When you bring your phone in for a screen replacement or a battery swap, you hand it to a technician who will have physical access to it for hours, sometimes longer. The screen is off. It’s in a back room you can’t see. And if you haven’t taken precautions, your camera roll, messages, documents, and saved credentials are a few taps away.
Research from Kaspersky documented what actually happens in service centers: in roughly half of all documented repair cases, technicians gained access to user files. The primary interest was photos, including intimate ones. In two documented cases, files were copied to an external device. These weren’t anomalies from one country or one type of shop — they represented a consistent pattern across multiple repair contexts.
Most users don’t take precautions before repairs. A survey by the Mobile Security Alliance found that 67% of consumers worry about data security when getting their phone repaired, yet fewer than 30% take concrete steps to protect their information. The gap between awareness and action is where the damage happens.
The good news is that modern devices have real protections, and the steps to use them before a repair are straightforward. Most people don’t take them because they haven’t thought about it. This is the prompt to think about it.
What Technicians Can Access and When
The answer depends on the type of repair, the device, and whether it’s locked.
If your device is locked and the repair doesn’t require unlocking it: Modern iPhones and Android devices, when locked, encrypt storage with a key derived from your passcode. Without the correct passcode, the storage is cryptographically opaque — a technician cannot access your files, photos, or messages through normal means. Screen replacements and battery replacements typically don’t require device access. Technicians should be able to complete most hardware repairs without your passcode.
If the repair requires your passcode or an unlocked device: Some repairs — software issues, factory resets, certain biometric sensor calibrations — genuinely require the device to be unlocked. When you hand over an unlocked device, everything on it is accessible: photos, messages, email, saved browser passwords, banking apps (depending on their own authentication), and any cloud-synced files.
If the device was unlocked when you handed it over: Many people hand their phone to a technician already unlocked — either because they didn’t think about it or because the technician asked them to “just open it up so I can check something.” In this case, there is no technical barrier to file access for the entire duration the device is in the shop.
Samsung Maintenance Mode: Samsung introduced Maintenance Mode in 2022 and has expanded it since. When enabled, the device runs in a restricted state: the technician can test hardware functions, but your photos, messages, contacts, and apps are hidden. Exiting Maintenance Mode requires your PIN. It’s the closest thing currently available to a built-in solution for the repair-shop scenario.
As of mid-2026, Apple has not shipped a general repair mode for iPhone with equivalent content-hiding capability. Google Pixel devices have a Lockdown Mode that prevents biometric authentication, but it doesn’t hide content the way Samsung’s maintenance mode does.
Before Any Repair: The Right Sequence
These steps apply whether you’re going to an authorized service center, a third-party shop, or a mail-in repair service.
Step 1: Back Up Everything
Before you restrict or wipe your device, verify you have a complete backup you can restore from.
iPhone:
- iCloud backup: Settings → [Your Name] → iCloud → iCloud Backup → Back Up Now
- Local backup via Mac or PC: Connect via USB, open Finder (Mac) or iTunes (PC), select Back Up Now. Check “Encrypt local backup” if you want passwords and health data included.
Android:
- Google backup: Settings → Google → Backup → Back up now
- Samsung-specific: Settings → Accounts and backup → Back up data
Verify the backup completed and note the timestamp before moving to the next step.
Step 2: Protect or Wipe the Device
Your options, from least to most thorough:
Samsung Maintenance Mode (Samsung devices only): Pull down the notification shade and tap the Maintenance Mode tile, or go to Settings → Device care → Maintenance mode. Enable it. Your personal files are hidden until you exit with your PIN. This is the recommended option for Samsung users — the repair completes normally and your content is protected throughout.
Factory reset (all devices): After verifying your backup, reset the device to factory settings. The technician receives empty hardware. When you get it back, restore from your backup. This is the most thorough approach — nothing on the device means nothing at risk.
For devices without maintenance mode and without doing a factory reset: Ensure the device is locked with a strong PIN (not biometric alone) before handing it over, and don’t provide the PIN unless the repair genuinely requires it. If a technician needs your PIN for a purely hardware repair, ask why.
