2026-08-18
Should you encrypt personal files before sending your laptop or phone in for repair?
Two field investigations, three years and one continent apart, tested the same question the same way: plant fake personal files on a device, drop it off for a routine repair, and record what the technician actually does with access nobody asked them to use. Neither found an isolated bad actor. Both found technicians opening photos, financial documents, and account credentials that had nothing to do with the repair ticket — and in each case, some of them copied what they found. If a laptop or phone is headed to a shop, a mail-in depot, or a manufacturer's repair program, that's a real, documented risk worth planning around before the device leaves your hands, not after.
What the peer-reviewed study actually measured
The most rigorous version of this test is a field study by University of Guelph researchers Jason Ceci, Jonah Stegman, and Hassan Khan, published as "No Privacy in the Electronics Repair Industry" and accepted to the 44th IEEE Symposium on Security and Privacy (IEEE S&P 2023) — a peer-reviewed academic venue, not a marketing survey. Researchers rigged 16 laptops with monitoring software and planted fake personal data — documents, pictures, financial records, browsing history — then dropped each one off at a real repair shop with an unrelated, verifiable hardware fault to fix. Technicians accessed that personal data in 6 of the 16 cases, and in 2 of those 16, copied files to an external device; one of the two also copied a file containing saved passwords. Three of the six who snooped tried to cover their tracks afterward, clearing Windows' Quick Access or Recently Accessed Files list. A companion 112-respondent survey found 33% of people who'd avoided getting a device repaired said privacy concerns were the reason — and the researchers' own interviews turned up technicians asking for device credentials even for repairs that never required booting into the account at all.
Not a 2022 fluke: the same pattern again in 2025
A separate, later investigation reached the same conclusion by a different route. In January 2025, Singapore broadcaster CNA's Talking Point program worked with the Greyhats student security group at the National University of Singapore to send 40 rigged phones and laptops in for repair with hidden screen-recording running. Technicians snooped in 12 of the 40 cases — 3 of the phone repairs, 9 of the laptop repairs — including attempts to open private accounts such as Snapchat, Gmail, and OnlyFans. In one case, a technician copied a customer's payslips, personal photos, and saved passwords onto a USB drive (reporting on the investigation). Different country, different researchers, three years later — and the proportion of technicians who couldn't resist looking barely moved.
Most repairs never actually need your files at all
The detail that makes both studies worse than "a few bad technicians exist" is how often the snooping had nothing to do with the job. A cracked screen, a swollen battery, a sticking key, a dead charging port — none of that requires the operating system to ever boot into your logged-in account, let alone open a photo folder. The Guelph researchers' own interviews found technicians asking customers for their device password even for repairs that plainly didn't call for it. Only a narrower category of repair — an intermittent freeze, a boot failure, a "my files disappeared" data-recovery job — genuinely requires the shop to have your account open and your files intact while they work. Knowing which category a given repair falls into is most of the practical decision here.
A realistic checklist before you hand the device over
For a hardware-only repair, the strongest move is also the simplest: back up anything sensitive, then actually delete it from the device before drop-off. If nothing sensitive is sitting on the drive, there's nothing left for anyone to browse, curious or not. For a repair that genuinely needs the OS booted and your files intact — the case both studies show is unavoidable sometimes — deletion isn't an option, so the file-level version of the same idea is to encrypt the specific sensitive files (tax returns, ID scans, financial records, private photos) with a passphrase before the device leaves your hands, while it's still fully working and in your possession. What's left sitting in that folder for a technician to open is then ciphertext, not the original document, regardless of whether their access to the account itself was ever really necessary. Either way, the passphrase itself travels nowhere near the device — not on a sticky note, not in a note-taking app that's still logged in on the same machine.
Where NearSeal fits, and where it honestly doesn't
NearSeal runs entirely in the browser — the file and the passphrase never leave the device, and there's no upload step for either, which matters here specifically because you're using it on the same device that's about to be handed to someone else, before it goes anywhere. Select one file or several at once (the file picker accepts multiple), and each one is encrypted individually — by default with a PBKDF2-SHA256-derived AES-256-GCM key, or with the interoperable age-encryption.org format if you'd rather the result open with a standard tool later — then bundled into a single zip if there's more than one. What NearSeal can't do is protect anything you didn't run through it: an unencrypted OS install, browser-saved passwords, cached email, or any file left in plaintext are exactly as exposed to a technician as they were before. It also can't turn a repair that genuinely needs your account open into one that doesn't — file-level encryption narrows what's readable inside that account, it doesn't remove the account access itself. What it does cover is the specific files most worth protecting from exactly the kind of browsing both studies documented.
The honest summary
Two field investigations, run independently, three years and one continent apart, found technicians opening personal files that had nothing to do with the repair they were asked to perform — 6 of 16 rigged devices in the first study, 12 of 40 in the second — and in both, some of them copied what they found onto their own devices. Most of that access wasn't necessary for the job at all. Removing sensitive files before a hardware-only repair closes that gap outright; encrypting the specific files that have to stay behind for a repair that genuinely needs your account open closes most of what's left. Neither step depends on trusting a shop's privacy policy, since — per the Guelph researchers' own field notes — most of the providers they tested didn't have one that addressed this at all.