Even if we don't all end up in dystopian bubbles that have some legal tie back to the U.S., the focus should be around proper architecture, defense in depth, plausible deniability by design, etc. If you are not required to keep logs, then don't. If you are, encrypt them with half of a key. You get half of the key and your customers get half of the key. Yes, logs per tenant. This is getting _somewhat_ easier to do these days. Design decentralized or partially centralized systems that permit delegation of control over encryption of data so that lawful intercept is less useful and so that hacking a thing is less effective both technically and legally. I.e. encrypted data-stores that you and your customers can partake in the legal custody of the data. Once you receive the NSL, you won't be able to talk about it and warrant canaries may not always be feasible either, so design your systems with that in mind.
If you code products that folks will use to protect their families freedom and/or way of life, then please consider the attack vectors and generalize your way out of them and/or create really easy to read docs that people can take away action items from and implement.
I only mention this because HN is full of intelligent creative thinkers, engineers, architects and highly experienced attorneys. Hopefully a few doc/tech writers too!
...now back to my really bad coffee.