The short version
boopr is an end-to-end encrypted social app operated by Boopr LLC. User content is encrypted on the user's own device with keys we never possess, so we have no technical ability to produce post content, photos, captions, comments, profile details, friend or list membership, or message content. This is an architectural fact, not a policy choice: there is no backdoor, master key, or escrow we can use, and we will not build one.
Under valid legal process we can produce a limited set of account metadata, described below. This page explains what we hold, what we don't, and how to submit a request. It summarizes our process; the controlling document is Section 21 of our Privacy Policy.
How to submit a request
Serve valid legal process as a PDF of the signed instrument on:
Please include the requesting agency and officer (name, identifier, and contact), the legal authority relied on, the specific account identifier (account UUID, or a friend code or invite code we can resolve to an account; boopr has no usernames and display names are encrypted), the precise records sought, and any return date.
We acknowledge properly submitted requests and respond within the time the process requires. Requests that are overbroad, legally deficient, or unsupported by the level of process the law requires for the data sought may be narrowed or challenged. We may verify the identity of the requesting agency and officer before responding, and we will never ask for payment to process a request.
Civil and third-party requests
The channel above is for government and law-enforcement requests. Civil litigants, private parties, and other non-governmental requesters seeking user data must serve process on our registered agent:
c/o Northwest Registered Agent Service, Inc.
8 The Green, STE B
Dover, DE 19901, United States
The technical limits described on this page apply equally to civil process: user content is end-to-end encrypted with keys we do not hold, so we cannot produce it regardless of who is asking or how.
Jurisdiction and valid process
boopr is a United States service. We respond to valid U.S. legal process issued under the Electronic Communications Privacy Act (ECPA) and the Stored Communications Act (SCA):
- A subpoena or a court order under 18 U.S.C. § 2703(d) for basic subscriber and metadata records.
- A search warrant issued on probable cause for any content. Under Carpenter v. United States, 138 S. Ct. 2206 (2018), a subpoena or 2703(d) order is not sufficient for content, though in practice we hold no decryptable content to produce.
Authorities outside the United States should proceed through a Mutual Legal Assistance Treaty (MLAT) or letter rogatory, or through U.S. legal process obtained by those channels.
What we can provide
Subject to valid legal process and to what exists for a given account, we may be able to produce:
- That an account exists and its status (active, restricted, suspended, banned, or deleted), its creation date, and last activity timestamp
- Public cryptographic keys (Ed25519 and X25519)
- Connection metadata (which account IDs are connected) and post timestamps, including which account tagged which
- Encrypted ciphertext blobs, which are useless without the user's private keys
- Salted HMAC-SHA256 hashes of IP address (raw IP addresses are not retained, and the salt rotates monthly so hashes cannot be correlated across months)
- Invite-chain information linking inviter and invitee
- Subscription status and the opaque transaction identifiers received from Apple or Google
- Enforcement-action records on the account (warnings, restrictions, bans)
- That a screenshot event of a given context type occurred between two accounts at a given time, plus the encrypted notification payload (which we cannot decrypt)
Accounts are identified by an opaque UUID (or a friend code or invite code we can resolve to one); boopr has no usernames, and display names are end-to-end encrypted, so we cannot look up an account by name. Please identify the account precisely. The complete enumeration is in Section 21 of the Privacy Policy.
What we cannot provide
Because this content is end-to-end encrypted with keys we do not hold, we cannot produce it for anyone, under any process:
- Post content, captions, comments, or likes
- Photos and videos
- Profile details (name, bio, avatar, birthday)
- List names or membership, and block or mute lists
- Recovery phrases (never transmitted to us)
- Push-notification content and screenshot-notification content (we store only content-free routing data)
- Raw IP addresses (not retained)
Our encryption architecture is not something we can bypass, disable, or circumvent in response to a request.
Emergency disclosure requests
Under 18 U.S.C. § 2702(b)(8) and § 2702(c)(4), we may voluntarily disclose account metadata (never content, which we cannot decrypt) when we believe in good faith that an emergency involving imminent risk of death or serious physical injury to any person requires disclosure without delay.
Submit an emergency request from a verified law-enforcement-domain email address to legal@boopr.com with the subject line "Emergency Disclosure Request." A valid request identifies the requesting agency and officer, describes the nature of the emergency, identifies the specific account(s) and data sought, and includes a senior-officer attestation to the emergency. Disclosure is at our discretion based on a good-faith review; we may decline if the emergency is not adequately substantiated or if the request seeks data unrelated to it. Every emergency request and our response is documented.
Preservation requests
On a valid request under 18 U.S.C. § 2703(f), we will preserve the account records available to us for 90 days, extendable once for an additional 90 days on renewal. Preserved data includes metadata and encrypted blobs, which remain undecryptable.
User notification and challenging demands
We notify affected users of requests for their data unless we are prohibited from doing so, for example by a non-disclosure order under 18 U.S.C. § 2705(b). We challenge demands that exceed statutory authority or are overbroad, and we challenge non-disclosure orders that exceed the duration permitted under current Department of Justice policy (generally one year absent exceptional circumstances). When a non-disclosure period expires and notice is no longer prohibited, we notify the affected user as soon as reasonably practicable.
Authentication of records
For records we produce under valid legal process, we can provide a written certification authenticating them as records of regularly conducted activity under Federal Rules of Evidence 902(11) and 902(13), so they may be admitted without custodial testimony. We generally do not provide live witness testimony; if a matter genuinely requires it, contact legal@boopr.com to discuss. Records are produced in standard electronic formats.
Child safety
boopr has zero tolerance for child sexual abuse material (CSAM). When we obtain actual knowledge of apparent CSAM (for example, through a user report), we report to the National Center for Missing & Exploited Children (NCMEC) via the CyberTipline as required by 18 U.S.C. § 2258A, preserve the relevant records as required by the REPORT Act, cooperate with investigations, and terminate the account. We do not notify the reported account. Because content is end-to-end encrypted, we do not and cannot proactively scan, hash, or monitor content. To report suspected CSAM, email legal@boopr.com with the subject "CSAM Report," or report directly to the NCMEC CyberTipline.
Transparency reporting
Starting on the one-year anniversary of public launch (August 15, 2027), we will publish an annual transparency report listing the number of legal requests received, the categories of data turned over, and the number of users affected. Where the law lets us report on national-security process (national security letters and orders under the Foreign Intelligence Surveillance Act), we will include it in the aggregate numerical bands permitted by the USA FREEDOM Act.
These guidelines are provided to assist law enforcement, are informational only, are not legal advice, and create no rights or obligations beyond those imposed by applicable law. We may update them at any time, and the current version governs. Nothing here waives any objection or right available to boopr or its users.