A device repair usually requires unlocking it and handing it to someone you don't know, in a back room you can't see, for however long the repair takes. That arrangement grants far more access than most people think about at drop-off — not just to the specific fault being fixed, but to photos, messages, saved passwords, and anything else stored on the device.
What's actually at risk
Most repair work doesn't require touching personal files at all — a cracked screen or a battery swap has nothing to do with your photo library. But an unlocked device sitting on a workbench doesn't enforce that boundary on its own. The access is broader than the job requires, and the only thing standing between "fixing a screen" and "browsing a photo library" is the judgment of whoever is holding the device.
The risk isn't that every technician will look. It's that the device doesn't stop them from being able to.
How to reduce the exposure before you hand a device over
- Back up, then factory reset if the repair allows it. Not always possible for hardware faults, but when it is, it removes the exposure entirely.
- Use a guest mode or a secondary, low-privilege account if your device's fault doesn't require full access — many phones and laptops support this natively.
- Remove or lock sensitive apps (banking, authenticator apps, password managers) rather than assuming a passcode alone is enough.
- Ask directly about the shop's data-handling policy before you leave the device — a reputable shop will have a clear answer, not a shrug.
- Where possible, physically remove storage (an SSD, an SD card) for repairs that don't require it, such as a screen or battery replacement.
This piece started as a hands-on look at what's realistically exposed during a routine repair, and what a device owner can actually do about it beforehand. I wrote up the full investigation and findings in more detail on Medium — worth reading before your next drop-off.