
At Facebook, we learned the same lesson from the other side. Short retention windows made it harder to reconstruct abuse because complaints, patterns and corroborating facts often arrived later, so we widened some windows. Deletion removes risk, but it can also destroy evidence needed to expose misuse. The better model is graduated retention backed by graduated controls. Seven days can remain the default. A community seeking more time should approve it publicly and accept stronger requirements, including verified identity, case-bound access, added justification for older data, supervisor review for sensitive searches, automated abuse detection, immutable logs, periodic renewal and independent audit. Retention should follow investigative value and control maturity. It cannot carry the burden that access control and accountability should carry.
A case number matters only if it is real and the user is assigned to it. An anomaly detector matters only if it works and triggers timely action. A portal matters only if it is complete and used. Engineering takes time, but interim protection often does not. Flock can disable high-risk sharing, require supervisor approval, review suspicious searches, restrict older data and suspend problematic accounts while permanent controls are built.
In just the last few weeks we’ve heard more reasons to move quickly. Boston’s newly released surveillance report says its contract required data sharing to be off, yet outside agencies could reach Boston’s data during the opening days of its pilot because nationwide sharing had been enabled in error. Separately, a September review of historical Flock logs found searches justified with entries such as “LMAO,” “idk” and “TBD.” Flock later replaced free text with preset categories, but a dropdown still cannot prove that a real case exists or that the user is assigned to it.
