Digital privacy law in the United States is a patchwork of court decisions, each addressing a narrow slice of technology, often years behind the technology itself. Knowing which rule applies in which situation is the difference between assuming you're protected and actually being protected.
What the Law Currently Protects
- Riley v. California (2014): Police generally need a warrant to search the digital contents of a phone seized during an arrest, recognizing phones as fundamentally different from physical containers.
- Carpenter v. United States (2018): Extended Fourth Amendment protection to historical cell-site location data, requiring a warrant for law enforcement to obtain records of your movements from your carrier.
- Fifth Amendment and passcodes: Courts remain split on whether you can be compelled to provide a passcode versus a biometric unlock (Face ID or Touch ID), with several rulings treating biometrics as less protected than a memorized passcode.
Where Those Protections Stop
- The border search exception: None of the above protections apply at international borders and ports of entry, where device searches can occur without a warrant or individualized suspicion.
- The third-party doctrine: Data voluntarily stored with a company — including iCloud backups — has historically received weaker protection than data on your device, since the doctrine holds you've already shared it with a third party.
- National security process: National Security Letters and FISA court orders operate under different, often secret standards, frequently paired with gag orders preventing disclosure.
- Jurisdiction matters enormously: Protections described above are U.S.-specific; other countries have entirely different frameworks, and some offer far less protection for device searches or cloud data requests.
What You Can Actually Control
Law defines what the government can compel from a third party or seize from your device. It has no bearing on data that was never created in a reachable form in the first place. Stash gives you that control directly: AES-256 encryption applied entirely on-device, with no cloud sync, no account system, and no server for any legal process to target.
A Practical Starting Point
Review what's currently syncing to iCloud in Settings, move anything genuinely sensitive into an on-device encrypted vault, and disable iCloud sync for that content going forward. This single change closes the most common exposure point — the one that doesn't require a warrant against you personally, just a request to a company you've already trusted with the data.
Disguise as a Practical, Not Just Legal, Layer
Legal rights are enforced after the fact, often in court, often after your data has already been seen. Stash's disguise modes — calculator, fitness tracker, music player — combined with a decoy vault, add a practical layer that prevents the situation from arising in the first place.
Know Your Rights, but Don't Rely on Them Alone
Organizations like the Electronic Frontier Foundation and the ACLU publish detailed, regularly updated guides on device search rights for specific situations — protests, border crossings, traffic stops. Pairing that legal knowledge with genuine technical protection is more resilient than either alone.
Download Stash from the App Store
