Law Enforcement Guide
Effective October 7, 2026
This guide explains how government and law enforcement agencies can ask BizMeet LLC for information about BizMeet accounts. It lists the data we actually hold, how long we keep it, and the legal process we need before we disclose it.
1. Purpose and scope
BizMeet is a professional networking app for adults 18 and older. It is operated by BizMeet LLC, a Wisconsin limited liability company, and it is intended for users in the United States.
BizMeet is meant for lawful professional networking and business. It does not offer jobs, employ or pay members, or handle money between members. Our Terms of Service prohibit fraud, job and task scams, money-mule schemes, off-the-books work, unlawful investment offers, threats and other illegal activity. When we find it, we may delete the account and, where the law allows, refer the matter to the authorities.
We want to help agencies keep people safe. We also owe our members real privacy protection. To balance both, we follow the Stored Communications Act, 18 U.S.C. 2701 to 2713, and other laws that apply to us. We review every request on its own facts, and we disclose only what the law allows and the legal process covers.
This guide is written for government and law enforcement agencies. If you are a member, a lawyer in a civil case, or another private party, see section 11.
This guide is for information only. It is not legal advice, and it does not create any rights or obligations for anyone. We may change it at any time and may depart from it where the law or the facts of a case require. Our Safety Policy (Safety Policy and Safety Tips) refers to this guide as our description of how we work with law enforcement.
2. How to submit a request
Send requests by email to contact@bizmeetapp.org. Please send them from an official government email domain. Before we act, we may verify the request independently, for example by calling the agency at a publicly listed number. Requests we cannot verify may be delayed or declined.
Use one of these subject lines so we can sort your request quickly:
- Law Enforcement Request
- Preservation Request
- Emergency Request
We do not accept requests by phone, by text message or through the BizMeet app.
Every request should include:
- The name of your agency.
- Your name, title, and badge or ID number.
- A callback phone number and an official email address.
- The legal authority for the request.
- For requests for disclosure, the signed legal process, on agency or court letterhead, attached as a PDF.
- The account identifiers described in section 3.
- The specific records you need and the date range.
- The nature of the investigation, such as the offense, if you can share it. This helps us find the right records and avoid disclosing more than you need.
For a preservation request, a signed letter on agency letterhead is enough. It should name the account, give the date range, and confirm that you are seeking legal process. For an emergency request, follow section 7; legal process is not required first.
Please send requests in English, or include a certified English translation.
We accept service by email for convenience. Accepting a request by email does not waive any objection we may have, including objections to jurisdiction, the manner of service, or the scope of the request.
Our mailing address for legal process is BizMeet LLC, 2809 E Hamilton Ave, Unit #2177, Eau Claire, WI 54701. Formal service of process on BizMeet LLC can also be made on its registered agent, as listed in the Wisconsin Department of Financial Institutions' business records.
Email is much faster than mail. If you send anything by mail, please also email a copy.
3. Identifying the account
BizMeet has no usernames, and profiles show only a first name. To find the right account, please give us at least two of these:
- The email address used for the account.
- A verified phone number, if the member verified one.
- The member ID (a UUID), if you have it.
- The first name shown on the profile together with the city shown on it.
- A screenshot of the profile.
- Dates when the person was in contact with the victim or another member.
If we cannot match the details to a single account with confidence, we will tell you and ask for more.
Accounts deleted before we receive your request may no longer exist. When a member deletes their account, most of their data is deleted right away. The same happens when we delete an account for breaking our rules. Section 4 explains what may remain.
After an account is deleted, we no longer hold its email address or phone number, so we cannot look it up that way. Moderation evidence that still exists can be found only by the member ID or through the other member's account.
Deleted data may remain for a limited time in our database provider's routine backups. Those backups exist for disaster recovery. We generally cannot restore individual records from them, and they are overwritten on the provider's schedule.
4. Information BizMeet may have
We describe here only what BizMeet actually stores. Any field may be empty if the member never provided it.
Account and profile
Account details. The account email address, the date the account was created, and the member ID.
Phone number. We do not store full phone numbers. If the member completed phone verification, we keep the last four digits and a keyed fingerprint of the number, so if you give us a number we can tell whether an account confirmed it.
Phone verification texts. A fingerprint of each phone number a verification code was texted to for the account, when, and whether the code was used, even if verification was never completed. Deleted 7 days after the text; if the account is deleted sooner, kept without the account ID until then.
LinkedIn connection. Only if the member connected LinkedIn in Get verified: their LinkedIn member ID, the first name on that LinkedIn account, and when it was connected. LinkedIn also sends the last name, a link to the member's LinkedIn photo and their language setting. We discard these right away and do not store them. We do not ask LinkedIn for the member's email address, connections, job history or posts. The record is deleted when the member disconnects LinkedIn or deletes the account.
