ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / UNCATEGORIZED
4 AUG 2026 · 18 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: UNCATEGORIZED
DOCKET NO. 180 · THE DEFENSE DESK

Deleted Doesn't Mean Gone: Cloud Retention in a Federal Case.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

In short, the answer is yes. Deleting a synced file, whether from your device, account, or the app itself, does not necessarily erase every copy that the cloud provider may have.

First, after you delete a file, it often remains available in a “trash” folder or “recently deleted” folder before it is erased forever.

Second, if you make a device backup while you have a file stored on it, that file will be included in the backup. If you then delete the file from your device or from the cloud, it may still exist in the device backup.

Third, if a cloud provider fulfills a law enforcement request for an export of your stored data, a copy of the data will remain available to law enforcement even if you delete it from your account in the future.

Importantly, the fact that a file remains on your cloud account or on the cloud provider’s servers does not necessarily establish that you know about the file’s existence, that you have control over the file, or that you possess the file in your account.

However, if you delete, wipe, or otherwise remove a file from the cloud (or from your device, account, or app) after you know that law enforcement has (or is likely to have) access to your device or account, this may expose you to charges under § 1519 if done knowingly and with the intent to impede, obstruct, or influence the investigation or matter.

If you make a statement, provide an admission, or offer a confession during the execution of a search warrant, this can become admissible evidence at trial, even if the search warrant’s return did not uncover the data you are suspected of possessing.

If you are facing federal charges under §§ 2252, 2252A, and/or § 2252 in the Fourth Circuit, it is essential that you have experienced legal representation. If you are facing a federal indictment for possession of child pornography under § 2252 or § 2252A, this can carry a penalty of up to ten years of federal incarceration. Penalties for receipt of child pornography and distribution of child pornography under § 2252 carry five-year mandatory minimums.

Where Does a Cloud File Go After I Delete It?

What happens after you delete a cloud file depends on the storage method. But in all cases, the answer is the same: you cannot assume that the file is completely erased.

For individuals who store files on “cloud accounts” (such as the ones provided by Apple, Dropbox, Facebook, and Microsoft) or who store files in “the cloud” through an application (such as that of a social media platform), the process is as follows:

First, a user-initiated deletion can move the file to a trash folder, which remains part of the user’s cloud account.

Next, after the expiration of the recovery window for that specific trash folder, the file will be removed from the view of the user’s active account.

Next, the file may (or may not) be available to the cloud provider’s administrators, depending on the cloud provider’s system and policies.

Finally, the file may be physically erased. However, this can occur only after any backup and replica retention periods have expired.

For those who store files on locally-administered private clouds (for example, a home server that is connected to a network ), the process is slightly different:

First, a user-initiated deletion may move the file from the cloud account to a recycle bin.

Next, a user-initiated deletion can trigger a “logical deletion,” meaning that the file is no longer visible in the user’s active cloud account, but it remains on the cloud’s storage drive(s).

Finally, the file may remain stored until the space that the file previously occupied is overwritten by new data.

In summary, when you initiate a “deletion” of a cloud file, you are not necessarily erasing the file from the cloud provider’s (or administrators’) storage. In many cases, you are merely moving it to a location where it can no longer be viewed in your active account.

Many cloud providers and service providers explicitly publish how long it takes for files and other data to be permanently deleted after user-initiated deletion. This is often termed the “retention period” for deleted files.

However, it is not uncommon for cloud providers and service providers to maintain access to user data well after the expiration of the stated retention period. This can be the result of legal obligations, internal policies, or other factors.

If you recently deleted (or wiped) a file from your local device, it will remain in unallocated space on the storage drive until it is overwritten. If you then sync your device with the cloud, it is possible that the device and cloud will retain the same file (or different versions of the same file) in unallocated space.

If you recently deleted (or wiped) files, data, or other information from the cloud, it is possible that the files, data, or information still exist on the cloud provider’s servers. It is also possible that you left “back-door” access to your cloud account open and that you are still subject to law enforcement’s surveillance.

If you are facing criminal prosecution for federal crimes involving the distribution or transmission of child pornography (or other crimes), you need to speak with an experienced federal defense attorney promptly. Spodek Law Group represents individuals on these charges in and around the DC and DMV area and across the United States. If you are facing criminal charges or if you have been charged under § 2252, § 2252A, or § 2252, please contact our office to speak with our federal defense attorneys.

What Does a Federal Cloud Preservation Request Actually Preserve?

In a case involving the storage of child pornography in the cloud, the government may send the cloud provider a preservation request pursuant to 18 U.S.C. § 2703(f).

