Law Enforcement Requests
Last updated: August 2026
Murmelt is a client-side application with no backend, no servers, and no user database. This page explains what we can and cannot provide in response to legal requests.
Murmelt has no data
Murmelt is a client application that runs entirely in the user's browser. It does not operate any servers, relays, databases, or storage. We do not collect, store, or have access to user messages, files, contacts, call data, private keys, or any other user content. There is no Murmelt backend to request data from.
Messages and files
All messages are end-to-end encrypted with NIP-17 before being published to Nostr relays. Files are encrypted with AES-GCM before being uploaded to Blossom servers. Murmelt never sees the plaintext of any message or file, does not route them, and does not store them. We cannot decrypt, read, or provide any user communication.
Calls
Voice and video calls use WebRTC peer-to-peer connections. Media flows directly between participants' devices. Murmelt does not route, record, or store call media. Only the ephemeral signaling messages (needed to set up the call) travel through Nostr relays, and they are encrypted.
Where to send requests
Since Murmelt does not host or store any content, requests for user data or content removal should be directed to the relevant Nostr relay or Blossom server operators. Each relay and server is an independent third party with its own legal address and compliance process. The relay or server URL is visible in the user's relay settings.
What we cannot do
We cannot identify users, provide account information, decrypt messages, hand over private keys, or remove content from relays or Blossom servers. We do not have this data. Users' private keys are generated and stored locally on their devices and are never transmitted to us.