Skip to content

Government Data Request Policy

How SpaltX handles law-enforcement and government demands for user data: required legal process, user notice, emergency disclosure, and non-US requests.

Effective July 19, 2026Last updated July 19, 2026
Contents · 9 sections

In short: we require valid legal process matched to the sensitivity of the data, we produce the narrowest responsive set, we tell users unless a court forbids it, and we publish the numbers twice a year. Aircraft do not report flight data to SpaltX by default, so most of what agencies ask about does not exist on our systems.

01

Scope and definitions

This policy governs how SpaltX (Optiarms Inc., d/b/a SpaltX Industries) responds to demands from law enforcement and other government agencies for information about our users. It applies to every SpaltX service: the store, accounts, firmware entitlements, fleet management, support, and Forge. It binds our staff worldwide and is applied by our legal team, not by individual employees.

Legal process
A subpoena, court order, search warrant, or equivalent instrument that is valid on its face, issued by an authority with jurisdiction, and properly served on SpaltX or its registered agent.
User data
Any record we hold that is linked or linkable to an identifiable user or account, whether supplied by the user or generated by our systems.
Non-content records
Metadata about the use of a service: sign-in timestamps, IP addresses, download logs, device registration records, and similar logs that do not include the substance of a communication or file.
Content
The substance of what a user stores or communicates through SpaltX: message bodies, Forge documents and CAD files, and uploaded attachments.
02

What data we hold

SpaltX is a hardware and software company, not a communications platform, and we collect accordingly. The categories of user data that exist on our systems are:

  • Account records — name, email address, hashed credentials, account creation date.
  • Order and shipping records — purchase history, billing and shipping addresses, payment method metadata (we never store full card numbers).
  • Contact and support messages — messages sent through our contact form and support desk.
  • Service logs — sign-in timestamps and IP addresses, firmware download and entitlement logs, fleet device registration records.
  • Forge documents — CAD parts, drawings, and exports a user stores in Forge.
What we do not have
SpaltX aircraft do not stream telemetry, imagery, or flight video to SpaltX by default. Flight data recorded by a customer’s aircraft stays on the aircraft and the customer’s own devices unless the customer chooses to share it with us. We cannot produce records we do not possess, and we say so in response to process that seeks them.
04

Emergency requests

Consistent with 18 U.S.C. § 2702(b)(8) and (c)(4), we may disclose user data without legal process where we have a good-faith belief that an emergency involving danger of death or serious physical injury requires disclosure without delay.

An emergency request must include, in writing:

  • the nature of the emergency and the imminent harm at issue;
  • why the specific records sought are necessary to address it;
  • the identity and agency of the requesting officer with a callback number; and
  • an attestation that the request is true and accurate, made under the requestor’s authority.
Case-by-case, narrow, and documented
Emergency disclosure is voluntary, evaluated case by case by our legal team, and limited to the narrowest data set that addresses the emergency. Every emergency disclosure is documented and counted in our transparency report. A denied emergency request may always be resubmitted as standard legal process.
05

User notice

Our default is to notify the affected user before producing their data, with a copy of the process, so they can object. We delay or withhold notice only where a court order under 18 U.S.C. § 2705(b) or an equivalent statute prohibits it, or in a bona fide emergency involving risk to a person.

Where notice is delayed by a nondisclosure order, we calendar the order’s expiry and notify the user when it lapses, unless it is renewed. We do not accept indefinite gag requests that lack legal basis.

06

Non-US requests

SpaltX is a US company and produces user data only in response to valid US legal process. Government agencies outside the United States must proceed through a mutual legal assistance treaty (MLAT), letters rogatory, or an executive agreement under the CLOUD Act, so that a US authority issues the process we act on.

We do not produce user data directly to non-US authorities, and we object to process that conflicts with US law or with the law of the user’s country of residence.

07

Preservation requests

On receipt of a valid preservation request under 18 U.S.C. § 2703(f), we preserve a point-in-time snapshot of the identified records for 90 days, extendable once by a further 90 days on a renewed request. Preservation is not production: preserved records are only disclosed in response to the legal process required by this policy, and are deleted when the preservation period lapses without process.

08

Cost reimbursement

As 18 U.S.C. § 2706 permits, we may seek reimbursement of reasonable costs for voluminous or technically burdensome productions. We do not charge for emergency requests, preservation requests, or routine productions of modest scope.

09

Transparency reporting

Twice a year we publish the number of government requests received and the number where any data was produced, broken out by request type, on the Government requests page. National security requests, if any, are reported only in the bands US law allows. Material changes to this policy are announced on that page and reflected in the effective date above.