Read the relevant page, build a recovery brief, call an engineer, or send the case securely, without opening a second popup.
Problem, device and brand cards are normal page links. The assessment button builds a saved recovery brief.
Choose the closest description. If you arrived from a problem card, this step is already complete.
Brand, model family, exact model and capacity improve the handoff to the correct engineer.
Tick everything that applies. “Other” fields are available where the usual choices do not fit.
This is an intake guide, not a remote diagnosis or guarantee. The laboratory confirms the method, quote and limitations after assessment.
Read the recovery method, limitations and intake process for this device or issue.
Read the relevant pageBest for uncertainty, dangerous batteries, active incidents, legal deadlines and Emergency 24/7.
Call 1300 806 557Keep the menu open and load Wildfire’s secure submission form in this same full-screen panel.
Save the structured summary for a call, email, internal approval or later submission.
Safety first. If someone may be checking this phone or computer, read this page on a device they cannot reach. Quick exit (or pressing Esc twice) leaves this page straight away, but it does not clear your browsing history.
Domestic violence digital forensics is the careful examination of your own phone, computer and accounts for evidence of tracking, spyware, account intrusion and deleted messages. We tell you what the technology can prove before you pay for anything, including the things no lab can do, because a report that overclaims can damage a case it was meant to help.
Often in part, rarely in full. A lab can show what is on your device, when it got there and sometimes which account did it. It cannot bring back data a factory reset has destroyed, it cannot see inside someone else's Apple or Google account without police legal process, and it cannot tell a court who was holding the phone unless the data itself ties an action to a person.
Some forensic websites promise to recover anything from any phone and list court wins beside their case numbers. In domestic violence matters that kind of promise does real harm: it sets expectations no examination can meet, and a report built on it can be pulled apart by the first question in cross-examination.
If a report states something the technology cannot do, the other party's lawyer only has to show that once. Every other finding in the report then looks less reliable, even the solid ones.
A Queensland court deciding a protection order is not bound by the rules of evidence. Breaches, stalking and coercive control are criminal charges, decided on the strict rules. We handle every device as if it will end up in the strictest court.
Before we call anything tampering we rule out the ordinary causes. A backup restore or a phone transfer can change the dates on hundreds of files at once. A report that has already tested that holds up far better than one that has not.
These are claims you may come across on forensic websites, in forums or from friends. Pick one to see what the technology actually allows, and where the evidence might be instead.
Apple builds the iPhone so that erasing it destroys the keys that unlock its storage. Apple's own deployment guide says erasing "obliterates all the keys in effaceable storage and renders all user data cryptographically inaccessible". No lab, tool or chip-level technique brings that data back.
When someone reports messages "recovered from a factory-reset phone", the messages came from somewhere else. That matters, because a court will want to know exactly where.
Android introduced file-based encryption in Android 7.0, and every phone that launched with Android 10 or later must use it. On these phones a factory reset wipes the encrypted user data, and we treat the phone's own copy as gone.
Some much older phones were never encrypted and can keep traces after a reset. Tell us the exact model and Android version and we will tell you which group your phone is in before any fee is charged.
An AirTag in use is paired to an Apple Account. Holding an NFC phone to the white side of the tag shows its serial number and the last four digits of the owner's phone number. Apple can give the paired account details to police who make a valid legal request, and its law enforcement guidelines say pairing history is available for up to 25 days.
So the honest answer is: we can read, photograph and seal the tag and preserve your phone's alerts, but the name behind it comes from Apple, through police, and time matters.
When an iPhone detects an AirTag travelling with you, Find My shows a map of where the tag was observed with you. Android's unknown tracker alerts show a similar map. Those records, plus your own location history, can show a pattern from your side.
The tag's full history belongs to the owner's account, and Apple says the location is end-to-end encrypted so only the owner can see it. A claim of months of tracking built only from your devices should say exactly which dates your phone actually recorded.
A forensic examination lists every installed app, including ones that hide their icon, and checks which apps hold device administrator rights or accessibility access, two permissions monitoring apps commonly rely on. It also records install dates, which can matter more than the app itself.
Some of the most detected stalkerware is sold as anti-theft software, so the name on the app does not settle anything. What it was able to do, and when it arrived, does.
