A factory reset is the last thing almost everyone does before selling, returning or recycling a handset. It clears the screen, removes the accounts, and hands back something that looks new. What it does to the data underneath depends entirely on how that particular device stored it, and the answer is not the same for every phone in the drawer.
What a reset actually does
On a device whose storage is encrypted, a reset does something genuinely strong: it discards the key. The data is still physically present on the flash, but without the key it is indistinguishable from noise, and there is no practical route back. This is why a reset on a modern, encrypted handset is a reasonable disposal step.
On a device that was never encrypted, a reset does something much weaker. It marks the user partition as free and rebuilds the filing system. The blocks that held photographs, messages and cached credentials are untouched until something else happens to overwrite them, and on a phone that is being sold rather than used, nothing will.
Which of the two you have
Android has required encryption by default since Android 10, and Apple has encrypted since well before that. The problem is the fleet in the cupboard rather than the phone in your hand: devices that shipped on older versions, devices where encryption was disabled by a custom ROM, and low-cost handsets from vendors who left it off to make the hardware feel faster.
The question is not "did you reset it". The question is "was it encrypted when you did".
What to do instead
- Check the encryption state before the reset, not after — once it is reset you have lost the evidence either way.
- For an unencrypted device, overwrite the user partition before resetting, so the reset is discarding blocks that no longer hold anything.
- Record what you did per device. A batch of forty handsets with one certificate between them answers nothing about handset seventeen.
- Treat a device that will not report its encryption state as unencrypted. That is the assumption that fails safe.
Data Sanitization Pro reads the encryption state over USB before anything is done, and records it on the certificate alongside the method — so the document says which of the two situations above applied, rather than simply asserting that the phone was wiped.



