Law Enforcement Guidelines
Last updated: September 23, 2026
These Law Enforcement Guidelines (“Guidelines”) are published by Deluxe Custom Apps LLC, the owner and operator of GlockApps (“GlockApps”, “We”, “Our”, “Us”). They explain how law enforcement and other government authorities may request information about GlockApps users, and how We respond. These Guidelines are not intended for GlockApps customers or their end users. Parties to civil proceedings should see Section 8.
If You do not need information, but believe that a GlockApps account is being used in breach of Our Acceptable Use Policy — for example, to monitor a domain without the authorization of its owner — please report it to legal@glockapps.com.
GlockApps provides email deliverability testing (Inbox Insight), a free spam checker, DMARC monitoring and reporting (DMARC Analytics), and uptime monitoring (Uptime Monitor).
GlockApps is not an email service provider. We do not host mailboxes or provide email accounts to Our customers, and We do not host websites. The reporting addresses We provide for DMARC receive only the automated reports that mailbox providers send about a domain’s email authentication. We are not a domain registrar or DNS host, We have no technical access to any domain’s DNS records, and We cannot determine who owns a domain other than from what that domain’s own DNS publishes.
Requests concerning the contents of a mailbox, or the registration details of a domain, should be directed to the relevant email service provider or domain registrar.
What We hold depends on which GlockApps tools an account uses. Data is retained for the periods set out in Our Privacy Policy, and data deleted at the end of its retention period cannot be recovered. In general, We may hold:
We disclose information about a GlockApps user to an authority only in response to valid legal process issued in compliance with applicable law, or with the consent of the account holder.
We review each request for its legitimacy, scope, and proportionality. We may object to, or seek to narrow, a request that is overly broad, unduly burdensome, or not supported by the legal process cited. Where a request is valid, We disclose only the data specifically identified in it. We do not give any authority direct or bulk access to Our systems or to customer data.
The Electronic Communications Privacy Act, including the Stored Communications Act (18 U.S.C. §§ 2701–2713), may restrict what We can disclose, and any response We make will be in accordance with it. In any event, We disclose the content of messages We hold only in response to a search warrant or with the account holder’s consent.
Where a request concerns personal data protected by the EU General Data Protection Regulation or the UK GDPR, We also assess the request against that law before responding. We keep a record of each request We receive and of any information We disclose.
Outside legal process, We do not confirm to any private party whether an account, a subscriber, or a reporting address published in a domain’s DMARC record is associated with GlockApps.
Requests should be sent to legal@glockapps.com
A request must identify the data sought with particularity and include:
On written request from a law enforcement authority, We will preserve the data identified, as it exists at the time of the request, for ninety (90) days pending service of legal process, and for one further period of ninety (90) days on a further written request. We will also preserve data on the same basis on the written request of a party asserting a legal claim in relation to a GlockApps account or a domain.
Preservation is not disclosure. Preserved data is held, and is not released until valid legal process under Section 3 is received. A preservation request does not oblige Us to confirm whether any data exists.
We reserve the right to notify the account holder before disclosing information about their account in response to legal process, so that they may seek to challenge it. Notice is at Our discretion and is not automatic, and We are under no obligation to give it. Where notice is given, it is sent individually from legal@glockapps.com.
We do not give notice where We are prohibited from doing so by law or by the legal process itself, or where We consider that notice would endanger a person, lead to the destruction of evidence, or otherwise obstruct an investigation. An authority that does not want the account holder notified should say so in its request and identify the legal basis for non-disclosure.
Deluxe Custom Apps LLC is a U.S. company, and Our agreement with GlockApps customers is governed by the laws of the State of Wyoming. We do not accept legal process issued outside the United States directly. An authority outside the United States seeking information should proceed through a Mutual Legal Assistance Treaty or another available channel of international cooperation, through which legal process enforceable in the United States may be obtained.
Before making a formal request, a non-U.S. authority may contact legal@glockapps.com to establish whether We are likely to hold the information sought, and to ask that it be preserved under Section 5 while the formal request is pursued. We will not disclose data directly in response to such contact.
Legal process in a civil matter must be issued, or properly domesticated, in the United States and served in accordance with applicable procedural rules. A party to proceedings outside the United States may seek an order from a United States court, for example under 28 U.S.C. § 1782. We do not respond to civil legal process issued outside the United States. Data may be preserved under Section 5 while such an order is sought.
Nothing in these Guidelines creates any enforceable right against Deluxe Custom Apps LLC. We may update these Guidelines from time to time, and the version in effect when a request is received applies to that request.
These Law Enforcement Guidelines (“Guidelines”) are published by Deluxe Custom Apps LLC, the owner and operator of GlockApps (“GlockApps”, “We”, “Our”, “Us”). They explain how law enforcement and other government authorities may request information about GlockApps users, and how We respond. These Guidelines are not intended for GlockApps customers or their end users. Parties to civil proceedings should see Section 8.
If You do not need information, but believe that a GlockApps account is being used in breach of Our Acceptable Use Policy — for example, to monitor a domain without the authorization of its owner — please report it to legal@glockapps.com.
1. About GlockApps
GlockApps provides email deliverability testing (Inbox Insight), a free spam checker, DMARC monitoring and reporting (DMARC Analytics), and uptime monitoring (Uptime Monitor).
