Law Enforcement Data Request Guidelines
Version 2026-10-07 · Effective 2026-10-07
On this page
1. General
StepGuardian (the "Service") handles data that carries a family's location and daily life. The Operator therefore bears two responsibilities at once: protecting users' personal information and cooperating with lawful legal process. These guidelines set out the standards that apply when law enforcement agencies request data about Service users.
- No voluntary disclosure: The Operator does not voluntarily provide user data to law enforcement without lawful process grounded in applicable law.
- Careful handling of children's data: Much of the data this Service holds is children's personal information. The Operator reviews requests concerning children's data with particular care.
- Legal review required: These guidelines take effect only after review by legal professionals. Until that review is complete, no provision here is final, and the contents may change as a result of the review.
- Related document: For details of data items, processing purposes, and retention periods, the Privacy Policy governs.
2. Data we hold and retention periods
The principal data the Operator holds, and its retention periods, are as follows. Retention periods are identical to Section 4 of the Privacy Policy.
| Item | Contents | Retention period |
|---|---|---|
| Account information | Parent account email, family profiles (nickname, photo) | Until account deletion |
| Location and routes | GPS location, movement routes | 90 days from collection |
| App-use records (detailed) | App usage time, launch records, installed-app list | 90 days from collection |
| App-use records (summary) | Summaries and statistics of usage records | 13 months |
| Family chat | Text, images, voice messages, stickers, files | 60 days |
| Activity and tamper alerts | Type and time of family events and of attempts to remove the app or turn off permissions | 90 days |
| Notification metadata | App, time, category and count of notifications (no content) | 30 days |
| Smombie alert history | Start and end time, duration, how the alert was cleared | While the family link lasts |
- Expired data cannot be produced: Data past its retention period is automatically and permanently deleted (Privacy Policy, Section 12). Deleted data cannot be produced even in response to valid legal process.
- Items not in the table above (device status, safe-zone settings, consent records, etc.) are governed by Sections 3 and 4 of the Privacy Policy.
- The child app has no separate account or login (anonymous authentication), so a child's data is identified through the connected parent account.
3. Request procedure and requirements
Data requests from law enforcement must satisfy the following requirements.
- Lawful process: The request must be supported by documents issued under lawful process as prescribed by applicable law, such as a court-issued warrant.
- Verification of the agency and officer: The request must include official documentation identifying the requesting agency, the officer's affiliation, name, and contact details, and a reply address.
- Identification of the subject: The request must include information that identifies the target user (such as the parent account email).
- Specific scope: The request must specify the data items and the time period sought. The Operator does not provide data beyond the requested scope and may require overly broad requests to be narrowed.
- Intake channel: Send requests to help@guardianlabs.app with "Law enforcement request" in the subject line. The Operator processes them only after verifying the requesting agency and officer.
- Requests that do not meet these requirements may be returned for supplementation or refused.
4. User notice principle
- When the Operator provides user data to law enforcement, its principle is to notify the affected user of that fact.
- Exception: Where notice is prohibited by law or by an order of a court or other competent authority, the Operator does not give notice; where the prohibition has a set duration, the Operator gives notice after that period ends.
- The same principle applies to data provided under emergency requests (Article 5).
5. Emergency requests
- Where there is an imminent risk to a person's life or physical safety (for example, a missing child or a risk of self-harm), the Operator reviews the request faster than the ordinary procedure, within the bounds permitted by applicable law.
- An emergency request must substantiate the nature of the imminent risk and why the requested data is necessary to prevent it.
- Where data is provided under an emergency request, the Operator may subsequently require the supporting documents of lawful process to be supplemented.
6. Version History
| Version | Effective date | Changes |
|---|---|---|
| 2026-07-10 | (not yet in effect) | Initial draft — pending legal review (DRAFT) |
| 2026-09-30 | 2026-09-30 | Aligned the data table with the revised Privacy Policy (notification metadata, alert history, etc.); set the intake email |
| 2026-10-07 | 2026-10-07 | Changed the request intake email to our company-domain (guardianlabs.app) address |
