What should I ask an app provider for?¶
Ask for records tied to a precise account, event and time range, such as registration, sessions, devices, security changes, content or message status.
Tailor the request to the issue¶
Attribution may need installation and session IDs, network addresses and linked devices. Compromise may need logins, password, recovery and authentication events. Edited or deleted content may need original, delivery and change records. Payments, reports or complaints require their own references.
Expect provider-specific limits¶
Retention and content availability vary; encrypted services may hold metadata but not message text. Use lawful preservation where loss is credible and avoid unbounded requests. Provider activity identifies an account or session before it identifies the person controlling it.
Key takeaway
Ask the app provider a focused account-and-event question and corroborate the returned session evidence with device and human-control records.