A preservation request has the following characteristics:

  • 18 U.S.C. § 2703(f)(1) requires cloud providers to preserve information, records, and other “stored communications” pending the application or issuance of a warrant, subpoena, or court order.
  • A preservation request may have an initial duration of up to 90 days.
  • The governmental entity may extend the preservation for an additional 90 days simply by making a renewed request to the cloud provider; no showing of “good cause” and no court approval is required.
  • A preservation request demands that the cloud provider preserve stored communications that it already has in its possession at the time of the request. It does not demand that the cloud provider provide the stored communications to the government (disclosure); it does not demand that the cloud provider produce the stored communications to the government in writing (production); it does not demand that the cloud provider or its personnel testify in court (testimony).
  • A preservation request does not, by itself, authorize disclosure of the content of stored communications.

What Information, Records, and Other Data are Covered by a Cloud Preservation Request?

The information, records, and other data covered by a cloud preservation request under 18 U.S.C. § 2703(f) are limited by the cloud provider’s “possession” of the information, records, and other data at the time of the preservation request.

While “possession” of data in the cloud is a complex issue, generally speaking, if you have stored a file in the cloud, you can reasonably expect that you will have “control” over the file. But this does not necessarily mean that the cloud provider is in “possession” of the file. This depends on the cloud provider’s system and, as often noted by the cloud provider itself, the file may be distributed across multiple server locations in the cloud, making it difficult for the cloud provider to “possess” (or even “store”) the file itself.

The cloud provider will possess the file when it is retrieved from the cloud in order to serve your request or to respond to law enforcement’s request for the stored communication. But this is what happens only when the file is called up and served or produced.

A federal cloud preservation request may preserve information, records, and other data stored in your cloud account that you have not deleted, and it may preserve information, records, and other data that you have deleted but that the cloud provider still has in its possession. It may also preserve information, records, and other data in backups. However, it cannot preserve information, records, and other data that you do not store in the cloud and that are not otherwise in the cloud provider’s possession at the time of the preservation request.

Moreover, a federal cloud preservation request typically cannot preserve information, records, and other data that you store in the cloud after the time of the preservation request. While the cloud provider may take steps to preserve such information, records, and other data, the government’s right to rely on a federal cloud preservation request to enforce this preservation can be a subject of dispute.

If you are facing federal criminal charges for possession of child pornography or another federal crime, you need to speak with an experienced federal defense attorney about your case promptly. Spodek Law Group represents federal defendants across the United States. If you are facing criminal charges, please contact our law firm promptly. Todd Spodek is the managing partner of Spodek Law Group, a second generation criminal defense firm that has been practicing since 1976.

How Do Prosecutors Get Deleted Files from a Cloud Provider?

In most federal prosecutions involving the distribution or possession of child pornography in the cloud, the case will follow a similar pattern. This pattern begins with the generation of a “CyberTip” and ends with an indictment for child pornography offenses.

Phase 1, Generation of a CyberTip

The case typically begins with a cloud provider or other service provider receiving information or evidence of a user’s possession, transmission, receipt, or distribution of a child pornography file.

These files can come from any source. Examples of sources include:

  • Child exploitation images or videos that are found during a user’s upload or download
  • Child exploitation images or videos that are transferred between two or more users
  • Files transmitted through a file-sharing network or peer-to-peer file sharing
  • Evidence that may come from a search warrant, a law enforcement examination of a seized computer or mobile device, or an undercover operation, among others

18 U.S.C. § 2258A(b) requires any “provider of a dial-up or broadband Internet access service or any electronic communication service, as such terms are defined in 18 U.S.C. § 2510(2)(A), that obtains-in the course of providing its service, any communication or other information containing a visual depiction or, as the case may be, a description of any act of sexual abuse that is apparently of a nature that would satisfy the meaning of the term ‘child pornography’ under 18 U.S.C. § 2256(c)(1)” to “report the description or visual depiction to the National Center for Missing and Exploited Children (“NCMEC”) as soon as reasonably possible after obtaining actual knowledge of it.”

These reporting requirements apply regardless of whether the individual reports the file to the NCMEC as a result of an automated process or a manual process of review. However, for reports that result from human review, the FBI notes that this is rare.

The information and evidence that a provider transmits to the NCMEC will typically include the following data:

  • IP address
  • Account or user identifier
  • Date and time (timestamp)
  • File name and file size
  • File hash (or a hash of a hash)
  • Link to the file(s)
  • Recipient of a message containing the file(s)
  • Sender of a message containing the file(s)

These data will be collected by the NCMEC, which will then forward the CyberTip (including the data) to the appropriate law enforcement authority. In many cases, the Federal Bureau of Investigation (FBI) will receive the CyberTip.

