Government and police data requests
What happens when an authority asks us for a creator's data.
Sometimes a police force, a court or a government department asks a company for information about one of its users. This page is the process Qubera Technologies Private Limited follows when that happens on Neroex. It is written in plain English because the people it protects are creators, not lawyers.
In effect from 11 October 2026. Owner: Abhay Arya, Grievance Officer.
1. Nothing is handed over without a legality check
Every request is reviewed before any data moves. No member of staff may answer one on their own judgement, however urgent it sounds. The review asks four questions and writes down the answers:
- Is it real? We confirm the request came from the authority it claims to, through a channel we can verify, and not from an email address that merely looks official.
- Is there legal authority for it? The request must cite the law it is made under. In India that normally means a written order under the Code of Criminal Procedure, a direction under the Information Technology Act, or a court order. A request citing nothing is not a legal request, and we say so.
- Does it cover us? The authority has to have jurisdiction over Qubera Technologies Private Limited, and the order has to be addressed to us rather than forwarded from somebody else.
- Is it specific? A request has to name the account or accounts it concerns. A request for "all users who did X" is treated as unlawfully broad and handled under section 2.
Where the law allows it, we tell the creator their data has been requested before we respond, so they can seek their own legal advice. Where the order forbids telling them, we do not, and we record that the order forbade it.
2. We push back on requests we believe are unlawful
A request that fails the review in section 1 is not answered. We respond in writing saying which part it failed and asking for it to be corrected or narrowed. Depending on the defect, we will:
- ask for a valid legal basis to be cited, and decline until it is;
- ask for a request covering many accounts to be narrowed to the accounts actually under investigation;
- take legal advice and, where the defect is serious and the authority will not correct it, challenge the request before the appropriate court or tribunal.
We will not challenge every request, and saying otherwise would be dishonest: a valid order properly made is one we comply with. What we will not do is treat an invalid one as valid because arguing is inconvenient.
3. We disclose the minimum, never the account
We give exactly what the order requires and nothing beyond it. If an order asks for the dates an account was active, it gets the dates, not the account’s messages. If it asks about one post, it gets that post, not the creator’s whole page. We do not volunteer context, and we do not hand over a database export because it is easier than writing a query.
Some data we simply cannot produce, by design rather than by policy, and this is worth stating because it is the strongest protection on this page:
- We never store a visitor’s IP address. It is turned into a code that cannot be reversed, so we cannot tell anyone who visited a page even if ordered to.
- Individual visit records are deleted after 90 days. Only totals remain, and a total identifies nobody.
- We hold no passwords. Signing in uses a one-time code or Google, so there is no password to disclose.
4. Every request is written down
We keep a record of each request we receive, whether we answered it or not. Each entry holds the date, the authority, the law cited, which accounts it concerned, the review decision and the reasoning behind it, who at Neroex took that decision, exactly what was disclosed, and whether the creator was told. Records are kept for at least five years.
The point of the record is that the reasoning survives the person. A decision nobody wrote down cannot be reviewed later, and the next request gets decided from memory.
Emergencies
Where there is a credible risk of death or serious injury, we may act on an emergency request faster than the full process allows, and disclose only what addresses the immediate danger. Every emergency disclosure gets the full review afterwards, is recorded in the same way, and the creator is told once the danger has passed unless the law forbids it.
Where to send a request
Requests must be in writing, cite their legal basis, and name the accounts concerned.
Abhay Arya, Grievance Officer
abhay@neroex.com
Qubera Technologies Private Limited
38 F, 1st Ashwini Layout, 2nd Main Road, Viveknagar, Ejipura, Bengaluru, Karnataka 560047
CIN U62012KA2026PTC219829
This page describes our process. It is not legal advice, it does not waive any right we or a creator holds, and nothing here is a promise to disclose anything we are not legally obliged to disclose.