Skip to main content
24/7 emergency lineFree diagnosis on eligible standard recoveriesFREE Postage Label, Australia-wide
WildfireData Recovery
No Data, No Fee policyNo success fee unless we recover your data
Quick exit

Safety first. If someone may be checking this phone or computer, read this page on a device they cannot reach. Quick exit (or pressing Esc twice) leaves this page straight away, but it does not clear your browsing history.

Hands holding a smartphone in a dark room, the personal phone at the centre of most domestic violence digital forensics
Brisbane forensic lab, Australia-wide

Domestic Violence Digital Forensics What the evidence can show, and what it cannot

Domestic violence digital forensics is the careful examination of your own phone, computer and accounts for evidence of tracking, spyware, account intrusion and deleted messages. We tell you what the technology can prove before you pay for anything, including the things no lab can do, because a report that overclaims can damage a case it was meant to help.

  • Limits stated in writing
  • Located and recovered labelled separately
  • Fixed staged fees
  • Chain of custody from collection

Can a forensic lab prove what was done to your phone?

Often in part, rarely in full. A lab can show what is on your device, when it got there and sometimes which account did it. It cannot bring back data a factory reset has destroyed, it cannot see inside someone else's Apple or Google account without police legal process, and it cannot tell a court who was holding the phone unless the data itself ties an action to a person.

Written by Viktor Burcevski, Lead Engineer and Co-Founder Last reviewed Checked against 15 published sources
Why this page starts with limits

Overclaimed evidence helps the other side

Some forensic websites promise to recover anything from any phone and list court wins beside their case numbers. In domestic violence matters that kind of promise does real harm: it sets expectations no examination can meet, and a report built on it can be pulled apart by the first question in cross-examination.

One overclaim sinks the rest

If a report states something the technology cannot do, the other party's lawyer only has to show that once. Every other finding in the report then looks less reliable, even the solid ones.

Different courts, different rules

A Queensland court deciding a protection order is not bound by the rules of evidence. Breaches, stalking and coercive control are criminal charges, decided on the strict rules. We handle every device as if it will end up in the strictest court.

We test innocent explanations

Before we call anything tampering we rule out the ordinary causes. A backup restore or a phone transfer can change the dates on hundreds of files at once. A report that has already tested that holds up far better than one that has not.

Claim checker

Can a lab really do that?

These are claims you may come across on forensic websites, in forums or from friends. Pick one to see what the technology actually allows, and where the evidence might be instead.

Not from the phone

A reset iPhone keeps nothing a lab can read

Apple builds the iPhone so that erasing it destroys the keys that unlock its storage. Apple's own deployment guide says erasing "obliterates all the keys in effaceable storage and renders all user data cryptographically inaccessible". No lab, tool or chip-level technique brings that data back.

When someone reports messages "recovered from a factory-reset phone", the messages came from somewhere else. That matters, because a court will want to know exactly where.

Where they might be instead: an iCloud Backup made before the reset, Messages in iCloud, a backup on a computer, a Mac or iPad signed in to the same Apple Account, or the other person's phone. Check which apply to you.
Not from a modern phone

Encrypted Android phones lose their data on reset

Android introduced file-based encryption in Android 7.0, and every phone that launched with Android 10 or later must use it. On these phones a factory reset wipes the encrypted user data, and we treat the phone's own copy as gone.

Some much older phones were never encrypted and can keep traces after a reset. Tell us the exact model and Android version and we will tell you which group your phone is in before any fee is charged.

Where the data might be instead: a Google or Samsung account backup made before the reset, a Smart Switch backup on a computer, a tablet or laptop that received the same messages, or the other person's phone.
Only through police

The owner's identity sits with Apple

An AirTag in use is paired to an Apple Account. Holding an NFC phone to the white side of the tag shows its serial number and the last four digits of the owner's phone number. Apple can give the paired account details to police who make a valid legal request, and its law enforcement guidelines say pairing history is available for up to 25 days.

So the honest answer is: we can read, photograph and seal the tag and preserve your phone's alerts, but the name behind it comes from Apple, through police, and time matters.

