Is this change in response to some government order? Just asking...
No. Previously IPs were logged sporadically but usually kept indefinitely; this is an overall
significant reduction in retention.
It's a bad idea to provide any IP log to the user themselves. Compromised accounts happen and the situation could become worse if the attacker can access your IP logs.
Right. Though if someone really wants to know, I might consider manually giving them their logs after verifying that their account doesn't look hacked.