What records might the mobile-account provider hold?¶
Apple, Google or another ecosystem provider may hold registration, recovery, trusted-device, login, backup, synchronisation and security records beyond the handset.
Ask according to the investigative question¶
Relevant categories can include password changes, account recovery, location services, app downloads, storage and device-link events. Availability depends on service, configuration, encryption, jurisdiction and retention. Some records may be short-lived or device-only.
Interpret technical associations narrowly¶
A trusted-device entry establishes account linkage; a login record establishes a connection. Neither identifies the physical operator. Use precise provider account IDs and time ranges and consider preservation where loss is credible.
Correlate the return with handset, app, network and contextual evidence rather than assuming the provider holds everything.
Key takeaway
Target mobile-account requests to a defined account, event and period and use provider records to build - not shortcut - the attribution chain.