These guidelines explain how Artorias, Inc. ("Artorias", "we", "us"), which provides SITREP, responds to requests from law enforcement and other government authorities for information about SITREP users, and to requests to remove content. They are written for authorities. Users can read them to understand what we do. Words such as "handle", "SCATTER", "Community Content", "Near me", "incident report" and "geolocation" have the meanings given in the SITREP Terms of Service (artorias.com/legal/sitrep/terms).
Nothing in these guidelines creates rights for any person or authority, and we may respond differently where the law or the facts of a case require.
01Principles
- Valid legal process, read narrowly. We disclose user information only in response to valid legal process that we are legally bound to follow, or in the emergencies described in section 5. We push back on requests that are overbroad, unclear or not properly served.
- We tell users about requests for their information before we disclose it, unless the law prohibits it (for example a valid non-disclosure order), or telling them would create a risk of death or serious physical injury, or would be counterproductive in a case involving the exploitation of a child.
- No back doors. We do not give any government direct access to our systems or data, and we do not build capabilities to intercept communications in real time, except as required by a valid court order.
- Anonymous to users, not to us. SITREP handles are anonymous to other users. Behind each handle is an account, and we keep account-level records. We treat those records as sensitive and disclose them only as set out in these guidelines.
- Verification marks give no special access. Holding a gold (government official) mark does not entitle anyone to user data.
- Transparency. We plan to publish information about the number and type of government requests we receive, and how we responded, at least once a year.
02What data we may have
What exists depends on the account and how it was used. Much of it is deleted on the schedule in our Privacy Policy (artorias.com/legal/sitrep/privacy), and we cannot produce what we no longer hold.
| Category | Examples | What we require (United States) |
|---|---|---|
| Basic subscriber information | Account creation date, current handle, plan and payment status; name and email address held by our sign-in provider; IP addresses recorded when the account opened SITREP alerts; server and load balancer log entries, for the limited period we keep them | Subpoena |
| Other non-content records | Handle history (past handles of the account), follows, blocks, channel memberships, verification mark records (result codes only), moderation and enforcement history, timestamps of posts and messages, conversation membership | Court order under 18 U.S.C. 2703(d) |
| Contents | Posts, replies, channel posts, images, messages, context notes, geolocation reasoning and evidence, incident reports, reports and appeals the user filed | Search warrant |
What we do not have, or keep only in limited form:
- Precise device location for Near me. Near me receives only a rough area (about 5 km across, or about 20 by 40 km), keeps only the current area, and deletes it when the user turns Near me off.
- Incident pins and geolocation proposals are stored as the user sent them (to 6 decimal places) and shown publicly on a coarse grid. An incident pin may already have been moved 150 to 400 meters on the user's device before it was sent. If the user turned that off, the stored pin can be where the user was. Incident pins are reduced to a 5 km grid 90 days after the event.
- Original image files and their metadata (including GPS location). They are deleted after processing, within 1 day, and we never keep their metadata. We keep the processed images and a checksum (SHA-256) of the file uploaded to us.
- End-to-end encryption keys. Messages are encrypted at rest with keys we control, so their contents can be produced in response to a search warrant. Messages are deleted 365 days after they are sent, unless they are preserved.
- Email addresses in the SITREP database. The account's name and email address are held by our sign-in provider and can be produced as basic subscriber information.
03Requests from the United States
- Subpoena: basic subscriber information (18 U.S.C. 2703(c)(2)).
- Court order under 18 U.S.C. 2703(d): other non-content records.
- Search warrant (federal, or an equivalent state warrant): the contents of communications and other stored content, including public posts.
- Preservation requests (18 U.S.C. 2703(f)): we preserve a one-time snapshot of the specified account data for 90 days, and for one further 90-day period if you renew the request, while you obtain formal legal process. We do not disclose preserved data without that process.
- Non-disclosure orders (18 U.S.C. 2705(b)): we comply with valid orders and may challenge orders with no end date.
- Civil and private requests (for example a subpoena from a party to a lawsuit): US law does not allow us to disclose the contents of communications in response to these, and we generally will not.
04Requests from outside the United States
- We generally require requests from outside the United States to come through a Mutual Legal Assistance Treaty, letters rogatory, or another process recognized under US law, including an agreement under the US CLOUD Act where one applies.
- We may decline a request that is inconsistent with international human rights standards or with US law; that comes from a government subject to comprehensive US sanctions; or that appears aimed at identifying people because of their reporting on, or discussion of, an armed conflict, a protest or the conduct of a government.
- Emergency requests from any country are considered under section 5.
05Emergency requests
We may disclose information without legal process when we believe in good faith that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay (18 U.S.C. 2702(b)(8) and (c)(4)). Emergency requests must come from a law enforcement officer, from an official email domain or on official letterhead, and must describe the emergency, who is at risk, and why the information is needed urgently. We disclose only what is needed to address the emergency.
We may also, on our own initiative, inform authorities of information suggesting a threat to someone's life or safety (for example a credible threat of violence), including where Article 18 of the EU Digital Services Act applies.
06Child safety
We report apparent child sexual exploitation, including child sex trafficking and online enticement, to the National Center for Missing & Exploited Children (NCMEC) CyberTipline, as 18 U.S.C. 2258A requires, and we preserve the reported content and related information for at least one year, as the law requires. Law enforcement that receives a CyberTipline report about SITREP should follow up with legal process as described in section 3, citing the CyberTipline report number.
07Requests to remove content
- We first review a government request to remove or restrict content against our Terms of Service and Community Guidelines. Content that breaks them is removed everywhere.
- Content that does not break our rules but is said to be illegal in a particular country is assessed against that law. We may restrict it where that is technically possible, or decline the request.
- Where the EU Digital Services Act or the EU Terrorist Content Online Regulation applies, we act on valid orders without undue delay and within the time the law requires.
- We tell the user whose content is restricted, with the reason, unless the law prohibits it.
08How to submit a request
- Email: hello@artorias.com, with the subject "Law enforcement request". For an emergency, use the subject "EMERGENCY disclosure request". Emergency requests are reviewed first.
- Mail: Artorias, Inc., Attn: Legal, 169 Madison Ave, Suite 11590, New York, NY 10016, United States.
- EU authorities: where the EU Digital Services Act applies, our single point of contact is hello@artorias.com. We communicate in English.
Accepting a request by email or mail does not waive any objection we may have, including to jurisdiction or to the manner of service.
Every request must include:
- the issuing authority, and the requesting officer's name, badge or ID number, official email address and phone number;
- the legal basis for the request;
- a clear description of the data sought and the date range; and
- the SITREP handle (for example
@0x3f9a0c71beor@username), with where and when the content appeared (the alert, channel or place, and the approximate time). Handles change: if the handle is a past one, say when it was seen. If you have only an email address or phone number, name it in your legal process and we will search for a matching account when we respond.
Requests we cannot verify, or that do not identify an account, will be returned.
We may seek reimbursement of reasonable costs where the law permits (for example under 18 U.S.C. 2706).
09User notice
Unless one of the exceptions in section 1.2 applies, we notify the user before we disclose their information, using the email address linked to their account or a notice in the app, and, where practical, give them at least 7 days to seek legal protection. We do not wait in an emergency. If a non-disclosure order expires, we notify the user then.
10Changes
We may update these guidelines. The current version is always at artorias.com/legal/sitrep/law-enforcement.