Trust center · updated 2026-08-04

Every request,
counted.

We say that anyone who wants your data comes through a European court, and through us first. This is where that becomes checkable: every government and law-enforcement request we receive, published each quarter, including the quarters where the answer is zero.

Q2 2026 · published 2026-08-04
Nothing to report.
Requests for Customer Data received0
Confirmed personal-data breaches0
Sub-processors added or replaced0

Next edition: Q3 2026, publishing October 2026. Sub-processor changes are listed in full, with dates, on the sub-processor page. Every edition is also available as JSON, so a quarter can be diffed against the last without scraping this page.

Method

How we count,
and what we cannot count.

What counts
Any demand from a public authority for Customer Data or for information about a customer: a police request, a prosecutor or court order, an administrative demand, or an emergency disclosure request. Every one that reaches us is logged in a single register, whether or not it results in disclosure, and these counts come from that register rather than from a search after the fact. Abuse reports and spam complaints are not requests for data and are not counted.
When we publish
Within 30 days of the end of each quarter, whatever the numbers say. The first edition covers everything before its quarter as well, so nothing since the service started is left out. The next edition covers Q3 2026 and publishes in October 2026.
What this page cannot tell you
If we were ever served an order that legally barred us from disclosing its existence, it could not appear in these counts, and no provider anywhere can promise otherwise. What we can tell you is what we do when a request arrives: we check that it is valid under Dutch law, narrow it to what is legally required, challenge it where there are grounds, and notify the customer unless the law forbids it. Remails B.V. has no US parent or affiliate, so a foreign authority has no domestic entity to serve and must go through a European court.

The rest of
the trust center.

The sub-processor list names every company that touches your data. The security page sets out the architecture and where each certification actually stands.

Sub-processorsSecurity & trust