New Jersey Police Don’t Need Your Social-Media Password
Police requests go to the company holding your account, not necessarily to your phone. The paperwork determines whether they receive subscriber details, metadata, stored messages or a stream of new records.
August 11, 2026 · 7 min read

The revealing detail was every 15 minutes.
In three criminal investigations reviewed by the New Jersey Supreme Court, communications data warrants directed Facebook to turn over account information on a rolling basis, with updates at intervals no longer than 15 minutes. The warrants initially covered 30 days. Police were not trying passwords against a login screen. They were serving legal process on the company already operating the screen, storing the account and maintaining the machinery behind it.
That distinction is the whole system. A password controls one route into an account. It does not erase the provider’s copy of information, stop a court from compelling disclosure or prevent investigators from seeking the records that describe how an account was used. Police can seize a device and pursue access there, but they can also walk around it.
The New Jersey court’s 2023 decision approved that second route for prospective Facebook records, provided police had probable cause and used a communications data warrant, the state’s term for a search-warrant equivalent aimed at electronic information. It cut the authorized collection period from 30 days to 10, while allowing investigators to seek extensions.
Every 15 minutes remained every 15 minutes. That was close enough to live surveillance to make Facebook object, yet delayed enough for the court to classify the material as stored communications rather than an interception. The gap sounds technical because it is. It also decides which safeguards apply.
The password is beside the point
Police seeking social-media records usually direct their demand to Meta, Snap, TikTok, X or another provider. The federal Stored Communications Act, a 1986 law governing government access to records held by communications services, supplies the basic ladder of legal process. State law and state constitutional protections can add requirements, but they operate on top of a federal statute written when a full mailbox still fit comfortably on office furniture.
The first rung is a subpoena. Under the federal baseline, a subpoena can compel specified subscriber records such as a name, account address, length of service, linked email address, payment information and certain connection records. Meta’s published law-enforcement guidance says subpoena returns can include recent login and logout IP addresses when available. An IP address identifies a network connection, not necessarily the human sitting behind it, although investigators routinely use it to connect an account with an internet provider and then seek the subscriber attached to that service.
New Jersey’s constitution has sometimes required more protection than federal doctrine. In State v. Reid, the state Supreme Court recognized a privacy interest in subscriber information linking an internet account to a person and required appropriate legal process rather than an informal police request. That protection matters.
It does not mean every identifying record requires a probable-cause search warrant.
A court order under section 2703(d) of the Stored Communications Act reaches further into non-content records. Police must offer specific and articulable facts showing reasonable grounds to believe the records are relevant and material to an ongoing investigation, a lower standard than probable cause. Platforms describe this category as transactional or account metadata: information about communications rather than what the communications say. Depending on the service and what it retains, that can include message headers, associated accounts, login history, device information, timestamps and records showing which account contacted which.
Content generally requires a search warrant supported by probable cause. Meta says a warrant can compel stored account contents that may include messages, photos, videos, posts and location information. Snap and TikTok draw the same broad line in their published guidance: subpoenas reach basic identifying records, court orders can reach additional non-content information, and warrants can compel stored content.
The categories look clean in a legal manual. Real accounts are not. A direct message contains words, but its sender, recipient and timestamp are metadata. A photograph is content, while its upload time and associated IP address may be treated differently.
A platform can also hold information generated by its own security systems, advertising operations or device tracking that the user never typed into a profile.
What the platforms can hand over
A valid warrant does not create data. It compels a company to disclose responsive material in its possession, custody or control, subject to the law and the warrant’s scope. Retention therefore matters as much as doctrine.
Meta’s guidance separates basic subscriber records, non-content account records and stored content. It also says it does not provide passwords. That is less comforting than it sounds. A readable password would give police direct account access, but a provider return can arrive as a package of records assembled by the company, without anyone signing in as the user.
Snap warns that some communications disappear from its systems according to the service’s deletion rules. A warrant served after material has been deleted cannot recover a provider copy that no longer exists, though opened messages, saved chats, Memories and account logs can follow different retention paths. TikTok likewise says disclosure depends on what its systems retain and which legal authority investigators produce. X describes a comparable split between basic subscriber information, non-content records and account content.