What to do: report it to police promptly and keep the tag. See the steps.
Partly

Your phone shows where the tag was with you, not its whole history

When an iPhone detects an AirTag travelling with you, Find My shows a map of where the tag was observed with you. Android's unknown tracker alerts show a similar map. Those records, plus your own location history, can show a pattern from your side.

The tag's full history belongs to the owner's account, and Apple says the location is end-to-end encrypted so only the owner can see it. A claim of months of tracking built only from your devices should say exactly which dates your phone actually recorded.

What we can add: your alert records and maps preserved under custody, lined up against your own location history and the dates you found or reported the tag.
Often, yes

Monitoring apps leave traces on the phone

A forensic examination lists every installed app, including ones that hide their icon, and checks which apps hold device administrator rights or accessibility access, two permissions monitoring apps commonly rely on. It also records install dates, which can matter more than the app itself.

Some of the most detected stalkerware is sold as anti-theft software, so the name on the app does not settle anything. What it was able to do, and when it arrived, does.

Important: do not remove it before it is examined and you have a safety plan. Read why.
Partly

The record of what they looked at is mostly not on your phone

Commercial monitoring apps are controlled from a web dashboard. Research on spyware used in intimate partner abuse describes commands going through the company's server, which then relays them to the phone. Traces of that activity on the phone itself vary from app to app.

The company's records can only be obtained by police through legal process. Our part is to identify the product precisely, so police know who to ask and what to ask for.

Partly

Access shows up, viewing usually does not

Your Apple Account lists the devices signed in to it, Safety Check shows who you are sharing with, and Apple sends email alerts when your account is used to sign in somewhere new. Those records can be preserved and dated.

What you cannot get from your side is a log of which photos someone viewed or when they looked up your location. Apple does not show the account owner that, and anything Apple holds comes through police.

Police or court only

We only examine devices you are entitled to give us

We work on your own phone, computer and accounts, or devices you are lawfully authorised to hand over. We will not access another person's device or account, and nobody else should either: doing it can be an offence and can make evidence unusable.

The other person's copy of a conversation is real evidence. Police can seize their device, and in family law proceedings a court can order material produced. Your solicitor can advise on that route.

Factory resets

What a factory reset actually destroys

A factory reset is one of the quickest ways domestic violence evidence disappears, sometimes because the other person did it, sometimes because a phone shop or a well-meaning friend did it to "clean" the phone. On a modern phone the reset does not just hide your data. It destroys the encryption keys that made the data readable.

"Erasing (or wiping) obliterates all the keys in effaceable storage and renders all user data cryptographically inaccessible."Apple, Erase Apple devices (deployment guide)

That is why we say it plainly: after a reset, the phone's own copy is gone. The good news is that messages rarely live in only one place. A backup, a synced account, another device or the other person's phone may still hold them, and some of those can be reached quickly if you act before anything else is deleted.

iPhone with a blank black screen on a charging cable beside a laptop, the state a factory reset leaves a phone in for domestic violence digital forensics
After a reset the phone powers on as new. What it held before has to be found somewhere else.

iPhone and iPad

  • Erase All Content and Settings destroys the storage keys, so the data is cryptographically inaccessible.
  • Restoring in Recovery Mode reinstalls iOS, and Apple says it "erases all your data".
  • No extraction tool, chip-off technique or lab process reverses either one.

Android phones and tablets

  • File-based encryption arrived in Android 7.0 and is required on every phone that launched with Android 10 or later.
  • Android 13 removed support for the older full-disk encryption entirely.
  • On these phones we treat a reset as final for the phone's own data. A few much older, unencrypted models are the exception.

Where could your messages still exist?

Tick what applies. The list shows where copies may survive and who can lawfully reach each one. Nothing you tick is sent anywhere.

The phone was
Before the reset or deletion

Every place worth checking is listed below.

  1. The phone itself

    After a factory reset, the phone's own copy is gone. If the phone has not been reset, do not reset it: messages deleted in the app can sometimes still be found on the device.

    Gone after a reset
  2. An iCloud Backup made before the reset

    A backup can hold your messages, or the key that unlocks Messages in iCloud. You can reach it by signing in. With your consent and your two-factor code, we can collect it under chain of custody.