Step 3: Remove Physical Accessories
- SIM card: Remove before handing the device over. The repair almost never requires the SIM, and a SIM in a reset or maintenance-mode device can still receive calls and messages.
- SD card (if applicable): Remove any external storage.
Step 4: Sign Out of Sensitive Accounts
If you’re doing a factory reset, account sign-out happens automatically. If you’re not resetting, manually sign out of the most sensitive accounts: email, banking apps, cloud storage, anything with credentials or financial data. You can sign back in when you pick up the device.
After the Repair: What to Check
Getting your device back doesn’t mean automatically restoring everything and moving on. A brief verification takes minutes.
Check your cloud backup timestamps. If your backup is set to run automatically, note when it last ran before the repair. An unexpected new backup created during the repair window could indicate the device was connected to an account or authenticated against your cloud service.
Review recent security activity. Both Google and Apple maintain login activity logs:
- Google: myaccount.google.com → Security → Your devices → Recent security activity
- Apple: Settings → [Your Name] — check the list of signed-in devices for anything unfamiliar
If the repair required account sign-in and you didn’t personally authorize it, this is where you’d see it. Sign out all unfamiliar sessions and change your account password if anything looks wrong.
Verify app authentication is intact. Apps that require biometric or PIN authentication separately from the device lock — banking apps, password managers — should prompt you to re-authenticate after a factory reset or certain repairs. If an app opens without prompting you in a situation where it normally would, investigate before using it.
The Structural Solution: Why Backing Up to Private Storage Matters
The most reliable protection against repair-shop data exposure is ensuring that your most sensitive files are backed up to encrypted private storage before you ever need a repair.
If your sensitive files are backed up and your device is wiped before the repair, there is nothing on the device for a technician to access. The backup exists in your encrypted storage. The device that goes in for repair is empty hardware. When the repair is done, you restore from your backup and continue.
This is why backing up to encrypted private storage is a practical prerequisite for responsible device repair, not just a general privacy improvement. The sequence: back up to a service that encrypts your content at rest, wipe the device (or use Maintenance Mode), hand it over for repair, restore from backup when you get it back.
daftei stores files encrypted with AES-256 at rest and TLS 1.3 in transit, is available across iOS, Android, and the web, and gives you 5 GB free to start — enough to back up your documents, most important photos, and critical personal records before any repair. You can also share access links for specific files without exposing your entire library.
The Kaspersky research findings become irrelevant to your device when there’s nothing on it to access.
Authorized vs. Third-Party Repair Centers
The documented repair-shop privacy violations predominantly involve third-party shops rather than authorized manufacturer service centers. Authorized centers generally have stronger employee training, NDAs, camera-monitored workspaces, and contractual obligations to manufacturers that create accountability for employee behavior.
That doesn’t mean authorized centers are uniformly safe or third-party shops uniformly problematic. It means the institutional controls are more likely to be present at authorized centers, and that a data incident is more likely to result in accountability there.
Regardless of where you go, the technical precautions above reduce your exposure at both types of centers. A technician at an authorized Apple Store can still access a device you’ve handed over unlocked. The technical protections — backup, wipe or maintenance mode, remove SIM — work independently of whether the shop has strong institutional controls.
For any repair that requires account credentials or software restoration, authorized centers are generally the right choice. The more software-intensive the repair, the more exposure to device content, and the more the shop’s institutional accountability matters.
The Practical Summary
The research is clear: file access during repairs happens, and photos are the primary target. The fix is straightforward:
- Back up to encrypted storage before any repair
- Use Samsung Maintenance Mode or factory-reset the device before handing it over
- Remove SIM and SD card
- Sign out of sensitive accounts if not resetting
- Check security activity logs when you get the device back
Most people skip all of these steps because repairs feel routine and most repair technicians are trustworthy. The precautions aren’t about assuming bad faith — they’re about removing the opportunity in the minority of cases where bad faith exists. The cost of the precautions is about thirty minutes. The cost of not taking them can be substantially higher.