The one step here that depends on nobody else
Every other route on this site ends in a decision somebody else makes: a moderator's, a search engine's, a judge's. Preservation depends on nobody. It needs no permission, and it is the only step in the sequence that expires.
It expires because the web does not keep things. Pew Research Center sampled roughly a million pages from Common Crawl archives across 2013 to 2023: 38% of webpages that existed in 2013 were not available when the study ran, and 8% of pages from 2023 had already gone. "Nearly one-in-five tweets are no longer publicly visible on the site just months after being posted" (Pew Research Center, When Online Content Disappears, 17 May 2024, read 12 August 2026).
The mechanisms that matter to a business are narrower and worse. A review can be edited in place: the author revises it, the page shows the current wording, and there is no public revision history. A one-star review that made a specific factual claim in March can say something merely unpleasant in June, and nothing records the change. If the earlier version was not captured, it exists nowhere a reader can reach. An anonymous account can be deleted, taking its reviews with it, and a publisher can rewrite an article in place while the address stays the same.
Capture before contact. The usual sequence: the business finds the content, sends an angry message or has a letter sent, the content changes within days, and the business has neither the content nor a record of it. The most reliable trigger for a post being edited is the subject noticing it. Capture first. Decide second.
What a capture has to contain to be worth anything later
A screenshot pasted into a document is not a record. It is a picture with no provenance. What follows is what I collect, in rough order of the weight each part carries.
- A full-page capture with the address bar and a timestamp in the same frame. Not the visible window — the whole scrolled page. Chrome DevTools has "Capture full size screenshot" in its command menu; Firefox has a full-page option. An address typed into a caption is an assertion; an address visible in the image is part of the exhibit.
- The page source, in both of its forms.
view-source:returns the HTML the server sent; a saved page or a copy of the DOM from developer tools returns the HTML after the page's scripts have run. On a modern review page those are different documents, and the review text often exists only in the second. - The HTTP response headers, from
curl -sSIor the network panel. They carry the server's ownDate:value and any redirect chain — a time source that is not your own computer's clock. - A hash of every file. A SHA-256 value for each screenshot, HTML file and header dump, in a manifest that is itself hashed — what later shows a file has not changed since collection.
- A capture log written at the time: date and time with the time zone, where the clock was set from, the machine, the browser and version, logged in or logged out, and who did the work. It cannot be reconstructed from memory, and it is the part people skip.
- An independent copy made the same day, in a system you do not control and cannot be accused of controlling. The Internet Archive's Save Page Now takes ten seconds and is the highest value per unit of effort in this topic.
A photograph of a screen sits at the bottom of that ladder. Take one when it is all that is possible — a screen photo of a disappearing story beats an empty folder — but know what it lacks. No address bar, so nothing distinguishes one page from another that looks identical. No headers, no source. Its timestamp is the phone's clock, which anyone can set, and nothing in it distinguishes the page from one whose text was edited in developer tools four seconds earlier. A screen photo proves a screen once looked a certain way, and an opponent will say exactly that.
The declaration the Internet Archive publishes about its own records
The Internet Archive publishes the affidavit it will sign when one of its captures is offered in litigation. Its terms are the terms on which a Wayback capture becomes evidence, and the Archive wrote them. The declarant is "a Records Request Processor at the Internet Archive," speaking "of my own personal knowledge," and the document states the Archive's own scale: the Wayback Machine "makes it possible to browse more than 450 billion pages stored in the Internet Archive's web archive."
What it attaches is narrower than most people assume:
"true and accurate copies of browser screenshots of the Internet Archive's records of the archived files for the URLs and the dates specified in the attached coversheet of each screenshot" … "I declare under penalty of perjury under the laws of the United States of America that the foregoing is true and correct."
