AWS S3 Integration for Mobile App File Storage
Imagine: your app generates thousands of user photos. Storing them in the database is a direct path to performance degradation. Routing through your own backend wastes resources on an extra hop and pays for traffic twice. AWS S3 with presigned URLs solves this elegantly: the client uploads directly to S3, and the backend only issues a temporary token. With over 50 AWS projects completed over a decade, we guarantee reliability and security.
Why Integrate AWS S3 into a Mobile App?
Modern mobile apps actively work with media files: avatars, images, documents, videos. Storage on the device is limited and unreliable. Your own file server is expensive and hard to scale. AWS S3 provides fault-tolerant object storage with global availability and low cost—just $0.023 per GB for the first 50 TB. Additionally, you can use lifecycle rules to automatically delete temporary files, saving up to 30% of costs under active usage.
How Upload via Presigned URL Works
The standard scheme involves three steps:
-
Request: The mobile client requests a presigned URL from the backend.
-
Upload: The client performs a PUT request directly to S3 using that temporary URL.
-
Confirm: The client notifies the backend of completion.
The backend never sees the file bytes—only metadata. This reduces load and simplifies security.
Example Code for iOS
// iOS: upload via presigned URL without SDK—using URLSession
let presignedURL = URL(string: urlFromBackend)!
var request = URLRequest(url: presignedURL)
request.httpMethod = "PUT"
request.setValue("image/jpeg", forHTTPHeaderField: "Content-Type")
let uploadTask = URLSession.shared.uploadTask(with: request, fromFile: localFileURL) { data, response, error in
guard let httpResponse = response as? HTTPURLResponse,
httpResponse.statusCode == 200 else {
// retry with exponential backoff
return
}
// Notify backend of successful upload
self.confirmUpload(fileKey: fileKey)
}
uploadTask.resume()
On Android via OkHttp or Retrofit—similarly. The key is to include the Content-Type header: S3 checks it matches what was specified during presigned URL generation. A mismatch gives 403.
Typical Problems and Their Solutions
The table below describes common errors and how to avoid them.
| Problem |
Solution |
| Presigned URL expires before upload |
Generate the URL immediately before the PUT request, not when opening the picker |
| CORS errors for web access |
Configure CORS policy on the bucket—browsers block requests without it |
| Large file uploads (>=5MB) |
Use Multipart Upload via API CreateMultipartUpload → UploadPart → CompleteMultipartUpload |
| Insufficient access permissions |
Configure IAM role with minimal permissions for specific prefixes (s3:PutObject) |
| Network errors during upload |
Implement exponential backoff with retries |
For multipart upload on Android, Amplify Storage is convenient as it automatically splits the file into parts, improving reliability for files over 100 MB.
// Android: using Amplify for automatic multipart
Amplify.Storage.uploadFile(
StoragePath.fromString("uploads/${userId}/${filename}"),
localFile,
StorageUploadFileOptions.builder()
.contentType("video/mp4")
.build(),
progress -> Log.i("Upload", "Progress: ${progress.fractionCompleted}"),
result -> confirmUpload(result.path),
error -> handleUploadError(error)
)
How to Configure Lifecycle Rules for Cost Savings
Lifecycle rules allow you to automatically move files to Glacier or Deep Archive after a certain period, then delete them. For example, set a rule to delete files older than 30 days. This reduces storage costs by up to 70% for unused data. On average, apps save $0.05 per GB per month with lifecycle policies.
Comparison: Direct S3 Access vs CloudFront CDN
For media files used by many users, consider putting CloudFront in front of S3. It caches content at edge nodes, reducing latency and origin load. CloudFront reduces latency by up to 90% compared to direct S3 access (10–50ms vs 200–400ms). It also improves security via signed URLs, though costs about 15% more per GB of traffic.
| Parameter |
Direct S3 |
S3 + CloudFront |
| Latency |
High for remote regions (200–400ms) |
Low (10–50ms from nearest edge) |
| Security |
S3 presigned URL |
CloudFront signed URL |
| Cost |
Cheaper traffic within same region |
More expensive, but caching saves traffic |
| Geo-distribution |
Only bucket region |
Global via 400+ points |
For presigned URLs with CloudFront, use CloudFront Signed URLs, which require their own key signing.
