Skip to content
Skip to main content
Cloud Services Technical Explainer

Could a file exist in the cloud but not on the device?

Yes. Cloud services can keep the full content with the provider while a device holds only a listing, placeholder, thumbnail or temporary cache. The file may still be available through the account even though no complete local copy is recovered.

“Shown on the device” has several meanings

A device may be in one of these states:

  • Online only: the application lists the cloud object but stores no full local content.
  • Placeholder: a small local record contains the filename, object ID and status; opening it triggers a download.
  • Preview or cache: the device holds a thumbnail, rendered page or temporary fragment rather than the original file.
  • Browser access: the content is viewed or streamed through a web session without a durable copy in the expected folder.

At 08:40 Dave's Windows laptop lists OneDrive object OBJ-8821, route-plan.pdf, with an online-only state. The provider holds the full object; the local entry supplies a name, mapping and state but not the full PDF. At 09:03 an application requests the object and the client makes it locally available.

A visible name does not tell you what the device stored
EstablishedThe provider made the object available and the device represented a defined storage state at each time.
Still openWhether Dave caused a retrieval, viewed the content or knew it was available.

Selective synchronisation may exclude the folder entirely. The same account may also have been used from another device that is not available for examination.

Absence of a full copy does not settle access

Provider records may show that an account viewed, downloaded, edited, shared or deleted the object. On the device, application databases, recent-item lists, browser history, notifications, thumbnails and sync records may corroborate interaction even where the full content is absent.

Those artefacts need careful interpretation. A thumbnail can be generated automatically, and a provider “download” event may describe retrieval by a sync client rather than a person opening the document. The event type and application context matter.

Cloud presence does not establish knowledge either

A file can be uploaded by another linked device, shared into the account or created by an application. Its presence in the provider's object list establishes availability to the account under the recorded permissions; it does not alone prove that the user saw it.

The distinction between cloud and local files helps state the result precisely:

Established: the provider held the object and the account had the recorded access or permission at the relevant time.

Still open: whether this device obtained the full content, whether the user interacted with it and who controlled the relevant account session.

Current OneDrive online-only example - checked 3 September 2026

Microsoft currently describes an online-only OneDrive item as visible in File Explorer without consuming space for the full file; opening it downloads it and makes it locally available. Thumbnails may also be shown for online-only content. These UI states can change, so preserve the underlying client state, object mapping and transfer evidence where available.

The point to remember

A cloud object can be available and used without leaving a full file on the examined device. Combine provider events with application and device artefacts before deciding what was accessible or known.

Reference: CLD-057Cloud Services