
If you have found stalkerware on your phone, do not delete it in the moment you discover it. Rushing to remove covert monitoring software can warn the person watching you, escalating the danger, and it destroys the evidence a court, advocate, or investigator would need. Instead: get to a safe device, preserve proof, build a safety plan with a domestic-violence advocate, and coordinate the removal so it happens on your terms — not theirs.
Stalkerware — commercial software marketed to secretly monitor another person’s phone or computer — has become one of the most common instruments of coercive control in abusive relationships. It reads messages, tracks location in real time, records calls, activates cameras and microphones, and reports everything back to the person who installed it, all while remaining hidden from the person being watched. For a survivor, discovering it is a terrifying moment, and the instinct is almost always the same: get rid of it immediately. That instinct, while completely understandable, is frequently the most dangerous thing a person can do. This guide explains why preservation and planning must come before removal, how detection actually works, and how to coordinate a safe response with advocates, law enforcement, and forensic professionals. It is written with equal regard for the executive protecting a family member, the general counsel managing a threat to a principal, and any individual who suspects their most private device has been turned against them.
What is stalkerware and how does it get onto a device?
Stalkerware — sometimes called spouseware or covert monitoring software — is a category of applications sold openly, often under the banner of “parental control” or “employee monitoring,” but used to surveil an intimate partner without consent. Once installed, it typically hides its own icon and runs silently in the background, exfiltrating messages, call logs, photos, browsing history, keystrokes, and precise GPS location to a dashboard the abuser controls. The Coalition Against Stalkerware — a global alliance of advocacy organizations and security vendors — defines it as tools that enable a person to covertly monitor another’s private life via a mobile device, and its use in domestic abuse is now well documented across the security and victim-services communities.
The critical point for a survivor to understand is that stalkerware usually requires physical access to install, which means the person surveilling you is almost always someone close — a current or former partner, a family member, or someone with a key to your home. In many cases there is no hidden app at all. The abuser may simply know your Apple ID or Google password and be reading everything through a shared or compromised cloud account; may have enabled location sharing you never noticed; may have slipped a Bluetooth tracker into a bag or a vehicle; or may control the family mobile plan and monitor your usage through the carrier. Because the vector is so often a person you know, the technical problem is inseparable from the safety problem — and that is exactly why the removal cannot be treated as a simple IT task.
Why does removing stalkerware too fast put you in danger?
This is the single most important idea in this guide, because it runs directly against instinct. Deleting stalkerware feels like taking back control. In an abusive dynamic, it can do the opposite. Many monitoring tools notify the person who installed them the moment the app is disabled, uninstalled, or the device is reset — and even those that do not send an explicit alert create an obvious signal: the surveillance simply goes dark. An abuser who has grown accustomed to watching a partner’s every message and movement will often experience that sudden blackout as a loss of control, and loss of control is precisely the trigger that research on intimate-partner violence associates with escalation. Removing the software can, in effect, tell the abuser you know — before you have a safe place to go, a protective order in hand, or anyone else aware of the situation.
The second cost is evidentiary. Stalkerware is not only a threat; it is proof of a crime. Its unauthorized installation may violate federal and state wiretap, computer-fraud, and stalking statutes, and its presence can be powerful corroboration in a protective-order petition, a custody dispute, or a criminal prosecution. Delete it in a panic and you erase the fingerprints: the app package, its configuration, the account it reports to, and the forensic traces of who installed it and when. What could have been a documented, court-ready record becomes an unprovable account of something that used to be there. A safe response therefore holds two goals in tension — protecting the person and protecting the proof — and resolves them by sequencing carefully rather than reacting. The table below contrasts the two paths.
| Consideration | Delete it yourself immediately | Preserve, plan, then remove |
|---|---|---|
| Physical safety | May tip off the abuser and trigger escalation before you are safe | Removal timed to a safety plan, ideally after separation or protection is in place |
| Evidence for court | Destroys the app, its data trail, and proof of who installed it | Captures forensically sound proof usable for orders, custody, and prosecution |
| Ongoing monitoring | Abuser knows surveillance ended; may re-install or switch methods | You can document the watching in real time and control when it stops |
| Completeness | You may remove one app while a cloud account or tracker keeps reporting | A full sweep addresses every vector at once, so nothing is left listening |
| Best when | Only when there is an immediate physical threat and no other option | Nearly always — the default for a survivor who is not in imminent danger |
The exception at the bottom of that table matters. If you are in immediate physical danger, your safety comes before any evidence — call 911, get to a safe location, and worry about the phone later. Preservation is the right default precisely because most survivors are living with a chronic threat rather than an active assault, and in that far more common situation, a few days of careful planning buys enormously more protection than a few seconds of deletion.
How do you know if there is stalkerware on your phone?
