Short answer: usually you cannot tell from the way your phone behaves. Battery drain, warmth and data use are real signals that something may be wrong, but on their own they prove nothing. A worn-out battery or a badly written app produces the same symptoms.
The signs that actually count are structural — an app you do not recognise with powerful permissions, a phone that has been rooted or jailbroken without your knowledge, an iCloud backup you never switched on, or monitoring that keeps working after you try to remove it. And there is one more signal that matters at least as much as any technical one: if someone in your life knows things about your private activity that they should not know.
This article goes through each sign in the order that is most useful — starting with the ones people worry about most, which are also the weakest.
Why There Is No Single "Spyware Symptom"
Monitoring apps are built to not be noticed. As the US Federal Trade Commission's consumer guidance on stalkerware explains, some developers supply instructions for disabling the very notifications that would warn you the app is running, and hide the app under an innocuous name such as "System Service" so it blends into system settings.
That design goal shapes what you will actually see. A well-built monitoring app tries to add nothing obvious to your phone. This is why the symptom lists you read elsewhere are unreliable: they describe the side effects of badly built spyware, not spyware itself.
The Weak Signals: What They Do and Do Not Prove
These are the signs most articles lead with. They are worth checking, but each has an innocent explanation, and none of them on its own establishes anything.
Battery draining faster than usual. Background monitoring uses power, so it can drain a battery. So can an ageing battery, a new app, a screen-on time increase, or a poor mobile signal. Proves: nothing on its own. Worth: comparing today against a known-good baseline, and looking at which app is using the power.
The phone running warm when idle. Sustained background processing can warm a phone. So can charging, a case, direct sun, or a stuck app from any source. Proves: nothing on its own.
Unexplained mobile data use. Monitoring means uploading what is collected, so data use can rise. So can automatic photo backup, streaming, or an app syncing more than it used to. Proves: something is transferring data — not who is receiving it.
Unexplained reboots, crashes, or slow performance. Genuine symptoms of a device under strain. Also the textbook symptoms of a phone that needs updating.
Strange noises or notifications. Occasionally reported as a spyware sign. Usually ordinary network behaviour, a handset fault, or a notification from an app you forgot you installed.
Here is the honest summary: one weak signal means very little. Several appearing in the same short window, especially after your phone was out of your hands, is when the pattern starts to matter. The Coalition Against Stalkerware puts the same point the other way round — unusual device behaviour may be a sign of stalkerware, "but it doesn't have to be, and some stalkerware runs without any such side-effects."
The Strong Signals: Structural Evidence
These are the signs that indicate something is actually installed or configured against your wishes. They are harder to manufacture by accident.
An app you do not recognise, with powerful permissions
On Android, two permission categories matter most. Accessibility services can read screen content — the text and images currently shown on the display. That means monitoring software can capture messages as they appear on screen, including messages inside apps such as Signal or WhatsApp: it is reading what the screen displays, not breaking the app's encryption. Device admin access can prevent an app from being uninstalled and change security settings.
Legitimate accessibility apps are screen readers, text-to-speech services and known productivity tools. A device-admin entry you do not recognise is worth investigating. If you did not set up work device management, an unfamiliar device-admin app has no obvious reason to be there.
Apps that can install other apps
On Android, monitoring software can arrive from outside the official app store. When it does, somebody had to grant "install unknown apps" permission to at least one app on the device. If a file manager or an app you do not recognise holds that permission and you did not grant it, that is meaningful.
A phone that has been rooted or jailbroken
"Rooted" (Android) means someone gained administrator-level control of the operating system. "Jailbroken" (iPhone) means the security restrictions the manufacturer put in place were removed. Both weaken the device's protections and both are common prerequisites for installing monitoring software. The National Network to End Domestic Violence's Safety Net Project publishes a guide to checking a device for rooting or jailbreaking.
If your phone is rooted or jailbroken and you did not do it, that is a strong finding — stronger than any combination of battery and heat symptoms.
An iCloud backup you did not enable
Some iPhone and iPad monitoring works by reading the device's backups in iCloud rather than by running anything on the phone. If backups are switched on and you never turned them on, somebody may have done it for another purpose. You can check in Settings by tapping your name, then your device, and looking at whether iCloud Backup is enabled.
Monitoring that survives removal
If you delete something suspicious and the same behaviour returns, or the same unknown entry reappears, that is one of the clearest indications that something is being reinstalled or that another account still holds access to your device.
Someone knows more than your phone told them
The Coalition Against Stalkerware states that the most common sign your activity is being monitored is a change in the other person's behaviour — they know where you were when you never told them, they know who you were talking to, they know what you were reading. This is the sign people are most tempted to dismiss as coincidence, and it is often the first real one. It is also the one that no amount of reading your own Settings will confirm.
