Phone SeizedToolsWhat's on your phone
What's on your phone
“A full extraction” is not one fixed thing — different tools, and different device states, reach different amounts of data. This walks through the categories that vendor marketing, independent reports, and phone makers’ own documentation describe a report as containing, each one linked to the quote it comes from.
Each line below is a category of data that a vendor’s own marketing, an independent report, or a phone maker’s own documentation describes a full extraction — or a particular data-protection class — as containing. Open a line to read the quote it comes from. Where a phone maker’s own documentation states which device state a category’s decryption key is available in, that is shown as a chip; most categories below carry no chip, because no cited source states one for them.
The full file system — not only what is currently visible in an app
Cellebrite, "Cellebrite Inseyets, powered by UFED" product page (cellebrite.com), as fetched 2026-09-08
“Access devices previously unreachable and extract the Full File System, including encrypted and containerized data.”
Read it at cellebrite.comquote checked 2026-09-08
Encrypted and containerized app data
Cellebrite markets its Inseyets/UFED product as reaching this, not only ordinary files.
Cellebrite, "Cellebrite Inseyets, powered by UFED" product page (cellebrite.com), as fetched 2026-09-08
“Access devices previously unreachable and extract the Full File System, including encrypted and containerized data.”
Read it at cellebrite.comquote checked 2026-09-08
System data and deleted data
A 2018 Privacy International report found MSAB markets its XRY Physical tool this way, and describes it as able to use extra functionality to try to overcome security and encryption.
Privacy International, "Digital stop and search: how the UK police can secretly download everything from your mobile phone", 27 Mar 2018
“MSAB's XRY Physical allows access to "system and deleted data and can use extra functionality to help overcome security and encryption challenges”
Read it at privacyinternational.orgquote checked 2026-09-08
Third-party app data
Apple documents this as the default Data Protection class for app data not otherwise assigned a class of its own.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“This is the default class for all third-party app data not otherwise assigned to a Data Protection class.”
Read it at support.apple.comquote checked 2026-09-08
Your most-protected data (Apple's 'Complete Protection' class)
UnlockedApple states the key for this class is discarded shortly after the device locks.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .”
Read it at support.apple.comquote checked 2026-09-08
App data kept in Android Credential Encrypted storage
Keys in memory (after first unlock)Android's file-based encryption documentation names this the default storage location for app data.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
System data kept in Android Device Encrypted storage
Android's file-based encryption documentation states this storage is available both before and after the device is first unlocked.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Device Encrypted (DE) storage, which is a storage location available both during Direct Boot mode and after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
iCloud Backup
Cloud & carrier copies may existOne of the iCloud categories Apple names as using end-to-end encryption once Advanced Data Protection is switched on.
Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
“With Advanced Data Protection, the number of data categories that use end-to-end encryption rises to 25 and includes your iCloud Backup, Photos, Notes and more.”
Read it at support.apple.comquote checked 2026-09-08
Photos backed up to iCloud
Cloud & carrier copies may existNamed alongside iCloud Backup and Notes in the same Apple sentence on Advanced Data Protection categories.
Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
“With Advanced Data Protection, the number of data categories that use end-to-end encryption rises to 25 and includes your iCloud Backup, Photos, Notes and more.”
Read it at support.apple.comquote checked 2026-09-08
Notes backed up to iCloud
Cloud & carrier copies may existNamed alongside iCloud Backup and Photos in the same Apple sentence on Advanced Data Protection categories.
Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
“With Advanced Data Protection, the number of data categories that use end-to-end encryption rises to 25 and includes your iCloud Backup, Photos, Notes and more.”
Read it at support.apple.comquote checked 2026-09-08
Personal data, broadly
The UK Information Commissioner reported in June 2020 that police extraction practices varied, with excessive amounts of personal data often extracted, stored and shared without an appropriate legal basis.
ICO, Mobile phone data extraction by police forces in England and Wales (June 2020)
“police data extraction practices vary across the country, with excessive amounts of personal data often being extracted, stored, and made available to others, without an appropriate basis in existing data protection law.”
Read it at ico.org.ukquote checked 2026-09-08
Read more, sourced the same way:
Last reviewed 2026-09-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.