Transparency

We publish what we can. We tell you when we cannot.

Trust requires accountability. This page documents Candidfy's legal-request history and our disclosure policy. We update it periodically.


On our warrant canary

We previously published a warrant canary here. A canary is only meaningful if maintained on a strict, verifiable cadence — and one that lapses can be misread as a signal it was never meant to send. We would rather not run a canary than run one unreliably, so we have deliberately retired it as of July 13, 2026. This is a considered policy decision, not the result of any legal order.

Our policy on disclosure is unchanged: we disclose sender identity only when compelled by valid legal process. We may reintroduce an automated, cryptographically-signed canary in the future.

Legal requests — cumulative record

PeriodRequests receivedComplied withChallengedUser data disclosed
Launch – May 20260000

Next update: November 2026.


Our disclosure protocol

When Candidfy receives a legal request for user data, we follow this process without exception:

1
Legal review

Every request is reviewed by qualified legal counsel. We verify jurisdiction, specificity, proportionality, and legal authority before taking any action.

2
User notification

Where legally permitted, we notify the affected user before complying. Where notification is legally prohibited, we log the prohibition and include it in our next transparency report.

3
Challenge where appropriate

We challenge requests that are overbroad, lack proper jurisdiction, or seek bulk data rather than specific individuals.

4
Maximum scrutiny

We treat any request for user data with maximum scrutiny, and disclose only when compelled by valid legal process.

5
Minimum disclosure

We disclose only the specific data required by the legal order — nothing more.

6
Record-keeping

We keep records of the legal requests we receive and reflect them in our aggregate transparency reporting.


What we will not do

Candidfy will never voluntarily disclose sender identity without valid legal process. We will never comply with informal requests from law enforcement. We will never comply with civil litigation requests without a court order. We will never disclose data in bulk. We will never build backdoors or weaken our encryption at the request of any government.


Data retention

Raw message contentDeleted immediately after AI processing
One-shot message contentDeleted when the recipient opens it
Journey thread contentRetained encrypted while active; auto-closed after 60 days of silence
Recipient contact (email/phone)Encrypted while the thread is active, then deleted
Account email/phoneRetained while account is active; deleted on account deletion request
Delivery logsRetained 90 days for abuse prevention; pseudonymous only
IP address logsRetained 7 days; gateway level only
Audit logsRetained indefinitely; append-only, tamper-evident

Contact

Legal requests: legal@candidfy.com
Privacy enquiries: privacy@candidfy.com
Security concerns: security@candidfy.com