— Internet Archive, standard affidavit, archive.org/legal/affidavit, read 12 August 2026
Screenshots, keyed to addresses in the extended-URL format the affidavit sets out as http://web.archive.org/web/[Year in yyyy][Month in mm][Day in dd][Time code in hh:mm:ss]/[Archived URL] — with the Archive's own worked example: http://web.archive.org/web/19970126045828/http://www.archive.org/ is the Archive's home page "archived on January 26, 1997 at 4:58 a.m. and 28 seconds."
One instruction falls out of that: record the full extended URL, not "the Wayback link". The date lives inside the address, and a shortened link or a cropped screenshot throws away the identifier that made the copy worth having.
Why a Wayback screenshot is a composite of dates
This is the part almost nobody quotes, and it is the reason this page exists. The Archive states a limitation about its own records that anyone offering one as proof — and anyone receiving one — needs to have read:
"The date indicated by an extended URL applies to a preserved instance of a file for a given URL, but not necessarily to any other files linked therein. Thus, in the case of a page constituted by a primary HTML file and other separate files (e.g., files with images, audio, multimedia, design elements, or other embedded content) linked within that primary HTML file, the primary HTML file and the other files will each have their own respective extended URLs and may not have been archived on the same dates."
— Internet Archive, standard affidavit, archive.org/legal/affidavit, read 12 August 2026
On navigation, the same document explains that clicking an archived hyperlink returns "the archived file found for the hyperlink's URL with the closest available date to the initial file containing the hyperlink."
Read together, the everyday description of a Wayback exhibit falls apart. A Wayback screenshot is not a photograph of a page on a date. It is a composite: the text may carry one capture date, the logo another, a banner image a third. Browsing forward from it walks the viewer silently across time, because every link lands on whichever archived copy was nearest.
That is not a reason to distrust the Archive — it is an unusually honest disclosure about the limits of its own product — but it changes how a capture should be described. "The page as it looked on 14 March" is a claim the record does not support. "The archived instance of this address, bearing this timestamp" is a claim it does. The difference is invisible until somebody competent looks at the exhibit, at which point it is the whole argument. And one boundary: what the declaration establishes and what a particular court will do with it are different questions, and the second is for a defamation attorney.
Live video disappears while you are deciding what to do
Live broadcast is the hardest preservation problem on this site, for a structural rather than a technical reason. Twitch's Community Guidelines cover "all content on our service, including video, chat, whispers, and accounts," across five categories — Safety, Civility and Respect, Illegal Activity, Sensitive Content and Authenticity (Twitch Community Guidelines, read 12 August 2026). None of them turns on whether what was said was false.
Then add how live content works. A stream that no viewer clips, and that the broadcaster does not save as a recording, is simply gone when it ends. No operator process reconstructs it afterwards, because the operator never kept it for you.
So the sequence collapses to one instruction: capture while it is happening. Record the stream if you can, note the channel, the start time and the time zone, and write down where in the broadcast the statement was made. If a clip exists, save the clip and its address immediately — clips can be deleted by whoever made them and by the broadcaster. Every hour spent deciding whether the statement was worth acting on is an hour in which the only copy can vanish.
The copies nobody can call back
The reverse problem cuts against the instinct that removal ends a matter. Reddit's Public Content Policy defines public content broadly — "public posts, comments, usernames, profiles, karma scores, and related metadata" — and licenses it in bulk to brand-monitoring companies, "large language model makers," and researchers. On deletion, the operator is candid:
"You can delete posts and comments. Deleted posts and comments are no longer publicly displayed on the Reddit platform. We also require licensees in our data licensing arrangements to stop using deleted posts and comments and provide them with compliance tools to help automate public content deletions. We cannot guarantee that third parties have deleted copies of Reddit public content they've made without your or our permission."
— Reddit Public Content Policy, Reddit, Inc., read 12 August 2026
Both directions matter. In your favor: a thread deleted tomorrow may already exist in somebody else's copy, one more reason a same-day capture is worth making. Against you: taking a post down stops it being displayed and starts deletion propagating through licensed copies, and the operator will not say that copies already taken are gone. Removal at the source is worth doing, and it is not an eraser.
