Ephemeral messaging is communication designed to auto-delete after a set period — Signal's disappearing messages, similar features in Slack, Teams and WhatsApp. The technology is lawful; using it for business communications after a duty to preserve attaches is what courts have treated as evidence of intent to deprive.
The line courts have drawn
No court has held that using encrypted or auto-deleting messaging is wrongful in itself. Organisations have legitimate reasons for it — confidentiality, data minimisation, and in some sectors a genuine security rationale.
What has drawn sanctions is the combination: a preservation duty had attached, the organisation knew it, and business communications continued on a channel configured to destroy them. Under Rule 37(e) the question becomes whether the party acted with intent to deprive another of the information, and a deliberate choice of a self-deleting channel is unusually good circumstantial evidence of exactly that.
The pattern that reads worst is a shift in behaviour — conversation migrating to a disappearing channel around the time a dispute became foreseeable. That is visible in the metadata even when the messages themselves are gone.
Off-channel communications are the adjacent problem
Regulated industries have faced a parallel issue: employees conducting business on personal devices and consumer messaging apps outside the firm's supervised systems. The regulatory theory there is recordkeeping failure rather than spoliation, and the penalties assessed across the financial sector have been substantial.
The two problems share a root cause. If the sanctioned channels are inconvenient, communication moves to the ones that are not, and policy alone does not stop it.
What preservation actually requires
A legal hold notice telling custodians to preserve messages does very little on a platform that deletes automatically. Preservation requires an administrator to disable the auto-deletion setting for the affected accounts, per platform — and on some consumer applications there is no administrative control at all, which means the only preservation option is capturing the device.
This is the most common failure. The notice was sent, the custodian complied in good faith, and the messages deleted themselves anyway because nobody changed a setting the custodian could not see.
What survives deletion
More than parties assume, which cuts in both directions. Messaging applications typically store messages in local databases, and deleted rows frequently persist until the database is compacted — recoverable by a file-system-level mobile extraction even after the app shows nothing.
Beyond content, the fact and timing of communication often survives independently: notification records, backups made before deletion, the other participant's device, and platform-side metadata. An organisation asserting that messages are simply gone should verify that before saying so, because being contradicted on it is worse than the deletion.
The policy that works
Decide in advance which channels are approved for business communication, configure retention on them deliberately rather than by default, and make suspending auto-deletion an explicit step in the hold process with a named owner. Organisations that permit these tools with no such step are accumulating an exposure that surfaces years later, in a case nobody has thought of yet.
From our work
Dealing with ephemeral messaging in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
