Are you a law enforcement officer conducting an investigation that may involve user content hosted on the Block Protocol? Or maybe you're a privacy-conscious person who would like to know what information we share with law enforcement and under what circumstances. Either way, you're on the right page.
In these guidelines, we provide a little background about what the Block Protocol is, the types of data we have, and the conditions under which we will disclose private user information. Before we get into the details, however, here are a few important details you may want to know:
Our users trust us with their data, software projects and code—often some of their most valuable business or personal assets. Maintaining that trust is essential to us, which means keeping user data safe, secure, and private.
While the overwhelming majority of our users use the Block Protocol's services to create new businesses, build new technologies, and for the general betterment of humankind, we recognize that with millions of users spread all over the world, there are bound to be a few bad apples in the bunch. In those cases, we want to help law enforcement serve their legitimate interest in protecting the public.
By providing public guidelines for law enforcement personnel, we hope to strike a balance between the often competing interests of user privacy and justice. We hope these guidelines will help to set expectations on both sides, as well as to add transparency to the Block Protocol's internal processes. Our users should know that we value their private information and that we do what we can to protect it. At a minimum, this means only releasing data to third-parties when the appropriate legal requirements have been satisfied. By the same token, we also hope to educate law enforcement professionals about the Block Protocol's systems so that they can more efficiently tailor their data requests and target just that information needed to conduct their investigation.
Before asking us to disclose data, it may be useful to understand how our system is implemented. The Block Protocol hosts a wide variety of projects, in a variety of different ways, including Git repositories. Projects on the Block Protocol—which may be public or private—are most commonly used for software development projects, but are also often used to work on content of all kinds.
Users — Users are represented in our system as personal Block Protocol accounts. Each user has a personal profile, and can own multiple projects. Users can create or be invited to join organizations or to collaborate on another user's project.
Collaborators — A collaborator is a user with read and write access to a project who has been invited to contribute by the project owner.
Organizations — Organizations can contain one or more users, and they typically mirror real-world organizations, such as businesses or projects. They are administered by users and can contain both projects and teams of users.
Accounts — Every user and organization corresponds to a unique account. Projects and data can be stored within and 'owned by' an account, sometimes also called a 'namespace' or a 'workspace'.
Projects — The term project can be used to describe one or more entities, types, blocks, services, or other Block Protocol Hub listings. A project may contain one or more files (including documentation), as well as revision history and other metadata. Projects can have multiple collaborators and, at its administrators' discretion, may be publicly viewable or not.
Here is a non-exhaustive list of the kinds of data we maintain about users and projects on the Block Protocol.
There is a variety of information publicly available on the Block Protocol about users and their repositories.
User profiles can be found at a URL such as https://blockprotocol.org/@username
. They display information about when the user created their account as well their public activity on the Block Protocol and social interactions.
All user public profiles display:
Public user profiles can also include additional information that a user may have chosen to share publicly. This may include:
The Block Protocol also collects and maintains certain private information about users as outlined in our Privacy Statement. This may include:
Information about organizations, their administrative users and repositories is publicly available on the Block Protocol.
Organization profiles can be found at a URL such as https://blockprotocol.org/@organization
. All organization profiles display:
Public organization profiles can also include additional information that the owners have chosen to share publicly. This may include:
You can browse almost any public repository to get a sense for the information that the Block Protocol collects and maintains about projects. This can include:
The Block Protocol collects and maintains the same type of data for private repositories that can be seen for public repositories, except only specifically invited users may access private repository data.
Additionally, the Block Protocol collects analytics data such as page visits and information occasionally volunteered by our users (such as communications with our support team, survey information and/or site registrations).
It is our policy to notify users about any pending requests regarding their accounts or repositories, unless we are prohibited by law or court order from doing so. Before disclosing user information, we will make a reasonable effort to notify any affected account owner(s) by sending a message to their verified email address providing them with a copy of the subpoena, court order, or warrant so that they can have an opportunity to challenge the legal process if they wish. In (rare) exigent circumstances, we may delay notification if we determine delay is necessary to prevent death or serious harm or due to an ongoing investigation.
It is our policy to disclose non-public user information in connection with a civil or criminal investigation only with user consent or upon receipt of a valid subpoena, civil investigative demand, court order, search warrant, or other similar valid legal process. In certain exigent circumstances (see below), we also may share limited information but only corresponding to the nature of the circumstances, and would require legal process for anything beyond that. The Block Protocol reserves the right to object to any requests for non-public information. Where the Block Protocol agrees to produce non-public information in response to a lawful request, we will conduct a reasonable search for the requested information. Here are the kinds of information we will agree to produce, depending on the kind of legal process we are served with:
The Block Protocol will provide private account information, if requested, directly to the user (or an owner, in the case of an organization account), or to a designated third party with the user's written consent once the Block Protocol is satisfied that the user has verified his or her identity.
If served with a valid subpoena, civil investigative demand, or similar legal process issued in connection with an official criminal or civil investigation, we can provide certain non-public account information, which may include:
In the case of organization accounts, we can provide the name(s) and email address(es) of the account owner(s) as well as the date and IP address at the time of creation of the organization account. We will not produce information about other members or contributors, if any, to the organization account or any additional information regarding the identified account owner(s) without a follow-up request for those specific users.
Please note that the information available will vary from case to case. Some of the information is optional for users to provide. In other cases, we may not have collected or retained the information.
We will not disclose account access logs unless compelled to do so by either:
In addition to the non-public account information listed above, we can provide account access logs in response to a court order or search warrant, which may include:
We will not disclose the private contents of any account unless compelled to do so under a search warrant issued under the procedures described in the Federal Rules of Criminal Procedure or equivalent state warrant procedures upon a showing of probable cause. In addition to the non-public account information and account access logs mentioned above, we will also provide private account contents in response to a search warrant, which may include:
If we receive a request for information under certain exigent circumstances (where we believe the disclosure is necessary to prevent an emergency involving danger of death or serious physical injury to a person), we may disclose limited information that we determine necessary to enable law enforcement to address the emergency. For any information beyond that, we would require a subpoena, search warrant, or court order, as described above. For example, we will not disclose contents of private repositories without a search warrant. Before disclosing information, we confirm that the request came from a law enforcement agency, an authority sent an official notice summarizing the emergency, and how the information requested will assist in addressing the emergency.
Under state and federal law, the Block Protocol can seek reimbursement for costs associated with compliance with a valid legal demand, such as a subpoena, court order or search warrant. We only charge to recover some costs, and these reimbursements cover only a portion of the costs we actually incur to comply with legal orders.
While we do not charge in emergency situations or in other exigent circumstances, we seek reimbursement for all other legal requests in accordance with the following schedule, unless otherwise required by law:
We will take steps to preserve account records for up to 90 days upon formal request from U.S. law enforcement in connection with official criminal investigations, and pending the issuance of a court order or other process.
Please serve requests to:
HASH, Inc. FAO: Block Protocol Legal Counsel 2109 Broadway Unit 1141 New York, NY 10023 USA
For the fastest response time, email a courtesy copy of your request to [email protected]
Please make your requests as specific and narrow as possible, including the following:
Please allow at least two weeks for us to be able to look into your request.
As a United States company based in New York, the Block Protocol is not required to provide data to foreign governments in response to legal process issued by foreign authorities. Foreign law enforcement officials wishing to request information from the Block Protocol should contact the United States Department of Justice Criminal Division's Office of International Affairs. The Block Protocol will promptly respond to requests that are issued via U.S. court by way of a mutual legal assistance treaty (“MLAT”) or letter rogatory.
Do you have other questions, comments or suggestions? Please contact support.