Android forensics lives or dies on the root question. The operating system sandboxes each app's private storage, so what a tool can reach without root is very different from what it can reach with it. A lot of confident marketing blurs that line. The assessments below keep it sharp, because under-claiming on what a non-rooted acquisition can reach is the safe and honest forensic direction. Over-claiming it is exactly the error a defense expert is paid to find. Each verdict uses a five-point scale from False to True.
Forensic Fact Checks
Android Forensics Fact Checks
Eight claims about Android evidence, rated by a working forensic examiner. Android turns hard on one line above all: what needs root and what does not. These verdicts hold that line exactly where the device does.
The Claim
"You always need root to acquire an Android phone."
Verdict: Mostly False
A non-rooted logical acquisition over the standard ADB path reaches a real set of categories: contacts, call logs, SMS and MMS, calendar, Wi-Fi networks, media, installed apps and notifications. No root needed for that. Root only becomes necessary for the deeper layer, an app's private storage. So root is required for some evidence, not for acquisition itself, which makes the absolute claim mostly false.
The Claim
"App-private data like WhatsApp and Signal message databases is readable without root."
Verdict: False
This is the hard line Android draws. App-private storage under the data partition is sealed by the sandbox and is not reachable over ADB without root. Without root, the WhatsApp database is limited to an encrypted backup on shared storage if one exists. Signal yields only contact sync, which of your contacts use it. The message databases themselves are a rooted-acquisition artifact. Any tool claiming to read them from a non-rooted device is overclaiming.
The Claim
"Deleted Android SMS can be recovered."
Verdict: Mixture
It depends on the acquisition and on physics. From a full-filesystem image, the SQLite reader replays the write-ahead log and walks the freelist, so a deleted message still present in the database file is recovered and clearly marked as recovered. What has already been overwritten is gone. The raw message database sits in app-private storage, so this recovery needs the deeper rooted image, not a logical pull. Real but conditional, which is a mixture.
The Claim
"Full Android browser history is recoverable without root."
Verdict: Mostly False
Chrome and OEM browser history lives in app-private storage, the same sandbox as the messaging databases, so on a non-rooted device it is not reachable over ADB. The old system Browser content provider that once exposed history was removed back in Android 6, so there is no modern non-root path to it. Browser history is a real capability on a rooted acquisition and should be scoped there, not promised from a logical pull.
The Claim
"A factory reset makes Android data unrecoverable."
Verdict: Mostly True
Modern Android is encrypted by default. A factory reset discards the encryption key rather than scrubbing every block. Without the key the remaining ciphertext is effectively unrecoverable by logical means, so for a current, encrypted device the honest answer leans true. The caution is only for older or unencrypted devices where remnants could survive, which is why this sits at mostly true rather than absolute.
The Claim
"An Android logical backup contains everything on the phone."
Verdict: False
A logical acquisition captures what the device exposes without root, the standard categories such as contacts, calls, messages, media and app inventory. It does not reach app-private storage, the messaging databases, browser history or the deleted-record layer inside those files. Those need a full-filesystem image. Logical is a genuine and useful scope, but it is a scope, not the whole phone.
The Claim
"Android location history can be pulled without unlocking the device."
Verdict: False
Acquisition needs the device unlocked and set to authorize the connection over ADB. A locked Android hands over neither its location history nor anything else to a logical pull. Location evidence comes from an authorized acquisition of an unlocked device, so the idea that it can be pulled from a locked phone does not hold.
The Claim
"Sherlock Forensics Android Acquirer uses the same class of method a repair shop uses."
Verdict: True
The non-rooted logical acquisition runs over the standard ADB connection across a USB cable, the same class of wired data path a repair shop uses to move data off a handset. The difference is discipline, not exotic hardware: Sherlock adds hashing, two-party integrity and a court-ready record on top of that ordinary connection. The method is familiar, the forensic rigor around it is the product.
Why We Publish Our Own Accuracy Lines
These verdicts are the exact scopes Sherlock Forensics holds inside a real Android examination, put in public. The root boundary is the one that gets overclaimed most, so it is the one we are most careful to state honestly: app-private data, messaging databases and browser history are rooted-acquisition evidence. A non-rooted logical pull is a real but bounded scope. Where deep evidence comes from a full-filesystem image, that image is read from any source, though obtaining one is a per-device question, never a guaranteed one-button capture of any Android.
Sherlock Forensics Android Acquirer captures a logical acquisition over ADB and reads a full-filesystem image where one is available, with deleted records marked as recovered and every scope stated. Assessments by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice.
Related: iPhone forensics fact checks · All fact checks · Android Acquirer