    You, or us with your consent
  3. Messages in iCloud

    Conversations sync to iCloud and stay there until they are deleted. Apple says deleting a message on one device deletes it from every device where Messages in iCloud is on, so stop anyone deleting anything else.

    You, or us with your consent
  4. Advanced Data Protection is on

    Apple does not hold the keys for this data, so it cannot hand it to anyone, police included. Signing in to your own account is the only route, which makes protecting your Apple Account password and trusted devices urgent.

    Only you
  5. Apple, through police

    Without Advanced Data Protection, Apple can respond to a valid legal request. For iCloud content, a request from Australia goes through formal international channels such as the Australia and United States data access agreement, so it is a police route, not a quick one.

    Police only
  6. A Google or Samsung account backup

    A backup made before the reset may hold messages, call history and settings, depending on the phone and what was switched on. With your consent and sign-in, we can collect and document what it holds.

    You, or us with your consent
  7. A backup on a computer

    A Finder, iTunes or Smart Switch backup on a computer is untouched by a phone reset. If the backup was encrypted, we will need its password. Do not open or update the backup software before it is preserved.

    You, or us with your consent
  8. Another device

    A Mac, iPad, tablet or laptop that received the same messages may still hold them. If it has stayed offline, a deletion made elsewhere may not have reached it yet, so keep it offline and do not open the messaging app.

    You, or us with your consent
  9. The other person's phone

    Their copy is real evidence, but neither you nor we can take it. Police can seize the device, and a court can order material produced in proceedings.

    Police or court only
  10. Your phone company

    Your account can list calls and standard text messages by number, date and time. It never holds message content, and iMessage, WhatsApp and Signal messages do not appear in it at all.

    You
  11. Screenshots and photos you already took

    Keep the original files on the device that took them. Copies sent through messaging apps can lose details such as the original date.

    You
  12. Talk to the investigating officer first

    Police may want to seize or examine the devices themselves. Tell us the officer's details before collection, and we will make sure our handling does not get in the way of theirs.

    Police
AirTags and other trackers

What an AirTag examination can and cannot prove

AirTags were built to find keys and bags, and Apple designed their location reports so that only the owner's account can see them. Apple's own words: "not even Apple knows the location of your AirTag". That design decides what any examination can show, whoever does it.

From your side, the evidence is what your phone noticed and what you found. From the owner's side, the evidence sits in their Apple Account, and only police can ask Apple for it.

Apple AirTag held between finger and thumb, the kind of tracker examined in domestic violence digital forensics
An AirTag's serial number can be read by holding an NFC phone to its white side.

What we can show

  • Your iPhone's "AirTag Found Moving With You" alert and the map Find My displays of where the tag was observed with you.
  • Android's unknown tracker alerts, available on Android 6 and later, which also map where a tracker moved with you.
  • The tag's serial number and the last four digits of the owner's phone number, read from the tag itself.
  • Your own location history lined up against the alert times. Google Maps Timeline is now stored on your phone, not on the web.
  • Photographs and the physical condition of the tag as found, sealed under chain of custody.

What no lab can show from your devices

  • Who owns the tag. Apple holds the paired account and releases it to police with a valid legal request.
  • The owner's full location history. It sits in their Find My account, end-to-end encrypted.
  • How long the tag travelled with you before your phone first noticed it.
  • Tracking by a tag that was not paired to anyone. An AirTag reports its location only to the Apple Account it is paired with.
25 days

Apple's guidelines for law enforcement say AirTag pairing history is available for up to 25 days. Report a tracker to police promptly so they can ask for it in time.

How to find an AirTag in my car, and what to do when you find one

  1. Start with the alertOn an iPhone, the alert lets you play a sound on the tag to locate it. On Android, open Settings, then Safety & emergency, then Unknown tracker alerts, and tap Scan now. Then look where a small disc can sit unnoticed in a car: under seats, in the boot and spare wheel well, the glovebox and door pockets.
  2. Do not throw it awayPhotograph it exactly where it sits before you touch it. Where it was hidden is part of the evidence.
  3. Read the serial numberHold the top of an iPhone or another NFC phone to the white side of the tag and screenshot the page that opens.
  4. Plan before you disable itRemoving the battery stops the owner seeing its location, which can also tell them it was found. Talk to police or a support worker first.
  5. Report it promptlyGive police the tag and your screenshots. We can preserve your phone's alert records and seal the tag under chain of custody.
Where the evidence really sits

Your devices, your backups, their accounts

Most of the confusion in domestic violence evidence comes from mixing up three places: what is on your devices, what is in your own accounts and backups, and what is held by the other person or by companies like Apple and Google. A private lab can work on the first two with your consent. The third needs police or a court.

