Skip to content

Power

Disappearing Messages Can Erase Public Business Before You Ask

Missouri officials’ use of Confide exposed the real gap in public-records law: a government message can disappear long before anyone knows to request it.

Lena VasquezPower — Courts & Policy

August 27, 2026 · 9 min read

A phone showing Confide’s covered-message interface beside a government records folder on a plain office desk.

Confide was built to leave little behind. A recipient dragged a finger across covered text to reveal a message, one section at a time. The app advertised end-to-end encryption, meaning only the participants’ devices could read the exchange, along with screenshot protection and deletion after reading.

Those features sold a feeling familiar to anyone who has regretted putting something in writing. They looked different after public reporting in late 2017 found that Missouri Governor Eric Greitens and members of his administration had Confide accounts.

The issue was never that state workers had discovered private conversation. Government employees can have those. The issue was whether officials used an app designed to destroy its own evidence for government work that Missouri law required them to preserve.

A state attorney general’s investigation did not establish that Greitens or his staff had violated Missouri’s open-records law through Confide. It also could not recover vanished conversations and determine their contents. That is the central problem in miniature. An investigation asked whether public business had been deleted, but the tool’s defining feature had already removed much of what investigators needed to answer.

Confide’s covered text panel did more than hide a message from someone looking over a shoulder. In a government office, it could also move the first meaningful accountability decision from a records officer applying a retention schedule to the sender choosing an app.

Public record and retained record are different questions

State open-records laws vary, sometimes sharply, but they commonly focus on a communication’s content and connection to public business rather than the logo on the phone. A message about an agency decision does not become personal merely because an official sent it through a private account, an encrypted app or a device the state never purchased.

That principle sounds reassuring. It is only the first half of the machinery.

Open-records law generally tells an agency what it must disclose when responsive material exists and no exemption applies. Records-management law governs how long different categories of material must be kept. A retention schedule is the binding timetable, adopted under state law or authorized agency rules, that says when a record may be destroyed.

Some government messages are transitory and can be discarded quickly. Others document policy, spending, enforcement, appointments or official decisions and must survive longer. A calendar reminder about a moved meeting is not the same record as a chat in which senior officials settle the wording of an emergency order, even if both arrive through the same app.

The duty therefore attaches before a reporter, resident, lawyer or watchdog files a request. A request creates a search obligation for records the government has. It does not travel backward through time and restore a Confide message that disappeared after it was opened.

Once an agency receives a records request, litigation hold, subpoena or court order, destroying responsive material can trigger additional consequences. A litigation hold is an instruction to suspend routine deletion because evidence must be preserved. Those duties are stronger and easier to enforce because a defined dispute already exists. The quieter loss happens earlier, while the message still looks like ordinary office chatter and the public has no reason to know it exists.

Encryption is not the part that deletes the record

Officials often collapse encryption and disappearance into one ominous package. They are separate functions.

End-to-end encryption protects a message while it travels and while a service handles it, keeping the platform or an interceptor from reading the content. Auto-deletion tells participating devices to remove the message after a timer expires or another condition is met. An encrypted message can be retained. A plainly readable message can be deleted.

That distinction matters because weakening encryption is a bad answer to a retention failure. Public employees, social workers, health departments and investigators handle information that should not sit exposed to data brokers, hostile intruders or casual device searches. Secure communication protects residents as well as officials.

The state’s legitimate demand is more precise: when employees conduct public business, the government needs an authorized copy held for the required period, protected by access controls and released only when disclosure law permits it. Some records contain personal, investigative or security-sensitive information that an agency must redact or withhold. Preservation does not make every record public on demand.

Confide bundled confidentiality with destruction, which made the distinction easy to miss. Signal and other encrypted messengers also offer disappearing-message timers, though agencies can prohibit those settings for official work or require employees to preserve qualifying communications elsewhere. The policy choice is not encrypted chat versus public accountability. It is managed retention versus a timer controlled by each participant.

The accountability gap opens at the moment of creation

A conventional records system makes preservation boring. An official sends an email through a government account; the server journals a copy, applies a retention rule and allows records staff to search it later. The employee does not need to predict whether a particular message will interest a newspaper two years from now.

Consumer messaging apps reverse that arrangement. The worker chooses the channel, the timer and sometimes the device, while records staff may never see the communication or even know which platform to search. If preservation depends on the sender taking a screenshot, exporting a thread or forwarding each relevant message into email, the person whose conduct may later be examined becomes the first and often only archivist.

