Law Enforcement Guidelines
Last updated 4 July 2026
This page explains how outr handles requests from law enforcement and other government or public authorities for data we hold. It gives authorities a clear route to make a valid request and tells our users how we handle those requests. Read it alongside our Privacy Policy.
We take our users' privacy seriously, and we take our legal obligations seriously. We disclose data only when the law requires or permits it, and only as far as required.
1. Who may request data
These guidelines cover requests from law enforcement agencies, courts, regulators, and other government or public authorities. Requests from private parties, for example in a civil dispute, go through the normal legal process for those matters and are not covered here. Intellectual-property complaints go through our Copyright and DMCA Policy.
2. The legal process we require
We need a valid legal instrument that fits the data requested and comes through proper legal channels. Depending on the request and the jurisdiction, that could be a court order, subpoena, warrant, or an equivalent lawful demand recognized where outr is established. A request must:
- come from an identifiable, authorized official, on official letterhead or through an official channel;
- state the legal basis and authority for the request;
- be specific about the account and the data sought, and be proportionate to the matter; and
- come from, or be enforceable in, the correct jurisdiction. outr is established in the European Union. Requests from authorities outside that jurisdiction generally need to come through the applicable mutual legal assistance or other recognized cross-border channels.
We may decline, narrow, or challenge a request that is overbroad, unclear, not proportionate, or not properly authorized.
3. What we can and cannot produce
We can produce only data we actually hold. That may include:
- account and profile data (for example, account email and account identifiers);
- subscription and billing metadata we hold (subscription status, plan, and billing period);
- campaign and usage data tied to an account (for example, campaigns, targeting criteria, and usage records);
- lead and recipient data stored in the account (for example, lead records and the content of replies received into the account's inbox).
We cannot produce data we do not hold, including:
- card numbers, expiry dates, or security codes. We do not store card data; it sits with our payment processor, so requests for it should go to that processor.
- data our providers hold on their own systems, which you may need to request from them directly (for example, sending records held by our email-sending provider).
Passwords are stored in hashed form by our authentication provider and we cannot recover them in plain text.
4. Telling the affected user
Our policy is to tell the affected user about a request for their data before we disclose it, so they have a chance to protect their rights, unless the law bars us from telling them (for example, a court order or a statutory non-disclosure rule) or there is an emergency involving a risk of death or serious physical harm. Where we are barred from giving notice for a limited period, we will consider telling the user once the bar lifts.
5. Emergency requests
In a genuine emergency involving an imminent risk of death or serious physical harm to a person, we may disclose a limited set of data to law enforcement without the usual legal process, where disclosure is needed to prevent that harm and the law permits it. An emergency request must come from an authorized official, describe the emergency and the specific harm, and identify the data needed to address it. We assess each emergency request on its own facts and disclose only what is necessary.
6. Data preservation
We will consider reasonable, specific requests to preserve data relevant to an active investigation for a limited period, pending valid legal process. A preservation request on its own does not require or authorize disclosure; disclosure still needs a valid legal instrument as set out above.
7. How to submit a request
Send law enforcement and government requests to support@tryoutr.io, addressed to the legal team. Include the legal instrument, the identity and authority of the requesting official, a clear description of the account and data sought, and a return contact. We acknowledge valid requests and respond within the time the applicable legal process requires.
8. Costs
Where the law permits, we may charge a reasonable fee to cover the cost of responding, particularly where a request is voluminous or burdensome.
9. Relationship to our Privacy Policy
How we handle personal data, including the legal bases on which we may disclose it, is set out in our Privacy Policy. These guidelines explain how we handle authority requests in practice and do not expand the categories of data we collect or hold.
10. Changes
We may update these guidelines. For a material change we will update the version and date above.
Questions about this page? Email support@tryoutr.io.