Contiguous U.S. mail-in service
$200 · standard return includedPay an invoice

Industry News

Data Retention Periods of Major Cell Service Providers

The leaked DOJ carrier-retention chart released by the ACLU, shown alongside the limited public disclosures carriers make today.

United States Department of Justice seal

Updated August 11, 2026: New research added; the leaked chart remains the baseline.

The leaked DOJ chart

This is the chart the article originally published in 2011. The ACLU obtained the Department of Justice’s August 2010 guide through a public-records request. It was prepared for law enforcement and gave specific retention periods across carriers and record types.

For this update, we reviewed current carrier notices and other public material. We found no newer public source comprehensive and specific enough to replace the ACLU release.

Since the original post, the surveillance apparatus available to state agencies has grown alongside the volume of data generated by phones. Without evidence of shorter retention, we think it is safe to treat the leaked figures as a baseline—not to assume the underlying practices suddenly became less restrictive. That does not make every 2010 number a verified 2026 schedule; it means carriers and government have not published a sufficiently detailed replacement.

DOJ retention chart released by the ACLU, August 2010

RecordVerizonT-MobileAT&T / CingularSprintNextelVirgin Mobile
Subscriber informationPostpaid: 3–5 years5 yearsDepends on length of serviceUnlimitedUnlimitedUnlimited
Call detail records1 rolling yearPrepaid: 2 years; postpaid: 5 years5–7 years18–24 months18–24 months2 years
Cell towers used by phone1 rolling yearOver 1 yearFrom July 200818–24 months18–24 monthsRetained by Sprint
Text-message detail1 rolling yearPrepaid: 2 years; postpaid: 5 yearsPostpaid: 5–7 years18 months18 months60–90 days
Text-message content3–5 daysNot retainedNot retainedNot retainedNot retained90 days with search warrant
PicturesIf uploaded to websiteUntil deletedNot retainedUnknownUnknownNot retained
IP session information1 rolling yearNot retainedNon-public IP retained 72 hours60 days60 daysNot retained
IP destination information90 daysNot retainedNon-public IP retained 72 hours60 days60 daysNot retained
Bill copies3–5 yearsNot retained5–7 years7 years7 yearsUnknown
Payment history3–5 years5 yearsDepends on length of serviceUnlimitedUnlimitedUnknown
Store-surveillance videos30 days2 weeks1–2 monthsDependsDependsUnknown
Service applications3–5 yearsNot retainedNot retainedDependsDependsNot retained

Download the original DOJ chart as a PDF.

Sprint, Nextel, and Virgin Mobile no longer exist as the independent national carriers represented here, and other ownership and network arrangements have changed. The table is the last detailed cross-carrier baseline we could verify, not a claim that every cell still describes a current system exactly.

The “official narrative” in 2026

Current public-facing policies mostly say records are retained for as long as the provider considers necessary for service, business, tax, security, or legal purposes. They rarely publish the concrete, record-by-record periods shown in the leaked chart. “No fixed schedule” below means the public notice does not provide one; it does not mean the provider keeps no records.