What preserving the evidence does not do
The verdict on this page is documents only, and it is not a hedge. Preservation changes nothing about the content. The review is still there, the article still ranks, and no platform has been asked for anything. None of the removal work on this site becomes more likely to succeed because a file was hashed.
What preservation does is make that later work possible. A platform report quoting exact wording, on an exact date, at an exact address is a different document from one saying a review "used to say" something. And the material either exists or it does not; nothing recovers it afterwards, at any price.
Three limits. Third-party captures are not permanent either: the Internet Archive accepts requests from site owners to exclude archives of their own sites, and says of the outcome, "We do not make any guarantees beforehand about the outcome of a request" (Internet Archive Help, read 12 August 2026) — which cuts both ways, so keep your own copy. Second, the absence of a Wayback capture proves nothing about whether a page existed; it proves the crawler did not take one. Third, anybody selling "court-admissible evidence" as a finished product is selling half a question: whether an exhibit is authentic and whether it is admissible for what it says are different tests, and the second is for a defamation attorney.
The policies quoted here are dated because they change. Read the operator's current page before acting on any of them.
Frequently Asked Questions
How do I save a web page as evidence?
Take a full-page screenshot with the address bar and a timestamp visible in the same image, then save the page source twice — the version the server sent and the version after scripts have run — plus the HTTP response headers. Hash each file with SHA-256 and list the values in a manifest. Write a short log at the time: date, time zone, machine, browser version, logged in or out, and who did it. Then make an independent copy the same day with the Internet Archive's Save Page Now, so a copy exists in a system you do not control.Is a screenshot enough on its own?
It is better than nothing and it is the weakest form of what you can collect. A screenshot carries no headers, no source and no independent time source, and a page's visible text can be edited in a browser's developer tools in seconds, so an image alone cannot be distinguished from a fabricated one. If a screenshot is all you have, keep it — a picture of an ephemeral story beats an empty folder. Just add the source, the headers and a same-day third-party copy while the content is still there to collect.Does a Wayback Machine capture prove what a page said on a date?
Not in the way people assume. The Internet Archive's own affidavit states that the date in an extended URL applies to that preserved file but "not necessarily to any other files linked therein" — images, media and design elements each carry their own capture dates. Clicking a link inside an archived page serves whichever copy is closest in time. So a Wayback screenshot is a composite of dates rather than a photograph of a page on one date. Record the full extended URL and describe the capture as the archived instance of that address.Should I contact the platform before or after I save copies?
After. The most common trigger for a post being edited or deleted is the author realizing the subject has noticed. Once a message has been sent, or a letter has arrived, the content can change within hours — and the version that mattered is then unrecoverable, because review platforms display current text with no public revision history. Capturing first costs an afternoon and changes none of your options. Contacting first can remove the option of ever showing what was written.Can a deleted review be recovered?
Usually not, and that is the honest answer rather than a cautious one. If a review was edited in place, the platform shows only the current wording and keeps no public history. If the account was deleted, its reviews generally go with it. Third-party copies sometimes exist — an archive crawl, a screenshot a customer took, a copy licensed out before deletion — but none of that is something to count on, and no vendor can produce what was never captured. This is why preservation is the first step rather than a later one.Does preserving evidence help get content removed?
Not by itself. Preservation documents; it does not remove. What it does is make every later argument concrete: a platform report that quotes exact wording at an exact address on an exact date, rather than a description of something that has since changed. It also protects against the common outcome where content disappears before anyone official looks at it, which is a problem for the business rather than for the author. Removal, where it is possible at all, runs on a platform's own rules and is separate work.What can I do about a defamatory live stream?
Capture it while it is live, because there may be nothing to capture afterwards. A stream that no viewer clips and the broadcaster does not save as a recording is gone when the broadcast ends, and no operator reconstructs it. Twitch's guidelines cover video, chat, whispers and accounts, but none of the five categories turns on whether a statement was false, so there is no falsity route to ask for either. Record the broadcast, note the channel, start time and time zone, and save any clip and its address immediately.Published