Commercial monitoring apps are controlled from a web dashboard. Research on spyware used in intimate partner abuse describes commands going through the company's server, which then relays them to the phone. Traces of that activity on the phone itself vary from app to app.
The company's records can only be obtained by police through legal process. Our part is to identify the product precisely, so police know who to ask and what to ask for.
Your Apple Account lists the devices signed in to it, Safety Check shows who you are sharing with, and Apple sends email alerts when your account is used to sign in somewhere new. Those records can be preserved and dated.
What you cannot get from your side is a log of which photos someone viewed or when they looked up your location. Apple does not show the account owner that, and anything Apple holds comes through police.
We work on your own phone, computer and accounts, or devices you are lawfully authorised to hand over. We will not access another person's device or account, and nobody else should either: doing it can be an offence and can make evidence unusable.
The other person's copy of a conversation is real evidence. Police can seize their device, and in family law proceedings a court can order material produced. Your solicitor can advise on that route.
A factory reset is one of the quickest ways domestic violence evidence disappears, sometimes because the other person did it, sometimes because a phone shop or a well-meaning friend did it to "clean" the phone. On a modern phone the reset does not just hide your data. It destroys the encryption keys that made the data readable.
"Erasing (or wiping) obliterates all the keys in effaceable storage and renders all user data cryptographically inaccessible."Apple, Erase Apple devices (deployment guide)
That is why we say it plainly: after a reset, the phone's own copy is gone. The good news is that messages rarely live in only one place. A backup, a synced account, another device or the other person's phone may still hold them, and some of those can be reached quickly if you act before anything else is deleted.
Tick what applies. The list shows where copies may survive and who can lawfully reach each one. Nothing you tick is sent anywhere.
Every place worth checking is listed below.
After a factory reset, the phone's own copy is gone. If the phone has not been reset, do not reset it: messages deleted in the app can sometimes still be found on the device.
Gone after a resetA backup can hold your messages, or the key that unlocks Messages in iCloud. You can reach it by signing in. With your consent and your two-factor code, we can collect it under chain of custody.
You, or us with your consentConversations sync to iCloud and stay there until they are deleted. Apple says deleting a message on one device deletes it from every device where Messages in iCloud is on, so stop anyone deleting anything else.
You, or us with your consentApple does not hold the keys for this data, so it cannot hand it to anyone, police included. Signing in to your own account is the only route, which makes protecting your Apple Account password and trusted devices urgent.
Only youWithout Advanced Data Protection, Apple can respond to a valid legal request. For iCloud content, a request from Australia goes through formal international channels such as the Australia and United States data access agreement, so it is a police route, not a quick one.
Police onlyA backup made before the reset may hold messages, call history and settings, depending on the phone and what was switched on. With your consent and sign-in, we can collect and document what it holds.
You, or us with your consentA Finder, iTunes or Smart Switch backup on a computer is untouched by a phone reset. If the backup was encrypted, we will need its password. Do not open or update the backup software before it is preserved.
You, or us with your consentA Mac, iPad, tablet or laptop that received the same messages may still hold them. If it has stayed offline, a deletion made elsewhere may not have reached it yet, so keep it offline and do not open the messaging app.
You, or us with your consentTheir copy is real evidence, but neither you nor we can take it. Police can seize the device, and a court can order material produced in proceedings.
Police or court onlyYour account can list calls and standard text messages by number, date and time. It never holds message content, and iMessage, WhatsApp and Signal messages do not appear in it at all.
YouKeep the original files on the device that took them. Copies sent through messaging apps can lose details such as the original date.
YouPolice may want to seize or examine the devices themselves. Tell us the officer's details before collection, and we will make sure our handling does not get in the way of theirs.
PoliceAirTags were built to find keys and bags, and Apple designed their location reports so that only the owner's account can see them. Apple's own words: "not even Apple knows the location of your AirTag". That design decides what any examination can show, whoever does it.
From your side, the evidence is what your phone noticed and what you found. From the owner's side, the evidence sits in their Apple Account, and only police can ask Apple for it.
Apple's guidelines for law enforcement say AirTag pairing history is available for up to 25 days. Report a tracker to police promptly so they can ask for it in time.
