Legal requests

Information for law enforcement and legal requests.

What Aura holds on each surface, what it can and cannot produce, how to ask, and how we handle emergencies, preservation and user notice.

Last updated: 3 October 2026 · See also the Terms and the Privacy Policy

Who this is for

This page is for law-enforcement agencies, courts and other authorities, and for lawyers acting under valid legal process, who need information from Aura. Aura is operated by Orgware Construct Pvt. Ltd., a company registered in Nepal. Users who want their own data should use the self-service routes on the privacy page instead.

We respond to requests from competent authorities in Nepal and, where applicable, other jurisdictions, through channels recognised by the applicable laws. We do not decide that a request is valid because it is on letterhead: see How we review requests.

What Aura holds, by surface

What can be produced depends on where the user's keys live. We set this out plainly because overstating it in either direction would mislead you.

SurfaceAura holdsAura does not hold
Android and desktop (macOS, Linux) Identity record (display name, public keys, device list); routing metadata (identity and contract identifiers, conversation identifier, sending device, object class, ciphertext size, timestamps, delivery state); encrypted envelopes and attachment blobs until they are pruned; contact-import hashes if the user used contact import; call metadata (caller, callee, times); the Android push token; security and audit records; business records; plan information. Message, note, Vault and attachment content in readable form; device private keys; the user's passphrase.
Hosted web app (app.auratt.com) Everything listed above, and in addition the user's device private keys, which are held by an Aura process on our servers. Message plaintext exists in that process's memory while a message is being sealed or opened. Aura does not retain, log or scan that plaintext. But technically it is within reach on this surface, and a lawful order could compel us to use it.
Backups A copy of the server database as of the last backup, kept for a limited time. A deleted account can persist in backups until they age out. Readable content for Android and desktop users.

Aura holds no email address and no phone number for users, so we cannot look an account up by either. Accounts are identified by Aura identity identifier or discovery handle. Calls are not recorded.

What we can and cannot produce

We can produce, when a valid request calls for it: account and device records, routing metadata, timestamps, delivery state, call metadata, audit entries, and ciphertext envelopes that we still hold.

We cannot produce readable message, note, Vault or attachment content for Android and desktop users, because we do not have the keys. We will say so in our response rather than leave it ambiguous.

Hosted web exception. For a user who uses the hosted web app, we technically hold keys and a lawful order could compel us to produce readable content that we are able to access. We do not store readable hosted-web message history, so what exists to produce is limited. We do not promise that compelled production is impossible on this surface.

Retention limits. Delivered ciphertext is deleted 30 days after the recipient's device acknowledges it, and undelivered items are kept until delivered. Reported content is kept longer, as described on the privacy page. Information that has already been deleted cannot be produced.

How to submit a request

Send requests in writing to [email protected] with the subject line "Legal request". This is the same contact listed on the support page; there is no separate legal mailbox today. Paper requests may be sent to Orgware Construct Pvt. Ltd., Prachin Marg-10, Old Baneshwor Height, Kathmandu, Nepal.

Please include:

  • the issuing authority, and the name, position and official contact details of the person submitting;
  • the legal basis: the order, warrant, summons or other process, attached in full;
  • the identifiers you are asking about (an Aura identity identifier or discovery handle; we cannot search by name, email or phone number);
  • the scope: exactly which data and which date range;
  • the urgency, and any deadline in the process;
  • whether you ask us not to notify the user, and the legal basis for that; and
  • a contact we can verify independently of the message itself.

Do not send requests through the in-app report tools, and do not send message content or personal data in an unauthenticated channel.

Emergency requests

If you believe there is an imminent risk to a person's life or of serious physical harm, say so at the start of the subject line ("Legal request - EMERGENCY") and in the first line of the message, and describe the risk and why it is imminent. We prioritise these above everything else and may disclose limited information we hold if we believe it is necessary to prevent that harm, even before formal process arrives, in which case we ask for the process afterwards. We cannot locate a user and have no location data, and the information we hold may not help; please also contact local emergency services.

Preservation requests

On a valid preservation request from a competent authority we will take reasonable steps to preserve, for up to 90 days while formal process is obtained, the account, device and routing records we hold about the named account. Preservation is limited to what we technically hold and cannot recover anything already deleted. In particular, message ciphertext on our servers is deleted on the schedule in our privacy policy (30 days after the receiving device acknowledges it), so it can only be preserved if it still exists when your request reaches us, and we cannot read it on Android or desktop in any case. Send preservation requests as early as you can.

How we review requests

Every request is reviewed by a person, and escalated to legal counsel where it is unclear. We check that it comes from a competent authority, has a valid legal basis, is specific, and that we are able to respond. We challenge or narrow requests that are overbroad, vague or not properly authorised, and we disclose only the narrowest data that satisfies a valid request. We record every request in an internal log.

We do not provide bulk access, standing access, real-time interception, or any backdoor or technical capability that would weaken encryption. For Android and desktop users no such capability exists, and we will not build one.

Notifying users

We notify affected users before or when we disclose their information, unless we are legally prohibited from doing so or notice could risk harm to a person or the integrity of an investigation involving serious harm. Because we hold no email address or phone number for users, notice is given inside the Aura app. Where non-disclosure is requested, we ask for the legal basis and, where it is allowed, we notify the user when the restriction ends.

Transparency

We commit to publishing aggregate figures about the legal requests we receive and how we respond: how many we received, how many we challenged or narrowed, how many produced data, how many involved emergencies or preservation, and how many users we notified. We will publish these without identifying the people or cases involved. If we receive a request that we are legally barred from reporting, we will say that such requests exist, to the extent that is allowed.

No transparency report has been published yet; this page will link to the first one when it exists.