A transparent, centralized reference mapping how our hardware-modified solutions align — and do not align — with global surveillance regulations. We publish this because clarity about legal constraints is itself a form of responsible practice.
Surveillance tools do not authorize surveillance. Legal authority comes from statute, consent, court order, or a recognized investigatory power — never from the availability of a device. This library exists to make that boundary explicit. We describe how our hardware-modified solutions relate to major regulatory frameworks, where they may lawfully be used, and where they may not. Where alignment is conditional, the condition is stated plainly.
This page is a transparency statement and not legal advice. Every buyer must engage qualified counsel to confirm authorization in the specific jurisdictions where monitoring will occur.
The matrix below states our position on alignment with major regulatory frameworks. Alignment does not imply permission; it means a lawful pathway exists. Conditional means a lawful basis must be established by the buyer. Prohibited means we will not supply the device for that use under any terms.
European Union
Processing of personal data captured by the device constitutes controller activity. Lawful monitoring requires a valid Article 6 basis — most commonly legitimate interests under Article 6(1)(f) balanced against data-subject rights, or a specific legal obligation. We do not sell for processing lacking a lawful basis.
Note: Buyers must conduct a Data Protection Impact Assessment (DPIA) for high-risk monitoring and honor data-subject rights (access, erasure, restriction).
United States (California)
Personal information collected through monitoring is subject to CCPA/CPRA where the buyer is a qualifying business. Employee-investigation and law-enforcement exemptions may apply, but transparency, minimization, and deletion obligations remain relevant to professional deployments.
Note: Buyers should map captured data against their privacy notice and honor consumer/employee rights as applicable.
United States (Federal)
Interception of electronic communications generally requires one-party or all-party consent depending on state law, or a court order. Title III criminalizes interception without authorization. We sell only where the buyer has documented legal authority — consent, court order, or a recognized statutory exception.
Note: Buyers are responsible for confirming consent requirements in each jurisdiction where interception occurs.
United Kingdom
Covert interception by private parties is unlawful without lawful authority. Authorized use by private entities is limited to specific contexts (e.g., consent-based monitoring of owned devices, or lawful investigatory powers). We do not supply devices for interception lacking lawful authority under UK law.
Note: UK buyers must confirm a lawful basis; self-authorizing interception is not supported.
European Union
Each EU member state maintains its own lawful-interception statute regulating private-party monitoring. Authorization thresholds, consent rules, and evidentiary admissibility vary. We defer to the buyer's qualified legal counsel to confirm per-jurisdiction compliance.
Note: Cross-border monitoring may implicate multiple national regimes simultaneously.
Global
Where monitoring is conducted under lawful authority, it must remain necessary and proportionate. Our vetting process refuses procurement where the stated purpose appears unnecessary, disproportionate, or inconsistent with internationally recognized human-rights norms.
Note: Necessity and proportionality are assessed at procurement and reconfirmed during the engagement.
All Jurisdictions
We will not supply any device for stalking, domestic abuse, harassment, or surveillance of a person who has not consented where consent is legally required. Every request is reviewed, and procurement is refused where the stated use is unlawful or intended to cause harm.
Note: This is a hard boundary. No commercial terms override it.
These commitments govern every engagement. They are not advisory; they are conditions of procurement and continued supply.
Every request is reviewed before procurement. Buyers must confirm authorized status — corporate, investigative, or compliance professional — and legal authority to monitor the target device.
Buyers must identify the lawful basis for monitoring in their jurisdiction before activation. We do not provision operator credentials without a stated, reviewed authorization rationale.
The hardware intelligence layer captures only what the operator directs it to capture. There is no passive bulk collection; capabilities are operator-invoked and audit-logged per command.
Every command issued to the implant and every data object retrieved is recorded in an append-only, tamper-evident log within the secure enclave — supporting internal review and evidentiary defensibility.
We refuse procurement for stalking, unlawful interception, surveillance without required consent, or any purpose inconsistent with lawful authority. This refusal is non-negotiable.
This library is a transparency statement, not legal advice. Compliance with applicable law is the buyer's responsibility. Buyers must engage qualified counsel to confirm authorization in each jurisdiction.
Before a device is prepared or operator credentials are provisioned, the following review is completed. Failure at any step halts the engagement.
The buyer's authorized status and legal authority to monitor the target device are confirmed before procurement. Requests that cannot establish lawful authority are refused.
The buyer identifies the jurisdictions where monitoring will occur and confirms the lawful basis (consent, court order, statutory exception) applicable in each.
The stated monitoring purpose is assessed for necessity and proportionality. Deployment scope is limited to what the lawful purpose requires.
Procurement is conditional on acceptance of our Legal Notice, Legal Use Policy, and Acceptable Use Policy. Violation of these terms voids the engagement.
The full lawful-use framework governing every engagement.
Read morePermitted and prohibited use of the platform.
Read moreController and processor obligations for captured data.
Read moreHow the hardware intelligence layer supports evidentiary integrity.
Read moreSpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.