Encryption changes possession. End-to-end encryption means only the communicating devices hold the keys needed to read a message, leaving the provider unable to supply plaintext it cannot decrypt. It does not make the account invisible. Registration data, contact patterns, login IP addresses, device records and unencrypted backups may remain available, depending on the product and its settings.
Platform architecture moves faster than law-enforcement guides, so any categorical promise about what a company can read deserves suspicion and a date stamp.
The 15-minute Facebook warrants expose the boundary. The New Jersey Supreme Court reasoned that Facebook collected communications through its ordinary systems before delivering them to law enforcement, so police were acquiring stored information rather than intercepting messages in transit. A wiretap order, which authorizes real-time interception, carries stricter requirements under federal and New Jersey law, including necessity findings and limits intended to reduce collection of irrelevant conversations.
The court refused to treat a short storage interval as a wiretap merely because police wanted repeated updates. Its 10-day limit borrowed a temporal restraint from New Jersey’s wiretap framework, but the legal category remained a communications data warrant. The result is a system where surveillance approaching real time can travel through the stored-records lane as long as the provider receives and stores each communication before handing it over.
The quiet requests around the warrant
Investigators have tools that do not immediately disclose account material. A preservation request directs a provider to freeze existing records for 90 days while police obtain formal process, and federal law permits one additional 90-day period. It is a pause button, not authority to inspect the preserved data. For a disappearing-message service, however, freezing what remains can shape the investigation before a judge reviews a warrant application.
Emergency requests work differently. The Stored Communications Act allows a provider to disclose records voluntarily when it has a good-faith belief that an emergency involving danger of death or serious physical injury requires disclosure without delay. Platforms review those submissions under their own procedures. The mechanism can save time in a genuine crisis, while also moving the first decision away from a judge and into a company compliance team.
Users may not learn about any of this while it happens. Providers often say they notify account holders before disclosure unless the law prohibits notice, an emergency makes notice dangerous or another stated exception applies. Prosecutors can seek a nondisclosure order under federal law by arguing that notice could produce flight, evidence destruction, witness intimidation or another serious consequence. Records can therefore be preserved, collected and used before the account holder sees an alert.
This is where the institutional incentive sits. Platforms profit from retaining enough account and behavioral data to secure their services, recommend content and sell advertising. Police benefit from dealing with a centralized company that can convert that retained material into a legible return. Neither side needs the suspect to volunteer a password.
The account holder is the only party who experiences the arrangement as a surprise.
Every 15 minutes made the arrangement visible because the demand resembled a feed built for police. Most requests are less cinematic. A subpoena for subscriber details or a court order for connection logs can still identify a person, map associations and establish a timeline, often without producing a single sentence from a private message.
The useful accountability questions concern the document served, the legal standard applied, the period covered, whether notice was delayed and what the provider retained. Password access belongs elsewhere in the inquiry. This is a map of the machinery, not legal advice, and the machinery works precisely because the company already stands between the user and the account.
Questions people ask
Can
New Jersey police read private social-media messages without my password?
They can seek stored message content from the platform with a search warrant supported by probable cause. Whether the company can provide readable messages depends on retention, deletion rules and encryption. Police may also pursue a seized device through a separate legal and technical process.
Will a platform tell me that police requested my records?
Possibly, but not necessarily before disclosure. Platforms commonly say they provide notice unless legally barred or an emergency applies. A court can delay notice when prosecutors show that warning the user could threaten an investigation, evidence or another person.
Does deleting a message prevent police from obtaining it?
Deletion from your screen does not establish deletion from every system. A provider may retain content, backups, logs or related metadata for different periods, and a preservation request can freeze records still present. If the provider no longer possesses the content, a warrant cannot make that copy reappear.
What can police obtain with only a subpoena?
Under the federal baseline, a subpoena can reach basic subscriber records such as identifying details, linked contact information, service dates, payment records and certain IP logs. More detailed non-content records generally require a court order, while stored message content generally requires a probable-cause warrant.
One update a day
Today's story, in your inbox
One story each morning — no hype, no filler, no algorithm deciding for you.