The government will then use the CyberTip to begin its investigation into the alleged possession of a child pornography file. This begins with the identification of the suspected subject based on the IP address and other information contained in the CyberTip.

Phase 2, Identification of the Subject

Based on the CyberTip, the FBI or other federal agency will then use the IP address, account identifier, or other information contained in the CyberTip to identify the suspected subject.

In most cases, this involves the issuance of a federal subpoena to the internet service provider (ISP) that issued the IP address contained in the CyberTip.

An ISP will typically respond to a federal subpoena with information, including the subscriber’s name, email address, billing address, and IP address.

If the CyberTip contains an account identifier, the FBI or other federal agency can then use the account identifier to identify the user. With the account identifier in hand, the FBI or other federal agency can then issue a federal subpoena to obtain the noncontent user records from the cloud service provider that owns the account.

Phase 3, Search of the Cloud Account

Once the FBI or other federal agency identifies the suspected subject and obtains sufficient evidence to support the issuance of a search warrant, law enforcement will then work to identify the subject’s cloud account(s).

Upon obtaining a search warrant for the subject’s device(s), FBI agents will identify the subject’s cloud account(s). The warrant will typically specify the cloud provider(s) that are being investigated.

Upon obtaining the warrant, FBI agents or other federal investigators will then contact the cloud provider(s) to execute their search warrant.

FBI agents or other federal investigators will typically contact the cloud provider(s) and their respective legal departments to execute search warrant(s). Once they execute their search warrant, they will typically receive a digital download of all stored data.

With the stored data in hand, federal investigators can then analyze the stored data to uncover evidence of the subject’s possession, receipt, or distribution of child pornography files or other illegal material.

Although this process may lead to an indictment in most cases, there is also a possibility of facing criminal charges or facing an investigation as a consequence of federal agents’ review of stored data from your cloud account.

If you are facing criminal charges for possessing a file on your cloud account, this is something to discuss with an experienced defense lawyer promptly. At Spodek Law Group, we help clients in all federal cases involving child pornography and other federal crimes.

Phase 4, Negotiation for Plea

After the investigation results in the search and seizure of child pornography, a federal prosecutor may present an indictment and seek to negotiate a guilty plea.

While this is a potential outcome, this does not mean you will face criminal charges and a prison sentence.

If you need to discuss your case with a federal defense lawyer, contact our team today.

Does Provider Retention Prove I Knowingly Possessed the File?

Cloud providers and other service providers have different retention policies and retention periods, and they have various means of retaining files and other stored data, whether intentionally or unintentionally.

Regardless of whether the provider has the file in its possession (i.e., whether the file is on the provider’s servers or in a backup and replica of your account), this does not necessarily establish that you possess the file.

In a federal CSAM case, the government must prove that you knowingly possessed the file. This means the government must prove that you (i) knew the content of the file and (ii) had the ability to exercise control over the file.

Although “control” is a term of art in legal contexts, generally speaking, you have control of a file when you have the ability to access, move, delete, or modify the file.

However, if you are unaware of the file’s existence, then you do not possess the file, even if you have the ability to exercise control over the file.

Does Proof of a Deletion Event Prove Consciousness of Guilt?

As discussed, a user-initiated “deletion” typically moves a file from the user’s active account view to another location. If a file is on your cloud provider’s server, then there is the potential for the existence of the file to be linked back to you.

If there is evidence that you deleted a file shortly before a search warrant was issued for your device(s), this can be evidence of consciousness of guilt, supporting a finding of knowing possession.

However, proving consciousness of guilt requires two steps.

First, it must be proven that the user initiated the deletion.

Second, it must be proven that the user initiated the deletion with the knowledge of what they deleted and because they knew that they were subject to an investigation for possession of child pornography.

While this can be a challenging determination in practice, there are several innocent explanations for any deletion event(s). If you are facing criminal charges, this is something to discuss with your defense lawyer.

Does the Deletion of a File from a Shared Folder Prove Knowing Possession?

A shared folder is a cloud storage folder that multiple users can access. A shared folder can grant users access to read, write, or delete files within the folder.

As a result, a shared folder creates a distinction between “possessing” the file and “having access” to the file. As a result, if someone else stores a file in a shared folder, you can possess the file in the shared folder without you having stored the file.

Likewise, if someone else uploads a file to a shared folder, they may possess the file, even if you have access to the file.