What's Included in the Work
We offer a full integration cycle:
- Requirements analysis and file storage schema design
- IAM role and bucket policy configuration with least privilege
- Upload/download via presigned URL on iOS/Android
- Backend integration (endpoints to issue URLs)
- CloudFront setup for media files
- Lifecycle rules configuration for cost optimization
- Performance and security testing
- Documentation and developer training
Timelines and Cost
Basic integration (one platform, presigned URL, no CDN): 3–5 days at $500. Full implementation with multipart, progress tracking, retry, lifecycle rules, CloudFront: 2–3 weeks at an average of $2,500. Cost is calculated individually—precise estimate after analyzing your requirements. Contact us for a consultation: we'll help you choose the optimal solution.
Order integration and get a reliable file storage system with minimal maintenance costs. AWS S3
How to Choose a Local Data Storage Solution (Room, Core Data, Realm, Isar)?
We've all seen the scenario: the app loses data when the network drops — and it's not just a bug, it's a failure of the use case. The user fills out a form, taps "Submit", gets a timeout, and loses everything. Or worse: data gets sent twice due to incorrect retry logic. A properly chosen and configured storage layer solves this problem once and for all. The wrong choice can cost teams months of rewriting code and up to 70% of time spent on synchronization. Our experience — 10+ years in mobile development, over 50 projects with offline storage — confirms: the storage choice determines 80% of future performance and synchronization issues.
In practice, storage selection is driven by two factors: data type and synchronization requirements, not library popularity.
Room (Android) — a wrapper over SQLite with compile-time verification of SQL queries. If a query is invalid, the build fails — better than a SQLiteException at runtime. Room integrates well with Kotlin Flow and LiveData, making reactive UI updates straightforward. The main challenge is schema migrations. @Database(version = N, exportSchema = true) with migration files in assets/databases/ is mandatory; otherwise, fallbackToDestructiveMigration() will simply delete the user's data on app update.
Core Data (iOS) — not a database, but an object graph management framework over SQLite (or XML, or in-memory). NSPersistentContainer with viewContext for reading on the main thread and newBackgroundContext() for writing is the basic setup. The trouble begins when a developer calls save() on viewContext from a background thread: EXC_BAD_ACCESS at a random moment, happens once a week, with almost nothing useful in the crash log. You must use performAndWait or perform for each context strictly on its own thread. Apple Core Data Programming Guide recommends this approach.
Realm wins where you need speed with large object sets and built-in reactivity through Results + observe(). Realm stores objects directly without ORM mapping, so reads require no deserialization. According to our measurements, Realm processes reads 2–3 times faster than Core Data for volumes over 10,000 objects. On Flutter, the Realm SDK (ex-MongoDB Realm) supports Device Sync — but that's a managed service with separate infrastructure.
Hive and Isar are Flutter-specific solutions. Hive is a key-value store, fast, simple, suitable for settings and caches. Isar is a full document-oriented database with indexes, written in Rust, compiled to native code. For Flutter apps with offline functionality, Isar is now preferred: built-in query builder with type-safe filters, transactions, watchObject/watchQuery for reactivity.
| Platform |
Solution |
Reactivity |
Synchronization |
| Android |
Room + Flow |
LiveData/Flow |
WorkManager |
| iOS |
Core Data |
NSFetchedResultsController |
CloudKit |
| Flutter |
Isar |
Streams |
Custom / Realm Sync |
| Cross-platform |
Realm |
RealmResults.observe |
Device Sync |
| Flutter (simple) |
Hive |
ValueListenable |
None |
Contact us for a free audit of your current storage and optimization recommendations — this will save you hundreds of development hours and up to 60% of server request traffic.
Why Is Offline Synchronization the Hardest Part?
Local storage itself is not complicated. The complexity lies in synchronizing with the server in the presence of conflicts.
The most common pattern is optimistic updates with rollback. The user edits a record, the UI reflects the change instantly, a background request goes to the server. If the server returns an error, we roll back the local state. Sounds simple. In practice: if the user has left the screen and returned before the rollback (which may take 3 seconds), the UX is broken. You need an explicit operation queue with states (PENDING, SYNCED, FAILED) in a separate table.