How to Check, Platform by Platform
Android. Open Settings and review installed apps, then choose to show system apps so nothing is hidden by default. Check Accessibility services and Device admin apps. Check which apps hold "install unknown apps" permission. Check Battery and Data usage and look for anything you do not recognise using resources in the background. Google Play Protect runs automated scans of installed apps; you can see its current status in the Play Store app under Play Protect. Cross-reference any unfamiliar app name — search it in quotes and see whether the results describe a known monitoring product.
iPhone. Use Safety Check (Settings → Privacy & Security → Safety Check), available on iOS 16 and later. It lets you review the people and apps you are sharing information with, review devices connected to your Apple Account, reset system privacy permissions, and update your passcode — including an Emergency Reset option that stops all sharing at once. Check your list of installed apps for anything unfamiliar, and check the iCloud Backup setting described above.
The account and carrier side of this question — whether someone else has access to your Apple or Google account, or has redirected your number — is a separate subject from the phone itself, and this article does not cover it.
Before You Remove Anything: Safety Comes First
If you are dealing with a partner or former partner, removing monitoring can be more dangerous than leaving it in place for now. Deleting an app, changing a permission or resetting a device can tell the person monitoring you that you have found out, and disclosed abuse sometimes escalates at exactly that moment. Removal can also destroy evidence you might need.
Every serious source — the FTC, the Coalition Against Stalkerware, the NNEDV Safety Net Project, Cornell's Clinic to End Tech Abuse — gives the same first instruction: talk to a domestic-abuse advocate and make a safety plan before you change anything technical. Do that research from a device the other person has never had access to, such as a friend's phone or a library computer. If you are in the US, the National Domestic Violence Hotline is reachable at 1-800-799-SAFE (7233), by chat, or by texting START to 88788. The Coalition Against Stalkerware maintains support resources for other countries.
If your situation involves serious organised targeting — for example you are a journalist, an activist, a lawyer or an executive working on matters someone would want to know about — the appropriate next step is different and more specialised. Malloc's work with high-risk individuals covers that case; so do Citizen Lab and Access Now, who investigate and document commercial surveillance targeting and publish guidance for potential targets.
A Note on "Pegasus-Class" Spyware
When people ask whether their phone has spyware, they often mean something like Pegasus — professionally developed commercial spyware sold to governments. It is real, it is serious, and it is used against journalists, activists and civil society. Citizen Lab and Access Now have documented confirmed infections in several countries.
It is also not what most people with a monitoring problem are dealing with. Commercial spyware of that class is used selectively, against specific targets, rather than sold as a mass-market tool, and it is a different product from the consumer "phone spy" apps. What public investigations describe is who is targeted and how the tools are used; they do not publish price data, so we state no figure here. Our assessment — a judgement drawn from that reporting, not a measurement — is that the realistic risk for an ordinary person is a commercially available monitoring app installed by someone with access to their phone, their account, or their trust, or an account someone else still controls. Starting with the structural checks above is the right order, because they address the likely problem.
What to Do Next
- Note down what you have observed and when — dates, symptoms, anything the other person knew that they should not have. A written log helps you spot patterns and is useful later if you report it. Keep that log somewhere the other person cannot reach: a device they have never had access to — a friend's phone, a work or library computer — or on paper. A log stored on the phone you suspect is a log they may be able to read.
- Run the platform checks above and note anything unfamiliar. This step is passive. You are only reading your own settings and writing down what you find; it changes nothing on the phone, so it does not yet tell anyone that you are looking.
- If another person may be involved, contact an advocate before removing anything.
- If you are not in that situation, change the passwords to your Apple, Google and email accounts from a different device, and turn on two-factor authentication using an app rather than SMS. Here, and only here, you can also run a reputable security scan and keep it running — a scan that finds something is more useful than a scan that finds nothing once. Be aware of the trade-off: installing or keeping a security app changes the app list on the phone, its power profile, and the notifications you receive from the app store, and all of those are observable to anyone monitoring the device. That is why this belongs in this branch, where no other person is involved, and not in the steps above.
Where Malloc Fits — and Where It Does Not
Malloc is a mobile security app for iPhone and Android that runs its detection on your device, not in the cloud, and shows you which exact domains the apps on your phone talk to. It alerts you when an app accesses your camera or microphone, and it flags apps with risky permissions. You can see what that looks like in practice in You can now know where your apps send data.
Saying this precisely matters: Malloc detects and reduces risk. It does not make any phone unbreakable, and no app can promise that. We publish what we can prove, and we state plainly where our evidence ends. Our own security posture is documented in the Trust Centre: Malloc holds a MASA Level 2 security assessment and ISO 27001, and operates a no-logs policy.
Android and iOS expose different levels of system access to the apps that run on them, so what you can check yourself differs by platform, and what a security app can see differs too. For Android users, Malloc for Android covers how the permission and domain views work on that platform. For iPhone, Malloc for iOS covers the iPhone and iPad side. The starting point for both is Malloc Mobile Security.
If you think your phone is being monitored, the two things worth doing today are: write down what you have noticed, and get advice from an advocate before you remove anything. Everything else can wait until you have done those.