This raises important questions concerning whether a shared folder’s existence can support a finding of possessing child pornography and other similar offenses.

It can also raise questions about whether a shared folder’s existence can provide a viable defense to these offenses.

As a result, sharing of files in the cloud is a complex topic that requires discussion with your federal defense attorney in the context of the specific circumstances of your case.

What if Files are in a Workspace?

Depending on the cloud provider’s interface, files in the cloud may be stored in a “workspace” rather than in a folder. An administrator typically manages a workspace, and the administrator grants users access to the workspace.

As with a shared folder, there is a distinction between having access to the workspace and possessing the files within the workspace.

If you are facing federal charges for accessing a cloud workspace, you should discuss this with an experienced federal defense attorney as soon as possible.

What Does Provider Production Prove?

If a cloud provider provides the government with a file that it has stored in its possession (whether because it is in your account or in a backup), this only proves that the cloud provider stored the file. It does not prove that you knew of the file’s existence, or that you have control over the file.

Depending on the circumstances, this may or may not constitute evidence of knowing possession.

As a result, if you are facing federal criminal charges, it is important to work with an experienced defense attorney to defend yourself.

How Can the Defense Test the Government’s Cloud Timeline?

In a case involving the cloud, the government will develop a “timeline” based on a search warrant’s return, device forensic report, and information from a cloud provider.

A cloud timeline is essentially a set of events, often represented as a series of timestamps, with chronological intervals between events that relate to the accused’s device, account, or a cloud-stored file.

Ultimately, the government will use the cloud timeline to develop a theory of when, where, and how the accused possessed, received, or transmitted child pornography.

As a result, the defense’s efforts to test the government’s cloud timeline must be thorough.

In a typical cloud case, the defense will test the government’s cloud timeline as follows:

1. Construct a Comprehensive Timeline

The defense will use a file produced by the provider (containing all timestamps from the file produced under the warrant) and a device forensic report to build a comprehensive timeline of events.

The l la l la

2. Normalize Timestamps and Time Zones

Cloud timelines require normalization of the relevant timestamps and time zones. In other words, if the device forensic report logs information based on UTC (and the server logs information based on UTC), then these logs will be chronological and easy to interpret. However, if the device logs in Eastern Standard Time and the cloud logs in Eastern Central Time (or the Pacific Standard Time), a date and time conversion must be conducted.

3. Compare the Provider Log to the User-Facing Evidence

The defense will also compare the provider’s logs to the user-facing evidence and account artifacts.

Again, this is to test the government’s theories about the timeline. While a provider’s production of records and logs under Federal Rule of Evidence 902(11) (which permits records and other documents to be authenticated by certification of a record-custodian), these logs and records may reflect automated processes.

For example, a cloud storage provider’s log may show access at a certain date and time, but as noted, this may reflect a background synchronization process rather than any user-initiated activity.

4. Challenge Interpretation of Timestamps and Timelines

Given the technical nature of cloud storage, there are various factors that can affect the timeline analysis of data stored in the cloud. Among others, these factors include:

  • Clock Drift: While most computers and devices utilize automatic synchronization between their local clock and the Internet time server (Network Time Protocol or NTP), local clocks can still deviate over time, a phenomenon referred to as clock drift.
  • Synchronization Events: Access to a cloud-stored file can also be automatically triggered by synchronization between a local device and a cloud account. If a user stores a file on a local computer or mobile device, synchronization can trigger an access event (i.e., a transmission to a server, and then a subsequent transfer from a server) that will not be attributable to any direct human user activity.
  • File Modification: Providers can also rewrite metadata for cloud-stored files during certain processes, such as when a file is moved or when multiple versions of a file are consolidated. This could cause subsequent access timestamps to become chronological, which may or may not suggest that the files were human-accessed.
  • Cloud Storage Techniques: Cloud storage providers can utilize deduplication to store redundant information, which can decouple the upload date from the physical storage event. This is another issue that a cloud-stored file’s forensic examination can uncover.

5. Work to Attenuate the Value of the Timeline

With the timelines tested and challenged, the defense can then work to attenuate the value of the timelines as a whole. If a comprehensive timeline reflects inconsistent dates and times, the timeliness of file deletions, or other issues, a defense team will use these to challenge the government’s theories of conscious guilt, knowing possession, and all related offenses.

Get Advice on Your Situation

If you want someone to look at the specifics of your case, Spodek Law Group handles federal criminal defense nationwide from New York and Los Angeles. The firm has been practicing since 1976 and its motto is simple: we owe loyalty to only you. Call 212-300-5196.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.