Detection is rarely a single smoking gun; it is a pattern. The most telling sign is behavioral rather than technical: the person you suspect knows things they should have no way of knowing — the content of private messages, where you were at a specific time, who you called, plans you made only on your phone. That knowledge, appearing again and again, is often the clearest evidence that something is listening. Technical symptoms can corroborate it: a battery that drains unusually fast, a device that runs hot while idle, unexplained spikes in data usage, unfamiliar apps or device-administrator permissions, or settings that change on their own. On an iPhone, the more common vector is not an app at all but Apple ID access and location sharing, so review who can see your location, which devices are signed into your account, and whether an unfamiliar configuration profile has been installed.
A crucial caution: do not investigate on the compromised device. If stalkerware or an abuser is watching, your searches for “how to detect stalkerware,” your visit to a hotline website, and your messages to a friend for help are all visible to them — and that visibility can itself provoke danger. Use a device the abuser has never had access to and does not know about: a friend’s phone, a public library computer, or a new device purchased in cash. Reputable antivirus and anti-spyware tools can flag many known stalkerware families, and the Safety Net project at the National Network to End Domestic Violence publishes survivor-focused guidance on doing this safely. But treat any scan on the suspect device as something that could alert the watcher, and make that decision as part of a plan — not on impulse.

Why does preserving evidence before removal matter so much?
Evidence of stalkerware is fragile and, once gone, usually unrecoverable. Preservation done properly transforms a frightening private suspicion into an authenticated record that a judge, prosecutor, or family-court commissioner can rely on. A forensic examiner captures a bit-for-bit image of the device through a write-blocker, calculates a cryptographic hash to prove the copy is exact and unaltered, and documents an unbroken chain of custody — the record of who handled the evidence, when, and how. That discipline is what allows the resulting proof to withstand challenge, and it is why do-it-yourself removal, however satisfying in the moment, so often leaves survivors with nothing to show for what they endured.
What can be preserved goes well beyond the app itself. Screenshots and photographs of suspicious behavior, the stalkerware’s configuration and the account it reports to, message threads and threats, location-sharing settings, the list of devices signed into a cloud account, carrier records, and the metadata showing when software was installed all combine into a picture of coercive surveillance. Because much of this evidence lives in accounts rather than on the handset, preservation frequently means securing cloud and carrier records in parallel with the device — and doing so before a password change or a factory reset quietly erases the audit logs that would have proven the intrusion. This is the same “change nothing until it is preserved” principle that governs all serious digital forensics work, applied to a context where the stakes are personal safety rather than a corporate dispute.
What is a safe response protocol for a survivor?
The sequence below distills how advocates and forensic professionals approach a suspected stalkerware situation. It is deliberately ordered: safety first, proof second, removal last. Work it on a safe device, and adapt it with an advocate who knows your specific circumstances.
- Assume you are being watched, and act normally. Until you have a plan, do not change your routine on the monitored device or search for help on it. Sudden changes in behavior can themselves signal to the abuser that you know.
- Move to a safe device and a safe channel. Use a phone or computer the abuser has never touched and does not know exists to research, reach out, and plan. Consider a device purchased with cash and kept private.
- Contact a domestic-violence advocate first. Call the National Domestic Violence Hotline at 1-800-799-7233 from a safe device. Advocates provide confidential safety planning and know the local resources, shelters, and courts.
- Build a safety plan before you touch the technology. Decide where you will go, who will know, and what protective legal steps — such as a protective or restraining order — you want in place before the surveillance is disrupted.
- Preserve the evidence. Engage a forensic professional, ideally through an attorney or advocate, to image the device and secure cloud and carrier records with a documented chain of custody — before anything is deleted or reset.
- Coordinate with law enforcement where appropriate. Unauthorized monitoring may be a crime; a police report and preserved evidence strengthen both criminal and civil protection.
- Address every vector at once. Change passwords and enable two-factor authentication from a safe device, review location sharing and account access, check for physical trackers, and plan removal of the app so no single channel is left reporting.
- Remove or replace, on your terms. With safety and proof secured, remove the software, factory-reset the device, or replace it entirely — timed to when you are protected, not before.
The through-line is control. Every step is designed to ensure that when the surveillance finally ends, it ends at a moment you have chosen, with support in place and a record preserved — rather than in a panicked instant that leaves you exposed and empty-handed.
How do you safely remove stalkerware once you are protected?
Once safety and evidence are secured, removal becomes a technical exercise rather than a gamble. There is no universal “delete” button, because stalkerware is engineered to resist uninstallation and to hide from the user, and because the true vector may be an account rather than an app. For many survivors the cleanest resolution is a full device reset to factory settings followed by careful reconfiguration — but only after passwords have been changed from a safe device, two-factor authentication enabled, and account recovery details (backup email, phone number, security questions) verified to be under your control alone. A reset that restores from a compromised cloud backup, or that leaves the abuser holding your account password, simply re-establishes the surveillance.
In higher-risk situations, the safest option is often to retire the compromised device entirely and start fresh with new hardware and new accounts, keeping the old device preserved as evidence. Whatever the method, the removal should be complete and coordinated: closing the app while leaving location sharing on, or resetting the phone while the abuser still controls the family plan, leaves a door open. This is where professional support pays for itself — a specialist can confirm every channel is closed, verify the device is clean, and ensure the survivor is not left with a false sense of security that is more dangerous than the surveillance itself.