GlockApps is not an email service provider. We do not host mailboxes or provide email accounts to Our customers, and We do not host websites. The reporting addresses We provide for DMARC receive only the automated reports that mailbox providers send about a domain’s email authentication. We are not a domain registrar or DNS host, We have no technical access to any domain’s DNS records, and We cannot determine who owns a domain other than from what that domain’s own DNS publishes.
Requests concerning the contents of a mailbox, or the registration details of a domain, should be directed to the relevant email service provider or domain registrar.
2. Information GlockApps May Hold
What We hold depends on which GlockApps tools an account uses. Data is retained for the periods set out in Our Privacy Policy, and data deleted at the end of its retention period cannot be recovered. In general, We may hold:
- Account information — first name, last name, email address, username, signup IP address, registration date, and subscription level.
- Access records — login dates, times and IP addresses, and a record of the actions taken in the account.
- Billing information — general billing records only, such as the purchase date, order reference number, service name, and price. Payments are processed by Our payment processor, Verifone (ex 2checkout.com), on its own systems. We do not store, and have no access to, payment card numbers or other payment credentials, and changes to payment details are made by the customer with the processor.
- DMARC Analytics — the domains an account monitors and the DMARC report data received for them, such as sending IP addresses, message volumes, and SPF, DKIM, and DMARC results, retained for 180 days for subscription accounts and 30 days for free accounts. The XML files of the reports themselves are retained for 30 days.
- Inbox Insight — the test reports and the complete test messages a customer submits, including message headers, HTML source, and raw message content, retained for 12 months.
- Free spam checker — a separate tool that collects only the minimal data needed for a basic check. Its reports, including message headers, are retained for 30 days.
- Uptime Monitor — monitoring data for the records, IP addresses, mail servers, and websites an account monitors, retained for 90 days.
3. How We Handle Requests
We disclose information about a GlockApps user to an authority only in response to valid legal process issued in compliance with applicable law, or with the consent of the account holder.
We review each request for its legitimacy, scope, and proportionality. We may object to, or seek to narrow, a request that is overly broad, unduly burdensome, or not supported by the legal process cited. Where a request is valid, We disclose only the data specifically identified in it. We do not give any authority direct or bulk access to Our systems or to customer data.
The Electronic Communications Privacy Act, including the Stored Communications Act (18 U.S.C. §§ 2701–2713), may restrict what We can disclose, and any response We make will be in accordance with it. In any event, We disclose the content of messages We hold only in response to a search warrant or with the account holder’s consent.
Where a request concerns personal data protected by the EU General Data Protection Regulation or the UK GDPR, We also assess the request against that law before responding. We keep a record of each request We receive and of any information We disclose.
Outside legal process, We do not confirm to any private party whether an account, a subscriber, or a reporting address published in a domain’s DMARC record is associated with GlockApps.
4. How to Submit a Request
Requests should be sent to legal@glockapps.com
A request must identify the data sought with particularity and include:
- the name of the issuing authority, and the name, badge or ID number, official email address, and direct telephone number of the responsible officer;
- a copy of the legal process, and the legal authority under which it is issued;
- the GlockApps account, email address, or domain concerned;
- the deadline for a response and how it arises, and any confidentiality requirement; and
- for a request from outside the United States, a copy of the Mutual Legal Assistance Treaty request or other international assistance request.
Requests that are overly broad or vague, or that omit this information, may be delayed or returned. We generally respond within ten (10) business days of receiving a complete request, unless the legal process requires a shorter period.
5. Preservation Requests
On written request from a law enforcement authority, We will preserve the data identified, as it exists at the time of the request, for ninety (90) days pending service of legal process, and for one further period of ninety (90) days on a further written request. We will also preserve data on the same basis on the written request of a party asserting a legal claim in relation to a GlockApps account or a domain.
Preservation is not disclosure. Preserved data is held, and is not released until valid legal process under Section 3 is received. A preservation request does not oblige Us to confirm whether any data exists.
6. Notice to the Account Holder
We reserve the right to notify the account holder before disclosing information about their account in response to legal process, so that they may seek to challenge it. Notice is at Our discretion and is not automatic, and We are under no obligation to give it. Where notice is given, it is sent individually from legal@glockapps.com.
We do not give notice where We are prohibited from doing so by law or by the legal process itself, or where We consider that notice would endanger a person, lead to the destruction of evidence, or otherwise obstruct an investigation. An authority that does not want the account holder notified should say so in its request and identify the legal basis for non-disclosure.
7. Requests from Outside the United States
Deluxe Custom Apps LLC is a U.S. company, and Our agreement with GlockApps customers is governed by the laws of the State of Wyoming. We do not accept legal process issued outside the United States directly. An authority outside the United States seeking information should proceed through a Mutual Legal Assistance Treaty or another available channel of international cooperation, through which legal process enforceable in the United States may be obtained.
Before making a formal request, a non-U.S. authority may contact legal@glockapps.com to establish whether We are likely to hold the information sought, and to ask that it be preserved under Section 5 while the formal request is pursued. We will not disclose data directly in response to such contact.
8. Civil Legal Process
Legal process in a civil matter must be issued, or properly domesticated, in the United States and served in accordance with applicable procedural rules. A party to proceedings outside the United States may seek an order from a United States court, for example under 28 U.S.C. § 1782. We do not respond to civil legal process issued outside the United States. Data may be preserved under Section 5 while such an order is sought.
9. Changes to These Guidelines
Nothing in these Guidelines creates any enforceable right against Deluxe Custom Apps LLC. We may update these Guidelines from time to time, and the version in effect when a request is received applies to that request.