

It’s all encrypted in storage. The decryption key is in the secure element / TPM chip, additionally protected by your PIN / password. Shutting it down unloads all encryption keys from memory.
Beware that US customs / immigration / border control can seize your phone and refuse entry.
It’s actually not, but the default services assume it. The protocol does not.
With DID:Web and no use of their DMs you can be 100% independent with only 3rd party code and only 3rd party servers