To protect a phone from stalkerware, you work from a separate trusted device: secure your accounts first, audit what is installed and what permissions it holds, remove anything suspicious, then update or reset the phone and watch it afterwards. Most of the job takes 30 to 60 minutes if you know where to look, and you can do most of it without a technician.
One thing to sort out before you touch anything: if the person who installed it may still have access to your accounts, do not start on the phone you are worried about. Use a laptop or a phone that is not connected to those accounts. Deleting the app first can wipe out something a support organisation or a court would want to see, and a sudden change in behaviour on a monitored phone is a signal you probably do not want to send.
Table of Contents›
- What You Need
- How to Protect a Phone from Stalkerware: Step-by-Step
- Step 1: Confirm the warning and choose a safe time
- Step 2: Protect the accounts connected to the phone
- Step 3: Review installed apps and device permissions
- Step 4: Remove suspicious apps and settings to protect a phone from stalkerware
- Step 5: Restart and update the phone
- Step 6: Use a factory reset when removal is uncertain
- Step 7: Monitor the phone and get help if needed
- Common Mistakes
- Frequently Asked Questions
- Is antivirus software necessary to protect a phone from stalkerware?
- Is a factory reset enough to remove stalkerware from a phone?
- What are the warning signs that a phone has stalkerware on it?
- Can someone still monitor my phone after I reset it?
- What should I do if the phone is the only device I have?
What You Need
Gather these before changing a single setting:
- A trusted device. One that the person you are worried about has never touched and that is not signed into your Google or Apple account.
- The affected phone and its charger. A dead phone is an unhelpful phone.
- Your account credentials, written down or stored on the trusted device. If you changed them from the monitored phone before, assume they are compromised.
- A recent backup, if one exists and you know when it was made. Backups can carry the problem forward, so this is optional and not always a good idea.
- A written record. Dates, times and specific things someone said or did that they should not have known. Write it on paper, not on the phone.
If you are checking someone else’s phone because they asked you to, they need to know you are doing it, and you should keep your own device out of reach of the person being checked.
How to Protect a Phone from Stalkerware: Step-by-Step

Work through these in order. Each step tells you what to do on both Android and iPhone, and how you can tell whether it worked.
Step 1: Confirm the warning and choose a safe time
Start by working out whether you have a confirmed problem or a worrying sign. A store warning about an app, an unfamiliar name in your app list, or a friend telling you someone’s location is a reason to check. A single odd sign, such as a warm phone or faster battery use, is not proof.
Signs worth taking seriously, especially in combination:
- Someone knows your location, schedule, or plans you never shared.
- Photos or messages arrive on a device you do not recognise, or one linked to an account you did not create.
- An app has device administrator or accessibility access that you never granted deliberately.
- Battery and mobile data use climb steadily with the screen off and nothing running.
- A security app disables itself, or logins behave strangely, such as a first sign-in attempt failing on a service you have used for years.
Battery drain on its own usually means something else, so treat it as a reason to look rather than as a verdict.
How to tell it worked: you can name the specific sign that triggered the check, in writing, with a date.
Step 2: Protect the accounts connected to the phone
Do this from the trusted device. Your email is the master key: if someone has read it, they can reset every other password.
- Sign in to your primary email from the trusted browser, review the recovery address and recovery phone number, and change the password to something long and unique.
- Sign out every other session. Gmail does this under Security, and Outlook does it under Account security.
- Turn on two-step verification, ideally with an authenticator app rather than SMS alone.
- Open the account security pages for your Apple ID or Google account. Remove devices you do not recognise, and check for passkeys and third-party connections granted to apps you did not install.
- Change the password on your banking, email, and social accounts, then check each one for forwarding rules and filters you did not set up.
How to tell it worked: your email account shows only one active session, your own devices, and no forwarding rules you cannot explain.
Step 3: Review installed apps and device permissions
This is the step that usually finds the problem. Read the list with fresh eyes rather than scrolling past the familiar names.
On Android:
- Open Settings and choose Apps, then See all apps. Sort by Recently installed or App install time, so new arrivals sit at the top.
- Go to Security, then Device admin apps. Anything there can uninstall other apps and wipe the phone. If a name means nothing to you, that is a finding.
- Open Accessibility, then Installed services. Accessibility access lets an app read what is on screen and tap on your behalf, which is the permission stalkerware needs most.
- Open Google, then Play Protect, then Scan to confirm Play Protect is on. An antivirus app that quietly switched itself off points at admin-level software.
- Open Apps, then Special app access, then Install unknown apps. Remove any app allowed to install files, since sideloaded malware arrives that way.
On iPhone:
- Open Settings, then General, then VPN and Device Management. An unfamiliar profile is a management tool and deserves to be removed.
- Open Settings, then Screen Time. Check the devices listed under your Apple ID and remove anything unexpected.
- Open Settings, then your name at the top, then Devices, and remove any handset or accessory you do not use.
- Look for a second app store such as AltStore or Cydia. Finding one usually means the phone is jailbroken.
How to tell it worked: you can explain the purpose of every app with admin, accessibility, or management access.