Knowing which is which saves money and time. It also stops you, or anyone helping you, from doing something that makes the evidence harder to use.

iPhone resting on a MacBook with a white cable plugged in, a reminder that a computer backup can survive a factory reset
A backup on a computer is untouched by a phone reset, which is why we ask about computers on the first call.
Who can lawfully reach each source of evidence
SourceWhat it can showWho can get itOur part
Your phoneMessages, call logs, photos, installed apps, alerts and settingsYouExtract, hash and examine it against your agreed questions
Your backupsCopies made before a deletion or reset, in iCloud, a Google or Samsung account, or on a computerYou, with your sign-in or backup passwordCollect with your consent and document exactly where each item came from
Your accountsSigned-in devices, sharing settings and sign-in alert emailsYouPreserve what the account shows, with dates, before anything is changed
The other person's devicesTheir side of conversations and any tracking apps they usedPolice by seizure, or a court orderNothing without lawful authority
Apple and GoogleAccount records, and iCloud content where Apple holds the keysPolice, through legal processExplain what exists so police know what to request
Stalkerware and tracker companiesRecords of commands sent through their serversPolice, through legal processIdentify the product precisely
Your phone companyCalls and standard text messages by number, date and time, never contentYou for your own account, and policeMatch those records against what is on the phone
Stalkerware and account intrusion

What a forensic check for stalkerware actually finds

Technology facilitated abuse often needs no special software at all. A shared password, location sharing that was never switched off, or an old phone still signed in to your account can be enough. So a proper check looks at three things: the phone, the accounts, and the sharing settings that connect them.

On an Android phone

Every installed app, including ones that hide their icon. Which apps hold device administrator rights or accessibility access, permissions monitoring apps commonly rely on. When each one was installed. The Coalition Against Stalkerware has reported that one of the most detected stalkerware apps was advertised as anti-theft software, so the label on an app proves nothing either way.

On an iPhone

The phone and the Apple Account behind it. Safety Check, in iOS 16 and later, reviews which people, apps and devices can reach your information. We record exactly what it shows, with the date, before anything is changed, along with configuration profiles and the devices signed in to your account.

In your accounts

Signed-in device lists for Apple and Google, sign-in alert emails, recovery phone numbers and email addresses, and location sharing. A recovery number that belongs to someone else can let them back into an account even after you change the password.

Before you remove anything. Deleting a monitoring app, resetting the phone or using Safety Check's Emergency Reset can destroy the evidence, and the other person may notice their access has stopped. The eSafety Commissioner suggests working through safety steps with a trusted person or a domestic, family and sexual violence support worker. We can image the phone before anything changes, so you can make that decision with your support worker or police without losing the evidence.

Do iPhone codes to check for spyware work?

No. Codes you may see shared online, such as *#21# and *#62#, ask your phone company about call forwarding. They can show whether your calls are being diverted, which is worth knowing, but they cannot see apps, profiles or account access on the phone. No dial code detects stalkerware.

How to know if someone is tracking your phone

Battery drain and a warm phone are unreliable signs. The checks that mean something are specific: unknown tracker alerts, location sharing in Find My or Google Maps, unfamiliar devices signed in to your accounts, and apps holding administrator or accessibility access. A forensic examination gives you a documented answer you can hand to police or a solicitor.

Queensland law

Where Queensland law draws the lines

Three pieces of Queensland law shape how digital evidence gets used. Knowing them explains why we handle a protection order matter as carefully as a criminal one.

Domestic and Family Violence Protection Act 2012, s 145

Protection orders

In a proceeding under the Act, a court "is not bound by the rules of evidence" and "may inform itself in any way it considers appropriate". Matters are decided on the balance of probabilities, so screenshots and printouts can be accepted.

