Most articles about phone surveillance are really about governments. This one is about the far more common case: monitoring software installed by somebody who knows your passcode.
The technical problem is the easier half. Stalkerware is not Pegasus. It does not need an exploit, it usually cannot hide from a determined search, and it leaves traces in ordinary settings screens. Finding it is often a ten-minute job.
The hard half is what you do next, and the honest answer is that deleting it immediately can be the worst available choice. That is what most guides get wrong, so it comes first here.
Read this before you search your phone
If the person you suspect has access to your home, your children, your finances or your safety, the sequence matters more than the scan.
Many monitoring products tell whoever installed them when they stop working. Disabling the app, revoking its permissions or factory resetting the phone can all send that signal. In a controlling relationship, the moment your monitoring goes dark is the moment the other person knows you found it, and that is a documented escalation risk rather than a hypothetical one. Domestic violence organisations plan around it for a reason.
Deleting the app also deletes the evidence. If you may involve the police, a lawyer, or a family court, what is on the phone right now is worth more than a clean phone.
Assume anything you do on that phone is visible. That includes reading this page, searching for help, and any message you send about it. If you need to research or ask for advice, use a device the other person has never had access to: a friend's phone, a work computer, a library terminal.
If any of that describes your situation, the right first step is not a scan. It is a conversation with people who do this professionally, from a device that is not being watched. The organisations at the end of this article exist for exactly this and the call is free.
What stalkerware is, and what it is not
Stalkerware, sometimes sold as parental control or employee monitoring, is commercial software that reports one person's phone activity to another person. Typical capabilities: messages from every app, call logs, location history, photos, browser history, keystrokes, and in some products the microphone and camera.
Two things separate it from the mercenary spyware that makes headlines.
It needs access, not an exploit. Somebody has to hold your unlocked phone for a few minutes, or know your Apple ID or Google password. That is the whole attack. It also means the list of possible people is short, and you probably already know who is on it.
It is often on the same phone bill as you. The person monitoring you may control the account, the family plan, the cloud storage, or the device itself. The technical problem sits inside a relationship, which is why the technical fix is rarely the first move.
If your concern is instead a government or a well-resourced attacker, the shape of the problem is different, and our guide to checking an iPhone for Pegasus covers that case.
How it gets onto a phone
- Physical access. By far the most common. Minutes with an unlocked phone is enough on Android. On iPhone it usually means installing a configuration profile or turning on a sharing feature.
- Your cloud account. No app is needed at all. Somebody with your Apple ID or Google password can read your backups, messages, photos and location from their own device. This is the most overlooked route and the hardest to notice.
- Legitimate features left switched on. Family location sharing, Find My, Google Family Link, screen time reports, shared calendars. Set up once during a happier period and never revisited, these are the single largest cause of people correctly feeling tracked with no malware present anywhere.
- A gifted or shared device. A phone bought and configured by somebody else may have had monitoring since the day you got it.
The signs, and how much each one is worth
No single sign proves anything. Several together, in a situation where someone had the access, are worth taking seriously.
Signs that carry real weight
- An app in your Accessibility services, notification access or device admin list that you did not install. On Android this is close to conclusive.
- A configuration profile on an iPhone that you cannot account for, in Settings, General, VPN and Device Management.
- A device signed in to your Apple ID or Google account that is not yours.
- Play Protect switched off on Android when you did not switch it off.
- The other person knowing things they had no ordinary way to know, particularly your location, or the contents of a private message.
Signs worth noticing but easily explained otherwise
- Battery draining faster than it used to.
- The phone feeling warm when idle.
- Higher data usage than you expect.
- The phone being slow, or restarting on its own.
Those four are what most articles lead with, and they are also what an ageing battery, a system update and a photo backup produce. Do not build your conclusion on them.
Checking an iPhone
The iOS sandbox means no App Store app can scan the system, so the checks are manual:
- Settings, General, VPN and Device Management. Empty is normal on a personal phone.
- Your Apple ID device list. Settings, your name at the top. Remove anything unfamiliar, keeping the safety warning above in mind.
- Settings, Privacy and Security, then Location Services, and separately the Microphone, Camera and Photos entries. Look for ordinary apps with extraordinary access.
