What these matters turn on
Social media disputes look varied and are technically repetitive. Nearly all of them come down to four questions: who posted it, when was it posted and for how long did it stand, how many people actually saw it, and is the copy in the file an accurate record of what the platform displayed.
The last question is the one attorneys underestimate. Most social media evidence arrives as screenshots, and a screenshot is a picture of a rendering that anyone can alter in a browser in under a minute. It is not a platform record. Treating it as one is how a case built on strong facts loses an exhibit at exactly the wrong moment.
My work is to take platform data productions, captures and account records, examine them systematically, and produce findings that separate what is documented from what is being assumed. That usually means telling the retaining attorney which parts of the story the data supports firmly, which parts are circumstantial, and which parts will need something the platform holds and the parties do not.
Platform data productions and what they contain
Most platforms let an account holder generate a complete export of their own data, and those archives are the richest single source in this practice. They are also widely misread.
An export typically includes posts and comments with timestamps, direct messages, profile change history, connections, advertising interest categories, and - most usefully in contested matters - login and session records with addresses, devices and times. Timestamps generally arrive as machine time in a single reference zone and must be converted, which is where hand-built timelines go wrong.
What an export does not contain matters just as much. Content the account holder deleted is usually gone. Other people's posts are absent except where they intersect the account. Some engagement detail is aggregated or omitted. Formats differ - a structured data export preserves fields that the readable version silently drops, so I ask for the structured version whenever the choice exists.
There is also a provenance issue nobody should skip past. An export that a party generated themselves is that party's own production, and its completeness depends on the selections made when it was requested. Where the content is genuinely contested, records obtained from the platform through proper process are a different and better class of evidence. I can specify what to request; the mechanism is counsel's.
Attribution: connecting an account to a person
This is the question I am asked most often and the one where I most often have to disappoint someone. Attribution from public content alone is rarely conclusive. It can be strongly circumstantial, and that is a different claim.
The evidence that carries real weight comes from records rather than from reading posts: the registration e-mail address and phone number, login history with addresses and device identifiers, linked accounts, payment instruments used for advertising or subscriptions, and session overlap with other known activity. Cross-platform reuse of a handle, an avatar or biography text adds support. Activity timing patterns - when an account is consistently awake - can corroborate or contradict.
Weaker signals get treated as weaker: writing style, topic knowledge, and mutual connections. Photograph metadata is usually stripped by platforms during upload, so an image posted to a platform rarely carries the location or device data people expect.
Then the alternatives that a careful report has to address head-on: shared household or business accounts, staff and agencies posting on someone's behalf, impersonation and parody profiles, compromised accounts, and purchased or rented accounts with an unrelated history. If a report does not engage with those possibilities, opposing counsel will raise them, and the failure to have considered them will do more damage than the possibilities themselves.
Altered screenshots and fabricated posts
Fabricating a convincing social media screenshot takes a browser, developer tools and a few minutes. Generating one from a template site takes less. So the question is not whether an exhibit could have been faked, but whether the record corroborates it.
Examination points I work through on a questioned capture:
- Interface consistency with the date. Platforms redesign constantly. A capture showing controls, badges or layouts that did not exist on the claimed date is a serious problem for whoever offered it.
- Timestamp formatting. Relative and absolute time formats change over time and by device, and a mismatch is often the first visible crack.
- Rendering artifacts. Font substitution, inconsistent scaling, edge halos around edited regions, and text that does not align to the platform's grid.
- Impossible states. Counts, badges or controls that could not coexist on that account type at that time.
- Corroboration. Whether the item appears in an export, an archive capture, a monitoring service record, a notification e-mail, or the recipient's own device.
An authenticity opinion should be graded honestly. "Consistent with a genuine capture" and "proven genuine" are different statements, and only one of them is usually available.
Reach, engagement and why follower counts make poor damages
When harm is at issue, someone eventually multiplies a follower count by something. It is worth understanding what those numbers are before they anchor a calculation.
Definitions differ by platform and change over time. Impressions, reach, views and plays are distinct metrics with distinct rules, and a platform can redefine one between the conduct and the filing. A counted video view may represent a few seconds of autoplay while the audio was muted.
Followers are not an audience. Any account accumulates inactive, abandoned, duplicate and automated followers, and platform distribution means only a fraction of followers see a given post. Engagement can be purchased outright, which inflates the very numbers a damages model treats as evidence of exposure.
The consequential spread often happens off-platform. A post that causes real harm is typically screenshotted and redistributed through messaging apps, e-mail and private groups, where no counter exists at all. Platform analytics understate that and no method recovers it precisely.
What can be done responsibly is to establish a documented floor from platform-reported figures, describe what those figures measure, identify secondary distribution that can be evidenced directly, and state plainly that total exposure is not measurable. A bounded, defensible number beats an impressive one that collapses under questioning.
Deleted, edited and ephemeral content
Social platforms are designed around disappearance, which puts a clock on every matter.
Deleted posts generally leave the account holder's export. Stories and similar formats expire by design, though some platforms retain an archive the account holder can access if they act quickly. Edit history exists on some platforms and not others, and where it exists it is often visible only for a limited window. Direct messages may be governed by disappearing-message settings that the parties themselves configured.
Practically, this means preservation is the first conversation, not a later one. Instructions to a client should be specific: stop deleting, disable disappearing messages, generate the structured export now, preserve the device rather than upgrading it, and capture the counterparty's public content immediately with proper page capture rather than phone screenshots.
Where content is already gone, secondary sources sometimes fill the gap - web archive captures of public profiles, monitoring service records, notification e-mails containing the original text, quoted or reposted copies, and other participants' devices. Reconstruction from those sources is legitimate and I will do it, but the report has to state that the item is reconstructed rather than collected, and identify what each source independently supports.
Working with counsel
The requests that pay off are specific ones. Rather than asking for "social media," ask for the account's structured data export, generated with all categories selected; login and session history; profile change history; message threads in native format with metadata; advertising account records where promotion was involved; and the devices used to post. Where the platform itself must be approached, the request needs to name the account identifiers and the date ranges rather than describe the account by display name, since display names change and identifiers do not.
Every review I perform is written as a script against the preserved production rather than assembled by hand, so the analysis can be re-run, checked and extended when a supplemental production arrives. Hand-built spreadsheets hide their own errors, and in a discipline where a single mis-converted timestamp can shift an entire timeline, that is not an acceptable risk.
I take these engagements on either side, and conflicts are cleared before substantive review begins. Retention is arranged through Hartzer Consulting - this site documents the practice rather than selling it.