Every request we receive, counted
Four times a year we publish how many requests for customer data, court orders, takedown demands and abuse reports reached us — and how many we acted on.
- Q3 2026current report
- 0data disclosed to authorities
- Quarterlypublication schedule
Publication scheduleEvery quarter
- Q3 2026
- Published 25 September 2026Current report — our first
- Q4 2026
- Early January 2027
- Q1 2027
- Early April 2027
- Q2 2027
- Early July 2027
Reports are added, never rewritten: past quarters stay online exactly as published.
See the Q3 2026 figuresThe numbers
1 July – 30 September 2026, figures as of 25 September 2026. DediCrypto opened in September 2026: this is our first report.
A zero here is a real zero, not a rounded number. When figures are not zero, we add what kind of request it was, which country it came from and what we did — without anything that could identify a customer.
| Type of request | Received | Complied |
|---|---|---|
| Requests for customer data from law enforcement or government | 0 | 0 |
| Court orders, subpoenas and warrants | 0 | 0 |
| Gag orders or secret requests (see the warrant canary) | 0 | 0 |
| Requests to remove content or suspend a service from an authority | 0 | 0 |
| Copyright notices (DMCA and equivalents) | 0 | 0 |
| Abuse reports: spam, phishing, malware, attacks | 0 | 0 |
| Next report: early January 2027, covering Q4 2026. | ||
How we handle a request
The same rules apply to every request, whoever sends it.
Is it valid?
Only a binding order from a competent authority in the country where the data is stored can compel us. Informal requests, emails and threats are answered with a request for proper legal process.
Is it narrow?
We push back on requests that are unlawful, too broad or aimed at people rather than specific services, and challenge them where the law allows.
We tell you
The customer is notified before any disclosure, unless a court order legally forbids it — which the warrant canary would reveal by its silence.
We count it
Every request lands in the next report, with what we did. Even the ones we refused.
Very little, by design
The best protection is data that does not exist. For a typical account, a valid order would find what is listed here — and nothing else.
What exists
- An email address
- Invoices and on-chain payment IDs
- Support tickets
- 30 days of client-area sign-in IPs
What does not
- Name, address, phone, ID
- Card or bank details
- Website visitor IP logs
- Anything stored on your server
