Calendar, Contacts and Reminders Databases on macOS
Where macOS stores Calendar events, Contacts (AddressBook .abcddb) and Reminders, and what they show about meetings, relationships and tasks.
- Location
- ~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendar
- Proves
- Who the user knew and how to reach them, which meetings and appointments existed, where and with whom, and which tasks were created or completed
- Timestamps
- Mac absolute time (seconds since 2001-01-01 UTC) in all three Core Data stores
- Access
- Owning user; each store is TCC-protected (Contacts, Calendars, Reminders), so the collector needs Full Disk Access
- Retention
- Until deleted locally or through sync; deleted items may persist briefly for sync and in WAL files
- Collection
- UAC, ditto, Disk image
Tools
Compare all tools- sqlite3CLI · built into macOS
- APOLLOCLI · open source
- plutilCLI · built into macOS
What it is
Calendar, Contacts and Reminders are three Apple apps backed by Core Data SQLite stores that mirror whatever accounts the user added: iCloud, Exchange, Google (CalDAV/CardDAV), or local "On My Mac" data. They are rarely the first artifact you pull, but they answer classic questions: who is this phone number, was there a meeting with that supplier, when was the "delete the files" task ticked off?
Because they sync, the Mac copy may contain entries created on a phone or by another person (shared calendars, invitations). Always identify the source account before attributing an entry to the user.
Where it lives
| Store | Path | Notes |
|---|---|---|
| Contacts (unified view) | ~/Library/Application Support/AddressBook/AddressBook-v22.abcddb | Core Data SQLite despite the extension |
| Contacts per account | ~/Library/Application Support/AddressBook/Sources/<UUID>/AddressBook-v22.abcddb | One store per account; the root store may be sparse |
| Contact images | .../AddressBook/Images/, .../Sources/<UUID>/Images/ | Photos by record ID |
| Calendar (older releases) | ~/Library/Calendars/Calendar Cache (+ Calendar.sqlitedb on some releases) | Core Data store and per-account folders |
| Calendar (recent releases) | ~/Library/Group Containers/group.com.apple.calendar/Calendar.sqlitedb | Reported from around macOS 14 Sonoma; check both locations |
| Reminders | ~/Library/Group Containers/group.com.apple.reminders/Container_v1/Stores/Data-<UUID>.sqlite | One store per account |
The version suffix of the Contacts file (-v22) has been stable for years but is not guaranteed; list the folder rather than hard-coding it.
What it proves
- Contacts: names, organisations, phone numbers, e-mail and postal addresses, notes and social profiles, with creation and modification times. Essential to resolve handles in Messages and Mail.
- Calendar: event titles, locations, start and end times, attendees and organiser, invitation status, alarms, attachments and URLs (video-conference links).
- Reminders: task titles, notes, due dates, completion flag and completion time, list membership, and sometimes location-based triggers.
Key fields
| Store | Table | Useful columns |
|---|---|---|
| Contacts | ZABCDRECORD | ZFIRSTNAME, ZLASTNAME, ZORGANIZATION, ZCREATIONDATE, ZMODIFICATIONDATE, ZNOTE (via ZABCDNOTE) |
| Contacts | ZABCDPHONENUMBER, ZABCDEMAILADDRESS, ZABCDPOSTALADDRESS | Value plus ZOWNER link to ZABCDRECORD.Z_PK |
| Calendar | CalendarItem (or Core Data Z* tables in older caches) | summary, start_date, end_date, location_id, calendar_id, has_attendees |
| Calendar | Participant, Location, Calendar | Attendee e-mail and status, place names, calendar and account |
| Reminders | ZREMCDREMINDER (older builds ZREMCDOBJECT) | ZTITLE, ZNOTES, ZCREATIONDATE, ZLASTMODIFIEDDATE, ZDUEDATE, ZCOMPLETED, ZCOMPLETIONDATE, ZLIST |
Schemas differ across releases, especially for Calendar. Start with .tables and PRAGMA table_info() rather than a saved query.
Timestamps
Dates are Mac absolute time (add 978307200 for Unix time). Calendar events also store a time zone per event; all-day events use floating dates that do not map to a single UTC instant. Modification times on synced items reflect the last change from any device on the account.
Retention
- Items persist until deleted. Deletions sync, so an entry removed on the phone disappears from the Mac at the next sync.
- Reminders keeps completed tasks unless the user clears them, which gives a useful history of finished work.
- Deleted rows may survive in
-walfiles, free pages, APFS snapshots and Time Machine.
Collection
sudo ditto "/Users/<user>/Library/Application Support/AddressBook" ./case/AddressBook_<user>
sudo ditto "/Users/<user>/Library/Calendars" ./case/Calendars_<user>
sudo ditto "/Users/<user>/Library/Group Containers/group.com.apple.calendar" ./case/calendar_gc_<user>
sudo ditto "/Users/<user>/Library/Group Containers/group.com.apple.reminders" ./case/reminders_<user>
UAC collects the AddressBook stores, metadata and images. Collect each database with its -wal and -shm files.
Parsing
-- Contacts with phone numbers
SELECT r.ZFIRSTNAME, r.ZLASTNAME, r.ZORGANIZATION, p.ZFULLNUMBER,
datetime(r.ZCREATIONDATE + 978307200, 'unixepoch') AS created_utc
FROM ZABCDRECORD r JOIN ZABCDPHONENUMBER p ON p.ZOWNER = r.Z_PK;
-- Completed reminders
SELECT ZTITLE, datetime(ZCOMPLETIONDATE + 978307200, 'unixepoch') AS done_utc
FROM ZREMCDREMINDER WHERE ZCOMPLETED = 1 ORDER BY ZCOMPLETIONDATE DESC;
APOLLO's KnowledgeC modules (for example knowledge_calendar_event_title and app activity for Calendar) add usage context on releases where KnowledgeC is populated.
Investigator tips
- Normalise phone numbers (strip spaces, country codes) before joining Contacts to Messages handles.
- A contact created minutes before a call or message exchange can matter; check
ZCREATIONDATE. - Calendar invitations include the organiser's address even when the user declined, which can place a person in a conversation.
- Account identifiers in each store tell you whether data came from a work Exchange account or a personal iCloud account, which affects scope and legal authority.