Chlann is not end-to-end encrypted. Content is encrypted in transit and where it is stored, but we hold the keys, so we are able to read message content.
We do that in two situations and no others:
- Where a valid legal order compels us.
- Where we need to act on a credible child-safety or abuse report.
Only the operator can do this. It requires a specific manual step rather than any part of the ordinary app, and every instance is written down before it happens, following a process published as a runbook in our code repository. An automatic, tamper-evident record of such access is not built yet, and we would rather say so than imply a safeguard we do not have. Where the law requires it, or where a child is at risk, we may pass information to the authorities. This is a deliberate design decision for a product with children on it, not an accident: it is recorded in our architecture decision record ADR-012, and the privacy page describes the same limits in more detail.