What should I ask an app provider for?¶
Ask the app provider for records that answer the specific investigative question.
What this means¶
Possible records include account-registration details, usernames, linked email addresses or telephone numbers, login history, device information, IP addresses, session records, security events, payment records, content, message metadata, linked devices and account changes.
The provider may also hold records of password resets, multi-factor authentication, account recovery, deletion, suspension, reports or complaints.
But availability varies.
Some providers retain message content.
Others hold only limited account or delivery information.
Make the request precise.
Broad requests can delay the enquiry and return large volumes of irrelevant data.
Where records may be volatile, consider preservation through lawful local process.
The operational takeaway is: ask the app provider targeted questions about the account, sessions, devices, content and security events. Use provider records to clarify the activity, then corroborate who controlled the account and device.
What to check or do next¶
- Identify the account, relevant time period, event and record type.
- If the issue is attribution, ask which device or session created the activity.
- If compromise is suspected, ask about new logins, password changes, trusted devices and recovery events.
- If content was edited or deleted, ask whether the provider records the original event, later change or deletion.
- Do not ask for everything by default.
Evidential limits¶
End-to-end encrypted services may not be able to provide message content, but may still hold useful account, device and connection records.