Skip to content
Skip to main content
Mobile Devices & Apps Foundation Explainer

What is actually stored on a mobile device?

A mobile device is not one sealed box containing a perfect history of its user. It combines hardware, an operating system, subscriptions, apps, accounts, local databases, cached material and links to provider or cloud data. Understanding which layer produced an item tells an investigator what it can establish and where a stronger record may exist.

In one sentence
A phone may store the content itself, a local record about it, a temporary copy, an account token or only the means to retrieve it from somewhere else. “It was on the phone” is therefore the start of the explanation, not the end.

One handset, several evidence layers

Hardware
Operating system
SIM or eSIM
Apps
Accounts
Cloud and providers

The layers interact, but they are not interchangeable. A handset identifier, subscription record, app account and human user answer different attribution questions.

The physical device has a manufacturer, model, serial number, storage and network-capable hardware. Its operating system manages encryption, permissions, notifications, usage and connections. Why the model and operating-system version matter is practical: access methods and available artefacts vary with hardware, software and security state.

A SIM or eSIM connects a subscription to the mobile network. It is not the handset. Handset, SIM, eSIM and subscription can move or combine in different ways, just as a telephone number may move between devices and providers.

Apps add local files, databases, thumbnails, caches and configuration. Accounts add a service identity that may be used on several devices. The app and the app account are separate, and one account can be used on several devices.

Local does not always mean created locally

Simplified device artefact
device_id=DEV-24application=com.example.messagesaccount_id=ACC-77104cache_object=MSG-4418synced_at=2026-07-06T01:18:04Z
Established the application stored this account-linked cached object on the deviceStill open where it originated, who caused the underlying event and whether the user saw it

Synchronisation can place material on a phone after it was created on a tablet or computer. A cloud restore can bring older messages, photographs or settings onto a replacement handset. A received attachment can exist locally without having been created there. Cloud-linked data may exist on the device while the more complete history remains with a provider.

The reverse is also possible. Drafts, unsynchronised files, local application databases and device-system records may exist on the phone but not in a cloud account. Evidence can exist on the phone but not in the cloud, while other evidence can exist in the cloud but not on the phone.

Local artefactcache_object=MSG-4418Shows the app stored a representation on this device.
Provider eventmessage_id=MSG-4418 · sender=ACC-77104May describe the service event, account and delivery history.

Neither record automatically identifies the person. Their shared identifier lets the records be compared instead of guessed together.

Apps leave more than the content on screen

An app may retain local account and content evidence, cached images, database rows, notifications, search indexes and usage records. Some are generated by user activity; others are created automatically by the app or operating system. An app can create records without being opened, so an artefact's presence is not always proof of a deliberate human action.

Deleting visible content may remove it from one interface while copies, notifications, attachments, recipient devices or provider records remain. Deleting an app does not necessarily delete the account, and deleting a message can leave evidence elsewhere.

01:17:49Provider records message event MSG-4418.
01:17:52Operating system creates a notification.
01:18:04Application synchronises a cached object.
LaterUser-facing conversation is deleted from the app.

These are related records, not four independent witnesses. The notification and cache may derive from the same provider message. A provider return, recipient device or real-world event can supply genuinely independent corroboration.

Device state affects what may be available

A powered-on unlocked phone may expose information that becomes inaccessible after restart. A connected phone may continue to receive, synchronise or delete data. Isolation may protect against remote change but also interrupt a process or connection. Locked, encrypted and powered off describe different states, not one condition called “inaccessible”.

That is why the scene record matters. Leaving a device connected can change evidence, but isolation can also have consequences. The handling decision should be supported, proportionate and documented rather than copied from a universal flowchart.

Presence, knowledge and authorship are separate propositions

A handset can be shared, borrowed, lost, stolen or remotely controlled. Accounts can be used on several devices. Background processes can generate records. Finding an artefact therefore supports a carefully framed proposition before it supports a conclusion about a person.

EstablishedThe identified device, application or system stored the specified artefact under the recorded conditions.
Still openHow it arrived, whether it was complete, who knew about it, who caused the underlying activity and what responsibility follows.

Evidence identifying the actual device user may include possession, regular account and subscription use, unlock behaviour, communications, contemporaneous location, provider sessions, witness evidence and consistent conduct. Linking a device, account, number and person is strongest when independent sources agree on distinctive identifiers and relevant times.

What a useful device description sounds like

“The extraction shows message MSG-4418 in the local cache for account ACC-77104 on DEV-24” preserves the source and attribution layer.

“Mila sent the message because it was on her phone” skips over origin, account control, device use and authorship. Those may all become well supported - but through evidence, not grammar.

Operational takeaway
Ask what stored the item, why it was there and which other system observed the same activity. Separate the device, subscription, app, account and user; then use their identifiers and times to build a positive attribution case.
Reference: MDA-003Mobile Devices & Apps