Carrier or brandWhat its current public notice says
AT&TNo fixed schedule. Retention depends on the type of information, how long it is needed to operate the business or provide service, and contractual or legal obligations.
Cricket WirelessNo fixed network-record schedule. Cricket uses the same kind of business, tax, and legal criteria. Its notice separately gives a defined limit for biometric information, illustrating that different data classes can have different rules.
VerizonNo fixed schedule. Verizon says sensitive and personally identifiable records are retained only as long as reasonably necessary for business, accounting, tax, or legal purposes.
VisibleNo fixed schedule. Visible says it keeps information only as long as reasonably necessary for business, accounting, tax, or legal purposes.
TracFone brands — Straight Talk, Total Wireless, Simple Mobile, SafeLink, Walmart Family MobileNo current per-record timetable found. The TracFone privacy center provides access, correction, deletion, and advertising-choice requests, including requests for former-customer service history. These brands are part of Verizon’s value portfolio.
T-Mobile and MetroNo fixed schedule. T-Mobile considers the amount, nature, sensitivity, purpose, risk of harm, and applicable legal, accounting, and reporting requirements.
Mint Mobile and Ultra MobileNo fixed schedule. Mint’s notice includes phone-call records among the identifiers it may collect and says retention lasts only as long as needed for stated business purposes unless law permits or requires longer.
Boost MobileNo fixed schedule. Boost says it may collect call and data-use history, location, websites visited, and apps used, and keeps personal information as needed for service, legal or tax requirements, fraud prevention, and other business purposes.
Xfinity Mobile and NOW MobileNo fixed schedule. Xfinity says it keeps identifying information while a person subscribes and may retain it afterward for business and legal needs. Its policy identifies call history, IP addresses, mobile geolocation, DNS searches, and network traffic among collected information.
Spectrum MobileNo fixed schedule. Spectrum’s policy describes account, device, network-traffic, service-use, and location information, but does not publish a comprehensive mobile-record timetable.
Google Fi WirelessNo Fi-specific fixed schedule. Fi says it maintains information about calls, texts, data use, connectivity, device performance, and location. The Google Privacy Policy supplies the broader retention framework.
Consumer CellularNo fixed schedule. Its policy says categories are retained for periods based on business needs, legal requirements, and regulatory obligations unless a specific period applies.
US MobileNo fixed schedule. US Mobile identifies account details, payment records, call and data-use logs, and device identifiers, and says retention may continue for security, business, tax, anti-fraud, dispute, and legal purposes.

What the official language leaves unanswered

Retention can differ between systems inside the same company. Public notices leave the exact periods for several important record types unanswered:

  • Subscriber and account records: name, address, account identifiers, activation history, plan, SIM or eSIM identifiers, and device identifiers.
  • Billing and payment records: invoices, taxes, payment history, installment information, and collections records.
  • Call and message metadata: the numbers involved, time, duration, routing, and delivery information. Metadata is different from the content of a call or message.
  • Location and cell-site records: information created when a device connects to towers, Wi-Fi systems, location services, or emergency services.
  • IP and data-session records: assigned addresses, connection times, data use, network diagnostics, and related session information.
  • Website and application activity: carrier websites, account apps, advertising identifiers, cookies, support chats, and customer-service recordings.
  • Communication content: voicemail, cloud-stored messages, or other content held by a provider. Whether content exists depends on the service and technology; it should not be inferred from a metadata-retention statement.

A retail mobile brand can also operate on another company’s network. The retail provider may hold account, billing, application, and support data while a network supplier processes network and location records. A prepaid or low-cost brand is not necessarily a single-data-holder arrangement.

The federal preservation rule

Under 18 U.S.C. § 2703(f), a provider that receives a qualifying government request must preserve records already in its possession for 90 days. A renewed request can extend that for another 90 days.

That rule does not create a universal 180-day retention schedule. It preserves material the provider already has after a request; it does not reveal how long the provider normally keeps each record.

Bottom line

The leaked DOJ chart is old but specific. Current carrier notices are newer but vague. Until carriers or government publish a comprehensive replacement, the honest presentation is to show both: the documented baseline and today’s official narrative.

Sources

  1. Cell Phone Company Data Retention Chart — American Civil Liberties Union
  2. How Long Is Your Cell Phone Company Hanging On To Your Data? — American Civil Liberties Union
  3. AT&T Privacy Notice — AT&T
  4. Cricket Wireless Privacy Notice — Cricket Wireless
  5. Verizon Privacy Policy — Verizon
  6. Visible Privacy Policy — Visible
  7. TracFone Privacy Center — TracFone
  8. T-Mobile Privacy Notice — T-Mobile
  9. Mint Mobile Privacy Notice — Mint Mobile
  10. T-Mobile Completes Acquisition of Mint and Ultra Mobile — T-Mobile
  11. Boost Mobile Privacy Notice — Boost Mobile
  12. Xfinity Privacy Policy — Comcast
  13. Spectrum Privacy Policy — Charter Communications
  14. Google Fi Privacy Notice — Google Fi Wireless
  15. Consumer Cellular Privacy & Security Policy — Consumer Cellular
  16. US Mobile Privacy Policy — US Mobile
  17. 18 U.S.C. § 2703 — U.S. House of Representatives