How to detect stalkerware on your phone

  • WeThePurple
  • Se protéger
  • 6 min de lecture

Read the safety note first: removing monitoring software usually alerts whoever installed it. Where to look on Android and iPhone, why battery drain proves nothing - and why the commonest case is not an app at all, but a shared account working exactly as designed.

Stalkerware is software installed on someone's phone, by someone with physical access to it, to report back where they go and what they say. It is sold openly as parental or employee monitoring, and it is used overwhelmingly against partners and former partners. Unlike the tracking this site usually covers, it is not commercial and impersonal — it is aimed at one person, by someone who knows them.

Read this before you check anything. If you think a partner or ex has installed monitoring on your phone and you are afraid of them, do not remove it as your first move. Most of these tools alert whoever installed them when they are disabled, and the moment surveillance ends is a documented point of escalation in abusive relationships. Get advice first, from a device that person cannot reach — a friend's phone, a library computer, a work machine. A domestic-violence support service will help you plan the order of operations, and that order matters more than any technical step below.

The signs, honestly assessed. Battery draining faster, the phone feeling warm, higher data use, occasional sluggishness — all of these appear on every list, and none of them is worth much on its own. Phones age, apps update, batteries degrade. Treat them as reasons to look, never as proof.

The signal that actually means something is behavioural: the person knows things they should not know. Where you were, who you spoke to, what you said in a message. That is evidence about the situation rather than about the hardware, and it is the reason most people start looking in the first place.

On Android, monitoring apps need permissions they cannot hide entirely. Open your settings and look at accessibility services — legitimate tools for people with disabilities, and the standard route for software that wants to read your screen and your messages. Anything enabled there that you did not enable deserves an explanation. Then check device admin apps, which grant deep control and resist uninstallation, and your app list with *show system apps* turned on, because these tools use dull names like *System Service* or *Device Health*. Finally, confirm that Play Protect is switched on: it is not perfect, but it now flags a large share of commercial stalkerware.

On iPhone, an app doing this quietly is much harder, because the sandbox does not allow it without a jailbreak. The usual method is different and simpler: someone knows your Apple account password. With it, they can see your location, your photos and your backups from any device, with nothing installed on yours at all. Check Settings for devices signed into your account that you do not recognise, and look under General for a configuration profile or device management entry you did not add — that is the other route, borrowed from corporate device management.

Which points at the most important thing on this page. The common case is not exotic software. It is shared accounts and features working exactly as designed — a family location-sharing setting, a Find My link, a smart-home account, a phone plan with tracking included, a password that was shared when the relationship was good. Nothing was hacked, nothing was installed, and no scan will find any of it. Reviewing what you share, and with whom, finds more than any app sweep.

If you find something, resist the urge to delete it that minute. Photograph the screen — the app, the permission, the profile — because it is evidence, and it disappears the moment you remove it. Then plan the removal for a time and place that is safe, ideally with support in place. A factory reset with a new account rather than a restored backup is the reliable end state, since a restore can carry the problem back with it. Change your passwords from a device you trust, not from the one you suspect.

It should not fall to the person being watched to run this audit. It does anyway, and knowing where to look is the difference between a suspicion you cannot act on and a fact you can.

À lire aussi