RainWillCome
LegalHome

Law enforcement cooperation

What we can and cannot give to authorities.

RainWillCome is a Netherlands-registered company committed to cooperating with lawful, properly authorised legal process, and equally committed to refusing requests that exceed it. Our end-to-end encrypted design also means there is data we simply do not hold and therefore cannot produce. This page is the plain-language summary. Last updated 2026-05-15.

  1. Our position

    We comply with valid legal orders from the competent Dutch authority. Foreign requests must be routed through the recognised mutual-legal-assistance channels: a European Investigation Order (EIO) for EU Member States, an MLAT request for non-EU jurisdictions, or, once they are in force for the Netherlands and the requesting state, the EU e-evidence regulation and the US CLOUD Act executive agreements.

    We do not voluntarily disclose user data outside of:

    • A valid legal order routed through the correct channel.
    • A genuine, time-critical emergency where there is an imminent risk to the life or physical safety of a person, in which case we may make a voluntary disclosure under GDPR Article 6(1)(d).
    • Mandatory reporting of apparent child sexual abuse material (CSAM) to NCMEC CyberTipline (United States, under 18 USC §2258A) and to Offlimits / EOKM (Netherlands) when we obtain actual knowledge.
  2. What we hold (and can produce)

    The following data is plaintext on our servers. With a valid legal order, we can produce:

    • Account record: email address, account creation date, last-login date and IP, current subscription tier and tier-paid-since date.
    • Team membership rows: team UUIDs the account belongs to, role (owner / admin / member), status (active / pending), joined-at timestamp.
    • Message metadata: per-message UUID, team UUID, author user UUID, created-at timestamp. Counts and timing patterns are derivable.
    • Skill-directory profile (if findable): display name, country, city, skills, additional skills, wishes, preferences, whatever the user chose to publish.
    • Abuse reports: reporter user UUID, reported user UUID, team UUID, message UUID, plaintext snapshot of the single reported message (the reporter has consented to share that one message), reporter notes, category, status.
    • Moderation audit log: account suspensions and the reason, dates, target user UUIDs.
    • Billing records (when subscriptions are wired): name and address on file at the payment processor, subscription history, invoice numbers. Card numbers and the full payment details live with the payment processor, not with RainWillCome.
  3. What we do not hold (and cannot produce)

    The following data is encrypted on the user’s device before it reaches our servers. We hold the ciphertext only. We cannot decrypt it. There is no key escrow, no master key, and no "ghost participant" mechanism.

    • Vault contents: questionnaire answers, household roster, plans, medications, inventory, drills, resilience responses, and any user-typed name.
    • Team-blob contents: the team’s shared notes and the roster display names recorded in that blob.
    • Team-message bodies: every message sent in team chat is AES-GCM ciphertext under the team key, which never leaves member devices.
    • Pending-join request display names: even the display name a user submits with a request to join a team is encrypted under the team key for the admins to decrypt.
    • Master keys, vault keys, or team keys. These are derived on, and live only on, user devices.

    If you require the content of any of the above, the only technical path is through the device of the user concerned, not through RainWillCome. We will state this fact clearly in any response to a legal request that asks for content.

  4. How to submit a request

    Requests must be on official letterhead, signed by an authorised officer, and routed through the correct channel for the requesting jurisdiction. Send to:

    legal@rainwillcome.com
    Subject line: "Legal request, [your reference]"

    We will acknowledge receipt within 5 business days and respond on the deadline set by the order. For genuine emergencies (imminent threat to life), email legal@rainwillcome.com with "EMERGENCY" in the subject line, we aim to triage within 4 hours.

  5. What we will refuse

    • Requests not routed through the correct legal channel (e.g. informal foreign-police requests without an EIO or MLAT).
    • Requests for content we technically cannot decrypt. We will state this fact rather than attempt to weaken the encryption.
    • Bulk or speculative requests not tied to a specific user or specific incident.
    • Requests with a clearly impermissible purpose under Dutch, EU, or international human-rights law (for example, persecution of journalists, activists, or lawful political opposition).

    Where a request includes a gag order or non-disclosure clause that we believe is unlawful or overreaching, we will challenge it through Dutch courts and update the warrant canary accordingly.

  6. Transparency report

    We publish a transparency report twice a year listing the number of requests received, by jurisdiction and outcome. See /legal/transparency.

  7. Single point of contact (DSA Art. 11)

    Authorities of the EU Member States, the European Commission, and the European Board for Digital Services may contact us at legal@rainwillcome.com or by post at the address in the imprint. Communications in English, Dutch, German, French, or Spanish are accepted.