8 signs your phone is being monitored

By

The short version: Most "signs of spyware" lists are useless because battery drain and warm phones have a hundred innocent causes. The symptoms that actually matter are the ones tied to capability — device admin rights, accessibility services, notification access — and to sensor activity you can't explain. Check those.

Search for signs your phone is being monitored and you'll get the same list every time: the battery drains fast, the phone feels warm, you hear clicks on calls, data usage is up.

Nearly all of it is unreliable. Batteries degrade. Phones get warm on video calls. Clicking on calls is a network artefact from the analogue era. If you go looking for these symptoms, you will find them on a perfectly clean phone, and you'll frighten yourself for no reason.

What follows is the version worth reading: which symptoms carry real signal, what each one actually indicates, and the specific check to run for each. If you're worried, work through it in order.

1. An app has device admin rights you didn't grant

This is one of the strongest signals on the list. Device administrator is a powerful Android privilege — it can enforce lock policies, wipe the device, and, crucially, make an app much harder to uninstall. Monitoring apps request it precisely so they can't be casually removed.

Check it: SettingsSecurity (or Security & privacy) → Device admin apps. On some phones it's under Advanced or Other security settings.

You should recognise everything there. Find My Device is normal. A workplace MDM profile is normal if your employer manages the phone. Anything else — especially something with a generic name like "System Service" or "Device Health" — deserves scrutiny. Disable admin rights first, then uninstall.

2. An accessibility service you didn't set up

Accessibility services exist to help people who need screen readers and alternative input. They're granted extraordinary reach: reading everything on screen, observing what you type, acting on your behalf. That makes them the single most abused permission in Android monitoring software.

Check it: SettingsAccessibility → look through Downloaded apps or Installed services.

If you don't use accessibility features, this list should be effectively empty. An enabled service you can't account for is a serious finding, not a maybe.

3. Notification access granted to something unfamiliar

Notification access lets an app read the content of every notification you receive — messages, verification codes, banking alerts. It's a quiet, high-value capability that doesn't announce itself once granted.

Check it: SettingsNotificationsDevice & app notifications (or search Settings for "notification access").

Smartwatch companions and launchers legitimately need this. Little else does.

4. Camera or microphone activity you can't explain

Now the sensors. This is the symptom people most want to check and the one Android makes hardest to verify.

Check it: SettingsPrivacyPrivacy DashboardMicrophone / Camera.

You get the last 24 hours, and only that. No durations, no lock-screen context, nothing from last week. So a single glance can rule things in — an unexplained entry is worth pursuing — but it can never rule anything out. We covered exactly where that ceiling sits in what Android's green dot doesn't tell you.

The pattern that actually matters is repeated access while the screen is locked, from an app with no reason to want a sensor. That's not visible in a log that empties itself daily — you need something keeping history.

5. Someone knows things they shouldn't

Not technical, and the most reliable indicator on the list. If another person consistently knows where you've been, who you've spoken to, or what you said in a private message — and there's no ordinary explanation — take that seriously.

Nearly all real-world phone monitoring is installed by someone with physical access to the device and knowledge of your passcode: a partner, an ex, a family member, occasionally an employer. It is not a remote hacker. That's why the checks in this article focus on permissions and installed apps rather than exotic exploits.

If you think someone with physical access is monitoring you: be careful about what you change and when. Removing monitoring software can alert the person who installed it, and that carries risk in an abusive situation. Organisations like the Coalition Against Stalkerware publish guidance written specifically for this, and a domestic abuse helpline can advise on safety planning before you touch the device.

6. Apps you don't remember installing

Monitoring software often hides behind a plausible name or a blank icon, and sometimes doesn't appear in the app drawer at all.

Check it: SettingsAppsSee all apps, then tap the menu and enable Show system apps. Read the whole list. Anything you can't place, search the exact package name — tap the app, scroll to App details or Advanced.

Also check SettingsAppsSpecial app accessInstall unknown apps. If sideloading was enabled for a browser or file manager and you never turned it on yourself, something was installed outside the Play Store.

7. Play Protect is switched off

Google's built-in scanner isn't comprehensive, but it does flag a good share of commercial stalkerware. Someone installing monitoring software will frequently disable it, and a disabled Play Protect on a phone you never touched that setting on is itself the finding.

Check it: Open the Play Store → tap your profile icon → Play ProtectScan. Make sure scanning is enabled in the settings there.

8. Unfamiliar devices on your accounts

Not all monitoring lives on the phone. If someone has your Google or iCloud credentials, they get your backups, photos, and location history without installing anything at all.

Check it: Google account → SecurityYour devices. Remove anything unfamiliar, then change your password and turn on two-factor authentication. Do the same for your email account, which is the master key to everything else.

The symptoms that mean less than you think

To save you some worry:

These aren't meaningless. They're just so common on healthy phones that on their own they tell you nothing.

What to do if you find something

  1. Don't act yet if there's a safety risk. Read the callout above first.
  2. Revoke before uninstalling. Remove device admin rights, accessibility access and notification access, then uninstall.
  3. Change passwords from a different device — a phone you no longer trust is the wrong place to type a new password.
  4. Enable two-factor authentication everywhere, using an authenticator app rather than SMS.
  5. Consider a factory reset if anything persists. Restore selectively; a backup made after the software was installed can carry it back.
  6. Then watch. A clean scan today doesn't prove a clean phone tomorrow.

The check Android can't do for you

Seven of the eight checks above are a snapshot. You run them, you get an answer for right now, and the answer expires.

Sensor access is different, because the meaningful evidence is a pattern over time — and Android deletes the data you'd need before a pattern can form. Twenty-four hours, no durations, no lock state.

Spytrap keeps that record: every camera and microphone access, which app, exactly when, for how long, and whether your screen was locked — as permanent history rather than a light you had to be looking at. You get an alert the moment a sensor opens, each app gets a trust score based on its actual behaviour, and you can cut off access in one tap.

It's a one-time $0.99 on Google Play, with no account and no cloud. Nothing leaves the phone, which is the only sensible design for a tool like this. To be clear about scope: it isn't an antivirus and it doesn't scan for known spyware signatures — it watches behaviour, and reports what reached for your sensors and when. Here's the technical account, including the cases where detection is imperfect.

Get Spytrap on Google Play — $0.99 →

Related reading