The month a litigation hold arrived 22 days after my logs expired, at $61K MRR
A composite founder diary. A preservation demand landed 22 days after my 90-day retention rule had already deleted the exact window it asked for. Rule 37(e) has three conjunctive conditions, and most of the panic failed at the first one.
In this story
“Please confirm that all logs, records and communications relating to webhook delivery between 1 November and 31 December have been preserved and that any automated deletion affecting them has been suspended.”
That sentence arrived on a Wednesday afternoon in March, from a law firm I had never heard of, on behalf of a customer who had been paying us for two years. We were at $61,400 MRR, eleven people, no general counsel, and a storage lifecycle rule that had been quietly deleting request logs at ninety days since the week we turned on billing. I read the letter twice, opened the storage console, and discovered that the exact window they were asking me to preserve had been deleted twenty-two days earlier.
Quick answer (2026): This is a composite founder diary. The company, the customer, the dates and the numbers are assembled from several real situations and are not one identifiable business. The useful part is the reading of the rule, which is real and is quoted from primary sources throughout. If a preservation demand arrives after your retention policy has already deleted the data, the first question is not what sanction you face. It is whether Federal Rule of Civil Procedure 37(e) engages at all, because the rule has three conjunctive conditions and most of the panic I felt that afternoon failed at the first one.
The letter, and the twenty-two days
The outage they were complaining about ran from 12 to 14 November. We had already settled the service-credit side of it the way an SLA breach normally gets settled, which I had assumed closed the matter. Their counsel wrote on 4 March, 112 days later. Our lifecycle rule expired objects at ninety days, so the logs covering 12 to 14 November were deleted on 10 to 12 February. The demand letter arrived 20 to 22 days after the last of them went.
I want to be honest about the order in which I thought about this, because the order was wrong. My first thought was that we had destroyed evidence. My second was that the deletion was automatic, so we were fine. Both were wrong, and the second was wrong in a way that cost me a bad night.
Condition one: the rule does not reach data that died before the duty did
Rule 37(e) opens with a compound condition. It applies where "electronically stored information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it, and it cannot be restored or replaced through additional discovery". Three things, all of them required, joined by "and".
The Advisory Committee's 2015 note is blunt about the first: "The rule does not apply when information is lost before a duty to preserve arises." The duty is a common-law one that the rule borrows rather than creates. It attaches when litigation is reasonably foreseeable, and the note tells courts to ask "the extent to which a party was on notice that litigation was likely and that the information would be relevant".
If the 4 March letter was the moment litigation became foreseeable, the logs had already been gone for three weeks and the rule never engages. That is the comfortable reading, and I did not get to keep it.
Going back through the support inbox, I found a ticket from 18 November in which the customer's head of engineering wrote that they were "escalating this internally". If a court decided that put us on notice, the duty attached on 18 November, and the logs then lived another 84 days under a preservation obligation nobody at the company knew existed, until the cron deleted them.
The note anticipates exactly this and does something I did not expect. It says these early signals "provide only limited information about that prospective litigation, however, so that the scope of information that should be preserved may remain uncertain", and then: "It is important not to be blinded to this reality by hindsight arising from familiarity with an action as it is actually filed." The rule-makers wrote a caution against hindsight into the rule's own commentary. No vendor page I read that week mentioned it.
Condition three: the escape hatch
The third condition is the one that actually decided our situation, and it is the one nobody quotes. The information must be data that "cannot be restored or replaced through additional discovery".
The note is emphatic about the sequence. It says the "initial focus should be on whether the lost information can be restored or replaced through additional discovery", and then, in seven words that I read about forty times: "If the information is restored or replaced, no further measures should be taken."
Not mitigated. Not reduced. No further measures.
Our webhook deliveries were not only in our logs. Every one of the 41,217 deliveries in that window produced a receipt on the customer's own side, and our payment processor held an independent event record with matching timestamps for the subset that touched billing. The data the letter demanded existed in two places that were not us, both reachable through ordinary discovery. On the rule's own terms that is the end of the analysis, and it was reachable on day one, before I had spent anything.
The 2015 amendment did two opposite things, and vendors sell you one of them
Here is the part that genuinely changed how I think about this, and it cuts against me.
Until 2015 the rule contained an explicit safe harbour: "Absent exceptional circumstances, a court may not impose sanctions under these rules on a party for failing to provide electronically stored information lost as a result of the routine, good-faith operation of an electronic information system."
