Today, smartphones, computers, SSDs, HDDs, memory cards and USB storage contain a large amount of important information. Photos, videos, documents and messages can sometimes be deleted accidentally.
This leads to an important question:
The answer is not the same for every device. Data recovery depends on storage technology, file system, encryption, activity after deletion, storage management and available backups.
The most important point is that deleting data from a device and deleting every other copy of that data are not necessarily the same thing.
When a file is stored, the operating system and file system maintain metadata and information about storage allocation.
Windows can use file systems such as NTFS, while Linux systems can use file systems such as ext4. Different file systems can handle deletion differently.
A normal delete operation does not necessarily mean that every piece of related storage information is physically erased at that exact moment.
If relevant information remains on the storage and has not been affected by later operations, recovery may be possible in some situations.
Mechanical HDDs use magnetic platters. If relevant information from a deleted file remains available and the affected storage area has not been overwritten, recovery may be possible in some situations.
However, there is no universal recovery guarantee.
SSDs use NAND flash storage and may use storage-management mechanisms such as TRIM or discard.
TRIM can inform the storage device that certain blocks are no longer needed by the operating system. How the SSD controller and internal garbage collection subsequently handle those blocks depends on the device implementation.
The accurate point is that SSD storage management can make recovery of deleted information very difficult or, in some circumstances, practically infeasible.
Modern smartphones can use flash storage technologies such as eMMC or UFS.
Android and device firmware can use different storage-management mechanisms.
Therefore, deleted-data recovery from a smartphone cannot be determined simply by looking at the Delete button.
Storage technology, file system, encryption and activity after deletion can all matter.
File-Based Encryption (FBE) is an important Android security technology. Android supports FBE from Android 7.0, and devices launching with Android 10 and later are required to use file-based encryption.
Encryption means that obtaining raw storage information does not automatically mean that it can be directly read as a normal photo, document or message.
The required encryption keys and authorized access are important.
If proper sanitization removes or invalidates the required encryption key so that decrypting the target data is no longer feasible, recovery of the original readable data can become practically infeasible.
Cryptographic erase involves sanitizing the encryption key that protects encrypted data.
Its purpose is to make recovery of the readable information from the encrypted data infeasible at a defined level of effort.
The exact erase process depends on the device, hardware and operating system implementation.
The technical behavior of a factory reset is not identical on every device.
Modern devices can use encryption and secure-erase mechanisms as part of their data-protection design.
Therefore, it is not accurate to claim that every factory reset works simply by destroying an encryption key.
The correct general statement is:
iPhone internal storage and iCloud should be understood as separate storage locations.
If iCloud Photos, iCloud Backup or another relevant iCloud service was enabled and a copy was successfully stored, some information may still be available through that cloud copy.
Example:
The information may then be available from the cloud copy.
This is not the same as recovering the deleted internal storage of the iPhone. It is retrieving an independent copy.
Not every type of data is automatically stored in iCloud.
Android internal storage and cloud backups are also separate.
If Google Photos Backup or another relevant backup or synchronization service was enabled and the data was successfully backed up, a separate cloud copy may be available.
Example:
The photo may then be available from the backup.
If backup was never enabled or the data was not successfully backed up, such a cloud copy does not necessarily exist.
Therefore:
NIST finalized SP 800-88 Rev. 2, Guidelines for Media Sanitization, in 2025.
The guidance describes sanitization with the goal of making access to target data infeasible at a defined level of effort.
Therefore, universal statements such as “100% impossible in every situation” should be avoided.
Appropriate sanitization depends on the storage type and the available sanitization technology. Cryptographic erase can also be relevant for properly encrypted storage.
| Situation | General Result |
|---|---|
| Normal Delete | 🟡 Recovery may be possible in some situations |
| Trash / Recycle Bin | 🟢 Usually available for restoration |
| Permanent Delete | 🟡 Depends on storage conditions |
| New Data Written | 🟠 Recovery may become more difficult |
| SSD + TRIM | 🔴 Recovery can become very difficult |
| Encryption + Key Available | 🟢 Authorized access may be possible |
| Encryption Key Sanitized | 🔴 Recovery can become practically infeasible |
| Proper Sanitization | 🔴 Recovery can become practically infeasible |
| Modern Factory Reset | 🟡 Depends on device implementation |
| Older / Unencrypted Device | 🟡 Depends on the device and storage |
| Cloud / Backup Copy | 🟢 Data may be available from the independent copy |
| Physical Damage | 🟡 Specialist recovery may be possible in some cases |
| Proper Physical Destruction | 🔴 Target recovery can become infeasible |
If an important file was accidentally deleted:
There is no universal recovery percentage that can accurately apply to every device or storage situation.
Normal Delete → Recovery may be possible in some situations.
Trash / Bin → Usually available for restoration.
New Data / Overwrite → Recovery may become more difficult.
SSD + TRIM → Recovery behavior is not the same as HDD.
Encryption → Keys and authorized access are important.
Cryptographic Erase → Proper key sanitization can make recovery infeasible.
Proper Sanitization → Can make recovery infeasible at a defined level of effort.
Backup Available → Data may be available from an independent copy.
“Data disappears permanently immediately after deletion” is not a universal rule.
“Forensic tools can recover every deleted file” is also not a universal rule.
Data recovery depends on storage technology, file system, encryption, storage management, activity after deletion and available backups or copies.
A cloud copy is relevant only when a backup or synchronization copy was actually created and remains available.
There is no single universal rule for deleted-data recovery.
In some situations, deleted information can remain on storage and may be recoverable. In other situations, new writes, SSD or flash storage management, encryption, key sanitization or proper sanitization can make recovery very difficult or practically infeasible at a defined level of effort.
If a backup exists, information may also be recovered from that independent copy without recovering the deleted device storage itself.
Deleted-data recovery depends on storage technology, file system, deletion process, activity after deletion, encryption and available backups or copies.
This article is provided for general technology education and knowledge. Actual recovery results can vary depending on the particular device, operating system, storage technology, encryption and available copies.