What is a factory reset and what does it remove?¶
A factory reset returns a mobile device to a fresh setup state.
What this means¶
It normally removes user accounts, applications, settings and access to locally stored user data.
The device may appear as though it has just been purchased.
A factory reset usually affects the handset itself.
Cloud backups, app-provider records, network records, linked devices, account activity and synchronised content may remain elsewhere.
The reset may also leave evidence that it occurred.
Investigators may find setup screens, reset timestamps, account-security alerts, device-management records or provider activity around the relevant period.
On modern encrypted devices, a reset often destroys or removes access to encryption keys, making previous user data difficult or impossible to recover through ordinary means.
But the effect depends on the model, operating-system version, storage design and how the reset was performed.
Devices are reset for sale, repair, troubleshooting, transfer or ordinary privacy reasons.
Equally, do not dismiss it where the timing is suspicious.
What to check or do next¶
- Compare the reset with the investigative timeline, account activity, replacement-device use, cloud backups and communications.
- If a device is found at a setup screen, record it exactly as found.
- Do not continue through the setup process or connect it to an account without specialist guidance.
Evidential limits¶
That does not mean every possible record connected with the device has disappeared.
Do not assume a reset proves deliberate evidence destruction.
The operational takeaway is: a factory reset usually removes local user access and settings, but it does not erase the wider evidence environment. Preserve the device state and pursue cloud, provider, linked-device and reset-timing evidence.