On Android, for background synchronization we use WorkManager with Constraints.Builder().setRequiredNetworkType(NetworkType.CONNECTED). Don't forget setInputMerger(ArrayCreatingInputMerger::class) when batching tasks — otherwise, concurrent runs will overwrite data. A typical operation queue implementation:
class SyncWorker(context: Context, params: WorkerParameters) : CoroutineWorker(context, params) {
override suspend fun doWork(): Result {
val pendingOps = syncDao.getPendingOperations()
for (op in pendingOps) {
try {
apiClient.send(op.payload)
syncDao.markSynced(op.id)
} catch (e: Exception) {
syncDao.markFailed(op.id, e.message)
return Result.retry()
}
}
return Result.success()
}
}
On iOS, the equivalent is BGTaskScheduler with BGProcessingTaskRequest. iOS limitations on background execution time (~30 seconds for refresh tasks) mean that synchronization must be incremental: not "sync everything," but "sync the next N records, save the cursor."
Conflicts in multi-device scenarios are resolved with one of three approaches:
- Last-write-wins based on
updated_at (simplest, loses data on concurrent edits)
- Server-wins (client always accepts server version)
- Three-way merge (complex, requires a common ancestor — suitable for documents)
For most B2C apps, last-write-wins with a user-level time vector is sufficient, but for collaborative editing, a CRDTs approach is needed — then look at Automerge or Yjs with mobile bindings.
How We Build the Storage Layer
The repository pattern is not optional — it's mandatory. UserRepository doesn't know where the data comes from: Room, Realm, or network. The ViewModel calls repository.getUser(id), gets a Flow/Stream, and displays data. Caching logic resides inside the repository.
For Flutter, a typical architecture: Isar for persistence, Riverpod for state management, ConnectivityPlus for network status, and a custom SyncService with an operation queue. Riverpod's AsyncNotifier conveniently covers the logic of "show cache, update from network, show new data." Example repository with caching:
class UserRepository {
final Isar isar;
final ApiClient api;
Future<User> getUser(String id) async {
// try from local storage first
final cached = await isar.user.where().idEqualTo(id).findFirst();
if (cached != null) return cached;
// otherwise from network
final remote = await api.fetchUser(id);
// save locally
await isar.writeTxn(() => isar.user.put(remote));
return remote;
}
}
Another important topic is encryption. If the app stores medical data, payment cards, or corporate documents, SQLCipher (Android) and NSFileProtection (iOS) are not optional. Realm supports encryption natively via a 64-byte key that must be stored in Keychain/Keystore, not in SharedPreferences. Skimping on security can lead to data leaks with serious consequences.
What the Work Includes
We guarantee a transparent process and document each stage:
| Stage |
Result |
| Requirements audit |
Document analyzing data types, volumes, synchronization scenarios |
| Schema design |
ER diagram, migration files, conflict resolution plan |
| Repository layer development |
Code with unit tests (in-memory DB + network mocks) |
| Synchronization integration |
Operation queue, error handling, fallback logic |
| Profiling and optimization |
Report from Android Profiler / Core Data SQLDebug, recommendations |
| Deployment and documentation |
Deployment instructions, API description, repository access |
Want to avoid common mistakes when designing storage? Contact us — we'll help design a reliable local storage from scratch or improve an existing one.
Stages of Work
We start with a requirements audit: what data, what volume, is synchronization needed, are conflicts possible. At this stage, it becomes clear whether Core Data or an SQLite-based solution is needed, whether Realm Sync is required or simple REST polling will suffice.
Next, we design the schema with migrations in mind. Schemas change in any project — the question is not "will there be migrations," but "how painful will they be." We export the schema as JSON, store it in the repository, and write tests for each version's migration.
Development includes unit test coverage for the repository layer: network layer mocks, a real in-memory database for query testing. Before release, we profile queries using Android Profiler (Database Inspector tab) or Core Data debug flags (-com.apple.CoreData.SQLDebug 1).
The implementation timeline for a storage layer with basic offline synchronization ranges from 2 to 6 weeks, depending on schema complexity and conflict resolution requirements. Contact us to get a consultation on choosing the optimal stack and migrations.