Buying A Second Hand Phone And What Is Still On It
A used phone listing usually says some version of “wiped and reset, ready to go.” That’s often true in the sense the seller intended: they went into settings and tapped the reset button. It’s not always true in the sense that matters to you, which is whether the phone is actually clean and actually yours to set up. Those are two different questions, and the gap between them is where most of the real problems live.
What a factory reset actually does
On a modern Android phone or iPhone, internal storage is encrypted by default. A factory reset doesn’t grind through the storage overwriting every byte, the way old-school “wipe” advice used to describe. Instead, it discards the encryption key. Without that key, the data that’s still physically sitting on the flash storage is unreadable, functionally garbage. This is why a reset on a current phone takes under a minute instead of hours: it’s throwing away the key, not shredding the files.
That’s a solid mechanism, and it’s the reason “just reset it” is decent advice most of the time. But it only covers what’s inside that encrypted user partition. It says nothing about accounts tied to the device, storage that lives outside that partition, or management profiles installed by someone other than the phone’s owner. Those are the places where “reset” and “clean” stop meaning the same thing.
The account lock that survives the reset on purpose
Both Google and Apple built anti-theft systems that are specifically designed to survive a factory reset, because the whole point is to make a stolen phone useless to a thief who wipes it.
On Android, this is Factory Reset Protection (FRP). If a Google account was signed in on the device before it was reset, the phone will ask for that same Google account’s credentials during setup after the reset completes. No account, no setup. On iPhone, the equivalent is Activation Lock, tied to Find My. If Find My was on and the previous owner didn’t sign out of iCloud before wiping, the phone will ask for their Apple ID password during activation. Samsung devices layer their own reactivation lock (tied to Knox) on top of this for the same reason.
None of this is a bug. It’s the feature working as intended to deter theft. But it means a seller has to actively remove the device from their account, not just reset it, or the phone arrives as a locked brick that neither of you can use. If you’re buying, this is the single most common way a “clean” used phone turns out not to be usable at all.
Data that lives outside the part that gets wiped
A few things sit adjacent to the phone’s internal storage and don’t get touched by a standard reset unless someone remembers to handle them separately:
A microSD card, if the phone takes one, is treated as removable storage. Resetting the phone doesn’t automatically erase what’s on the card. Photos, downloads, and app data can sit there through the reset process entirely intact.
An eSIM profile is digital, but it’s still a profile that has to be deleted on purpose. If a seller swaps to a new phone and forgets to remove the old eSIM, it can persist, and it’s tied to their carrier account, not the device’s storage.
A physical SIM card is the most obvious thing to forget, and people forget it constantly. It’s usually just sitting in the tray.
An MDM or work profile shows up on phones that were ever enrolled in a company’s device management system, including phones from device financing plans or corporate deployments. That profile can restrict what you’re able to do with the device, and removing it usually requires the organization that installed it to release it, not a factory reset from the settings menu.
Backups reappearing after you sign in
Once a buyer sets up a wiped phone with their own account, the setup wizard will typically offer to restore from their own cloud backup, not the seller’s. That’s expected and fine. The concern is really the reverse case: if a seller’s account wasn’t properly removed and Activation Lock or FRP got bypassed through unofficial means rather than a legitimate account removal, the device’s relationship to that account can stay tangled in ways that are hard to see from the surface. A phone that looks freshly set up isn’t automatically one where the previous owner’s account ties have been cleanly severed. If a listing description mentions an “unlocked” FRP or Activation Lock status through anything other than the owner signing out themselves, treat that as a reason to ask more questions, not less.
A short checklist before you hand over money
Before buying, power the phone on in front of the seller if you can. A phone that’s genuinely ready for a new owner should boot straight into the setup wizard, not a lock screen or a login prompt tied to someone else’s account. In settings, check for any mention of Activation Lock (iOS) or a Google account requirement (Android) and confirm neither is present. Look for an inserted SD card and ask the seller to confirm it’s been removed or wiped. Check whether an eSIM profile is still listed under cellular settings. If the phone shows any sign of enterprise management or a “device is managed by your organization” notice, that’s worth walking away from unless the seller can show it’s been properly unenrolled.
It’s also worth checking the phone’s IMEI status through your carrier or an independent IMEI checker before paying, to see whether it’s reported lost, stolen, or still tied to an active financing plan. This won’t tell you anything about data privacy specifically, but it’s a quick, low-effort step that catches a different category of problem with the same device.
Once it’s yours, do a fresh erase yourself regardless of what you were told, then set it up with your own account rather than restoring any backup you didn’t create. On Android that’s Settings, System, Reset options, Erase all data. On iPhone it’s Settings, General, Transfer or Reset, Erase All Content and Settings.
What to do if you’re the one selling
The order matters. On iPhone, sign out of iCloud and turn off Find My before you erase the device, that’s what actually releases Activation Lock. On Android, remove your Google account from Settings, Accounts before resetting, or be ready to confirm the removal if the reset flow asks for it. Pull the SIM and any SD card. If the phone was ever enrolled in a work or carrier MDM profile, get it unenrolled through that organization first, since a local reset won’t do it for you. After the reset, boot the phone once yourself to confirm it lands cleanly on the setup screen with no accounts, no lock prompts, and no leftover files, before you hand it over.
What a wipe doesn’t do
A proper reset and account removal handles the realistic risk with a used phone, which is leftover access to accounts, files, or management systems, not identity theft from recovered data. It’s worth being clear about what it doesn’t do too: the IMEI is permanently tied to the hardware and isn’t something a software reset changes, and no single step here makes a device’s history or ownership untraceable. That’s not really the goal. The goal is a phone that’s actually been released by its previous owner and actually starts fresh for its new one, which is a more modest and more achievable thing.
The bottom line
Most used-phone privacy problems aren’t sophisticated. They’re a seller who reset the phone but forgot to sign out of iCloud, a microSD card nobody thought about, or an eSIM that never got deleted. A few minutes of checking, on both sides of the transaction, closes almost all of that gap.
For more guides like this, visit The Privacy Wire.