Skip to content
MDA-070 Mobile Devices & Apps

What records might the mobile-account provider hold?

A mobile-account provider may hold records that sit above the physical handset.

What this means

For an Apple or Google account, possible records may include account registration details, recovery information, trusted devices, security alerts, login history, backup activity, synchronisation settings and service use.

The provider may also hold information about device changes, password resets, account recovery, location services, app downloads or cloud storage.

The exact records vary by provider, service, user settings, jurisdiction and retention period.

Some data may be encrypted, synchronised separately or stored only on the device.

Some records may exist only for a limited time.

The provider record may also identify an account or connection rather than the human user.

A trusted-device entry may show that a handset was linked.

A login record may show that the account was accessed from a connection.

Neither automatically proves who was physically using the device.

Are you trying to establish account ownership, device linkage, backup activity, security changes, login history or remote-control events?

Where data may be volatile, consider preservation through lawful local process.

The operational takeaway is: the mobile-account provider may hold valuable account, security, backup and device-link evidence. Ask targeted questions and interpret the records as one part of the wider attribution case.

What to check or do next

  • Investigators should define the question before making a request.
  • Use precise account identifiers and relevant time periods.

Evidential limits

Do not assume that the provider holds everything.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.