Terms acceptance. Which versions of our Terms the member accepted, and when.
Profile. First name, date of birth, city and region text, up to 6 profile photos, three short written statements, and the answers the member chose from our lists (for example goal, sector, status, education, languages, interests, and weekly availability).
Settings. Visibility settings (such as Incognito and hiding age, location or online status), notification settings, age and distance filters, and privacy choices.
Location
Approximate location only. We keep one approximate point for each member. The latitude and longitude are rounded to a 0.02-degree grid, roughly 2 km across, so the stored point can be up to roughly 1 km in each direction from where the phone was. We also keep the time that point was saved, and a city and region name. The city name can be updated more recently than the point and has no separate timestamp. Each new point replaces the previous one. A member can delete the saved point and city at any time.
We do not have GPS history, precise coordinates, or a record of where a member has been over time. The app does not collect location in the background.
Activity
Connections and requests. Connection requests sent and received, whether each was accepted, declined or is still pending, request notes (up to 300 characters), Priority message flags, and dates. A pass on a Discover card is stored the same way as a declined request. We also keep a record of connections that were ended by a disconnect or block. Those records are deleted within about 8 days after the connection ends.
Visits. Records of who opened a member's full profile, and when. Visits are not recorded in some cases, for example when the viewer uses Incognito or the member has muted visit notifications.
Notifications. In-app notifications, with their type, the related member and the time. A notification about a message does not contain the message text. Notifications are deleted automatically 90 days after they are created.
Last seen and read times. The most recent time the member was active in the app (we keep only the latest time, not a history), and the time the member last opened each chat.
Crash reports. If the member's Crash reports choice was on: error details, where in the app's code they happened, the app version and Android version. Deleted 90 days after they are sent, or with the account.
Other features. Records of unblurs, boosts, and extra perks bought from the store. Boost records are deleted 8 days after the boost starts.
Messages
Messages. Text messages between connected members, with sender and time. Chats are text only. There are no photos, files, voice or video in chats.
Messages are deleted when either member blocks or disconnects from the other, and when either member deletes their account. In those cases the whole chat is deleted for both members. Members cannot delete single messages.
Safety records
Moderation evidence. When a member reports, blocks or disconnects from someone, we save a copy of recent messages in that chat. A report saves up to the latest 100 messages and keeps them about 180 days. A block or disconnect saves up to the latest 500 and keeps them 30 days, or about 180 days if a report about that member follows within those 30 days. Each copy holds the member IDs of both people, the sender, the first 1,000 characters of each message, and the time sent. Copies remain for that period even if an account is deleted.
Reports. Who reported whom, the reason chosen from a fixed list, and the date. When either account is deleted, we remove that member's ID from the report. Reports we have reviewed are deleted 2 years after they were made.
Blocks. Who blocked whom, and when.
Purchases and devices
Purchase records. Subscription plan and dates, and records of store purchases and refunds, including store transaction IDs and times. When a member deletes their account, we remove the member ID from these records. We never receive card numbers or other payment details, and we do not store prices.
Push tokens. Push notification tokens for the member's devices (up to 10), with platform and last update time.
Sign-in records and provider logs
IP addresses and sign-in records. Our app tables do not store IP addresses. Our sign-in system (Supabase Auth) runs in the same database. It keeps a record of each signed-in session, which can include the IP address and the app or browser user-agent, plus sign-in and email-confirmation times. It may also keep an audit log of sign-in events that includes IP addresses. Session records are deleted when the account is deleted. Audit log entries and our provider's own system logs are kept for periods our provider sets, and they may cover only a short time. We can provide what we are able to access when we receive the request.
Provider service logs. Supabase, our database and hosting provider, keeps its own service logs. We do not control how long those logs are kept.
Records held by other companies
Some records are held by other companies, and we cannot produce them for you:
- Google holds Google Play payment details and the member's Google account. Google also delivers our push notifications through Firebase Cloud Messaging.
- RevenueCat holds subscription and purchase records under a random billing ID. We can give you that ID while the account exists; it is deleted with the account.
- Resend, our email provider, handles the sign-in codes we email to members.
- Twilio sends the text message codes for phone verification, and may keep records of those messages.
- LinkedIn holds the member's LinkedIn account and its own records of the sign-in used to connect it.
- Cloudflare runs the invisible bot check on sign-up, log-in, email code resend and password reset. We receive only a pass or fail result.
You may need to send legal process to those companies directly.
What we do not have
We do not collect last names. We also do not collect employers, addresses, government ID, gender, contacts, call logs, device identifiers other than push tokens and the user-agent text recorded with sign-in sessions, payment card data, or GPS history. We do not have voice, video or image messages.
