Why capture first
A host that acts on your notice removes the page, which is what you wanted and also erases your record that it was ever there. That matters if the same material reappears, if a counter-notice arrives, or if you later need to show a pattern of repeat infringement. Capture takes ten minutes per site and it is the step people skip.
The nine things to capture
- The full URL, copied from the address bar rather than from a link.
- A full-page screenshot with the URL and the system date visible in the image.
- The page title and any post title, copied as text.
- The upload or post date shown on the page.
- The uploader's username or handle.
- The view, download or reply count, as a measure of reach.
- The URL of your own original post, so ownership is demonstrable.
- The date and time you captured all of it.
- A note of how you found it — search, a message from a fan, an alert.
How to store it
Keep one folder per incident, named with the date in year-month-day order so folders sort chronologically. Inside, one screenshot file per URL, named after the domain. Keep a single plain-text file listing the URLs, because a text list is what you paste into a notice or a search removal form, and retyping from screenshots is where errors get in.
What not to capture
- Do not download the leaked files. You do not need copies to file, and holding them creates a problem rather than solving one.
- Do not create an account on a leak site to see more. It ties your identity to it.
- Do not capture other people's content that happens to be on the same page. Your notice covers your work only.
Where this pays off
Three moments repay the ten minutes: a counter-notice, where a dated capture is the difference between a firm reply and a shrug; a re-upload, where the earlier record shows a pattern rather than a first offence; and a search removal form, which asks for the original work's location and rejects requests that cannot supply it.