Step 4: Remove suspicious apps and settings to protect a phone from stalkerware
Now act on what you found. Take screenshots of anything relevant first if you intend to report this, since uninstalling an app removes it from view.
- Uninstall unfamiliar apps from Settings, Apps, then the app, then Uninstall.
- Revoke device administrator access first on Android, or the uninstall will fail or the app will reinstall itself.
- Switch off accessibility services you cannot account for.
- Delete suspicious VPN or configuration profiles on iPhone through General, then VPN and Device Management.
- Clear the browser if you tapped a link that triggered a download, and delete the downloaded file.
If abuse is suspected, keep the phone as it is and ask a specialist organisation how to preserve the evidence instead of cleaning it.
How to tell it worked: the app no longer appears in the list, and no new one has appeared after a restart.
Step 5: Restart and update the phone
Restart it, then install every pending system update from the manufacturer’s settings menu rather than from a link in a message. Updates close known holes that stalkerware relies on.
How to tell it worked: the warning or the odd behaviour does not come back once the phone has been idle for a day or two.
Step 6: Use a factory reset when removal is uncertain
A reset is the cleanest practical answer when you cannot tell what was installed, or when the same app keeps returning. Before you do it, decide whether a backup helps or hurts, because restoring a backup can bring the problem back with it.
On Android, open Settings, then System, then Reset options, then Erase all data or Reset phone. On iPhone, open Settings, then General, then Transfer or Reset iPhone, then Erase All Content and Settings.
Set the phone up without signing back into an account that the other person could reach. Do not treat a reset as proof of anything: it removes most known software, but no consumer action guarantees a clean device, and confirmation takes professional forensic analysis.
How to tell it worked: after setup, the admin and accessibility lists are empty, no management profile appears, and behaviour stays normal.
Step 7: Monitor the phone and get help if needed
For the next few weeks, check account activity from the trusted device, watch for a returning warning, and keep anything essential on a device the other person has no access to. If monitoring appears tied to immediate danger, contact a domestic violence or survivor support service, local law enforcement, or the Coalition Against Stalkerware before you make further changes.
How to tell it worked: nothing new appears over several weeks, and your accounts show only your own sessions.
Common Mistakes
Deleting the app before making a safety plan. It removes the visible warning and may remove the evidence. Contact a support organisation first if that applies to you.
Changing passwords on the suspect phone. The person monitoring it may see the notification or the reset email. Use another device.
Installing random security apps you found in a search ad. Many of them are just as invasive as what you are removing. Stick to Google Play Protect on Android, or a well-known scanner for iPhone such as iMazing, and treat a clean result as reassurance rather than proof.
Ignoring accessories and shared sessions. A watch paired to the phone, a shared cloud login, AirPlay, or a smart speaker at home can explain what looks like a phone app. Check paired devices in your account settings too.
Restoring the same backup after a reset. If the backup carried the problem, you have undone the reset. Restore only what you know is clean, and nothing at all if you are unsure.
Treating a factory reset as a clean bill of health. No home check proves it. A professional examination is the only real confirmation.
Confronting a suspected abuser on your own. Read the messages before you send them, and have support lined up. Knowledge of the monitoring can change how someone behaves.
Underestimating an exposed passcode. Forum accounts of phone monitoring repeatedly describe someone using an unlocked phone while its owner slept or left it unattended. After any period where that happened, treat the passcode as known and change it.
Frequently Asked Questions
Is antivirus software necessary to protect a phone from stalkerware?
No. Google Play Protect runs by default on Android and covers ordinary malicious software. Purpose-built stalkerware is designed to avoid it, so a clean scan means little either way. Use a reputable free scanner only for reassurance, and remember that consumer scans are not forensic proof. Only a professional examination can confirm what was on the phone.
Is a factory reset enough to remove stalkerware from a phone?
A factory reset removes the great majority of known monitoring software, but it is not a guarantee. Some tools survive a reset through linked accounts or reinstalled profiles, and some abuse happens through account sessions rather than the phone itself. Do not sign back into an account another person could reach, and consider a professional examination if you need certainty.
What are the warning signs that a phone has stalkerware on it?
The strongest sign is behavioural: someone knows details they could only get from the phone, or names and photos you never shared. Other clues include unfamiliar apps with admin or accessibility access, an unexpected VPN or device management profile, a second app store, steady battery and data use with the screen off, and security apps turning themselves off. A single battery warning on its own is weak evidence.
Can someone still monitor my phone after I reset it?
It is possible if monitoring works through your accounts rather than the phone itself. If someone has your email password they can reset your other passwords, and a shared Apple or Google account keeps location sharing alive. That is why you change passwords from a trusted device, remove unknown sessions, enable two-step verification, and check paired devices before signing back in.
What should I do if the phone is the only device I have?
Borrow one if you can, even an old handset or a computer in a library or community centre, and do your account work there first. If no other device exists, keep the investigation basic: check the settings lists, note what you find, and contact a survivor support service before uninstalling anything. Support workers can often arrange access to a safe device and help with a plan.
If you take one thing from this, do not start on the phone you are worried about. Start from a trusted device, secure your email, then work through the app and permission lists in order. And if being monitored could put you in danger, talk to a support organisation before you change anything on the phone itself.