How long we keep it
| Record | How long we keep it |
|---|---|
| Account, profile, settings | Until the account is deleted |
| LinkedIn connection | Until the member disconnects LinkedIn or deletes the account |
| Terms acceptances | Until the account is deleted |
| Photos | Until the member replaces or removes them, or deletes the account |
| Location | Only the latest point, until updated, removed by the member, or the account is deleted |
| Messages | Until a block, disconnect, or deletion of either account |
| Connections, visits, notifications | Until the account is deleted. Notifications are deleted automatically 90 days after they are created. A block deletes the pair's connection, chat and notifications, including visits. A disconnect deletes the chat and the message and accept notifications. Ended connections are kept as a record for up to about 8 days after they end. |
| Blocks | Until the member unblocks (possible after 24 hours) or either account is deleted |
| Moderation evidence | Report copies about 180 days after capture; block and disconnect copies 30 days (about 180 days if a report follows), even after account deletion |
| Reports | Open reports until reviewed; reviewed reports 2 years after they were made. Member IDs are removed when an account is deleted. |
| Purchase and refund records | Kept, with the member ID removed when the account is deleted |
| Push tokens | Until sign-out, the end of the sign-in session, 60 days without refresh, the token stops working, or account deletion |
| Phone verification text records | 7 days after the text (the account ID is removed at account deletion) |
| Session records (sign-in IP and user-agent) | Until sign-out or account deletion |
| Sign-in audit log | As long as our provider keeps it |
| Provider logs | As long as our provider keeps them, which may be short |
| Backups | Our database provider keeps backups for a limited period it sets, for disaster recovery. We generally cannot restore individual records from them. |
Our Privacy Policy (Privacy Policy) describes our data practices in more detail.
5. Legal process required
Except in an emergency (section 7), when we report to NCMEC (section 10), or where a member has given lawful consent, we disclose member records to government agencies only with valid legal process of the type the Stored Communications Act requires. A search warrant also covers the records a court order or subpoena would reach, and a 2703(d) court order also covers basic subscriber information.
| Type of record | Examples | Process we require |
|---|---|---|
| Basic subscriber information | Email, first name (and the first name from a connected LinkedIn account), verified phone, account creation date, plan type and dates, sign-in times and IP addresses where available | Subpoena, under 18 U.S.C. 2703(c)(2) |
| Other non-content records | Approximate location and city, date of birth, LinkedIn member ID and connection time, fingerprints of phone numbers a verification code was texted to, Terms acceptance records, connection and request records, visits, blocks, reports, chat participants and times, read times, last seen, purchase and refund records, push tokens | Court order under 18 U.S.C. 2703(d) |
| Content | Message text, moderation evidence text, photos, profile statements and answers, request notes | Search warrant |
We accept legal process from US federal, state and local authorities. A subpoena may be a grand jury, trial or administrative subpoena authorized by law. Process from a state other than Wisconsin should be issued by, or domesticated in, a court with jurisdiction over BizMeet LLC, unless we agree otherwise.
We produce records only for the account named in the legal process. A chat includes messages written by the other member. If you need that member's messages or records, please name their account in the legal process as well.
Member consent. If a member who took part in a conversation gives written consent, we may disclose that member's records and the messages they sent or received to the agency they name. We may verify the consent with the member directly. Often the member can simply share what they see in the app.
We may ask you to narrow a request that seems too broad or unclear, and we may object to process that does not meet legal requirements.
We do not have the technical ability to provide real-time interception or pen register data. We will review any such order and respond as the law requires.
6. Preservation requests
Under 18 U.S.C. 2703(f), an agency can ask us to preserve records while it gets legal process. When we receive a valid preservation request, we export a copy of the records for the named account that exist at that time and store it separately, so our normal deletion schedule does not remove it.
We keep preserved records for 90 days. We extend this once, for another 90 days, if you send a renewed request before the first period ends.
Preservation covers only data that exists when we act on the request. It does not capture later activity; send a new request if you need that. Data that was deleted before we acted, for example after a block, disconnect or account deletion, is removed from our live database and usually cannot be recovered. Section 3 explains our provider's backups.
We do not disclose preserved records until we receive valid legal process for them.
Accounts we remove. We may delete an account that breaks our rules even while it is the subject of an investigation, because it may put members at risk. If we have already received a preservation request or legal process for the account, we first export the records it covers and keep them as described in this section. Deleting an account removes most of its data (section 3). If an account matters to your investigation, send a preservation request as early as you can. If you ask us to leave an account open, we will consider it, but we may still act to protect members.
