A man lands back home from holiday, is pulled aside at his own city's airport, and hands over his phone. He enters a passcode. The screen flickers, blanks, and restarts, and the phone is now empty. Months later, he isn't just on a watch list, he's facing federal charges, accused of destroying evidence. The twist is that he didn't smash the phone or throw it in a bin. He typed in a passcode, and the phone did exactly what its privacy software was designed to do.

This is the case of Samuel Tunick, and it has become a flashpoint for a question most of us never think about: who does the data on your phone actually belong to when someone in authority wants it?

What happened

In January 2025, Tunick, a resident of Atlanta, was returning to the United States from the Dominican Republic and passed through Atlanta's Hartsfield-Jackson International Airport. According to reporting on the case, border agents demanded access to his phone without a warrant. He entered a passcode, and the device wiped itself.

His phone was running GrapheneOS, a privacy-hardened version of Android. GrapheneOS includes a feature called a duress passcode: a second, decoy PIN you can set that looks and behaves like a normal unlock code, right up until you enter it, at which point it triggers an immediate and irreversible wipe of the device. There's no confirmation dialog and no visible sign of what it's doing. It exists for exactly the scenario where someone is being physically pressured to unlock a phone.

Prosecutors have since indicted Tunick under a federal law covering the destruction of property to prevent its seizure, alleging he knowingly deleted the phone's contents to stop the government taking control of it. His lawyers argue the encounter was mishandled from the start: that he was questioned without being read his rights, that repeated requests for a lawyer were denied, that the search was an unreasonable seizure, and that questions about illegal imagery were a pretext to probe his alleged links to protests against Atlanta's "Cop City" police training facility. As of writing, a judge is not expected to rule on the defence's motion until at least the end of October.

To be clear about what this article is and isn't. This is a look at a live legal case and what it says about device privacy. It is not legal advice, and it is not a suggestion that you should wipe a phone during a search. Obstructing or destroying evidence during a lawful search can carry serious consequences. The point here is the bigger picture, not a how-to.

Why this one hit a nerve

The reason this case travelled so far beyond privacy circles is the uncomfortable line it draws. A duress passcode is a legitimate, built-in safety feature. The people who rely on it most are journalists protecting sources, activists in hostile environments, and domestic-abuse survivors who could be forced to unlock a device by the very person they're escaping. Using a security feature that ships with the operating system is not most people's idea of a crime.

And yet the prosecution's framing is that entering that passcode was an act of destruction aimed at the state. Strip away the specifics and you're left with a genuinely hard question: is protecting your own data the same thing as obstructing an investigation? The law doesn't have a settled answer, which is precisely why this case is being watched so closely.

The border is a legal grey zone

Part of what makes this possible is that borders are where digital-privacy protections are at their thinnest. Inland, searching someone's phone typically needs a warrant. At many international borders, that bar drops sharply.

It isn't a US-only quirk, either. In the UK the mechanism is different but no friendlier: under Schedule 7 of the Terrorism Act, officers at a port or airport can demand that you hand over a device password, and refusing to comply is itself a criminal offence, with no requirement that you're actually suspected of anything. Different country, different statute, same underlying reality: the moment you're at a border, the device in your pocket is far more exposed than you might assume.

The thing people underestimate

Your phone isn't a phone. It's your email, your banking, your photos, your location history, your saved passwords, every account you've ever signed into, and a contact book that maps your entire social and professional life. Handing it over isn't handing over a device. It's handing over the master key to your identity, all in one place.

The lesson isn't "wipe your phone"

It's tempting to read a story like this and conclude the answer is a cleverer wipe trick. It isn't, and going down that road is how you end up as the test case. The more useful takeaway is quieter and applies to everyone, whether or not you ever go near a border: the risk comes from how much is concentrated on one device, and how much of it points straight back to the real you.

Every account wired to your real phone number and primary email address is another thread tying your whole digital life together. A single search, a single data breach, or a single leaked database can pull on one of those threads and unravel the rest, because they all trace back to the same two or three identifiers. The defence against that isn't a dramatic self-destruct button. It's data minimisation, spreading your identity out so that no single point of failure exposes all of it.

In practice that means a few unglamorous habits:

Privify is built around exactly this idea. It gives you unlimited email aliases and a private UK number, so the accounts and services on your phone aren't all hard-wired to your real identity. It won't change what happens at a border, but it means that far less of "you" is sitting in any one place, or behind any one screen, to begin with.

The bottom line

Samuel Tunick's case will be argued on its own facts, and whatever a judge decides won't settle the broader question overnight. But it's a useful jolt. It shows how aggressively device data is now pursued, how thin the protections are at the exact moments you're most exposed, and how a routine airport stop can turn a privacy feature into a criminal charge.

You can't control every rule you'll run into. What you can control is how much of your identity is bundled into a single device and a single real-world number and email. The less concentrated it is, the less any one search, breach or leak can ever take.

Spread your identity out

Email aliases and a private UK number, so your accounts aren't all wired back to the real you.

Get started with Privify →