Before any check on this page, one thing outranks all of them. The Coalition Against Stalkerware describes stalkerware as software that lets another person, often a partner or family member, secretly monitor and record a person's phone activity, and says installing it usually requires physical access to the device and the ability to unlock it. Whoever put it there is normally close to you. Malwarebytes states the consequence plainly: in situations involving domestic abuse, the removal of a stalkerware-type app could anger an abuser and further endanger a survivor.
The Coalition Against Stalkerware, founded in 2019 by ten partners including the Electronic Frontier Foundation, Avira and Malwarebytes, tells survivors that removing stalkerware, or making other significant changes, may be detected by the abuser and could increase the abuse and harassment, and that you should only attempt removal if you believe it is safe to do so. It recommends a safety plan built on a safer device, with help from a trusted survivor assistance program.
No single number belongs here, since readers are in different countries, but national domestic abuse services exist almost everywhere and the Coalition lists organisations by area. One more of its points: deleting the app deletes the evidence with it.
Most Android trouble arrives because somebody installed something they should not have. Stalkerware arrives because somebody else did, with the phone in their hand and the screen unlocked. If your real worry is pop-up adware or an APK you regret, the guide to spotting and removing Android malware covers Safe Mode, device admin and the greyed out Uninstall button.
Symptoms are weak evidence. The Coalition says a rapidly draining battery, data usage spikes, higher screen time and strange notifications may be a sign but do not have to be, and that some stalkerware runs with no side effects at all; the most common sign, it says, is the abuser's changes in behaviour. A warm phone is usually just a phone, and the battery drain guide starts with the per app breakdown.
Google says Play Protect checks Play Store apps before download, scans your device for potentially harmful apps from other sources, and may deactivate or remove them, at install and on a periodic scan.
Google Play's own policy on monitoring software is blunter. Play prohibits apps from monitoring another individual by collecting and transmitting personal and sensitive user data, unless the app is exclusively designed and marketed for parents monitoring their children, or for enterprise management of employees. Even then it cannot track anyone else, a spouse for example, with or without their permission, and it must show a persistent notification while running and a unique icon that clearly identifies the app.
So a permitted monitoring app announces itself twice over. Anything watching with no icon and no notification is not something Google Play permits, though software installed from outside the store is not bound by that policy at all. A policy is a rule rather than a guarantee, so a Play install is not on its own a clean bill of health.
Malwarebytes says many apps in the category it calls Android/Monitor do not reveal their presence to the user of the device, can be listed under another name, and can disguise themselves as banal apps, such as a calculator, a calendar, or system updates. Scrolling the app drawer proves nothing.
The grants that matter are not ordinary pop-up permissions, and they are not on one screen. Notification access, usage access and install unknown apps sit under Settings, then Apps, then Special app access, the page Android's documentation gives for permissions guarding particularly sensitive resources; manufacturers rename and move that screen, so if it is not under Apps on your phone, type Special access into the Settings search box. Nothing asks for these in a dialogue, so somebody chose each entry on the list. The two that matter most are elsewhere: accessibility under Settings, then Accessibility, and device admin with the security settings. The malware guide has the Pixel and Samsung paths for both, but it is written for removal, so settle the safety question at the top of this page before you switch anything off. Checking one screen and stopping misses exactly the two that find stalkerware.
Expect familiar names on these lists. A password manager, a launcher, a screen reader, a smartwatch companion or a car app can each hold one of these grants for an ordinary reason, so an entry is a question rather than an answer. Read all five, then widen the view with how to check what an app can access on Android.
Removing an app does not close an account. Google says you can check google.com/devices to see computers, phones and other devices where you are or were recently signed in to your Google Account. Do that from a device the other person has never held.
App passwords are the quiet one: Google describes one as a 16-digit passcode that gives a less secure app permission to access your Google Account, and says it revokes them when you change your Google Account password. That makes a password change one of the significant changes the Coalition warns can be noticed, so put it in the safety plan rather than ahead of it. Read the backup codes section of the two-factor guide first, then change passwords from the other device, using the password manager roundup.
Then look for a work profile you did not create: Google describes one as separating work apps from personal ones, set up by an IT administrator, with work apps marked by a briefcase badge. If nobody at your job set one up, the guide to running two accounts of the same app explains how one gets created without an employer.
The Coalition's guidance says the best way to get rid of stalkerware is to buy a new phone, while acknowledging that for many this may be expensive or unsafe, and that a factory reset is almost as effective.
The trap is the rebuild, and its advice there is one sentence worth following exactly: when re-installing apps on your device, make sure you only install the apps you actually need and use. Restoring everything in a single tap can hand back what you just removed. It also warns that an abuser may reinstall it, which is why its prevention advice is a phone that locks after 30 seconds.
The Coalition says good antivirus products should be able to largely detect stalkerware, and Avira and Malwarebytes are on its list of ten founding partners. What matters more is how scanners classify what they find.
Malwarebytes labels results Android/Spyware or Android/Monitor and says that because it believes in user choice, it is up to you whether to remove such an app: it flags rather than deletes. ESET makes the equivalent category optional, describing Detect potentially unsafe applications as an option you enable, covering commercial software including remote access tools and keyloggers. A clean result depends partly on where that switch is set.
Checked on 4 August 2026, none of Malwarebytes Mobile Security, Avira Security Antivirus and VPN, Norton360 Antivirus and Security or ESET Mobile Security Antivirus uses the word stalkerware in its description, and none carries a Contains ads label. The Android antivirus roundup compares twelve scanners.
Then the point this page opened on, from the other side. Malwarebytes says stalkerware-type apps can often reveal every action taken on a device, including whether a malware scan is run, and that if a scan could anger an abusive partner you should contact a support organisation first, from a safe device. Running one is a decision about a person rather than a phone.
Not if you are afraid of the person you suspect. Malwarebytes warns that stalkerware-type apps can often reveal every action taken on a device, including whether a malware scan is run. The Coalition Against Stalkerware advises contacting a survivor support service from a safer device first, and only removing anything if you believe it is safe.
Partly. Google says Play Protect checks Play Store apps before download, scans the device for potentially harmful apps from other sources, and may deactivate or remove them. Google also requires any permitted monitoring app on the Play Store to show a persistent notification while running and a unique icon. Software installed from outside the Play Store carries no such obligation.
No. The Coalition Against Stalkerware says unusual device behaviour such as rapid battery drain, data usage spikes and strange notifications may be a sign of stalkerware but does not have to be, and that some stalkerware runs with no such side effects.
Only once it is safe to do it. The Coalition Against Stalkerware says a reset may be unsafe for some survivors, that significant changes may be detected by the abuser, and that you should only attempt removal if you believe it is safe. Past that point it says the best way to get rid of stalkerware is a new phone and that a factory reset is almost as effective, with one catch in the rebuild: install only the apps you actually need and use, because restoring everything can put the monitoring software back.
Usually not. Malwarebytes labels stalkerware-type apps Android/Spyware or Android/Monitor and says that because it believes in user choice, it is up to you whether to remove one, so it reports rather than deletes. ESET documents Detect potentially unsafe applications as an option you enable, covering commercial software such as remote access tools and keyloggers.