How to wipe and sell an old phone without giving away your data

The erase itself is close to foolproof on any phone made in the last decade, because it destroys a key rather than scrubbing files. Almost everything that goes wrong happens in the ten minutes either side of it — and the most common failure leaves the buyer with a device they cannot switch on.

Illustration of a phone being erased, with a single key breaking apart beside it

There is a drawer in most homes with a phone in it. The UK's Information Commissioner's Office put some numbers on that in December 2024: in a Savanta survey of 2,170 UK adults, three-quarters said they had held on to at least one old device, the average person had three of them sitting unused, and 29 % said they did not know how to wipe their personal information from one. A fifth were keeping devices specifically because they worried about what was still on them.

That worry is largely misplaced on any recent phone, provided you use the manufacturer's own erase function rather than deleting things by hand. What deserves the worry instead is the sequence: do the steps in the wrong order and you either lock the buyer out permanently or leave an account, a number or a memory card behind.

The short answer

Why a factory reset actually works now

A decade ago this advice came with a real caveat. In 2014 Laurent Simon and Ross Anderson of the University of Cambridge bought 26 second-hand Android handsets running Android 2.2 to 4.3 and tried to recover data from them after a factory reset. On most of them they could: Google authentication tokens on around 80 % of the affected devices, plus messages, contacts, Wi-Fi credentials and images. They estimated that up to 500 million devices then in circulation might not properly sanitise the data partition. That paper is the origin of much of the folklore still repeated about resets.

What changed is that the erase stopped being an erase. Modern phones encrypt storage from the moment they are set up, so wiping them means destroying the key instead of the data. Apple describes the mechanism plainly in its platform security documentation: files are protected by a hierarchy of keys, the file system key sits at the top, and when you choose Erase All Content and Settings the key protecting it is deleted from dedicated storage. "Erasing the key in this manner renders all files cryptographically inaccessible."

Android arrived at the same place by a different route. The Android Open Source Project requires that "all devices launching with Android 10 and higher are required to use file-based encryption", which splits storage into credential-encrypted data — readable only after the user unlocks the phone — and device-encrypted data available earlier. Keys are bound to the lock-screen credential and to hardware, so a reset that discards them has the same effect as Apple's: the bytes remain, and nothing can read them.

Deleting files compared with destroying the key Deleting a file only removes its entry from the index, leaving the contents on the storage chip where forensic tools can find them. Destroying the encryption key leaves the encrypted contents in place but makes them unreadable, which is the method modern phones use. TWO WAYS TO MAKE DATA GO AWAY Deleting files Index entry removed Contents still on chip Recoverable in a lab What a file manager does. Not enough. Destroying the key Contents stay, encrypted Key is wiped Nothing can read them What the built-in erase does. Sufficient.
Manually deleting photographs and messages is the weaker of the two methods. The manufacturer's own erase function is the one that removes the key.

Where that guarantee stops

Key destruction is a recognised sanitisation method, but it comes with conditions, and the US National Institute of Standards and Technology sets them out in its media sanitisation guidelines. NIST treats cryptographic erase as a way to purge media — its middle tier, above a simple clear — on the basis that "without the encryption key used to encrypt the target data, the data is unrecoverable". Two caveats attach to it. The first is about timing: "do not use CE to purge media if the encryption was enabled after sensitive data was stored on the device without having been sanitised first." The second is about copies: an organisation must ensure "all copies of the encryption keys used to encrypt the target data are sanitized".

For a phone encrypted out of the box whose key was never escrowed anywhere, both conditions hold. For a very old handset, an unlocked bootloader or a device that spent part of its life unencrypted, they may not. The UK's National Cyber Security Centre keeps the same door open, noting that after a reset "a determined expert — using specialist tools — may still be able to recover the data". So a reset is comfortably enough for selling to a stranger on a marketplace, and not the right answer for a device holding material you are legally obliged to protect, which should be destroyed rather than resold.

Advertisement

The mistake that strands the buyer

The failure that fills marketplace dispute threads is not leaked data. It is a phone that erases perfectly and then refuses to set up, because it is still tied to the seller's account.

On iPhone the mechanism is Activation Lock, which Apple describes as "a feature that's designed to prevent anyone else from using your iPhone or iPad if it's ever lost or stolen". It is not something you switch on deliberately: "Activation Lock turns on automatically when you turn on Find My on your device." Once active it requires your Apple Account password before anyone can turn off Find My, wipe the device or reactivate it, and it survives a remote erase by design — "even if you erase your device remotely, Activation Lock can continue to deter anyone from reactivating your device".

Android's equivalent is Factory Reset Protection. Google's description is the same idea in different words: after a reset, "only someone with your Google Account or screen lock could use it". The remedy is likewise the same. "To turn off device protection, remove your Google Account from your device", and remove the screen lock as well, before you reset.

