# Evidence-preservation checklist — image copyright claims

> **General information—not legal advice.** This checklist does not determine whether any
> use is lawful, create an attorney-client relationship, or guarantee any result. Preserve
> first; consult qualified counsel about preservation duties, deadlines, and strategy.

Do **not** delete logs, cached files, notices, source responses, or the challenged asset
after receiving a claim. Preserve before removing or changing anything, then label every
item: **contemporaneous** (captured when the alleged use occurred), **historical** (from a
dated archive or log), **current** (visible now, not necessarily then), **inferred**
(supported indirectly — state the limitation), **user-confirmed** (asserted from memory,
not yet documented), or **missing** (requested, not yet available).

## 1. The notice itself

- [ ] Complete email with full headers, envelope, and every attachment
- [ ] Portal URL, invoice, reference number, and payment instructions
- [ ] Every follow-up communication, with dates and delivery records
- [ ] If you or your business carries general, media, or cyber liability insurance:
      check the policy's claim-notice requirement now — late notice can forfeit coverage

## 2. The alleged display

- [ ] Full-page screenshots with visible headline, attribution, source link, and context
- [ ] Page HTML and timestamps (with time zone)
- [ ] Rendered image size (CSS pixels) and served file resolution
- [ ] Whether any standalone or full-resolution download was available

## 3. Source metadata (how the image was selected)

- [ ] Source article HTML at the relevant time (and dated archive copies)
- [ ] Raw Open Graph tags (`og:image`, `og:title`, `og:url`)
- [ ] Raw X/Twitter Card tags
- [ ] Raw JSON-LD `Article` / `NewsArticle` blocks, including `image`
- [ ] oEmbed request URL and the complete raw JSON response (`type`, `html`, `url`,
      `thumbnail_url`, `cache_age`)
- [ ] RSS/Atom or API responses supplying the image
- [ ] Crawler/worker logs and the code path showing automated selection

## 4. Image identity and delivery route

- [ ] Original image URL and final URL after redirects (full redirect chain)
- [ ] HTTP status, headers, content type, content length, ETag
- [ ] File dimensions and SHA-256 hash
- [ ] HAR or browser network trace: request initiator and the host that transmitted the bytes
- [ ] Cache/proxy/CDN records: cache key, TTL, creation/expiry, purge history,
      storage location, and proof processing was automatic and unmodified

## 5. Display period (duration)

- [ ] Feed-rotation schedule or slot records
- [ ] Cache TTL and expiry records bracketing the display window
- [ ] Deploy logs and dated captures before/after the window
- [ ] Note: a claimant's single screenshot establishes a moment, not a period —
      request their evidence of the alleged duration

## 6. System and business context

- [ ] Server/CDN/proxy logs, software versions, parser rules
- [ ] Impressions, clicks to the source, active dates, territory, and revenue context
- [ ] Publisher, platform, feed, API, embed, vendor, proxy, and CDN terms in effect

## 7. Mitigation (if you disable the display)

- [ ] Preserve everything above **before** removal
- [ ] Dated removal record and archived before/after copies
- [ ] Keep the headline and source link if only the image is disabled
- [ ] Describe removal neutrally — mitigation is not an admission, and it does not by
      itself resolve a monetary demand

## 8. Claimant-side records to request

- [ ] Their capture files, timestamps, and chain of custody
- [ ] Ownership, chain of title, registration, and group-registration identification
- [ ] The representative's written authority
- [ ] Their evidence of the alleged display period
- [ ] Damages support: ordinary rates and materially comparable arm's-length licenses
