What is actually stored on a mobile device?¶
A mobile device is not one sealed box containing a perfect history of its user. It combines hardware, an operating system, subscriptions, apps, accounts, local databases, cached material and links to provider or cloud data. Understanding which layer produced an item tells an investigator what it can establish and where a stronger record may exist.
One handset, several evidence layers¶
The layers interact, but they are not interchangeable. A handset identifier, subscription record, app account and human user answer different attribution questions.
The physical device has a manufacturer, model, serial number, storage and network-capable hardware. Its operating system manages encryption, permissions, notifications, usage and connections. Why the model and operating-system version matter is practical: access methods and available artefacts vary with hardware, software and security state.
A SIM or eSIM connects a subscription to the mobile network. It is not the handset. Handset, SIM, eSIM and subscription can move or combine in different ways, just as a telephone number may move between devices and providers.
Apps add local files, databases, thumbnails, caches and configuration. Accounts add a service identity that may be used on several devices. The app and the app account are separate, and one account can be used on several devices.
Local does not always mean created locally¶
Synchronisation can place material on a phone after it was created on a tablet or computer. A cloud restore can bring older messages, photographs or settings onto a replacement handset. A received attachment can exist locally without having been created there. Cloud-linked data may exist on the device while the more complete history remains with a provider.
The reverse is also possible. Drafts, unsynchronised files, local application databases and device-system records may exist on the phone but not in a cloud account. Evidence can exist on the phone but not in the cloud, while other evidence can exist in the cloud but not on the phone.
cache_object=MSG-4418Shows the app stored a representation on this device.message_id=MSG-4418 · sender=ACC-77104May describe the service event, account and delivery history.Neither record automatically identifies the person. Their shared identifier lets the records be compared instead of guessed together.
Apps leave more than the content on screen¶
An app may retain local account and content evidence, cached images, database rows, notifications, search indexes and usage records. Some are generated by user activity; others are created automatically by the app or operating system. An app can create records without being opened, so an artefact's presence is not always proof of a deliberate human action.
Deleting visible content may remove it from one interface while copies, notifications, attachments, recipient devices or provider records remain. Deleting an app does not necessarily delete the account, and deleting a message can leave evidence elsewhere.
MSG-4418.These are related records, not four independent witnesses. The notification and cache may derive from the same provider message. A provider return, recipient device or real-world event can supply genuinely independent corroboration.
Device state affects what may be available¶
A powered-on unlocked phone may expose information that becomes inaccessible after restart. A connected phone may continue to receive, synchronise or delete data. Isolation may protect against remote change but also interrupt a process or connection. Locked, encrypted and powered off describe different states, not one condition called “inaccessible”.
That is why the scene record matters. Leaving a device connected can change evidence, but isolation can also have consequences. The handling decision should be supported, proportionate and documented rather than copied from a universal flowchart.
Presence, knowledge and authorship are separate propositions¶
A handset can be shared, borrowed, lost, stolen or remotely controlled. Accounts can be used on several devices. Background processes can generate records. Finding an artefact therefore supports a carefully framed proposition before it supports a conclusion about a person.
Evidence identifying the actual device user may include possession, regular account and subscription use, unlock behaviour, communications, contemporaneous location, provider sessions, witness evidence and consistent conduct. Linking a device, account, number and person is strongest when independent sources agree on distinctive identifiers and relevant times.
What a useful device description sounds like¶
“The extraction shows message MSG-4418 in the local cache for account ACC-77104 on DEV-24” preserves the source and attribution layer.
“Mila sent the message because it was on her phone” skips over origin, account control, device use and authorship. Those may all become well supported - but through evidence, not grammar.