Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Mac & Apple Ecosystem · Stored in a Database

What He Cares Most About Is Exactly What a General Recovery Misses

His enquiry lists priorities and the last one explains the whole result. A machine showing a folder icon with a question mark, where a local firm fitted a new drive but "recovered very little from the old drive. I wish to recover as much as possible, particularly photos, music, and most importantly the very extensively used notes, which contained much original writing." Notes are not stored as files — which is why a recovery that found his photographs found none of them.

MediaInternal hard drive from a laptop of 2012 vintage — host firmware unable to locate a bootable system; prior recovery returning limited content; application database content required
Reported situationMachine crashing suddenly · host displaying a folder icon with a question mark · replacement drive fitted by a local provider · limited content recovered from the original · photographs, music and extensive notes required · notes described as the highest priority
Fault classFilesystem or boot structure damage with content present — application data held in databases rather than discrete files, and therefore missed by signature-based recovery
Equipment usedPrior recovery method inferred from what was and was not returned · application database locations enumerated as targets before general carving · imaged write-blocked under strict per-sector timeouts · databases recovered intact and their records extracted · output delivered on media readable by the original machine

The decode: why the notes were missed, and what the icon meant

What the question-mark folder means: the firmware searched attached storage for something bootable and found nothing it could start from. It is a statement about bootability rather than about the drive — the machine looked, and the answer was no. The drive may be entirely readable.

Why the previous recovery returned little: almost certainly signature carving — scanning for the recognisable opening bytes of known file types and writing out what follows. That finds photographs and music reliably, because those exist as discrete files with recognisable headers.

Why it found no notes: because there are no note files to find. Notes applications keep every note inside a single database — one file containing hundreds of records, structured internally. A carver scanning for note documents finds nothing, correctly, because none exist.

Why that is the crucial point for him specifically: the material he values most is the material a general recovery is least likely to return. Not because it is more damaged, but because it does not have the shape the method looks for.

What else is stored the same way, and it is a long list: mail, messages, contacts, calendars, browser history and bookmarks, and most applications that manage many small items. All of them live in databases, and all of them are invisible to carving while being perfectly recoverable if sought deliberately.

What the route actually is: locate the application's database in its known location within the user's library, recover that file intact, and extract the records from it. One file recovered correctly returns every note, which makes the notes considerably more recoverable than his photographs rather than less — provided somebody knows to look.

Why "recovered very little" may therefore understate what remains: if the previous attempt carved, everything database-held is still on the drive and untouched. The gap in what came back is a gap in method, not evidence of loss.

What matters practically about delivery: he wants the output readable on his own machine. That means specifying the delivery filesystem, which is worth agreeing rather than discovering.

On the bench

The prior recovery method was inferred from what was and was not returned — signature carving locating discrete files with recognisable headers, which returns photographic and audio content while finding no notes, since notes exist as records within a single database rather than as individual files. Application database locations were enumerated as targets before general carving, mail, messages, contacts, calendars and browsing data being stored identically. Databases were recovered intact and their records extracted.

The outcome

The prior method inferred from its output, application databases targeted specifically, and records extracted from recovered database files. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: your notes are not files. They are records inside a single database, so a recovery scanning for documents finds none — correctly, because none exist. Recovered deliberately, one file returns all of them.

Recovery that missed your notes, mail or messages

Ask specifically for the application databases — that's why they were missed. Notes, mail, messages, contacts, calendars and browser history aren't stored as individual documents; each application keeps everything in a single database file containing hundreds of records. A recovery that scans for recognisable file types finds your photographs and music reliably and finds no notes at all, correctly, because there are no note files to find. That makes them look lost when they're often more recoverable than anything else: one database recovered intact returns every record. Say what applications matter, and specify what filesystem you need the output on.

Recovery that returned photos and nothing else?
Ask about the databases — call Oxford Data Recovery on 01865 593000; prior method inferred from its output, application databases enumerated as targets, records extracted and delivered on media your machine reads.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.