Most of the confusion in domestic violence evidence comes from mixing up three places: what is on your devices, what is in your own accounts and backups, and what is held by the other person or by companies like Apple and Google. A private lab can work on the first two with your consent. The third needs police or a court.
Knowing which is which saves money and time. It also stops you, or anyone helping you, from doing something that makes the evidence harder to use.
| Source | What it can show | Who can get it | Our part |
|---|---|---|---|
| Your phone | Messages, call logs, photos, installed apps, alerts and settings | You | Extract, hash and examine it against your agreed questions |
| Your backups | Copies made before a deletion or reset, in iCloud, a Google or Samsung account, or on a computer | You, with your sign-in or backup password | Collect with your consent and document exactly where each item came from |
| Your accounts | Signed-in devices, sharing settings and sign-in alert emails | You | Preserve what the account shows, with dates, before anything is changed |
| The other person's devices | Their side of conversations and any tracking apps they used | Police by seizure, or a court order | Nothing without lawful authority |
| Apple and Google | Account records, and iCloud content where Apple holds the keys | Police, through legal process | Explain what exists so police know what to request |
| Stalkerware and tracker companies | Records of commands sent through their servers | Police, through legal process | Identify the product precisely |
| Your phone company | Calls and standard text messages by number, date and time, never content | You for your own account, and police | Match those records against what is on the phone |
Technology facilitated abuse often needs no special software at all. A shared password, location sharing that was never switched off, or an old phone still signed in to your account can be enough. So a proper check looks at three things: the phone, the accounts, and the sharing settings that connect them.
Every installed app, including ones that hide their icon. Which apps hold device administrator rights or accessibility access, permissions monitoring apps commonly rely on. When each one was installed. The Coalition Against Stalkerware has reported that one of the most detected stalkerware apps was advertised as anti-theft software, so the label on an app proves nothing either way.
The phone and the Apple Account behind it. Safety Check, in iOS 16 and later, reviews which people, apps and devices can reach your information. We record exactly what it shows, with the date, before anything is changed, along with configuration profiles and the devices signed in to your account.
Signed-in device lists for Apple and Google, sign-in alert emails, recovery phone numbers and email addresses, and location sharing. A recovery number that belongs to someone else can let them back into an account even after you change the password.
Before you remove anything. Deleting a monitoring app, resetting the phone or using Safety Check's Emergency Reset can destroy the evidence, and the other person may notice their access has stopped. The eSafety Commissioner suggests working through safety steps with a trusted person or a domestic, family and sexual violence support worker. We can image the phone before anything changes, so you can make that decision with your support worker or police without losing the evidence.
No. Codes you may see shared online, such as *#21# and *#62#, ask your phone company about call forwarding. They can show whether your calls are being diverted, which is worth knowing, but they cannot see apps, profiles or account access on the phone. No dial code detects stalkerware.
Battery drain and a warm phone are unreliable signs. The checks that mean something are specific: unknown tracker alerts, location sharing in Find My or Google Maps, unfamiliar devices signed in to your accounts, and apps holding administrator or accessibility access. A forensic examination gives you a documented answer you can hand to police or a solicitor.
Three pieces of Queensland law shape how digital evidence gets used. Knowing them explains why we handle a protection order matter as carefully as a criminal one.
In a proceeding under the Act, a court "is not bound by the rules of evidence" and "may inform itself in any way it considers appropriate". Matters are decided on the balance of probabilities, so screenshots and printouts can be accepted.
Coercive control has been a criminal offence in Queensland since 26 May 2025, with a maximum penalty of 14 years. It covers a course of conduct of domestic violence on more than one occasion. A criminal court applies the strict rules of evidence.
Unlawful stalking, intimidation, harassment or abuse includes "monitoring, tracking or surveilling a person's movements, activities or interpersonal associations without the person's consent, including, for example, using technology".
Coercive control is a pattern, and police and courts look at the whole course of conduct rather than any single message. Digital evidence can document parts of that pattern: repeated messages and calls, tracking, access to your accounts, and restrictions you can see in banking or sharing apps. Keep a dated record of what happened alongside the devices, and give police originals rather than forwarded copies. A solicitor or police officer can tell you what is needed in your situation.
