Updated July 2026 · Reviewed by Quinnlan Varcoe, digital forensics examiner. If this phone may be monitored, browse and sign up from a safer device, because activity here can be visible to monitoring software. The Quick Exit button above works on every page.
What this service does
Worried there is spyware on your phone? This is detection and removal: a forensic examiner checks your iPhone or Android for stalkerware, hidden tracking apps, rogue device-management profiles, and AirTags or GPS trackers, and if something is found, removes it on a timeline that keeps you safe. You get a plain-language answer backed by evidence rather than a guess, and a written record if you ever need one.
What makes forensic work different from an antivirus scan is the order it protects: preserve → attribute → report → recover. A scanner can sometimes find monitoring software; only preserved evidence can show who put it there, and the finding-out usually destroys the proof unless the preservation comes first. The sections below walk that order.
Before you remove anything, preserve it
If you think an abusive partner installed it, plan before you remove it. Pulling stalkerware can alert the person who put it there, so for intimate-partner situations the safest first step is often a call with a domestic-violence advocate. See domestic violence digital forensics. The Coalition Against Stalkerware puts it plainly: deleting stalkerware also deletes the evidence, and removal can be detected by the person who installed it. NNEDV’s Safety Net project adds the practical corollary. Proving mobile spyware usually takes a forensic professional, and it takes the device before anyone has cleaned it.
The costliest mistake we see is well-meaning: the factory reset. It is the advice most articles give, and it is the single most evidence-destructive act available. It erases when the software arrived, how it was configured, and where it reported. If there is any chance you will want a protective order, a police report, or a custody filing, the device (or a forensic image of it) needs to be preserved un-reset first. Preservation doesn’t commit you to anything; it keeps every later option open, including the option to simply move on.
When removal is the right call and the timing is safe, the step-by-step is its own guide: how to remove stalkerware, step by step, with per-OS instructions and the preserve-first sequencing built in. After removal, privacy hardening closes the exposure that let it in.
How we establish who installed it
“Who did this?” is usually the question that matters most, for a protective order, for a police report, or just to know. It is also the question no scanner and no removal guide answers. In an examination we work it as an attribution problem across three independent channels, and we corroborate across them rather than relying on any one:
The three-channel attribution check
- The vendor account. Consumer monitoring products are subscriptions: someone bought a license, and someone logs into a dashboard to read what it collects. We establish whose purchase and whose access that is. That trail exists off the device and can be formally requested or subpoenaed.
- Install evidence × physical access. We establish when the software arrived on the device and correlate that window with who had hands-on access to it. Opportunity plus timing, documented.
- Account-level access. Much “spyware” is really a person holding your iCloud or Google credentials, or a management profile. The installer is then whoever holds that access, and the account’s own records can show it.
Two honesty notes
First, we describe these channels at the category level on purpose. This page is for the person being watched, not a how-to for covering tracks. Second, attribution is evidence work, not magic: what we produce is a documented, court-ready basis for “this account, this access window, this person had the means”, and the court or investigator draws the conclusion.
Familiarity with the consumer products matters here in one specific way: knowing what mSpy, FlexiSpy, or TheTruthSpy installations look like in evidence. We read what a license receipt, a dashboard login, or an install footprint means for attribution. (That is the only sense in which product names belong on this page; we don’t compare their features, and we don’t link to them.)
It may not be an implant, but account-level access
The peer-reviewed finding most “spyware check” services skip: the Cornell Tech study of spyware in intimate partner violence found that most real-world “my phone is being monitored” cases involve no spyware app at all, especially on iPhone. They are account-level access. Someone who knows the Apple ID or Google password reads synced messages, photos, and location from their own device. Apple’s Safety Check exists precisely because the sharing surfaces are the exposure.
This changes both the check and the fix. No device scan, ours or anyone’s, can clear your accounts, which is why no honest examination ends with “you are safe”; it ends with what was found, what was checked, and what that does and doesn’t rule out. And if the access was account-level, the fix is credential rotation done in the safe order, not app removal. That order is walked through in what to do if someone has access to your phone.
What to hand police if you want this investigated
Officers see stalkerware rarely enough that the report often goes nowhere without preparation. What moves a case is handing over a package they can act on:
- The named product. “Monitoring software” is a shrug; “this specific app, installed on this date” is a case.
- The preserved, un-reset device (or a forensic image of it). This is the physical evidence, in the state that still proves something.
- An incident log with dates the phone was out of your hands, dates they knew things they shouldn’t have, screenshots with timestamps.
- A written examiner report tying together what was found, how, and what it means, in language a detective and a prosecutor can use.
Two companion guides cover the handoff itself: how to report digital evidence to law enforcement (who to report to, in what order) and the court-readiness checklist for digital evidence (what your documentation needs so it holds up).
Not every monitored phone is the same case
Most of this page assumes an intimate partner and a safety risk. That is the hardest version and the one where wrong moves cost the most, and it is why the domestic-violence resources above lead. But the same forensic questions show up in calmer postures. If the monitoring belongs to a relationship dispute headed for attorneys rather than advocates, that path is infidelity investigation coordination. It covers evidence on your own devices and accounts, coordinated lawfully for a divorce or custody matter. And if what worries you is nation-state spyware such as Pegasus and its relatives, you are looking at a different threat class from consumer stalkerware, with different checks: what Pegasus and zero-click attacks actually are.
Engagements are confidential and structured to begin within 48 hours of the consultation. Some service tracks are offered at a fixed fee; complex investigations are billed hourly with a clear scope, milestone updates, and a cap agreed up front. Quinn (Founder and CEO) oversees every engagement and reviews every case before findings leave the practice; the practitioner team executes the technical work under her methodology.
- A direct line to Quinn, the founder, not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
How an engagement begins
- Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
- Scoped engagement. Written proposal with defined deliverables and pricing, fixed fee where it applies, hourly with milestone caps for open-ended investigations.
- Investigation and findings. Prepared to support admissibility under FRE 901/902. Written report you can act on.
Why this work matters
Stalkerware detection means finding spyware on an iPhone or Android and removing it without tipping off the installer. It is precision forensic work, not an antivirus scan. Quinn holds 9 active certifications across GIAC, a methodology trusted by Fortune 50 enterprises, defense contractors, and the attorneys who refer to us.

















