Android is the opposite of the iPhone problem. On iOS, the sandbox is so strict that no app can scan the system, which is why iPhone virus scanners cannot do what their listings imply. On Android you are allowed to look in several of the places that matter, and most of them are ordinary settings screens you can open right now.
That openness is also why Android carries more stalkerware. Anyone who can unlock your phone for five minutes can install an app from outside the Play Store, grant it the permissions it needs, and hide its icon. No exploit, no jailbreak, no technical skill. Just your passcode and a few minutes alone with your device.
This guide covers what you can check yourself, in the order worth checking, and then the one thing that has to happen from a computer.
Before you start, if you think you know who is watching
If the person you suspect is a partner, an ex, a family member or an employer, read the safety section near the end of this article before you change a single setting. Some monitoring apps notify whoever installed them when they are disabled, and in a controlling situation that notification can make things worse. Nothing below is urgent enough to skip that.
How Android stalkerware actually works
Almost every commercial monitoring app on Android relies on the same three features. They are legitimate parts of the platform, built for real purposes, and they are the reason this software can watch nearly everything without exploiting anything.
Accessibility Services. Built so that screen readers can work, this permission lets an app see the content of your screen and observe what you type. That is exactly the capability keylogging requires. If you check one thing on this page, check this.
Notification access. Every notification your phone receives, including the full text of messages from apps the monitor cannot otherwise read, passes through this permission.
Device administrator. Intended for company phone management, this makes an app harder to uninstall and lets it resist removal.
A monitoring app with those three is not hiding in some dark corner of the operating system. It is sitting in your settings with your permission recorded next to it, because somebody granted that permission while holding your phone.
Seven checks you can do yourself
Menu names vary between Samsung, Pixel, Xiaomi and the rest. If a path below does not match your phone, open Settings and use the search box at the top with the words in bold.
1. Run Play Protect, then check whether it was switched off
Open the Play Store, tap your profile icon, then Play Protect, then Scan. It will flag known monitoring apps.
The more revealing detail is whether it was already disabled. Play Protect is on by default, it warns you when apps are installed from outside the Play Store, and switching it off is a deliberate act. If you find it turned off and you did not turn it off, somebody wanted an installation to go unnoticed.
2. Read your Accessibility list
Settings, then Accessibility, then look for downloaded or installed services. On a normal phone this list is empty, or contains tools you chose: a screen reader, a magnifier, a password manager, a launcher.
Anything here that you did not install deserves an explanation. Names are chosen to look boring on purpose, along the lines of System Service, Device Health, Update Manager, Sync Services or Accessibility Helper. A genuine system component will not appear in the downloaded section of this screen.
3. Check notification access
Settings, then Notifications, then Device and app notifications or Special app access, then Notification access. Same logic: anything you do not recognise with permission to read every notification on your phone is a serious finding.
4. Look at device administrator apps
Settings, then Security, then Device admin apps. Most personal phones show either an empty list or Find My Device. A work profile may legitimately show your employer's management tool. An unfamiliar app with device admin rights is both a red flag and the reason an uninstall attempt may have failed before.
5. Work through special app access
Settings, then Apps, then Special app access. The entries worth reading are Display over other apps, Usage access, Install unknown apps, and All files access. Monitoring software commonly needs several. Usage access in particular reveals which apps can see everything you open and for how long.
6. Find apps that are not on your home screen
An app can hide its icon, so scrolling your launcher proves nothing. Go to Settings, then Apps, then See all apps, and open the menu to show system apps. It is a long list and most of it is legitimate, which is why the two specific things to look for are:
- Two copies of something that should exist once, particularly a calculator, a file manager, a notes app or a system tool. A duplicate is a classic disguise.
- Any app whose name you cannot account for. Search the exact name before you panic, because almost everything in that list is normal, and then check its permissions.
While you are there, open the Play Store, tap your profile, then Manage apps and device, then Manage, and switch the filter to Not installed by Play Store. Sideloaded software is not automatically bad, but on a phone you never sideload to, every entry needs a reason.
7. Compare battery and data with how you use the phone
Settings, then Battery, then battery usage; then Settings, then Network and internet, then mobile data usage. You are looking for an app you never open near the top of either list, or background data that does not fit your habits.
