00 Lawful interception

We can’t deliver what we never decrypted.

Our position on lawful interception.

Not political defiance but architectural fact: we have no plaintext, no keys, and no recording capability to hand over.

We can't deliver what we never decrypted.

Multiple European and national legal regimes require electronic communications operators to implement lawful interception capabilities: Article 706-102 of the French Code de procédure pénale, Articles 23 and 31 of the UK IPA 2016, Articles 110 and 112 of the German StPO, and equivalent statutes across the EU. uOS does not implement any such capability.

This is not an act of political resistance. It is a consequence of our technical architecture.

Why it is technically impossible

A lawful interception capability, at minimum, requires the operator to be able to:

  • identify a specific target (user or device);
  • record content or metadata of the target's communications;
  • deliver that recording to the requesting authority.

uOS does none of these for plaintext content:

  • Identification: uOS can identify the user_pub of a target, but cannot map a user_pub to a real-world identity, nor can it verify that a user_pub corresponds to a person who is the named target of an interception order.
  • Recording of content: uOS has no access to plaintext content of any message at any time.
  • Delivery: there is nothing to deliver.

For metadata, our capability is similarly limited. Our servers only retain the minimum required to route WebSocket frames: target identifier (user_pub), platform_id, counter, timestamp, and transport size. This is insufficient to meet the content of a typical lawful interception order and we make this clear in any judicial proceeding.

What we will do

  • We will contest any order that requires us to implement interception capability against our architecture.
  • We will comply with narrowly-scoped orders that ask for what we can technically provide (e.g. confirmation that a user_pub exists on a specific platform and timestamp), in a manner proportionate to the order.
  • We will publish every such interaction in our annual Transparency Report.

Why law enforcement does not need us to comply

Modern European criminal procedure has well-tested, rights-respecting mechanisms for investigating crime involving encrypted communications:

  • Direct judicial seizure of the suspect's device, under standard search warrant procedures.
  • Court-ordered cryptographic recovery using keys held by the user, with full due process.
  • International cooperation through MLAT and second-generation EU mutual recognition instruments.

These mechanisms work. They respect the rule of law. They require uOS to do nothing more than what we already do: nothing at all.

Free forever

Free for individuals and families. Forever.

No ads, no data mining, no trial clock. Individual and family accounts are free — permanently. Organisations pay per seat, and that is what funds it.

Request your account Invite-only while we scale