What can an app learn about the device?¶
An app may be able to learn a great deal about the device, depending on its permissions, design and the operating system.
What this means¶
It may collect the device model, operating-system version, language, time zone, network type, screen size, app version and advertising identifier.
It may also obtain location, contacts, photographs, Bluetooth information, sensor data or notification access where permission is granted.
Some services create their own device or installation identifier.
That can help the provider recognise the same app installation or device across several sessions.
The app may also see IP addresses and connection times when communicating with the provider.
This information can support an investigation.
It may link an account to a particular handset, distinguish several devices using the same account or show changes in location and network use.
But device information has limits.
Identifiers may reset, be randomised or change after reinstallation, account changes or privacy settings.
An IP address identifies a connection, not automatically a person.
The operational takeaway is: apps can collect technical and contextual information about the device, but each identifier has its own reliability and lifespan. Use device data to correlate evidence, not as automatic proof of the user.
What to check or do next¶
- Investigators should ask which identifiers are generated, how stable they are and what event caused them to be recorded.
- Compare provider records with the seized device, operating-system information and other accounts.
Evidential limits¶
A device name may be chosen by the user and may not be accurate.
And a provider may not retain every device attribute it collects.