7. Emergency requests
If you believe someone faces an imminent danger of death or serious physical injury, you can send an emergency request. The law allows us to disclose information voluntarily in these cases (18 U.S.C. 2702(b)(8) and 2702(c)(4)).
Use the subject line "Emergency Request" and include:
- The nature of the emergency and why the danger is imminent.
- Who is at risk.
- Why the harm cannot wait for normal legal process.
- The specific data you need, and how it will help prevent the harm.
- Your contact details, as described in section 2.
- A statement, signed by the requesting officer, that the information is true and that the request is made in good faith.
We decide whether to disclose, and what to disclose, in good faith based on the information you give us. We usually limit disclosure to what is needed to address the emergency. We may ask for legal process afterward.
BizMeet is a small company. We do not have a staffed 24-hour response line or an emergency phone number. We check this inbox regularly and handle emergency requests before all other work, but we cannot promise a response time. If a life is at risk, contact local emergency services first and do not wait for us.
8. Notice to members
We believe members should know when someone seeks their data. Our practice is to notify the member by email before we disclose their records, so they have a chance to seek legal help.
Before we send notice, we preserve the records covered by the legal process, so that later deletion by the member does not affect our response. We do not notify members about preservation requests alone.
We do not give notice before disclosure when:
- A court order under 18 U.S.C. 2705(b), or another law, prohibits it.
- The request is an emergency under section 7.
- The case involves child sexual exploitation.
- We believe notice would be counterproductive, for example because it would create a risk of harm to someone, or because the account appears to be compromised.
If you believe notice would put an investigation at risk, please get a nondisclosure order and send it with your request. A request letter alone is not enough. When a nondisclosure order ends, or an emergency has passed, we may notify the member at that time.
9. International requests
BizMeet is a US company, and our service is intended for users in the United States. Agencies outside the United States should send requests through a Mutual Legal Assistance Treaty (MLAT) or letters rogatory, or under an agreement that applies under the CLOUD Act.
We consider emergency requests from outside the United States case by case. Where the law allows, we may disclose limited non-content information. We generally cannot disclose message content or other content to a foreign agency without US legal process or an applicable CLOUD Act agreement.
10. Child exploitation
BizMeet is for adults only, and we do not allow any content that sexually exploits children. When we become aware of apparent child sexual abuse material, or apparent child sex trafficking or enticement of a child, on our service, we report it to the National Center for Missing and Exploited Children (NCMEC) through its CyberTipline, as 18 U.S.C. 2258A requires.
Before we remove anything, we export a separate copy of the reported material and related account data and keep it outside our normal automatic deletion. We keep it for one year after we make the report, as 18 U.S.C. 2258A requires, and longer if an agency asks us to preserve it. Agencies can request it with the legal process described in section 5.
We do not use automated scanning of content. We act on what we learn, for example through member reports. Our Child Safety Standards (Child Safety Standards) explain our approach in more detail.
11. Civil litigants and private parties
The Stored Communications Act does not allow us to disclose the contents of communications in response to a civil subpoena. This applies to lawyers in civil cases, criminal defendants, and other private parties. We do not disclose message content, photos, or other content to them.
In most cases the best source is the account holder. A member can ask for a copy of their own data by emailing contact@bizmeetapp.org from the email address on their account. We review valid, properly served civil subpoenas for non-content records case by case, and we may object to them. Where we can, we give the member notice before we respond.
Members who are victims of a crime. If someone you met on BizMeet defrauded, threatened or harmed you, report it to your local police. For online fraud, including job, investment and money-mule scams, you can also report to the FBI at https://www.ic3.gov and the FTC at https://reportfraud.ftc.gov. Take screenshots of the profile and messages first. Then report the member in the app, which saves a copy of recent messages in your chat for our review, as our Safety Policy and Safety Tips explains. Police can then ask us for records under this guide.
12. Format, authentication and costs
Format. We provide records electronically. Database records are usually exported as CSV or JSON files. Photos are provided as the JPEG files we store. Times are in Coordinated Universal Time (UTC). We send records to the requesting official by email or a download link.
Authentication. On request, we will provide a records custodian certification under Federal Rule of Evidence 902(11). This is meant to avoid the need for a custodian to testify in person.
Costs. We do not routinely seek cost reimbursement under 18 U.S.C. 2706 for responding to legal process. We may seek reimbursement, where the law allows, for requests that are unusually large or burdensome. If we do, we will tell you before we begin.
Response time. We aim to respond to valid legal process within a reasonable time, and we will contact you if we cannot meet a deadline in the process. Clear requests that name the account and the records needed are the fastest to handle.
Questions. Send questions about this guide to contact@bizmeetapp.org. We update this guide when our practices change, and the date at the top shows when it last changed.