How do advocates, law enforcement, and forensics work together?
A stalkerware case sits at the intersection of three disciplines, and the best outcomes come from aligning them rather than choosing one. Domestic-violence advocates own the safety plan: they understand the dynamics of coercive control, maintain confidentiality, and connect survivors to shelters, counseling, and the courts. Law enforcement can investigate the unauthorized monitoring as a potential crime, and preserved forensic evidence makes their job dramatically easier and their charges more durable. Forensic examiners supply the technical proof — the authenticated image, the identification of the software, the account it reported to, and the timeline — that both the advocate’s protective-order petition and the officer’s report rely on.
The sequencing usually flows from advocate to forensics to law enforcement, though the order flexes with the danger level. What should never happen is for the technology to be handled in isolation from the safety plan. A resource like the Stalking Prevention, Awareness, and Resource Center can help survivors and the professionals assisting them document a pattern of stalking and understand their legal options. When forensic work is structured at the direction of an attorney, it can also carry the protection of privilege and be positioned for use in exactly the proceeding the survivor needs — a protective order, a custody matter, or a prosecution — rather than being a well-intentioned effort that ultimately proves nothing.
How does Honeybadger support survivors and the people protecting them?
Honeybadger Solutions delivers digital forensics and investigations led by in-house examiners, which means a survivor — or the family, attorney, or corporate security team acting on their behalf — receives guidance in the critical first hours from the same command that will later image, analyze, and defend the evidence. Because our forensic, cybersecurity, and background-intelligence capabilities are handled internally and delivered nationwide and internationally, a case never fragments across incompatible vendors, and the preservation posture is set correctly from the very first call, before anything is deleted or reset.
Our role is deliberately coordinated, not competitive, with the domestic-violence advocates and counsel who own the safety plan. We work at the direction of attorneys to preserve privilege where it applies, produce methodology defensible on the record, and confirm that every vector — app, cloud account, tracker, and carrier — is addressed so nothing is left listening. This work pairs naturally with the broader security support that principals and their families often need when a threat is personal. From Arizona home command — with offices in Casa Grande, Phoenix, and Oro Valley — we support individuals, families, executives, and general counsel across the United States and abroad. If you suspect your device is being monitored, reach out from a device the person you fear cannot see, and let us help you plan before you act.
Frequently asked questions
Will the abuser know if I delete the stalkerware?
Often, yes. Many monitoring apps notify the person who installed them when they are disabled or uninstalled, and even those that do not send an alert make the change obvious because the surveillance suddenly stops. In an abusive relationship, that loss of control can trigger escalation. Unless you are in immediate physical danger, do not delete the software the moment you find it. Get to a safe device, contact a domestic-violence advocate, preserve the evidence, and plan the removal so it happens after you are protected.
Can I just do a factory reset to remove stalkerware?
A factory reset removes most stalkerware apps, but on its own it is rarely enough and it can be dangerous. It destroys the evidence of the surveillance, it signals to the abuser that you know, and it does nothing about a compromised cloud account, a shared family plan, or a physical tracker. If you restore from a backup the abuser controls, or leave your account password in their hands, the monitoring returns. Change passwords from a safe device, enable two-factor authentication, preserve evidence first, and address every vector before you reset.
How can I check for stalkerware without tipping off the person watching?
Never research or investigate on the device you suspect is compromised — your searches, hotline visits, and messages for help are all visible to whoever is watching. Use a device the abuser has never had access to and does not know exists, such as a friend’s phone, a library computer, or a new phone bought with cash. From there you can reach an advocate and plan a safe examination. Any scan or check on the suspect device should be a deliberate step within a plan, not an impulsive action, because it too can alert the watcher.
Is installing stalkerware on someone’s phone illegal?
In most circumstances, covertly monitoring another adult’s device without consent can violate federal and state wiretap, computer-fraud, and stalking laws, and it is frequently relevant to protective orders and custody matters. The specifics depend on your jurisdiction and facts, so consult an attorney and law enforcement. This is a central reason to preserve the evidence forensically rather than delete it: properly documented, the stalkerware is not just a threat you removed but proof of unlawful conduct you can use to protect yourself.
About Honeybadger Solutions
Honeybadger Solutions is an Arizona-licensed security and investigations firm delivering intelligence-led forensics, investigations, and cyber services to individuals, families, executives, general counsel, and organizations nationwide and internationally. Digital forensics, cybersecurity, financial investigations, and background intelligence are handled in-house, so a stalkerware or tech-abuse matter is preserved, analyzed, and defended under a single accountable chain of command — coordinated with the domestic-violence advocates and counsel who own the safety plan.
Offices: Casa Grande (HQ), Phoenix, and Oro Valley, Arizona.
Phone: 602-725-2818
Confidential consultation: if you suspect your device is being monitored, contact us from a device the person you fear cannot see — we can help you preserve evidence and plan before anything is removed.
If you are in immediate danger, call 911. For confidential support, the National Domestic Violence Hotline is available 24/7 at 1-800-799-7233.