious physical harm, and will disclose only what is needed to address that specific emergency.
Sebairo is a small team without a staffed 24-hour desk. An emergency request is prioritised above everything else, but nobody should treat this channel as a substitute for the mechanisms that guarantee an immediate response. If someone's life is in danger, use the emergency services first.
8. Telling the user
Sebairo's policy is to notify a user before disclosing their data in response to a legal request, so that they have an opportunity to seek their own advice.
Notice is withheld where:
- the law prohibits it, or a court has ordered non-disclosure — in which case the order should be provided with the request;
- notice would create a risk to someone's life or physical safety;
- the matter involves the exploitation of a child;
- notice would be futile, for example where the account is already known to the user to be under investigation.
Where a non-disclosure obligation expires, the user may be notified afterwards.
9. What Sebairo will refuse
- Requests without an identified legal basis, or from a non-official address.
- Requests that do not identify an account precisely enough to be sure the right person's data is produced.
- Requests for “all data” about an account without narrowing.
- Requests for content where the process supplied only authorises subscriber information.
- Requests to build a capability that does not exist — a backdoor, a bulk export, a live tap, or the retention of data that is not otherwise retained.
- Requests to remove lawful content, absent a valid order. Content removal requests are handled through the ordinary reporting and moderation process, not this channel.
10. Reporting on these requests
Requests received under these guidelines, and Sebairo's responses to them, are the subject of the Transparency Report. No report has been published yet; that page says so, and sets out what the first one will count.
ملخص بالعربية
هذه الصفحة موجهة إلى الجهات الرسمية وممثليها القانونيين؛ وإن كنت مستخدمًا في خطر فاتصل بخدمات الطوارئ في بلدك أولًا ثم أبلغ عن الحساب في التطبيق. المبدأ: بيانات المستخدمين ملك لهم، ولا نفصح إلا استجابةً لطلب قانوني صحيح ملزم محدد النطاق، وبأضيق قدر يفي به، ومع مراجعة كل طلب على حدة. والبيانات الموجودة: بيانات الاشتراك الأساسية، والمحتوى العام، والمحتوى غير العام — وسيبايرو ليس مشفَّرًا طرفًا إلى طرف فالمحتوى موجود بصيغة تقرؤها الخدمة وقد يُلزم أمرٌ صحيح بالإفصاح عنه — وسجلات المعاملات وسجلات الذكاء الاصطناعي وسجلات الإشراف والسجلات التشغيلية. وما لا وجود له ولا يمكن إنتاجه: نسخة من دفتر عناوين أحد، وأرقام البطاقات، ومفاتيح الذكاء الاصطناعي بصيغة مقروءة، وسجل مواقع ما لم يشغّله المستخدم، وتسجيلات المكالمات، وكلمات المرور. ولا نوفّر وصولًا جماعيًا أو دائمًا أو مباشرًا لقاعدة البيانات، ولا يوجد باب خلفي ولن يُبنى. ويجب أن يتناسب الإجراء القانوني مع المطلوب: أمر قضائي للمحتوى، ومسار المساعدة القانونية المتبادلة للجهات غير البريطانية، وأمر محكمة للمتقاضين المدنيين. وتُرسل الطلبات إلى support@sebairo.com بعنوان يبدأ بـ [Law Enforcement] من بريد رسمي، متضمنة الجهة والضابط والسند القانوني وتحديد الحساب بدقة والبيانات المطلوبة والمدة. وطلبات الحفظ توسم بـ [Law Enforcement — Preservation] وتؤدي إلى الاحتفاظ لا الإفصاح. وحالات الطوارئ توسم بـ [Law Enforcement — Emergency] وتُعالَج بأولوية قصوى، مع التنبيه أن الفريق صغير ولا يملك مكتبًا يعمل على مدار الساعة. وسياستنا إخطار المستخدم قبل الإفصاح إلا حيث يمنع القانون أو يعرّض ذلك أحدًا للخطر أو في قضايا استغلال الأطفال. هذا الملخص للتوضيح فقط، والنص الإنجليزي هو المعتمد.