That is precisely the defence I reached for in the storage console. It was deleted. The note says flatly: "New Rule 37(e) replaces the 2006 rule." The routine-operation safe harbour is not narrowed, it is gone, and what replaced it is a judgement about whether your steps were reasonable. Worse for me, the note says a preservation duty "may call for reasonable steps to preserve information by intervening in that routine operation". You are expected to go and stop the job.
So the belief that automatic deletion protects you is not merely optimistic. It is a citation to a rule that has not existed for over a decade.
The same amendment moved the risk hard in the other direction, and this is the half the eDiscovery vendors have no reason to advertise. The severe sanctions, the ones people actually fear, live in Rule 37(e)(2), and they are available "only upon finding that the party acted with the intent to deprive another party of the information's use in the litigation". Only. The note names the case it is overruling: "It rejects cases such as Residential Funding Corp. v. DeGeorge Financial Corp., 306 F.3d 99 (2d Cir. 2002), that authorize the giving of adverse-inference instructions on a finding of negligence or gross negligence." And it explains why: "Negligent or even grossly negligent behavior does not logically support that inference."
A jury instruction that our missing logs were unfavourable to us was not on the table for a misconfigured lifecycle rule, however careless. It required someone to prove we deleted them to hurt them. The lesser measures under 37(e)(1) remain available on a finding of prejudice, but they are capped: "measures no greater than necessary to cure the prejudice".
One amendment, two directions. It took away the defence I assumed I had and added a protection I did not know about.
Proportionality is written for companies our size
I had assumed proportionality was a large-company concept. It is the opposite. The note lists it as a factor in whether preservation steps were reasonable and says: "The court should be sensitive to party resources; aggressive preservation efforts can be extremely costly, and parties (including governmental parties) may have limited staff and resources to devote to those efforts." Then: "A party may act reasonably by choosing a less costly form of information preservation, if it is substantially as effective as more costly forms."
It goes further. The standard "does not call for perfection", and courts should be "sensitive to the party's sophistication with regard to litigation in evaluating preservation efforts". An eleven-person company with no general counsel is not held to the standard of a company with an eDiscovery team, and that is written down.
There is also a timing gap worth knowing. The scope of what you must preserve is meant to be negotiated: Rule 26(f) requires parties to "discuss any issues about preserving discoverable information" and the discovery plan must address "any issues about disclosure, discovery, or preservation of electronically stored information, including the form or forms in which it should be produced". But that conference happens "at least 21 days before a scheduling conference is to be held", which is well after a case is filed. The duty attaches at foreseeability. The conversation about its scope happens months later. You are required to guess correctly, alone, in between.
What I got wrong
Two things, and I am recording them because I acted on both before checking.
I believed there was an irreconcilable conflict between the duty to preserve and privacy law's duty to delete. There is not. California's deletion right is subject to a list of exceptions, and a business "shall not be required to comply with a consumer's request to delete the consumer's personal information if it is reasonably necessary" for one of them. The list includes "Comply with a legal obligation." and, separately, the right to "Exercise free speech, ensure the right of another consumer to exercise that consumer's right of free speech, or exercise another right provided for by law." A preservation obligation sits comfortably inside those. The collision I spent an evening worrying about is foreclosed by the statute itself.
What survives is narrower and is about order of arrival rather than conflict. The deletion right runs on a hard clock: a business must act "within 45 days of receiving a verifiable consumer request from the consumer", and that period "may be extended once by an additional 45 days when reasonably necessary, provided the consumer is provided notice of the extension within the first 45-day period". The preservation duty has no clock at all. It attaches when litigation becomes foreseeable, which may be before or after the deletion request lands, and you are the only person who can see both dates.
The second thing I got wrong: I assumed that having a written retention policy and then breaching it would be held against us. The note says close to the opposite. It observes that independent preservation requirements "may be addressed to a wide variety of concerns unrelated to the current litigation", and that "the fact that the party failed to observe some other preservation obligation does not itself prove that its efforts to preserve were not reasonable with respect to a particular case".
Nothing here is a claim about any product or vendor, and no pricing or tier fact carries any part of the argument. It is all statute and commentary.
