Skip to content
Phone SeizedThey have your phone?
Menu

Phone SeizedWhat is on your phoneWhat a 'full file system' extraction actually contains

What a 'full file system' extraction actually contains

Applies to: England & Wales · Scotland · Northern Ireland · Australia · United States. The law differs materially between jurisdictions this site covers — do not apply this page outside the one named here. Law also varies by state and territory in Australia — this page does not describe every state or territory. Law also varies by state, and by federal circuit, in the United States — this page does not describe every state or circuit.

What you must do, what you can refuse, and what they can do

Every claim below links to the law it comes from, with the wording quoted so you can check it yourself.

Lawful to refuse — but it costs you

Not an offence, but it carries a penalty or an inference.

  • Cellebrite's own marketing describes its Inseyets product, powered by UFED, as able to access devices previously unreachable and extract the Full File System, including encrypted and containerized data.

    Cellebrite, "Cellebrite Inseyets, powered by UFED" product page (cellebrite.com), as fetched 2026-09-08
    Access devices previously unreachable and extract the Full File System, including encrypted and containerized data.

    Read it at cellebrite.comquote checked 2026-09-08

  • Magnet Forensics markets its Graykey product as offering same-day access to the latest iOS and Android devices.

    Magnet Forensics, Magnet Graykey product page (magnetforensics.com), as fetched 2026-09-08
    Get started with Graykey's same-day access to the latest iOS and Android devices

    Read it at magnetforensics.comquote checked 2026-09-08

  • A 2018 Privacy International report on UK police extraction found that MSAB markets its XRY Physical tool as able to access system and deleted data and to use extra functionality to help overcome security and encryption challenges.

    Privacy International, "Digital stop and search: how the UK police can secretly download everything from your mobile phone", 27 Mar 2018
    MSAB's XRY Physical allows access to "system and deleted data and can use extra functionality to help overcome security and encryption challenges

    Read it at privacyinternational.orgquote checked 2026-09-08

  • A 2020 Upturn report, based on 110 public records requests, documented more than 2,000 US state and local law enforcement agencies, across all 50 states and Washington DC, that had purchased mobile extraction tools.

    Upturn, "Mass Extraction", October 2020
    Based on 110 public records requests to state and local law enforcement agencies across the country, our research documents more than 2,000 agencies that have purchased these tools, in all 50 states and the District of Columbia.

    Read it at upturn.orgquote checked 2026-09-08

  • The UK Information Commissioner's Office reported in June 2020 that police data extraction practices varied across England and Wales, with excessive amounts of personal data often extracted, stored and made available to others without an appropriate basis in data protection law.

    ICO, Mobile phone data extraction by police forces in England and Wales (June 2020)
    police data extraction practices vary across the country, with excessive amounts of personal data often being extracted, stored, and made available to others, without an appropriate basis in existing data protection law.

    Read it at ico.org.ukquote checked 2026-09-08

  • Apple states that shortly after a device locks, the key for its most-protected data class is discarded, rendering that class of data inaccessible until the passcode is entered again or the device is unlocked.

    Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
    Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .

    Read it at support.apple.comquote checked 2026-09-08

  • Apple documents a default Data Protection class that applies to all third-party app data not otherwise assigned to a class of its own.

    Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
    This is the default class for all third-party app data not otherwise assigned to a Data Protection class.

    Read it at support.apple.comquote checked 2026-09-08

  • Android's file-based encryption documentation states that Credential Encrypted storage, the default storage location for app data, is only available after the user has unlocked the device.

    Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
    Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.

    Read it at source.android.comquote checked 2026-09-08

  • Android's file-based encryption documentation states that Device Encrypted storage is available both during Direct Boot mode, before the device is first unlocked, and after.

    Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
    Device Encrypted (DE) storage, which is a storage location available both during Direct Boot mode and after the user has unlocked the device.

    Read it at source.android.comquote checked 2026-09-08

Four states, one vocabulary

What a phone gives up, to anyone holding it, depends less on which tool is used than on which of four states the phone is in at the time. This site uses the same four terms on every page in this section and in Protect:

  • Off / before first unlock (BFU) — the phone is switched off, or has been switched on but not yet unlocked once since it booted.
  • After first unlock (AFU) — the phone has been unlocked at least once since it booted, and is now locked again.
  • Unlocked — the phone is currently unlocked, in someone’s hand or on a desk.
  • Cloud / carrier — data that is not on the phone at all, held instead by the phone maker, an app maker, or the mobile network operator. See Cloud and carrier.

The rest of this page, and the next two in this section, describe what changes between those states in the words of the vendors and researchers who document it — never as a blanket “police can” or “police cannot” statement.

What extraction vendors say their own tools do

Cellebrite and Magnet Forensics are the two forensic vendors most UK, Australian and US police forces buy from. Both describe their flagship products, in their own marketing, as reaching further than a normal file browse:

  • Cellebrite markets its Inseyets product, powered by UFED, as able to “access devices previously unreachable and extract the Full File System, including encrypted and containerized data.”
  • Magnet Forensics markets its Graykey product as offering “same-day access to the latest iOS and Android devices.”

Neither statement says which specific models or OS versions that reaches at any given time — that changes constantly as vendors and phone makers move against each other. See Passcode and updates for what was separately reported about the gap between a vendor’s marketing and its actual, model-by-model support.

What independent reports found tools obtain, and how widely deployed they are

Two reports, six years apart, describe the same class of tool from outside the vendors:

  • Privacy International’s 2018 report on UK police extraction found that MSAB markets its XRY Physical tool as able to access “system and deleted data” and to “use extra functionality to help overcome security and encryption challenges.”
  • Upturn’s 2020 “Mass Extraction” report, based on 110 public records requests, documented more than 2,000 US state and local law enforcement agencies, in all 50 states and Washington DC, that had purchased mobile extraction tools.

In England and Wales specifically, the Information Commissioner’s Office reported in June 2020 that police data extraction practices varied across the country, “with excessive amounts of personal data often being extracted, stored, and made available to others, without an appropriate basis in existing data protection law.”

How device state changes what a tool can reach

Apple and Google both document that a locked phone does not treat all of its data the same way. Apple states that shortly after a device locks — about 10 seconds, if the passcode setting is Immediately — the key for its most-protected data class is discarded, “rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device.” Apple separately documents a different, default class that applies to third-party app data not otherwise assigned to a class of its own — a class whose key is not the one discarded at lock.

Android’s file-based encryption documentation draws a comparable line: Credential Encrypted storage, “the default storage location,” is “only available after the user has unlocked the device,” while Device Encrypted storage is available both during Direct Boot mode — before that first unlock — and after.

That is why the BFU/AFU/unlocked distinction above is not academic: it is the line the phone makers themselves draw around what a key holds shut. See Deleted is not gone for what happens to data the user has already deleted, and the cross-country comparison for how the legal power to demand a passcode differs from the technical question this page answers.

Last reviewed 2026-09-08. Next review due 2026-12-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.