Evidence Guide · 18 min read

How to organize text messages into court-ready evidence.

A useful message packet keeps the original export, participant map, timestamps, surrounding context, redactions, and report notes connected. Textimony is built around that workflow.

This guide is for people organizing message records before professional review. It covers source preservation, participant maps, context windows, redaction, timelines, and report handoff.

The short answer

Text messages become easier to review when the packet shows where each message came from, who sent it, when it was sent, what came before and after it, and what changed during redaction or export. A screenshot can help, but it is usually only a view of the record. A stronger handoff keeps the original export, working copy, context window, source manifest, participant map, and report build notes together. Start with preservation. Do not begin by rewriting messages into a summary. Keep the raw export intact, then build review copies from it.

What to save before you review

Save the original conversation export or backup first. Keep the file name, device or account source, export method, date range, timezone clue, media decision, and any error shown during export. If the source is an app screenshot, keep the image files in their original order and avoid cropping away timestamps, contact headers, message tails, attachment labels, or surrounding messages. Original export file, backup, or screenshot set. Date range and timezone assumptions. Device, account, app, or platform where the messages were found. Export method and whether attachments were included. Unedited working copy for review. Redacted copy for sharing. Source manifest listing every file used in the packet.

Build a source map before making claims

A source map is the table that says what was supplied: file, row count, date range, participant clues, export format, media status, and review status. The source map prevents the common mistake of treating a clean PDF as the source. The PDF is the review copy. The export or original capture set is the record that the review copy points back to. Artifact label — Gives each source a stable public name such as Artifact A instead of leaking file names. File type — Shows whether the record came from CSV, TXT, XML, EML, JSON, screenshot, or another source. Date coverage — Shows gaps, overlaps, or ranges that need review before a timeline is trusted. Row count — Lets reviewers spot missing sections, duplicate exports, and unexpectedly small files. Media choice — Separates text-only exports from exports that include attachments. Review status — Shows whether the source was accepted, skipped, duplicated, corrupted, or needs follow-up.

Map participants before reading meaning into the thread

Participant mapping comes from structural evidence: sender headers, account direction, phone numbers, email addresses, contact labels, platform fields, and user confirmation. Do not decide who sent a message because the sentence sounds angry, apologetic, masculine, feminine, parent-like, or victim-like. That kind of guessing corrupts every metric after it. Keep raw sender labels separate from normalized participant IDs. Treat Me, You, Sender, Recipient, Person A, and redacted labels as aliases that need evidence. Use UNKNOWN when the record does not support a reliable sender assignment. Do not force a group chat into two people. Ask one focused confirmation question when the system can separate two speakers but cannot tell which speaker is the account owner.

Make the timeline reviewable, not just sorted

A good message timeline keeps source order and resolved order visible. Some exports have missing timestamps, duplicated timestamps, date headers, timezone gaps, copied sections, or reverse chronological order. Sorting everything by timestamp can hide extraction problems. Keep source row numbers, preserve warnings, and state the timezone used for review. When a timestamp is missing or ambiguous, the honest result is an unresolved time—not an invented one. Structured row index — Usually stronger than a guessed timestamp. Keep it. Full timestamp — Strong when parseable and consistent with surrounding rows. Date-only header — Useful for grouping, weaker for ordering within the day. Missing timestamp — Keep source order and mark timestamp confidence lower. Duplicate timestamp — Do not remove a message just because time matches another row. Reverse order — Repair only when the evidence is consistent across the file.

Screenshots and exports do different jobs

Screenshots show what a person saw. Exports are usually better for row-level review because they can carry timestamps, sender fields, attachments, and larger date ranges. When both exist, use screenshots to corroborate visible display and use exports for source-linked organization. Do not let a screenshot replace the source inventory. Screenshots: useful for visible layout, contact headers, bubble sequence, and app display. Exports: useful for searchable text, row counts, timestamps, sender fields, and manifest-backed reports. PDFs: useful as review packets, but only when they point back to the source rows.

Redact the copy, not the source

Redaction protects names, phone numbers, emails, addresses, school labels, child identifiers, file paths, and account handles without changing the underlying source record. Keep a separate note of what kind of information was removed and why. The goal is a safer sharing copy, not a rewritten conversation, and the untouched source should remain available to an authorized reviewer. Keep originals untouched. Create a working copy and a sharing copy. Replace private identifiers with consistent labels. Keep row IDs, dates, and source references intact when safe. Record each redaction category in review notes.

What belongs in a report packet

A review packet should make the record easier to inspect without pretending the software is the decision-maker. Useful sections include source labels, participant assumptions, message counts, candidate issue lanes, selected excerpts, context windows, and the reviewer decisions used for a curated report. Textimony separates direct measurements from review candidates. Direct measurements include row counts, date ranges, sender labels, and timestamps supplied by the record. Candidate labels point to messages that still need human reading in context. Control sheet — Identifies the packet, date range, row volume, source count, and review state. Source manifest — Lists source artifacts, accepted rows, skipped rows, and verification IDs. Participant map — Shows labels, aliases, confidence, and unresolved mapping questions. Issue index — Groups candidate messages into review lanes without deciding what they mean. Excerpt queue — Shows selected messages with source references and surrounding context. Review decisions — Records which candidates a reviewer accepted, rejected, or left unresolved. Available exports — Packages the selected material in the formats offered by the current workspace.

Print checklist

Use this checklist before sharing a review packet. It is deliberately plain because the work is already complicated enough. Original source file is saved and untouched. Working copy is separate from the original. Participant map is confirmed or marked unresolved. Each selected excerpt keeps its available source reference and surrounding context. Timestamps show timezone assumptions where known. Duplicate exports and repeated sections were checked. Redactions in a sharing copy are documented in review notes. The packet says what was skipped and why. The reviewer can reach the underlying source record.

Are screenshots enough for text message evidence?

Screenshots can be useful, but they are easier to separate from surrounding context. A stronger packet ties screenshots or PDFs back to source exports, row IDs, timestamps, and a manifest.

What if the sender names are wrong?

Stop and fix the participant map before trusting metrics or summaries. Wrong sender attribution changes harassment counts, custody-interference lanes, response timing, and every participant-specific finding.

Should repeated identical messages be removed?

No. People really do send repeated messages. Treat duplicates as a source question, not a text-only question. Compare sender, timestamp, source artifact, attachment data, and overlapping provenance before marking a row duplicate.

Published by

Textimony. Editorial status: Product and evidence-workflow guide. Human review recommended before case use. Updated: 2026-07-23.

Sources

Federal Rule of Evidence 901 — Legal Information Institute, Cornell Law School; Federal Rule of Evidence 1006 — Legal Information Institute, Cornell Law School; Federal Rule of Evidence 106 — Legal Information Institute, Cornell Law School; Guidelines on Mobile Device Forensics — National Institute of Standards and Technology; How to export your chat history — WhatsApp Help Center; Use Messages in iCloud — Apple Support