Legal
Last updated: 31 August 2026
These guidelines are for law enforcement and government authorities seeking records from Flirtly. They are informational and are not a submission to any jurisdiction, a waiver of any objection, or consent to any process. Nothing here creates a right that the law does not already give.
Flirtly is operated by Roushan, Inc. It is a Delaware corporation with its registered office at 1111b S Governors Ave, STE 55131, Dover, DE 19904, United States. Its registered agent is a matter of public record on the Delaware register, which is where service of process should be directed if you are serving formally.
Email abuse@flirtly.co from an official government domain, attaching the signed process as a PDF. That mailbox is monitored and every request is acknowledged. Requests sent to a support address will be routed there, which costs you a day.
A request we can act on tells us:
We require valid legal process appropriate to the data sought, and we do not disclose content without it. Voluntary requests, unsigned letters and informal enquiries are answered, but answered by declining.
| Category | What it is | Minimum process |
|---|---|---|
| Basic subscriber records | The account email address, account creation date, last activity, plan, and whether the account is anonymous. | Subpoena, or equivalent legal process |
| Non-content records | Session and device metadata, IP addresses within their retention window, age-attestation records, safety event records, generation job records and asset metadata. | Court order under 18 U.S.C. § 2703(d), or a warrant |
| Content | Chat messages, character descriptions and prompts, distilled memories, and generated images, video and audio. | Search warrant issued on probable cause |
We object to requests that are overbroad, vague, or that seek records outside the scope of the process served. We would rather narrow a request with you than produce more than the process authorises.
Described honestly against the schema, so nobody drafts a warrant for something that was never collected:
There is no point serving process for records that were never created. We do not hold, in any table, log, backup or error report:
Where identity verification applies, the identity is held by the verification vendor and we receive a result, not a document. That vendor, not us, is who holds what you are probably looking for.
Chat and generated media are encrypted at rest with per-user keys, so a stolen database alone does not yield readable content. This is not end-to-end encryption — the application reads content in order to moderate it and to generate replies. In plain terms: content can be produced in readable form under valid legal process. We say so rather than let a warrant be drafted on a wrong assumption in either direction.
Where there is an emergency involving an imminent risk of death or serious physical injury to any person, we may disclose information without legal process, as US law permits. Send the request to abuse@flirtly.co with EMERGENCY DISCLOSURE REQUEST in the subject line, and include:
This is a discretionary disclosure, made in good faith on the facts you give us. Ask for the narrowest set of records that addresses the emergency; everything beyond that should follow on normal process.
We honour preservation requests under 18 U.S.C. § 2703(f). Send the request to abuse@flirtly.co identifying the account and the records to preserve. We preserve for 90 days, extendable once for a further 90 days on a renewed request. Preservation freezes a copy; it does not disclose anything, and legal process is still required to obtain it.
A preservation request is worth sending early. Chat is deleted on a one-year rolling basis automatically, and backups roll off in about 35 days.
Our practice is to notify a user before we produce their records, so they can seek to challenge the request. We do not notify where the law prohibits it, where a valid non-disclosure order applies, in an emergency of the kind described in section 7, or where notice would risk harm to a child or to another person. Where a non-disclosure order expires, we may notify the user then.
Apparent child sexual abuse material is reported to the National Center for Missing & Exploited Children as soon as reasonably possible, and the associated prompts, verdicts, hashes and account references are preserved for the statutory period and are exempt from deletion. If your investigation follows a CyberTipline report from us, cite the report number and we will work from it. See the Child Safety Standards.
Roushan, Inc. is a United States entity and its records are held in the United States. Foreign authorities should proceed through a mutual legal assistance treaty, a letter rogatory, or other process recognised by a United States court. We review a foreign request made directly to us, but we are not obliged to act on one and generally will not disclose content on one. Emergency requests under section 7 are the exception, and they are considered on their facts wherever they come from.
We produce records electronically. We do not charge for responding to a request. Where you need the production authenticated for court, ask and we will provide a business-records declaration with it.
Content takedowns and complaints from authorities are handled through the Removal Policy and Complaints & Contact. Every channel reaches a person: abuse@flirtly.co for authorities, legal@flirtly.co for contractual and copyright notices.