That setup works very well for the institution until it does not. Officials get the speed and intimacy of texting without the drag of a formal system. Agencies avoid paying for enterprise archiving, managed devices, staff training and routine audits. App makers win adoption by reducing friction, not by satisfying every state’s retention schedule.

The public pays later through delayed requests, litigation and investigations forced to reconstruct decisions from calendars, partial emails and participants’ memories.

Intent can matter to penalties, but the structural failure does not require a conspiracy. An official may enable a one-week timer because a crowded phone feels easier to manage that way. The deletion still occurs before a records officer classifies the message. Convenience does the work that deliberate concealment would otherwise have to do.

This is why an agency policy that merely tells workers to obey public-records law is weak. It assigns a legal classification task to people composing messages between meetings, then assumes they will preserve the exchanges that could later embarrass them. Confide’s disappearing panel made that weakness visible, but the same arrangement survives anywhere an official channel lacks automatic capture.

What is binding, and what is office theater

The binding duties come from state public-records statutes, archives and records-management laws, valid retention schedules, court rules, litigation holds and specific orders. Their application depends on the jurisdiction, the employee, the message’s content and the kind of record involved.

An app’s marketing is not binding. A governor’s office memo may be enforceable as workplace policy, but it does not replace statutory duties. Training slides, ethics pledges and promises to conduct official business on official accounts matter only if the agency configures its systems to make compliance likely and checks whether employees route around them.

Enforcement remains awkward because proof often depends on the record whose destruction is disputed. Investigators may find metadata, which is information about a communication such as participants and timing, without finding its text. They may locate a reply preserved on another device or an email referring to the vanished thread. None of that guarantees a complete account of what officials decided.

Courts can impose sanctions in litigation when parties fail to preserve evidence after the duty has attached. Records statutes may authorize civil penalties, attorney fees or other remedies, depending on the state and the official’s conduct. Yet a requester often must first show that a missing record existed and concerned public business. Auto-deletion makes that threshold harder to clear.

No app can fix a law that gives archives little authority, sets trivial penalties or treats messaging as an afterthought. Technology can, however, remove the employee’s timer from the retention decision.

The fix is controlled retention, not permanent memory

Agencies can designate approved encrypted tools that archive official conversations into systems governed by retention schedules. They can disable disappearing messages on managed accounts, issue government devices where the work demands them and require prompt transfer when emergencies force employees onto another channel. Regular audits should compare known accounts and devices against the records systems meant to capture them.

That costs money and staff time. It also creates a larger store of sensitive information, which raises surveillance and security risks for residents who contact government. The answer is not to retain every message forever. Agencies should collect only official records, apply narrow schedules, restrict internal access, log searches and delete material when the lawful retention period ends.

Personal conversation should remain personal. Public business should enter a public system, even when exemptions later protect it from release. Those categories cannot be sorted reliably by trusting every official to copy the important parts after the fact.

The useful test is concrete. If a governor’s aide opens a Confide message about state policy and the covered text disappears, where did the government’s copy go? If the answer is nowhere, the accountability failure happened at that moment, not months later when a records clerk reports that a search produced no responsive documents.

Questions people ask

Are officials allowed to use

Signal, Confide or private phones for government work?

That depends on state law and agency policy, but using a private device or encrypted app usually does not erase a communication’s public-record status. If its content documents government business, the official or agency may have to preserve it through an approved system for the applicable retention period.

Does encryption violate public-records law?

Encryption alone does not destroy a record or block lawful disclosure. It protects content from outsiders while the message travels or sits on a device. The records problem arises when an agency cannot retain, search, export or produce the official copy because employees used disappearing settings or unmanaged accounts.

Can an agency deny a request because the messages already disappeared?

An agency cannot produce a record it no longer has, but that does not settle whether the record was lawfully destroyed. A requester may challenge the search or deletion under state law, though proving what existed is difficult when the app erased the content before records staff captured it.

Should government messages be kept forever?

No. Permanent retention would expose residents and workers to unnecessary surveillance, security breaches and internal misuse. Governments need enforceable schedules that preserve records long enough for oversight, protect exempt material while it is held and require deletion when its authorized lifespan ends, rather than whenever a sender’s timer runs out.

Was this worth your time?
ShareFacebook
internet policysurveillancepublic recordsencrypted messaginggovernment transparencydigital surveillance

One update a day

Today's story, in your inbox

One story each morning — no hype, no filler, no algorithm deciding for you.

Read next