Legal

Law Enforcement Guidelines

Last updated: 31 August 2026

These guidelines are for law enforcement and government authorities seeking records from Flirtly. They are informational and are not a submission to any jurisdiction, a waiver of any objection, or consent to any process. Nothing here creates a right that the law does not already give.

1. Who we are

Flirtly is operated by Roushan, Inc. It is a Delaware corporation with its registered office at 1111b S Governors Ave, STE 55131, Dover, DE 19904, United States. Its registered agent is a matter of public record on the Delaware register, which is where service of process should be directed if you are serving formally.

2. How to send a request

Email abuse@flirtly.co from an official government domain, attaching the signed process as a PDF. That mailbox is monitored and every request is acknowledged. Requests sent to a support address will be routed there, which costs you a day.

A request we can act on tells us:

  • The issuing agency, the officer’s name, badge or ID, direct phone and email.
  • The account, identified by the email address on it or by a URL, character or asset reference. “A user in your service” is not identification we can search on.
  • A specific date range, and a specific list of the records sought.
  • The signed legal process itself, and the deadline for response.
  • Whether a non-disclosure order accompanies it, and its expiry.

3. What we require

We require valid legal process appropriate to the data sought, and we do not disclose content without it. Voluntary requests, unsigned letters and informal enquiries are answered, but answered by declining.

CategoryWhat it isMinimum process
Basic subscriber recordsThe account email address, account creation date, last activity, plan, and whether the account is anonymous.Subpoena, or equivalent legal process
Non-content recordsSession and device metadata, IP addresses within their retention window, age-attestation records, safety event records, generation job records and asset metadata.Court order under 18 U.S.C. § 2703(d), or a warrant
ContentChat messages, character descriptions and prompts, distilled memories, and generated images, video and audio.Search warrant issued on probable cause

We object to requests that are overbroad, vague, or that seek records outside the scope of the process served. We would rather narrow a request with you than produce more than the process authorises.

4. What data actually exists

Described honestly against the schema, so nobody drafts a warrant for something that was never collected:

  • A pseudonymous account. An email address, a display name the user chose, and timestamps. Sign-in is a six-digit code emailed to that address — there is no password on the account, so there is no password to produce or to crack.
  • Anonymous sessions. A visitor can use the service before giving an email at all. Such an account has a placeholder address and no verified contact of any kind; if they sign up later, it merges into the real account.
  • Age attestation records. A timestamp, the method, an IP-derived country and region, and a hash of the user agent. This is self-attestation, not identity verification. It tells you a person clicked a button from a region on a date. It does not tell you who they are.
  • Session and device metadata. IP addresses and user agents associated with sessions. Raw IP from age attestation is kept for no more than 30 days.
  • Safety event records. Classifier verdicts, refusal reasons, the text excerpt that triggered them, and the account reference.
  • Generation job and asset records. What was requested, when, what it cost in credits, the resulting asset, its safety state and its content hash.
  • Content. Chat messages, character descriptions and prompts, distilled long-term memories, and generated media.

5. What does not exist

There is no point serving process for records that were never created. We do not hold, in any table, log, backup or error report:

  • Identity documents, document numbers, or names taken from an ID.
  • Dates of birth.
  • Face scans, biometric templates, or any biometric data.
  • Verified legal names. Users may sign up with an alias or a disposable address.
  • Telephone numbers. We never ask for one.
  • Card numbers or bank details. There is no payment processor connected to the service at all today; when one is, card data lives with the processor and we hold tokens.
  • Any user-uploaded image. There is no upload surface in this product and no code path from a user-supplied image to anything. Every likeness in every asset is synthetic. If your investigation concerns a real person’s photograph, it did not come from here.

Where identity verification applies, the identity is held by the verification vendor and we receive a result, not a document. That vendor, not us, is who holds what you are probably looking for.

6. Encryption

Chat and generated media are encrypted at rest with per-user keys, so a stolen database alone does not yield readable content. This is not end-to-end encryption — the application reads content in order to moderate it and to generate replies. In plain terms: content can be produced in readable form under valid legal process. We say so rather than let a warrant be drafted on a wrong assumption in either direction.

7. Emergency disclosure requests

Where there is an emergency involving an imminent risk of death or serious physical injury to any person, we may disclose information without legal process, as US law permits. Send the request to abuse@flirtly.co with EMERGENCY DISCLOSURE REQUEST in the subject line, and include:

  • The nature of the emergency and why the risk is imminent.
  • The person at risk, and how the requested records would help.
  • The account identifier, and the specific records you need right now.
  • Your agency, name, badge or ID, and a direct number we can call back on.

This is a discretionary disclosure, made in good faith on the facts you give us. Ask for the narrowest set of records that addresses the emergency; everything beyond that should follow on normal process.

8. Preservation

We honour preservation requests under 18 U.S.C. § 2703(f). Send the request to abuse@flirtly.co identifying the account and the records to preserve. We preserve for 90 days, extendable once for a further 90 days on a renewed request. Preservation freezes a copy; it does not disclose anything, and legal process is still required to obtain it.

A preservation request is worth sending early. Chat is deleted on a one-year rolling basis automatically, and backups roll off in about 35 days.

9. Notifying the user

Our practice is to notify a user before we produce their records, so they can seek to challenge the request. We do not notify where the law prohibits it, where a valid non-disclosure order applies, in an emergency of the kind described in section 7, or where notice would risk harm to a child or to another person. Where a non-disclosure order expires, we may notify the user then.

10. Child safety

Apparent child sexual abuse material is reported to the National Center for Missing & Exploited Children as soon as reasonably possible, and the associated prompts, verdicts, hashes and account references are preserved for the statutory period and are exempt from deletion. If your investigation follows a CyberTipline report from us, cite the report number and we will work from it. See the Child Safety Standards.

11. Requests from outside the United States

Roushan, Inc. is a United States entity and its records are held in the United States. Foreign authorities should proceed through a mutual legal assistance treaty, a letter rogatory, or other process recognised by a United States court. We review a foreign request made directly to us, but we are not obliged to act on one and generally will not disclose content on one. Emergency requests under section 7 are the exception, and they are considered on their facts wherever they come from.

12. Format, costs and authentication

We produce records electronically. We do not charge for responding to a request. Where you need the production authenticated for court, ask and we will provide a business-records declaration with it.

13. Everything else

Content takedowns and complaints from authorities are handled through the Removal Policy and Complaints & Contact. Every channel reaches a person: abuse@flirtly.co for authorities, legal@flirtly.co for contractual and copyright notices.