Transparency report

Zero, and we publish it anyway.

In the six months to 30 June 2026 Orbislo received zero law enforcement requests for customer data, made zero disclosures, and received zero national security orders. We publish this report at zero, twice a year, on a fixed schedule, so that the first number that is not zero is impossible to miss.

The reporting period is 1 January 2026 to 30 June 2026, published on 8 July 2026. The next report covers the second half of the year and is published in the first fortnight of January.

Government and law enforcement

CategoryRequests receivedAccounts affectedData disclosed
Subscriber information requests000
Content requests000
Real time interception orders000
Preservation requests000
Emergency disclosure requests000
National security orders000
Requests refused for invalid process000
Content removal requests000

Every row is counted whether or not it resulted in a disclosure. A refused request still happened, so it still appears.

Why publish a table of zeros

A company that starts publishing a transparency report only once it has something to report has told you something by the timing alone.

Publishing at zero, on a fixed schedule, removes that ambiguity in both directions. If the next report carries a one, the one is visible against seven previous zeros rather than against silence.

It also forces us to build the counting before we need it. The process that logs a request, routes it to counsel, records the outcome and lands it in this table has been exercised at zero volume, which is a much better time to discover it is broken than the afternoon a first order arrives.

This report is the canary

This report is the canary. It is published in the first fortnight of January and the first fortnight of July. A report that arrives late, or with a section quietly removed, is itself information, and you should read it that way.
A traveller waiting with luggage in an airport departure area
What we hold about a customer is thinner than people expect, which is the strongest privacy control we have.

Customer data requests

These are requests from customers about their own data, under the GDPR, the UK GDPR, the CCPA and CPRA, the LGPD, PIPEDA and the APPI.

We count them in one total rather than splitting them by regime, because splitting makes every individual number look reassuringly small.

Requests from customers about their own data

Request typeReceivedHonouredMedian time to complete
Access and export1,4121,4124 days
Correction3183181 day
Account deletion90690611 days, ceiling 30
Objection to coverage measurement2,2042,204Immediate, it is a switch
Requests refused0Not applicableNot applicable

The statutory ceiling is usually a month. We publish the median rather than the deadline we did not miss.

What the numbers mean

Deletion runs within 30 days including from backups, and the median is shorter because backup rotation is the slow part rather than the decision.

The objection figure is high on purpose. Switching coverage measurement off is one tap in the app rather than a written request, and we count every one of those taps here, so the number is not flattered by friction we removed.

0

law enforcement requests received

0

accounts with data disclosed to any authority

906

account deletions honoured, out of 906 asked

4 days

median time to answer an access request

Our stance

The last point is the one that matters most. Coverage measurements carry a geohash of roughly one kilometre rather than a position, they never carry browsing history or message content, and nothing is published for a cell with fewer than 25 samples.

The design is described in full on the security page and in the privacy policy. Data that was never collected cannot be demanded.

  • We require valid legal process. A request by email from a government address is not legal process, and it will be refused and counted
  • We read every order narrowly. If it asks for more than it can lawfully compel, we push back before we produce anything
  • We notify the customer unless a court order forbids it, and where a gag applies we challenge it if there is a reasonable basis
  • We do not build capability we are not required to build. There is no interception facility waiting to be switched on
  • We do not sell personal data. There is no version of this business where that is the plan
  • We hold less than people assume, which is the control that survives a bad day in court

How to reach us about this

Legal process should be served on legal at orbislo.com.

Customers exercising their own rights should use the app, where access, export and deletion are all self service, or write to privacy at orbislo.com.

Journalists should start at the media centre, which carries the boilerplate, the brand facts and a named press contact.

Questions people actually ask

Why publish a report when every enforcement number is zero?
Because a report that only appears once there is something to report is itself a signal. Publishing at zero every six months means the first number that is not zero is visible the moment it exists, and nobody has to wonder whether the silence was policy or a decision.
What would you actually hand over if you were compelled?
What we hold, which is less than people assume. An email address, a purchase history, the device model a profile was installed on, and coarse connection quality events at roughly one kilometre. We do not hold browsing history, message content, page addresses or precise location, so no order can compel them out of us.
Would you tell me if my account were the subject of a request?
Yes, unless a court order forbids it. Where we are permitted to notify, we notify, and where a gag applies we challenge it if there is a reasonable basis. If a request arrives without valid legal process, we refuse it and count it in the refused row.
Does a warrant canary exist?
This report is the canary, and it runs on a fixed schedule rather than on our mood. It is published in the first fortnight of January and the first fortnight of July, covering the six months before. A late report is itself information.
What counts as a data request?
Any request from a customer to see, correct, export or delete their own data, under the GDPR, the UK GDPR, the CCPA and CPRA, the LGPD, PIPEDA or the APPI. We count them all in one number rather than splitting them by regime to make the total look smaller.
How fast are customer requests answered?
A median of four days for access and export, and deletion runs within 30 days including from backups. The statutory ceiling is usually a month, so we treat the median as the number worth publishing rather than the deadline we did not miss.
Do you publish law enforcement requests you refused?
Yes, as their own line. A request that arrived by email with no legal process and was refused still happened, and burying it would defeat the purpose of counting.