Someone going through a divorce or breakup may have an unsettling suspicion: their former partner seems to know where they have been, who they have contacted or what they have been doing on their phone.
That does not necessarily mean the ex is an expert hacker.
In many cases, the explanation may be an old password, shared account, connected device or location-sharing permission that was never removed when the relationship ended.
Actual spyware, sometimes called stalkerware, is also possible. Some monitoring apps can secretly collect a phone’s location, messages, photos, call information and other activity.
Before searching the phone or changing any settings, however, there is an important safety warning.
If you believe a current or former partner is monitoring your phone, do not immediately begin deleting apps, removing devices or changing every password.
Cutting off access may alert the person doing the monitoring. In an abusive relationship, that person could escalate their behavior. Deleting an app or resetting the phone could also destroy evidence that might be useful to police, an attorney or the courts.
The Safety Net Project of the National Network to End Domestic Violence recommends considering personal safety and evidence collection before attempting to remove suspected stalkerware.
Whenever possible, use a different phone, computer or tablet that the other person has never been able to access. From that safer device, contact someone you trust, a domestic-violence advocate, an attorney or law enforcement.
Take screenshots or photographs of suspicious devices, account activity, apps, permissions, messages and alerts before changing anything.
There is no single warning sign that proves a phone has been compromised. However, possible clues include:
- A former partner knows your location when you did not tell them.
- Someone knows details from private messages or conversations.
- You receive notices about account logins you do not recognize.
- You find unfamiliar phones, tablets or computers connected to an account.
- Location sharing is turned on with someone unexpectedly.
- An unfamiliar app has powerful access to the phone.
- The phone’s battery begins draining unusually fast.
- Mobile data use increases for no apparent reason.
- The phone becomes unusually warm when it is not being used.
- Settings or passwords change without your knowledge.
Some of those symptoms can have innocent explanations. An aging battery, a malfunctioning app or an old device can look suspicious without being evidence of spying.
The best approach is to methodically check accounts, connected devices, location-sharing settings and app permissions.
- Open Settings.
- Tap your name at the top of the screen.
- Scroll down to see the devices connected to your Apple Account.
- Tap each device for more information.
You may see an old iPhone, iPad, Mac, Apple Watch or other device that you still own or previously used.
An unfamiliar device deserves closer attention, but do not assume that it proves someone is spying. Make a record of the device before removing it.
Apple also allows users to review connected devices, trusted phone numbers and other account security information through its Safety Check feature.
Google users can review phones, computers and other devices that are signed into their accounts.
- Open Settings.
- Tap Google.
- Choose Manage your Google Account.
- Tap Security or Security and sign-in.
- Find Your devices or Manage all devices.
The wording may differ slightly depending on the phone and version of Android.
Review each device and note anything you do not recognize. An old phone, television, tablet or computer may still appear even if you no longer use it.
Do not remove suspicious devices until you have documented them and considered whether doing so could create a safety risk.
Apple’s Safety Check is one of the most useful tools for someone concerned about unwanted access or sharing.
Safety Check is available on iPhones running iOS 16 or later.
- Open Settings.
- Tap Privacy & Security.
- Scroll down and select Safety Check.
Safety Check provides two main options.
This allows you to review information being shared with individual people and apps. It can also help you inspect devices connected to your Apple Account.
Emergency Reset can quickly stop sharing with people and apps. It also allows you to review account security, connected devices, trusted phone numbers and your Apple Account password.
Emergency Reset is powerful, but using it could immediately alert someone who suddenly loses access to your location or information. Consider your safety before selecting it.
Google Location Sharing can allow another person to see your real-time location.
To review it on many Android phones:
- Open Settings.
- Tap Location.
- Select Location services.
- Tap Google Location Sharing.
You can also check through Google Maps:
- Open Google Maps.
- Tap your profile picture.
- Select Location sharing.
Google allows users to see who can access their location and stop sharing with specific people.
Again, stopping location sharing could be noticeable to the other person. Document the setting and consider personal safety before changing it.
Location may also be shared through apps that have nothing to do with Apple or Google’s main location-sharing tools.
- Snapchat
- Facebook Messenger
- Life360
- Find My
- Family tracking apps
- Fitness apps
- Vehicle apps
- Wireless carrier family-location services
Also consider physical tracking devices. Someone may be using an AirTag, another Bluetooth tracker or a tracking system built into a vehicle rather than monitoring the phone itself.
Review which apps have access to your location and whether that access is allowed all the time, only while using the app or never.
Most ordinary iPhone users will not have a configuration profile installed.
- Open Settings.
- Tap General.
- Select VPN & Device Management.
You may see a profile installed by an employer or school. A work-managed phone may also have legitimate mobile-device management software.
If you see a profile you do not recognize, take a screenshot or photograph of it before doing anything else.
Do not assume that an empty VPN and Device Management screen proves the phone is safe. Not every form of unwanted access will appear there.
Android phones provide apps with different levels of access. Monitoring software may attempt to obtain powerful permissions that allow it to observe activity or prevent its removal.
The exact menu names vary by manufacturer, but search the phone’s Settings app for the following:
Device administrator access can give an app additional control over the phone and may make it harder to uninstall.
Accessibility services are designed to help people use their phones. However, a malicious app may abuse this permission to read information on the screen or observe what the user is doing.
