Skip to content
MDA-052 Mobile Devices & Apps

What evidence might the app provider hold?

An app provider may hold evidence that is not present on the handset.

What this means

Possible records include account-registration details, login history, device information, IP addresses, security events, payment records, message metadata, content, reports and account changes.

The exact records depend on the service, provider, account type, user settings, location and retention period.

Some services retain message content.

Others may retain only delivery, connection or account records.

Provider records may also clarify activity seen on the phone.

They may show whether a message was created from that device, another device or a web session.

They may identify login attempts, password changes, trusted-device additions or account recovery.

But provider records also have limits.

A login record may identify a connection, not the person using it.

An IP address may be shared or obscured.

Where records may be volatile, consider preservation early and follow lawful local process.

Make requests specific.

Broad requests can create delay and unnecessary data.

What to check or do next

  • Identify the account, time period, event and record type needed.

Evidential limits

Do not assume that every provider holds the same data.

End-to-end encrypted services may still hold useful information about registration, devices, sessions or timing even where they cannot read message content.

A device label may be supplied by the user and may not be reliable.

The operational takeaway is: app providers may hold account, session, content and security evidence that the handset does not. Ask precise questions, avoid assuming availability and interpret provider records as part of the wider attribution picture.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.