What actually happened
Scroll to see more
| Item | Figure |
|---|---|
| MRR at the time | $61,400 |
| Outage window the letter named | 12 to 14 November |
| Storage lifecycle expiry | 90 days |
| Logs auto-deleted | 10 to 12 February |
| Demand letter received | 4 March, 112 days after the outage began |
| Gap between deletion and letter | 20 to 22 days |
| Earlier signal in the support inbox | 18 November, 84 days before the first deletion |
| Webhook deliveries in the window | 41,217 |
| Independent copies of the same data | 2 (customer receipts, processor event log) |
| Adverse-inference instruction exposure | None absent proof of intent to deprive |
| Outside counsel hours bought | 2.5 |
| Changes made to the lifecycle rule | 1 (a documented suspension procedure, not a longer retention period) |
We did not extend retention. Deleting logs on a schedule is a privacy posture I still think is correct, and the rule does not ask you to keep everything forever. What we added was a way to stop it: a written procedure naming who can suspend the lifecycle rule, a list of the four systems it has to be suspended in, and a standing instruction that any message from a customer's lawyer, or any support ticket using the word "escalate", triggers it the same day.
The one thing I would tell you
Read the three conditions before you read the sanctions. Most of what frightens you in a preservation letter is written on the assumption that the rule engages, and for a small company whose data usually exists somewhere else as well, it frequently does not. The condition that saved us was not a clever argument. It was the third clause of the first sentence, and it was free.
And if you take one operational thing from this: the expensive gap is not your retention period, it is not having a way to pause it. A ninety-day policy with a same-day suspension procedure is defensible. A five-year policy you cannot stop is just a larger pile of things to produce.
Written by
Anya PetrovaFrequently asked questions
Is this a real founder's diary?
It is a composite. The company, the customer, the outage dates and the figures are assembled from several real situations and are not one identifiable business. Everything quoted from Federal Rule of Civil Procedure 37(e), its 2015 Advisory Committee note, Rule 26(f) and the California Civil Code is real and verbatim from the primary sources linked in the piece.
Does Rule 37(e) apply if my logs were deleted automatically before I knew about the dispute?
Not if the loss happened before a duty to preserve arose. The 2015 Advisory Committee note states that the rule does not apply when information is lost before a duty to preserve arises. The duty attaches when litigation is reasonably foreseeable, so the question is what put you on notice and when, not when the complaint was filed.
What is the condition most people miss in Rule 37(e)?
The third one. The rule only reaches information that cannot be restored or replaced through additional discovery. The Advisory Committee note says the initial focus should be on whether the lost information can be restored or replaced, and that if it is restored or replaced, no further measures should be taken. If a counterparty, a processor or a backup holds the same records, the analysis can end there.
Can a court tell a jury to assume deleted data was bad for me?
Only on a finding that you acted with the intent to deprive the other party of the information's use in the litigation. The 2015 amendment expressly rejected cases allowing adverse-inference instructions on a finding of negligence or gross negligence, and the note says negligent or even grossly negligent behavior does not logically support that inference.
Is automatic deletion still a safe harbour?
No. The 2006 version of the rule contained an express safe harbour for information lost through the routine, good-faith operation of an electronic information system. The 2015 amendment replaced that rule. What remains is a reasonableness test, and the note says a preservation duty may call for intervening in that routine operation, meaning you are expected to suspend the job.
Do privacy deletion duties and preservation duties conflict?
Less than founders assume. California's deletion right is subject to exceptions, and a business is not required to comply where retention is reasonably necessary to comply with a legal obligation, or to exercise another right provided for by law. The practical problem is order of arrival rather than conflict, because the deletion request runs on a 45-day clock while the preservation duty has no clock at all.
More stories
The month I could not sue my own customer, at $59K MRR
A composite founder diary. I sent a $21,600 collection letter and got back a sentence about a certificate I did not hold. California bars an unregistered company from suing on that business while deeming it to consent to being sued. The threshold that decided it was $177,000, not the $757,070 every guide quotes.
The month a security questionnaire nearly killed my biggest deal at $34K MRR: a founder diary (2026)
At $34K MRR, running solo, a 214-question security questionnaire and a SOC 2 ask nearly froze my biggest deal. The interim packet that closed it, and what it really cost.
The month honouring every STOP was not TCPA compliance, at $62K MRR
A composite founder diary. Our SMS vendor handled every STOP perfectly, and a customer who typed a plain sentence instead was texted again nine days later. What the statute and the regulation actually require, read end to end at $62K MRR.