The company which consider every single bit of data as "gold" decided not to keep their API's access log > 2 weeks? wow!
I'm not surprised. They (claim to) do something similar with the logs of their DNS service: two weeks of anonymized logs after which they "randomly sample a small subset for permanent storage".
Out of curiosity, when was this policy adopted? After these security holes were discovered?
If you don't have a good business case for keeping it, you're often better off erring on the side of deletion.
They had plenty of experience to suggest to them that keeping highly-detailed logs around indefinitely could do more harm to their users than good.