Criminal Code (Qld), s 334C

Coercive control

Coercive control has been a criminal offence in Queensland since 26 May 2025, with a maximum penalty of 14 years. It covers a course of conduct of domestic violence on more than one occasion. A criminal court applies the strict rules of evidence.

Criminal Code (Qld), s 359B

Stalking and tracking

Unlawful stalking, intimidation, harassment or abuse includes "monitoring, tracking or surveilling a person's movements, activities or interpersonal associations without the person's consent, including, for example, using technology".

How to prove coercive control: where digital evidence fits

Coercive control is a pattern, and police and courts look at the whole course of conduct rather than any single message. Digital evidence can document parts of that pattern: repeated messages and calls, tracking, access to your accounts, and restrictions you can see in banking or sharing apps. Keep a dated record of what happened alongside the devices, and give police originals rather than forwarded copies. A solicitor or police officer can tell you what is needed in your situation.

This is general information about Queensland law, not legal advice. Quotations are from the current versions on the Queensland legislation website, checked .

How we work

How we handle a domestic violence matter

Safety comes before devices. Our first questions are whether you are safe to talk, whether police are involved, and whether anyone else can reach the phone you are calling from.

  1. A confidential first call

    Use a phone the other person cannot check. We explain what is possible for your devices before any fee is charged.

  2. Agree the questions

    We write your scope as numbered questions and work only to them, so the report answers what your matter needs.

  3. Collection under seal

    Devices go into numbered evidence bags and the custody record is signed at handover, by appointment or by collection.

  4. Image and hash

    Phones are extracted with network access blocked where that matters. Computers are imaged through a write blocker. Every image is hashed so any later change would show.

  5. Examine, then test the innocent explanations

    Backups, transfers, time zones and automatic updates all change data. We rule them out before we call anything tampering.

  6. Report in plain language

    Every finding is labelled located or recovered, limits are stated, and the method is set out so another examiner can repeat it.

Two words that matter in every report

Located

Live data that was still on the device or account. You may already have had it.

Recovered

Deleted data restored from the device. We never describe live data as recovered.

Our duty is to the court, not to the person paying. We report what the data shows, including findings that do not support the matters alleged. We cannot promise a report will be admitted: that is the court's decision.
Fees

How our fees work

Forensic work is charged in fixed-fee stages, never by the hour. You approve each stage in writing before it starts, and you always know the price of the next step before you decide.

Stage 1

Forensic access and imaging

A fixed fee per device, quoted before collection. Covers secure handling, the extraction or image, hashing and the custody record.

Stage 2

Examination and report

A fixed fee for each question in your scope, quoted once Stage 1 shows what the extraction contains. You can choose which questions to go ahead with.

Only if needed

Further work

Supplementary reports, conferences with your lawyers and court attendance are quoted as fixed fees when they are actually needed.

  • Each stage is paid before it begins.
  • The fee pays for the forensic work performed, so it is payable whatever the examination finds. Nobody can know what survived on a device until it has been imaged and examined.
  • No outcome is guaranteed, and completed stages are not refundable.
  • If the total is beyond your budget, we can reduce the scope or discuss a payment plan.
Before you pay anyone

Six questions to ask any forensic examiner

Ask these of us or anyone else. Clear answers are a good sign. Promises are not.

  • What did the factory reset destroy?An honest examiner will say the phone's own copy is gone and talk about backups instead.
  • Will findings be labelled located or recovered?Live data presented as recovered is the fastest way to lose credibility in court.
  • Do you promise court outcomes?No lab can promise an order or a conviction. Courts decide those.
  • How will you get the other person's data?The right answer is police or a court. Any other answer is a red flag.
  • Is the fee fixed, and is it payable whatever you find?Forensic work is paid for the work done. You should know the terms in writing before you start.
  • Who signs the report, and who do they owe a duty to?The examiner's duty is to the court. A report written to please the client will not survive scrutiny.
Who wrote this page

Written from the lab, checked against the source

Every technical statement on this page was checked against the manufacturer's documentation or the legislation itself, and quoted statements link to their source where they are made. Where those sources are silent, we say so rather than guess.

