Law enforcement requests
For officers and authorities seeking records. Everything below is also published so that users can see the standard we hold requests to, and so that nobody has to take our word for it.
- Effective 4 September 2026
- Valid legal process required
- Very little data exists
Before you write
Telvio holds no name, no email address, no phone number and no payment details for any user, and does not record call audio. What exists is an anonymous installation identifier, the calls made against it — destination number, time, duration, rate, amount — purchase receipt identifiers issued by Apple or Google, and technical data including IP addresses. That is the complete set, and a request cannot produce what does not exist.
Send requests to [email protected] with the subject Law enforcement request, on official letterhead, from an official domain. Requests are handled by Vast Flow, LLP, the publisher of the app.
In force since
What a request must contain
- The issuing authority and the legal basis — the statute, instrument or court order relied on, and the jurisdiction it was issued under.
- An identifier we can actually search. A destination number that was called, with a date and time window, is the strongest. An installation identifier is stronger still if you have one. A name or an email address is not searchable, because we hold neither.
- A specific and proportionate time window. Requests for records over open-ended periods, or for all users who called a country, will be declined as disproportionate.
- The data actually sought, itemised. A request for “all information” will be answered with what this page says exists and nothing more.
- Contact details of the officer, including a verifiable official telephone number and an email address on an official domain.
- Any non-disclosure order, if user notification is to be delayed or withheld. Without one, our default is stated below.
What we hold, precisely
This is set out in full in the privacy policy and repeated here because a request framed against what exists is answered faster than one framed against what an investigator might expect to exist.
Call records — the destination number dialled, the time the call started, its duration in seconds, the rate applied and the amount deducted. In the ordinary course these are retained for up to twelve months and then deleted or aggregated into statistics that cannot identify an installation.
An anonymous installation identifier, generated on the device, which holds a credit balance. It is not linked to an identity and cannot be resolved to a person by us.
Purchase records — transaction identifiers from the App Store or Google Play and which pack was bought. The payment itself is processed by Apple or Google, so a request for payment instrument details, billing addresses or cardholder identity has to go to them, not to us.
Technical data — IP address, device model, operating system and app version, network type, and crash reports. Crash and diagnostic data is retained for up to ninety days.
What does not exist: call audio, which is never recorded; contact lists, which are never uploaded; precise or GPS location, which is never collected; names, email addresses, phone numbers and payment card details, none of which are ever asked for.
How a request is handled
Each request is assessed against the law applicable to us and against the standards on this page. We require valid legal process appropriate to the data sought and to the jurisdiction, and we decline requests that are overbroad, unclear, or not supported by a legal basis we can verify. Where a request is defective we say what is missing rather than refusing without explanation.
Requests arriving from a jurisdiction other than the one we are established in are handled through the recognised channels for cross-border requests, such as a mutual legal assistance treaty or an equivalent instrument. A direct email from a foreign authority citing its own domestic law is not by itself sufficient basis for disclosure, and saying so is not obstruction — it is the standard the law expects of us.
We aim to acknowledge a properly formed request within five working days. Genuine emergency requests — where there is an imminent risk of death or serious physical harm — are handled without waiting for formal process, and should be marked Emergency disclosure request in the subject line with the nature of the risk stated in the first paragraph. Bear in mind while making one that this service cannot locate a user: we hold no GPS data, and an IP address indicates a region at best.
Telling the user
Our default is to notify a user whose records are requested, before disclosure where practicable, so that they have an opportunity to seek their own legal remedy. This is the position most responsible services take and it is stated here so that it is a commitment rather than a discretion.
We will not notify where notification is prohibited by law or by a court order, or where we have a good-faith belief that notification would create a risk of death, serious physical harm, or harm to a child. If a request should not be disclosed to the user, include the order or the statutory basis with it.
A practical constraint follows from the design: because we hold no email address, telephone number or any other contact route for a user, notification can generally only be delivered inside the app. A user who has stopped using the app may be effectively unreachable.
What this page is not for
- A member of the public reporting a call — that is report a call, which needs no legal process and no account.
- A civil litigant or a private investigator — we do not disclose user data on request to private parties. A court order obtained through proper process is the route.
- A request for payment or cardholder information — Apple and Google process every purchase and hold those details. We receive a signed receipt identifier and nothing else.
- Emergency call location — the app cannot place emergency calls at all and holds no location data. Why that is is set out separately.
- A vulnerability in our systems — responsible disclosure has its own route and its own commitments.
Why so little data exists
This is not obstruction and it is worth explaining, because a request framed against an expectation of a user database will be answered with a description of why there is not one.
The service was built without accounts. There is no registration step, so no name, email address, telephone number or password has ever been collected from any user — not withheld, not deleted, never asked for. Payment is processed entirely by Apple and Google, which are the merchants of record, so no payment instrument, billing address or cardholder identity exists on our side either. Requests for those have to go to Apple or Google, who hold them.
Call audio is never recorded. It is carried in encrypted form for the duration of the call and does not exist afterwards in any form, so no legal process can produce it. Contact lists are never uploaded. Precise and GPS location is never collected, which also means there is no capability to locate a user — an IP address indicates an approximate region and can be a different country entirely behind a VPN.
What is left is the call record — destination, time, duration, rate, amount — the anonymous installation identifier it is filed under, purchase receipt identifiers, and technical data. That is a genuinely useful set for investigating calls, and it is the entire set.
Bottom line
Send requests to [email protected] with the subject “Law enforcement request”, on official letterhead, naming the authority, the legal basis, a searchable identifier and a specific time window.
The searchable identifier is a destination number with a date and time window, or an installation ID. A name or an email address cannot be searched, because none is held.
No call audio, no contact lists, no location and no payment details exist. Call records are retained for up to twelve months. Our default is to notify the user unless a legal prohibition applies.
Frequently asked questions
How does law enforcement request records from Telvio?
By email to [email protected] with the subject Law enforcement request, on official letterhead from an official domain, naming the issuing authority, the legal basis, a searchable identifier and a specific time window. Requests are handled by Vast Flow, LLP.
What user data does Telvio hold?
An anonymous installation identifier, call records comprising the destination number, time, duration, rate and amount, purchase receipt identifiers from Apple or Google, and technical data including IP addresses. No name, email address, phone number or payment card details are ever collected.
Does Telvio record calls?
No. Call audio is carried in encrypted form for the duration of the call and is never recorded, stored or analysed. There is no recording that any legal process can produce.
How long are call records kept?
Up to twelve months in the ordinary course, after which they are deleted or aggregated into statistics that cannot identify an installation. Crash and diagnostic data is kept for up to ninety days, and accounting records for as long as tax law requires.
Does Telvio notify users of law enforcement requests?
Yes by default, before disclosure where practicable, so that a user can seek their own legal remedy. We do not notify where prohibited by law or a court order, or where notification would create a risk of death, serious harm, or harm to a child.
Can Telvio locate a user?
No. The app collects no GPS or precise location data. An IP address is held, which indicates an approximate region and can be a different country entirely if a VPN is in use. There is no capability to locate a person.