Treat this as the weakest signal, exactly as you would on an iPhone. An ageing battery, a system update or a photo library syncing after a holiday all produce the same pattern. It is a reason to look closer, never a verdict.
Why an app on the phone cannot finish the job
Everything above is worth doing and it catches a lot of real monitoring. It has three limits that no scanner installed on the phone can get past.
Apps still cannot read each other. Android is more open than iOS about listing what is installed, but one app cannot read another app's private data. A scanner can tell you a suspicious package exists. It cannot open it and show you what has been collected.
Sophisticated software hides from the screens you just checked. Anything that gained root access can remove itself from app lists, hide from Play Protect, and survive an uninstall. Once a phone is rooted, the tools on the phone are no longer trustworthy witnesses.
You are asking the suspect for its own alibi. If the device is compromised at a deep level, every answer it gives you comes from software the intruder may control. That is the structural problem, and it is the same on every operating system.
What analysis from a computer adds
Connect the phone to a computer by USB and enable developer access, and an external tool can enumerate every installed package, read the system logs, and compare all of it against known indicators of compromise: package names used by commercial stalkerware, domains that monitoring software contacts, permission combinations that only surveillance needs.
The important part is where the analysis runs. The computer is not asking the phone to assess itself. It is reading the phone's contents and drawing its own conclusions, which is why this is the method used by the researchers who publish this work. Amnesty International's Security Lab maintains an open-source tool, the Mobile Verification Toolkit, that does exactly this for both Android and iOS.
It is also a command-line tool that expects you to install Python packages, pull an ADB backup and interpret forensic output. The method is sound and public; the distance between a worried person and a finished analysis is the problem. Closing that distance is what Haris Shield is for, with the same external analysis and a report written to be read rather than parsed.
If you find something, do not delete it yet
This is the part most guides get wrong, and it matters more than anything above.
If the person monitoring you is someone in your life, removing the app can be the most dangerous thing you do. Many products alert whoever installed them the moment monitoring stops. In an abusive or controlling relationship, that alert tells the other person you found it, at a moment you have not prepared for. The Coalition Against Stalkerware, which brings together domestic violence organisations and security companies, warns about this directly, and adds a second reason: deleting the app also deletes the evidence you may need if you involve the police.
A safer order:
- Change nothing on the phone yet, and do not confront anyone.
- Get advice first, using a device the other person has never had access to. A domestic violence organisation can help you plan the order of events.
- Document what you found. A forensic report carries more weight than a screenshot.
- Change passwords and turn on two-factor authentication from a different device, starting with your Google account.
- Decide about removal last, with support already in place.
If nobody in your life is a plausible source and this looks like ordinary crime, the calculus is simpler: update Android, remove what you found, change your Google password, sign out of unknown sessions, and consider a factory reset without restoring a backup that may reinstall the problem.
Making the phone a harder target
- Set a passcode nobody else knows and check that no extra fingerprints have been enrolled. Settings, then Security, then Fingerprint. Physical access is how nearly all of this starts.
- Leave Play Protect on and check occasionally that it still is.
- Install updates promptly, both Android and Google Play system updates.
- Do not root the phone, and do not let anyone do it for you.
- Review your Google account devices at myaccount.google.com, since a monitor with your Google password does not need an app on the phone at all.
- Be deliberate about family sharing. Ordinary location sharing, set up once and forgotten, accounts for a great deal of what people experience as being tracked.
The short answer
You can genuinely check an Android phone yourself, and you should: Play Protect, Accessibility services, notification access, device admin apps, special app access, the full app list including hidden entries, and battery and data patterns. That covers most commercial stalkerware, because most of it needs permissions that show up in those screens.
What it cannot cover is anything with root access, or anything that has taught the phone to lie about itself. For that you need analysis from outside the device.
And if you suspect somebody you know, get advice before you touch a setting. The detection is the easy half.
Sources
- Coalition Against Stalkerware, Information for survivors: stopstalkerware.org/information-for-survivors
- Amnesty International Security Lab, Mobile Verification Toolkit: mvt.re and github.com/mvt-project/mvt
- Google, Play Protect: support.google.com/googleplay/answer/2812853
- Electronic Frontier Foundation, Surveillance Self-Defense: ssd.eff.org
Related reading: how to detect spyware on iPhone, stalkerware signs and what not to do, and how to tell if your phone is hacked.