These features work, which is exactly why they cause trouble: a seller who resets first and signs out afterwards has already handed over a locked device. It is fixable, but only from your side. On Apple's Find Devices page at icloud.com/find, select the device and choose Remove This Device; for one that is offline, "Activation Lock is removed immediately, and your device is also immediately removed from Find My". On Android, remove it from your Google account's device list.

The order of operations

Everything above reduces to a sequence. It differs slightly by platform but the logic is identical: get your data out, detach your identity, then erase.

The order of operations for wiping a phone before sale Four steps in order: back up and verify the backup; unpair watches and other accessories; sign out of the Apple or Google account and remove the screen lock on Android; then erase the device. Afterwards, remove the phone from the account device list and take out the SIM tray and memory card. DO IT IN THIS ORDER 1 Back up, and open the backup to check it 2 Unpair the watch and other accessories 3 Sign out of the account; clear the lock on Android 4 Erase the device, then pull the SIM tray Step 3 before step 4. Reversing them locks the buyer out.
The sequence matters more than any individual step. Signing out after the erase is the single most common way to ship an unusable phone.

On an iPhone, Apple's own checklist runs: make a backup; unpair a paired Apple Watch; sign out of iCloud, iTunes and the App Store from Settings under your name; then Settings › General › Transfer or Reset iPhone › Erase All Content and Settings. Apple notes that this removes cards, photos, contacts, music and apps, and turns off Find My and Activation Lock in the process. Afterwards, remove the old device from your list of trusted devices.

On Android, remove your Google account from Settings › Accounts, remove your screen lock, then run the factory data reset from Settings › System. Manufacturers add their own accounts on top of Google's — Samsung, Xiaomi and others each maintain one with its own find-my-device service — so check the accounts list rather than assuming Google is the only one present. Then remove the handset from your Google account's device list from a browser.

If you are still deciding whether the phone is worth replacing at all, the arithmetic in our guide to when to upgrade and when to hold on is the place to start; if you are doing this because a backup once let you down, the 3-2-1 rule covers the part of this sequence that people skip.

The eSIM is a separate thing

An eSIM is not storage, and the erase does not automatically settle it. It is a carrier credential that lives in a separate secure element, and it has to be moved or removed on purpose.

Apple's erase flow asks: "if you erase content and settings from your iPhone or iPad, you can choose to erase your eSIM or keep it." Keep it if you are handing the phone to someone in the same household who will use the same plan, or if you have not yet moved your number. Erase it if the phone is going to a stranger — but do that only once your number is running somewhere else, because Apple's warning is unambiguous: "if you erase an eSIM, you'll need to contact your carrier to get a new one."

The tidier route on both platforms is to transfer the profile to the new phone first and let the old one lose it as a consequence. Google's Pixel documentation puts the transfer under Settings › Network & internet › SIMs › Add SIM › Transfer SIM from another device, with both handsets present on Android 12 or later with a screen lock enabled, and notes that the existing eSIM keeps working if the transfer does not complete. Our explainer on what an eSIM actually is covers why a credential behaves differently from a plastic card.

What a reset does not touch

The erase is bounded by the device. Several things people assume it covers sit outside that boundary.

Loose endDoes the reset handle it?What to do
Files on a microSD cardNoRemove the card; treat it as a separate device
The SIM trayNoEject it and keep the card or destroy it
The eSIM profileOnly if you choose toTransfer it first, then erase or keep deliberately
Your cloud backups and photo libraryNoThey stay in your account, which is the point
Sessions on other devicesNoUnaffected; you are signing out of this phone only
Two-factor codes tied to the numberNoMove the number first, then check a code arrives
Smart home devices paired to the phoneNoConfirm you can still manage them from elsewhere
The device in your account's device listNoRemove it manually after the erase

The NCSC's pre-flight list is the useful version: before erasing, check you have a backup of what you want to keep, that you know the passwords for accounts the phone logs into automatically, that smart home kit can be managed another way, and that verification codes reach you on a different device. A reset removes, in its words, "messages, contacts, photographs, browsing history, Wi-Fi codes, passwords, and any apps you've installed" — including the things you were relying on without noticing.

Before it leaves your hands

Four checks, and they take about two minutes between them.

  1. Boot it. A correctly wiped phone starts at the language picker with no account prompt. If it asks for a password, it is still locked to you — fix that before it ships, not after.
  2. Check your account. The handset should no longer appear in your Apple or Google device list. If it does, remove it there.
  3. Empty the trays. SIM tray out, memory card out, case off. Photograph the IMEI and the condition while you still have it.
  4. Be accurate in the listing. Battery health, cracks, whether it is carrier-locked. The vocabulary sellers use is worth getting right, and our guide to refurbished grades sets out what the common labels actually mean.

The hard part is already solved for you. Encrypting phones by default turned a genuinely difficult problem — removing data from flash storage that deliberately moves it around — into a key deletion that takes a minute. What is left is administrative: detach yourself from the device, in that order, and check the result before it goes out of the door.

Sources

Share this guide X WhatsApp LinkedIn Email