Capture
- Posts from named accounts, over any date range, or matching key words.
- Full history of an account, month by month, as far back as X shows it.
- Replies, links and media references are kept with each post.
- For each account: its permanent user ID, @username, display name and follower count (both names can change later), plus a dated history of its profile (name, bio, location, followers) from the first capture.
- Views, likes, reposts, replies and quotes, as X reported them when the post was captured.
- Every post is saved the moment it is found. The captured text and its fingerprint are never silently overwritten (any correction is logged and disclosed), and a post is never stored twice.
- Deleted-post checks: posts that later disappear from X are flagged, and the preserved copy stays.
- A picture of each post as X displayed it (author, text, photos, date, likes and views), from a thread, a search, a profile or a list of post links.
Proof and integrity
| Check | What it proves | Who can verify it |
|---|---|---|
| Post ID date | When the post was created. X builds the time into every post ID. | Anyone, with a calculator and the public formula |
| SHA-256 fingerprint | The record has not changed since capture. | Anyone, with any SHA-256 tool |
| Bitcoin timestamp (OpenTimestamps) | The record existed no later than a fixed date. | Anyone, with the free OpenTimestamps tools and a .ots proof file |
| X embed cross-check | X's own public service confirmed the text and author at capture. | Anyone, by repeating the request while the post is live |
| Chain of custody | Every action taken on a record, in order. Each entry is linked to the one before it, so a removed or edited entry is detected. | An expert, from the exported log |
X Spaces (live audio rooms)
- Room details: title, host, co-hosts, speakers, start and end times.
- Who was in the audience, and who was brought on stage.
- The room chat and X's live captions, searchable by word.
- The recording, where X kept a replay.
Search and analysis
- Search every preserved post by word, account, date, media type or case tag.
- Who appeared in Spaces together, and who spoke on stage with whom.
- Timelines and activity summaries for a person or a topic.
Deliverables
| Format | Contents |
|---|---|
| PDF exhibit packet | Bates-numbered posts with dates, links and fingerprints, ready to attach. |
| Word document | The post list (dates, authors, links and fingerprints), editable for your filings. |
| Post images (PDF or image files) | Each post pictured as X displayed it, one per page or one file per post. |
| CSV (opens in Excel) | Every record and field, for review or your own analysis. |
| Proof files (.ots) | The Bitcoin timestamp proof for each post, for an expert to verify. |
| Declaration or certification | Describing the capture, signed by the person who made it: the federal 28 U.S.C. § 1746 declaration or a New Jersey certification in lieu of oath (Rule 1:4-4(b)). |
Confidentiality
- Never posted publicly and never sent to web-archive services.
- Each matter is tagged and exported on its own, never mixed with another client's.
Have a matter in mind?
Email: ozdemir@salesforcehub.us
Service area: New Jersey and nationwide
Send the accounts, date range or key words. We reply with a written flat-fee quote, usually the same day.
Email ozdemir@salesforcehub.usCaptures are made of content visible to a standard signed-in X account, through the ordinary X website. Not a law firm; no legal advice is given, and admissibility is always for the court to decide. Not affiliated with or endorsed by X Corp. "X" is a trademark of X Corp.
Terms used on this page
X and its accounts
- @username and display name
- The @username (handle) is the account's address on X; the display name is the name shown above posts. The owner can change either at any time, so both are recorded at capture.
- User ID
- A permanent number X gives each account. Unlike the @username and display name, it never changes, so it identifies the account even after a rename.
- Post ID
- The long number at the end of a post's web address. X builds the exact moment the post was created into this number (X calls it a "Snowflake" ID), so anyone can decode the posting date with a public formula.
- X Spaces
- Live audio rooms on X. A host runs the room, co-hosts and speakers talk "on stage", and everyone else listens in the audience. X sometimes keeps a replay afterwards.
- Live captions
- The automatic text X shows on screen while people speak in a Space.
- X's public embed service (oEmbed)
- The service X itself provides so websites can display a post. Asking it about a post returns X's own copy of the text and author, which is compared with the capture.
Proof and integrity
- SHA-256 fingerprint (hash)
- A 64-character code calculated from a record's content. The same content always gives the same code; changing even one character gives a completely different one. So if the code still matches later, the record has not been changed. The code cannot be turned back into the content.
- Chain of custody
- A record of every step taken with a piece of evidence: who handled it, when, and what was done, to show it was not altered along the way. Here each entry is linked to the one before it, so a deleted or edited entry is detected.
- Bitcoin timestamp (OpenTimestamps)
- OpenTimestamps is a free, open service that writes a record's fingerprint into the Bitcoin blockchain. That proves the record existed no later than that date. Only the fingerprint is sent, never the post itself.
- Deleted-post check
- A later look at X to see whether captured posts are still there. Posts that have disappeared are flagged; the preserved copy and its proof stay unchanged.
Legal terms
- Declaration (28 U.S.C. § 1746)
- A written statement signed under penalty of perjury, which federal law accepts in place of a notarized affidavit. New Jersey state courts accept a similar "certification in lieu of oath" (Rule 1:4-4(b)).
- Bates numbering
- A unique, sequential number given to every page or item produced in a lawsuit (for example EX-0001), so each one can be cited and tracked without confusion.
What you receive
- Exhibit packet
- The set of documents delivered for a matter: the captured posts laid out and numbered, ready to attach to a filing as exhibits.
- .ots proof file
- A small file, one per post, that lets anyone check the Bitcoin timestamp with the free OpenTimestamps tools, without using this software.
- CSV
- A plain spreadsheet file that opens in Excel, Numbers or Google Sheets.