An app with notification access may be able to read the contents of incoming notifications, including portions of messages.
Check which apps are allowed to install software from outside the Google Play Store.
Apps with usage access may be able to see which other apps are being opened and how often they are used.
A suspicious VPN may be able to redirect or observe portions of the phone’s internet traffic.
Review every app with permission to use the phone’s location, microphone or camera. Pay particular attention to apps allowed to use those features in the background.
An unfamiliar permission is a reason to investigate, but it is not automatic proof of spyware.
An app can be removed from the home screen without being uninstalled.
On an iPhone, swipe through the App Library or open:
Settings > General > iPhone Storage
This displays the apps installed on the phone.
Then choose the option to view all installed apps.
Look for apps you do not recognize, especially those with generic names or icons. Some monitoring apps may attempt to disguise themselves as system services, security programs or ordinary utilities.
Do not immediately delete a suspicious app if doing so could alert an abusive partner. First document its name, icon, permissions and storage information.
The phone itself may be secure while an email or social media account remains compromised.
Review recent login activity for:
- Email accounts
- Snapchat
- TikTok
- Microsoft accounts
- Cloud storage services
- Wireless carrier accounts
- Banking and payment apps
Also check whether an unfamiliar email address, phone number or authentication method has been added as a recovery option.
An ex who knows the password to the primary email account may be able to reset passwords for many other services.
Someone with access to an email account may set up automatic forwarding so copies of incoming messages are quietly sent elsewhere.
Review the forwarding, filter and rule settings for each important email account.
Also inspect the Sent, Trash and Deleted folders for security alerts or password-reset messages you did not initiate.
Couples sometimes share a password manager, browser profile or computer.
Check whether passwords are being synchronized through:
- Apple iCloud Keychain
- Google Password Manager
- Chrome
- Microsoft Edge
- Safari
- A third-party password manager
Creating a new password will not provide much protection if it is automatically synchronized to a browser or device the other person still controls.
When it is safe to make changes, use a phone or computer that you believe has not been compromised.
Start with the primary email account because it may be used to reset passwords for nearly everything else.
- The Apple Account or Google Account
- Wireless carrier accounts
- Banking and payment accounts
- Social media
- Cloud storage
- Important shopping and delivery accounts
- Password managers
Use a different password for every important account.
Turn on two-factor authentication when available. An authenticator app or physical security key is generally stronger than relying only on text messages, particularly if another person has access to the cellular account.
Review trusted phone numbers, recovery addresses and backup authentication methods. Otherwise, someone may be able to regain access after the password is changed.
Someone listed as an account owner or authorized user on a shared cellular plan may have access to billing records or account-management features.
- Who is authorized to manage the account?
- Are any family-location services enabled?
- Has a SIM card or eSIM been added or changed?
- Are calls or messages being forwarded?
- Does anyone else know the account PIN?
- Can the phone number be moved to an individual account?
Do this from a safe device or location when possible. Changes to the cellular account may generate emails, text messages or billing notices.
If you find a suspicious app, profile, account or connected device:
- Photograph or screenshot what you found.
- Write down the date and time.
- Record the app, device or account name.
- Save copies somewhere the other person cannot access.
- Speak with an advocate, attorney or law-enforcement officer.
- Make a safety plan before removing access.
- Change passwords from a safer device when appropriate.
The FTC advises people who suspect stalkerware to consider their safety before removing it and to seek help using a different device when possible.
A factory reset may remove many forms of stalkerware, but it should not be the first step when evidence or personal safety is a concern.
- Save important photographs, contacts and documents.
- Record suspicious apps, settings and connected devices.
- Consult an advocate or attorney if the information may be evidence.
- Make sure the person monitoring the phone will not be alerted in a way that puts you at risk.
- Create new account credentials from a safe device.
After the reset, set the phone up as new.
Do not automatically restore the entire old backup. Restoring a compromised backup could return unwanted apps or settings to the phone. Safety Net specifically recommends avoiding reconnection to a potentially compromised backup after a reset.
You can manually copy essential photos, contacts and documents after the phone has been secured.
Buying another phone will not necessarily stop the monitoring if you sign into the same compromised accounts, restore the same backup or remain on a shared wireless plan.
Before using a replacement phone:
- Create a new passcode.
- Secure the primary email account.
- Change the Apple or Google account password.
- Review trusted devices and recovery methods.
- Consider creating a new account.
- Turn on two-factor authentication.
- Avoid restoring a questionable backup.
- Check whether the cellular plan is still shared.
- Be careful who receives the new phone number.
The Safety Net Project, operated by theNational Network to End Domestic Violence, provides re
The Federal Trade Commission also provides consumer guidance about stalkerware, warning signs and steps to consider.
Anyone in immediate danger should contact emergency services when it is safe to do so.
Technology can make abuse and stalking easier, but it can also provide evidence and a path toward regaining control. The most important steps are to avoid panicking, document what you find and make changes in a way that protects your physical safety as well as your digital privacy.
Stream News 10 Lansing on your favorite devices!Here’s how to download the News 10+ app on Roku, Fire TV or Apple TV.
Be the first to see the Mid-Michigan headlines you care about –download the News 10+ appand subscribe to ourNews 10 newsletterandYouTube pageto receive the latest local news and weather.
Copyright 2026 WILX. All rights reserved.