Government and legal requests

Effective 11 September 2026. Transparency report last updated 11 September 2026.

The one-paragraph answer

Yapmesh has no server, no accounts and no logs. We do not know who uses the app, cannot see, decrypt, intercept or preserve any message, file, contact list, location or IP address, and there is no switch we could flip to start. A request for user data will be answered with this page. We say this before any request arrives so that it is never a surprise, and we will publish every request we receive in the report below.

What we hold, item by item

Asked forWhat we haveWhere it actually is
Account or registration recordsNone. There are no accounts.A key pair on the user's phone.
Message contentNone.On the sending and receiving phones, end-to-end encrypted in transit and encrypted at rest. Relaying phones carry ciphertext.
Message metadata (who, when, to whom)None.Observable only by a phone in radio range at the time, or by a relay operator as an IP address and an hourly random tag if the user switched internet reach on. We are not a relay operator.
Contact lists, groupsNone.On the phone.
LocationNone.Sent only inside a message the user chose to attach it to, to the people they were messaging.
IP addressesNone. We run nothing a phone connects to.Google Play, GitHub and Cloudflare hold their own download and access logs under their own policies. Public Nostr relays, MQTT brokers, STUN servers and any push distributor a user enabled hold theirs.
Encryption keysNone. We cannot decrypt anything.Generated on the phone, never leave it.
Abuse reportsOnly those a user emailed to us, kept as described in the privacy policy.The user's phone, and our mailbox if they sent it.
Our own correspondenceYes: emails sent to [email protected].Our mailbox.

What we can be compelled to do

Because we hold no user data, the only things a valid order could reach are our own email, the website, and the software itself. We will comply with a lawful order to produce our own correspondence. We will not build, and would publicly refuse to build, a version of Yapmesh that weakens its encryption, adds a hidden capability, or reports on its users; the protocol is public and the app is built reproducibly so that such a change could not be hidden. If we were ever legally forced to stop distributing the app, copies already installed would keep working, because they do not depend on us.

How to serve a request

  • Email [email protected] with "Legal:" at the start of the subject, from an official address, with the legal instrument attached.
  • We accept requests that are valid under the law of Pakistan, where Yapmesh is made and where its maker lives. Authorities elsewhere should proceed through mutual legal assistance with Pakistan; we will explain the app to any authority that asks, which needs no order, and is usually the useful thing.
  • We will acknowledge a request within seven days and answer it, which in every foreseeable case is this page, within thirty.
  • Emergency requests involving imminent danger to life or to a child are read first; there is still nothing to disclose, but we will help the requester understand what the phones involved hold and how a report from a phone is exported.

Transparency report

Updated whenever a request is received and at least once a year. Counts are cumulative since the first publication of this page.

Since 11 September 2026ReceivedUser data produced
Requests for user data from any government or court00 (none exists)
Emergency disclosure requests00
Requests to remove or block content0not possible
Requests to alter the software0refused on principle
Child-safety reports received by email and forwarded to an authority0see the child safety page

This report is not a warrant canary and does not rely on silence: a request we are legally barred from describing will still be counted, and one we are barred from counting will be reflected by a statement that the report can no longer be kept complete.