Reporting period: 7 May 2026 – 20 May 2026 (pre-launch) Publication date: 7 May 2026 Version: 1
beebeeb.io publishes an annual transparency report in which we report, in aggregated form, on requests from government authorities and other third parties for the disclosure, removal or alteration of data. We do this to be transparent about how we handle our responsibilities under Dutch and European law, and to give users and partners insight into the extent to which the Service is the subject of government requests.
This report is in line with our Law Enforcement Guidelines and our obligations under the Digital Services Act (including Articles 15, 24 and 42 DSA where applicable to our services).
Methodology
- Requests are counted per unique request number in our internal register.
- "Account" refers to a unique beebeeb.io account; multiple requests relating to the same account count separately as requests.
- "Fully granted" means we provided all requested information to the extent we have it.
- "Partially granted" means we provided part of the requested information or limited the scope of the request.
- "Refused" means we provided no information, either because the request did not meet legal requirements, or because the requested information does not exist (due to Zero-Knowledge or retention periods).
1. Government request overview
Total
|
Category |
Number |
|
Total requests received |
0 |
|
Fully granted |
0 |
|
Partially granted |
0 |
|
Refused / returned for supplementation |
0 |
|
Number of unique accounts affected |
0 |
|
Number of accounts notified |
0 |
|
Number of accounts where notification was delayed |
0 |
Breakdown by request type
|
Type of request |
Number |
Full |
Partial |
Refused |
|
Production order Art. 126nd DCP |
0 |
0 |
0 |
0 |
|
Production order Art. 126ng DCP (with investigating-judge warrant) |
0 |
0 |
0 |
0 |
|
Decryption order Art. 125k / 126nh DCP |
0 |
0 |
0 |
0 |
|
Dutch Intelligence and Security Services Act 2017 (AIVD/MIVD) |
0 |
0 |
0 |
0 |
|
EU Data Act Art. 17-22 (public emergency) |
0 |
0 |
0 |
0 |
|
Civil claims / lawyers |
0 |
0 |
0 |
0 |
|
Tax authority requests |
0 |
0 |
0 |
0 |
|
Emergency Disclosure Requests |
0 |
0 |
0 |
0 |
|
Foreign requests (via MLAT/EIO) |
0 |
0 |
0 |
0 |
|
Foreign requests (direct, refused) |
0 |
0 |
0 |
0 |
|
Total |
0 |
0 |
0 |
0 |
Geographical origin
|
Country / jurisdiction |
Number of requests |
|
Netherlands |
0 |
|
Other EU member states (via EIO / MLAT) |
0 |
|
United States |
0 |
|
United Kingdom |
0 |
|
Other |
0 |
Nature of data requested
|
Type of data |
Number of requests |
Provided? |
|
Account registration data |
0 |
0 |
|
Login / session logs |
0 |
0 |
|
Billing data |
0 |
0 |
|
Encrypted file content (as stored) |
0 |
0 |
|
Unencrypted file content |
0 |
0 (technically impossible due to Zero-Knowledge) |
|
Decryption keys or passwords |
0 |
0 (technically impossible due to Zero-Knowledge) |
2. Notice-and-Action requests (DSA)
Under our Notice-and-Action procedure, third parties can report suspected unlawful content. Requests can be submitted by individuals, organisations, rights holders or competent authorities.
|
Category |
Number |
|
Total reports received |
0 |
|
By rights holders |
0 |
|
By authorities |
0 |
|
By other third parties |
0 |
|
Granted (content restricted or removed) |
0 |
|
Refused (unfounded, insufficiently specified) |
0 |
|
Abusive reports |
0 |
|
Average handling time |
n/a |
Breakdown by reported category
|
Type of reported content |
Number |
Granted |
|
Suspected copyright infringement |
0 |
0 |
|
Suspected criminal material |
0 |
0 |
|
Suspected Article 240b DCC (CSAM) |
0 |
0 |
|
Privacy / personal data violation |
0 |
0 |
|
Phishing or fraud |
0 |
0 |
|
Malware |
0 |
0 |
|
Other |
0 |
0 |
Measures taken
|
Measure |
Number of times applied |
|
Shared link restricted or blocked |
0 |
|
Account temporarily suspended |
0 |
|
Account permanently terminated |
0 |
|
Reported to authorities / authorities informed |
0 |
|
No action taken (report unfounded) |
0 |
3. Internal complaints (DSA Art. 20)
Users whose content has been removed or blocked on the basis of a report can object via our Complaints Policy.
|
Category |
Number |
|
Total complaints received |
0 |
|
Complaints upheld (decision reversed) |
0 |
|
Complaints rejected |
0 |
|
Complaints referred to out-of-court dispute settlement |
0 |
|
Average handling time |
n/a |
4. Changes to the Zero-Knowledge architecture
In the reporting period:
- ☑ No material changes have been made to the Zero-Knowledge architecture
- ☑ No requests have been received that would have led to a change to the architecture if granted
5. Personal data breaches
|
Category |
Number |
|
Data breaches internally registered |
0 |
|
Data breaches reported to the Dutch Data Protection Authority (Art. 33 GDPR) |
0 |
|
Data breaches where data subjects were informed (Art. 34 GDPR) |
0 |
|
Estimated number of affected accounts |
0 |
For more information on individual data breaches, to the extent we are permitted to communicate publicly, please refer to our status and incident page at status.beebeeb.io.
6. Warrant Canary
On the date of publication of this report, InitLabs B.V. ("beebeeb.io") confirms the following:
- ☑ We have not received any request to install a back door or weaken our encryption.
- ☑ We have not received any request to disclose information that we are not permitted to inform our users about, other than regular criminal procedural powers on which we report aggregated in this report.
- ☑ We have not received any National Security Letter (NSL) or comparable instrument.
The absence of this declaration in future reports may be an indication of a changed situation.
7. Questions or comments
Do you have questions about this report or about how we handle government requests? Please contact legal@beebeeb.io.
We expect to publish the next transparency report around 1 January 2027.
Next reporting: 1 January 2027. Earlier reports will be listed on the Transparency Report page when available.
— End of Transparency Report —