Last reviewed
, by Viktor Burcevski
Forensic tools we use
Cellebrite UFED, Oxygen Forensic Detective, Magnet AXIOM and MOBILedit Forensic Ultra
Business
Wildfire Data Recovery, ABN 79 664 657 376
Corrections
If anything here is wrong or out of date, email admin@wildfiredata.com.au and we will check it against the source and correct it.
Plain-language glossary

Ten terms you will see in a forensic report

Factory reset
Erasing a phone back to its out-of-the-box state. On modern phones it destroys the encryption keys, so the old data cannot be read.
File-based encryption
Android's way of encrypting each file with its own key. Required on phones that launched with Android 10 or later.
Effaceable Storage
A small area in Apple devices that holds the keys protecting your data. Erasing the device wipes it.
Extraction
Copying data out of a phone with forensic tools. Different methods reach different amounts of data.
Hash value
A digital fingerprint of an image or file. If a single bit changes, the hash changes, which proves the copy is untouched.
Chain of custody
The signed record of who held a device or copy, when, and why, from collection to court.
Located
Live data found on a device or account. It was still there, not restored.
Recovered
Deleted data restored from a device. Reported separately from located data.
Stalkerware
Software used to monitor a person's phone without their knowledge, often sold as parental control or anti-theft software.
Unwanted tracking alert
A warning from iPhone or Android that a tracker separated from its owner is moving with you.
Questions

Questions people ask us

Phones and resets

Can deleted messages be recovered after a factory reset?

Not from the phone itself. Modern iPhones and Android phones destroy their encryption keys during a reset, so the old data cannot be read by anyone. The messages may still exist in an iCloud or Google backup made before the reset, a computer backup, another device that received them, or the other person's phone.

Can you recover deleted messages if the phone was not reset?

Sometimes. Messages deleted in an app can remain in the phone's databases for a while, and backups may hold older copies. How much survives depends on the phone, the app and how much the phone has been used since. Nobody can tell you in advance, which is why we never promise a result.

Should I reset my phone if I think it has spyware?

Not before it has been examined and you have a safety plan. A reset destroys the evidence of what was installed and when, and the other person may notice their access has stopped. Talk to a support worker or police first, and let us image the phone before anything changes.

Trackers and spyware

What does an "AirTag detected near you" alert mean?

Your phone has noticed an AirTag that is away from its owner and has been moving with you. Apple notes it can have an innocent explanation, such as an item you borrowed. If you cannot explain it and you feel unsafe, contact police, who can work with Apple to request information about the tag.

Does playing a sound on a tracker warn the owner?

Google says playing a sound from an Android unknown tracker alert does not notify the owner. Removing an AirTag's battery is different: the owner stops seeing its location, which can tell them it was found.

Can you tell who installed the spyware?

We can show what was installed, what it could do and when it arrived. Whether that points to a particular person depends on other evidence, such as who had the phone and the passcode at that time. We will not name a person the data does not identify.

Working with us

Can you examine my ex-partner's phone or account?

No. We only examine devices and accounts you own or are lawfully authorised to provide. Their devices can be seized by police, and a court can order material produced. Accessing someone else's account yourself can be an offence and can make the evidence unusable.

Will your report get me a protection order?

No one can promise that. The court decides. What we can promise is a report that says exactly what the data shows, where it came from and what its limits are, so it can be relied on.

Do police need to be involved first?

No, but if police are involved or likely to be, tell us before collection. They may want to seize or examine the devices themselves, and we will make sure our handling does not interfere with theirs.

Will the other person find out?

We never contact the other person. If our report is used in proceedings, the other side will usually receive a copy, and changes you make to shared accounts can be noticed. Talk to your solicitor or support worker about timing.

How much does it cost and how long does it take?

Fees are fixed and staged: a fixed fee per device for imaging, then a fixed fee for each question in your scope once we know what the extraction contains. Stage 1 is normally completed within 10 to 15 business days of collection and payment, and urgent matters can be prioritised.

Confidential enquiries

Talk to us before anything changes on the device

Call from a phone the other person cannot check, or email from an account they cannot open. Tell us first whether you are safe and whether police are involved. We will explain what your devices can and cannot show before you commit to anything.

Contact Wildfire

1300 806 557 admin@wildfiredata.com.au Contact form

In danger now, call 000. For support any time, call 1800RESPECT on 1800 737 732.