- Find My, and any family sharing. Check who can see you.
- Search for Cydia, Sileo or Zebra. Their presence means somebody removed Apple's protections from the phone.
Our full walkthrough is in how to detect spyware on iPhone.
Checking an Android phone
Android lets you see more, and the three permissions that matter are all visible:
- Settings, Accessibility, downloaded services. This is where keylogging lives.
- Notification access, under special app access.
- Device admin apps, under Security.
- The full app list with system apps shown, looking for duplicates of ordinary tools and names you cannot place.
- Play Protect, including whether it was disabled.
The detailed version is in how to detect spyware on Android.
The five mistakes to avoid
1. Deleting it the moment you find it. The single most common and most dangerous reaction, for the two reasons at the top of this article.
2. Confronting the person. It ends any chance of documenting what happened, and in an abusive situation it raises the risk to you. Get advice first.
3. Factory resetting straight away. It destroys the evidence, it may alert the other person, and if you restore from a backup they control, you can reinstall the monitoring on the first day of your clean phone.
4. Changing passwords from the phone you suspect. If there is a keylogger on the device, you have just handed over the new password. Use a different device.
5. Researching it on the monitored phone. Searches, page visits and messages are exactly what this software reports. This page included.
A safer order of operations
- Get advice first, from a device the other person has never touched. Free, confidential, and staffed by people who handle this daily.
- Document before you change anything. A forensic report from an external analysis is worth considerably more than a photograph of a settings screen, and it is readable by a lawyer or an officer who is not technical.
- Secure your accounts from a different device, in this order: email first, because it resets everything else, then your Apple ID or Google account, then messaging and banking. Turn on two-factor authentication as you go, and check each account's list of signed-in devices and recovery addresses. A recovery email or phone number belonging to the other person hands the account straight back.
- Plan removal with support in place, and decide deliberately whether the phone gets cleaned, replaced, or left exactly as it is for now. Sometimes a second, private phone is the safer answer while the first one continues to look normal.
- Then clean the device, if that is still the right call: update the operating system, remove what was found, and reset without restoring a suspect backup.
Detection you can trust
There is a structural reason to analyse a phone from outside it. Any scanner running on the device is asking a possibly compromised system to report on itself, and anything with deep access can lie. Analysis from a computer over a cable does not depend on the phone's cooperation: it reads the phone's own contents and reaches its own conclusion, and it produces something you can hand to somebody else.
That is what Haris Shield does. It runs on your computer, examines the phone over USB, and produces a report suitable for a lawyer, an officer or a support worker rather than a screenshot of a settings page. Scanning is free; the full report is the paid part.
If you want the same class of analysis with no product involved, Amnesty International's Mobile Verification Toolkit is open source and well regarded, and it is what the researchers who publish this work actually use. It is a command-line tool.
Where to get help
- Coalition Against Stalkerware — guidance written for survivors, and a directory of member organisations: stopstalkerware.org
- National Network to End Domestic Violence, Safety Net — technology safety planning: techsafety.org
- Refuge (UK) — tech abuse support: refuge.org.uk
- Access Now Digital Security Helpline — free, for those at elevated risk: accessnow.org/help
- Electronic Frontier Foundation, Surveillance Self-Defense: ssd.eff.org
If you are in immediate danger, contact your local emergency number rather than working through a checklist.
The short answer
Stalkerware is easier to find than mercenary spyware, because it needs permissions that appear in ordinary settings screens: Accessibility services, notification access and device admin on Android; configuration profiles, account devices and sharing features on iPhone. The cloud-account route needs no app at all, and gets missed most often.
The scan is not the hard part. The order is. If somebody in your life may be behind it, get advice before you change a setting, document before you delete, and secure your accounts from a device that was never in their hands.
Sources
- Coalition Against Stalkerware, Information for survivors: stopstalkerware.org/information-for-survivors
- National Network to End Domestic Violence, Safety Net project: techsafety.org
- Amnesty International Security Lab, Mobile Verification Toolkit: mvt.re
- Electronic Frontier Foundation, Surveillance Self-Defense: ssd.eff.org