This is general information about Queensland law, not legal advice. Quotations are from the current versions on the Queensland legislation website, checked .
Safety comes before devices. Our first questions are whether you are safe to talk, whether police are involved, and whether anyone else can reach the phone you are calling from.
Use a phone the other person cannot check. We explain what is possible for your devices before any fee is charged.
We write your scope as numbered questions and work only to them, so the report answers what your matter needs.
Devices go into numbered evidence bags and the custody record is signed at handover, by appointment or by collection.
Phones are extracted with network access blocked where that matters. Computers are imaged through a write blocker. Every image is hashed so any later change would show.
Backups, transfers, time zones and automatic updates all change data. We rule them out before we call anything tampering.
Every finding is labelled located or recovered, limits are stated, and the method is set out so another examiner can repeat it.
Live data that was still on the device or account. You may already have had it.
Deleted data restored from the device. We never describe live data as recovered.
Forensic work is charged in fixed-fee stages, never by the hour. You approve each stage in writing before it starts, and you always know the price of the next step before you decide.
A fixed fee per device, quoted before collection. Covers secure handling, the extraction or image, hashing and the custody record.
A fixed fee for each question in your scope, quoted once Stage 1 shows what the extraction contains. You can choose which questions to go ahead with.
Supplementary reports, conferences with your lawyers and court attendance are quoted as fixed fees when they are actually needed.
Ask these of us or anyone else. Clear answers are a good sign. Promises are not.
Lead Engineer and Co-Founder, Wildfire Data Recovery. Wildfire has worked in data recovery since 2016 and examines phones, computers and storage for private clients and their lawyers from its Brisbane lab. About Wildfire and its engineers.
Every technical statement on this page was checked against the manufacturer's documentation or the legislation itself, and quoted statements link to their source where they are made. Where those sources are silent, we say so rather than guess.
Not from the phone itself. Modern iPhones and Android phones destroy their encryption keys during a reset, so the old data cannot be read by anyone. The messages may still exist in an iCloud or Google backup made before the reset, a computer backup, another device that received them, or the other person's phone.
Sometimes. Messages deleted in an app can remain in the phone's databases for a while, and backups may hold older copies. How much survives depends on the phone, the app and how much the phone has been used since. Nobody can tell you in advance, which is why we never promise a result.
Not before it has been examined and you have a safety plan. A reset destroys the evidence of what was installed and when, and the other person may notice their access has stopped. Talk to a support worker or police first, and let us image the phone before anything changes.
Your phone has noticed an AirTag that is away from its owner and has been moving with you. Apple notes it can have an innocent explanation, such as an item you borrowed. If you cannot explain it and you feel unsafe, contact police, who can work with Apple to request information about the tag.
Google says playing a sound from an Android unknown tracker alert does not notify the owner. Removing an AirTag's battery is different: the owner stops seeing its location, which can tell them it was found.
We can show what was installed, what it could do and when it arrived. Whether that points to a particular person depends on other evidence, such as who had the phone and the passcode at that time. We will not name a person the data does not identify.
No. We only examine devices and accounts you own or are lawfully authorised to provide. Their devices can be seized by police, and a court can order material produced. Accessing someone else's account yourself can be an offence and can make the evidence unusable.
No one can promise that. The court decides. What we can promise is a report that says exactly what the data shows, where it came from and what its limits are, so it can be relied on.
No, but if police are involved or likely to be, tell us before collection. They may want to seize or examine the devices themselves, and we will make sure our handling does not interfere with theirs.
We never contact the other person. If our report is used in proceedings, the other side will usually receive a copy, and changes you make to shared accounts can be noticed. Talk to your solicitor or support worker about timing.
Fees are fixed and staged: a fixed fee per device for imaging, then a fixed fee for each question in your scope once we know what the extraction contains. Stage 1 is normally completed within 10 to 15 business days of collection and payment, and urgent matters can be prioritised.
Call from a phone the other person cannot check, or email from an account they cannot open. Tell us first whether you are safe and whether police are involved. We will explain what your devices can and cannot show before you commit to anything.
In danger now, call 000. For support any time, call 1800RESPECT on 1800 737 732.