How DeSpy works

Your phone. Your computer. Your evidence.

DeSpy is a desktop app for Windows and macOS. It connects to your phone over a USB cable and analyzes it right there, on your own computer. No cloud. No account. Nothing is ever uploaded — the evidence stays where it belongs: with you.

  • 100% local analysis
  • No account required
  • Works offline after install
Stylized illustration of a phone under a protective shield, surrounded by scan particles and encrypted signal paths.

1 The extraction process

A guided scan that never leaves your desk.

Extraction is the moment DeSpy reads evidence from your phone. It happens over a USB cable, into a folder on your own computer — and you decide, explicitly, how deep it goes before anything runs.

It starts with a setup wizard, not a manual

Phones don't hand over their data to just anyone — that's a good thing. DeSpy's guided setup walks you through preparing your device step by step, in plain language, before the scan begins.

On iPhone / iPad

The wizard covers everything Apple requires before a computer may read the device:

  • Responding to the “Trust This Computer” prompt so the connection is authorized.
  • Enabling Developer Mode when a deeper diagnostic path needs it.
  • Backup-password readiness — making sure you know your encrypted-backup password before a backup-based scan starts, so you're never locked out of your own evidence.

On Android

Android asks for a developer handshake before a computer may talk to it. The wizard guides you through:

  • Unlocking Developer options on your specific device.
  • Turning on USB debugging so DeSpy can read diagnostics over the cable.
  • Approving the connection on the phone itself — the phone always gets the final say.

You choose exactly how deep the scan goes

There is no hidden “collect everything” mode. Every scan runs under an explicit profile that you pick, and each profile states up front what it will and won't touch.

iOS

No Backup Fast

Privacy-first

Quick diagnostics with no device backup created and no personal media copied. The lightest possible footprint — signals only.

iOS

Forensic Full

Consented backup

With your explicit consent, DeSpy makes a local backup of the device on your computer and performs deep extraction against it.

Android

Non-root Triage

Quick check

A fast look using standard, non-root access — installed apps, settings, and monitoring-capable configurations.

Android

Deep Security (No Media)

Recommended default

Expanded collection for a thorough security review — without your photos, videos, audio, or documents. Depth where it matters, privacy where it counts.

Android

Full Preservation

Explicit opt-in only

The most complete acquisition, offered only after you explicitly opt in to including personal files. It is never selected for you.

Personal media is off by default — on every platform. DeSpy never copies photos, videos, audio, or documents unless you deliberately choose a full-preservation scan and confirm that choice. The recommended profiles do a deep security review without ever touching them.

Where your data travels — and where it never goes

Every artifact the scan collects makes exactly one trip: down the cable, into a vault on your computer, and out again only as your report. Here is the entire journey.

The local evidence chain Four steps flow left to right: your phone connects by USB cable to your computer, evidence lands in a hashed local vault, and a report is produced. A bold boundary line labeled "nothing crosses this line" separates this local flow from a crossed-out cloud marked no cloud, no account, no upload. 1 2 3 4 Your phone Guided setup USB cable A wire, not a network Your computer DeSpy runs here Evidence vault SHA-256 at capture Your report Readable, private, yours NOTHING CROSSES THIS LINE No cloud No account · No upload
The local evidence chain. 1 — your phone, prepared with the guided wizard. 2 — a USB cable: a wire, not a network. 3 — your computer, where DeSpy runs. 4 — a local evidence vault, hashed at acquisition, from which your report is produced. Nothing on the left of the boundary ever reaches the crossed-out cloud on the right.

A local vault, sealed with math

Everything lands in one folder

Every artifact the scan collects is stored in a DeSpy Evidence folder on your own computer. You can see it, copy it, back it up, or delete it — it's an ordinary folder, and it's entirely yours.

Fingerprinted the moment it arrives

Each artifact is hashed with SHA-256 at acquisition. If a single byte changes later, the fingerprint no longer matches — so you, or any expert you share it with, can prove the evidence is intact.

Under the hood, DeSpy orchestrates industry-standard, open extraction tooling — including the same Mobile Verification Toolkit indicators used by human-rights forensics labs — all coordinated locally on your machine. Proven methods, without the lab coat, and without the lab's servers.

Stylized illustration of the DeSpy evidence pipeline: device evidence and account telemetry cards flow through signal correlation into explained risk.
From raw evidence to explained risk. Device artifacts — and, only if you supply one, a Google account export — are correlated and turned into explained findings. Every stage of this pipeline runs on your computer.

2 The reporting process

Findings you can read. Reasons you can check.

A pile of extracted files answers nothing. DeSpy turns the evidence vault into a report a person can actually use — and shows its work at every step.

From artifacts to answers, in five stages

  1. Parse the evidence

    The collected artifacts — installed apps, permissions, settings, and system records — are parsed into structured facts, locally.

  2. Run deterministic detection rules

    The facts are checked against a catalog of known stalkerware and against monitoring-capable configurations: accessibility services, notification listeners, device administrators, and sideloading. Deterministic rules, not black-box guesses — the same input always produces the same finding.

  3. Rate every app, with reasons

    Each app gets a risk rating with a plain-English explanation of exactly which behaviors or permissions earned it.

  4. Score the device

    Findings roll up into an overall 0–100 risk score with plain-language tiers, so you can see at a glance how much attention the results deserve.

  5. Produce the report

    You get a consumer-friendly PDF report plus machine-readable evidence files — ready to keep, or to hand to an expert, advocate, or attorney.

The reporting pipeline Five stages flow left to right: evidence, detection rules with known-indicator matching, findings explained in plain English, a zero-to-one-hundred risk score, and finally the report as a PDF with evidence files. 1 Evidence Parsed artifacts 2 Detection rules Known-indicator matching 3 Findings Explained, with reasons 4 Risk score 0–100, with tiers 5 Report PDF + evidence files Every stage runs locally · the report also states what was not covered
The reporting pipeline. Evidence is parsed, matched against deterministic rules and known indicators, explained as findings, rolled into a 0–100 score, and delivered as a PDF plus machine-readable evidence files — all on your computer.

Every finding is explained — never just flagged

A scary red label with no context helps nobody. Each finding in a DeSpy report carries five things:

  • What was detected
  • Why it matters
  • Possible benign explanations
  • A confidence level
  • Next steps — safety warnings first

Recommended next steps always lead with safety. Where a removal could tip off the person doing the monitoring, the report says so before it tells you how to remove anything.

The DeSpy honesty principle

A scan that finds nothing is not proof that you're safe. Your report states exactly what was checked and what wasn't — and it never turns “no match” into “your phone is clean.”
Stylized illustration of an evidence table listing signals such as an unknown MDM profile, accessibility abuse, a suspicious OAuth grant, and root or jailbreak artifacts, each with a risk bar.
The signals the rules look for. Monitoring rarely announces itself — it shows up as configurations: management profiles, accessibility grants, cloud access, boundary changes, and leftover traces.
Stylized illustration of a DeSpy report screen with a confidence dial, a list of flagged artifacts, and recommended next actions.
An evidence-first report. Findings, confidence, and next actions live side by side — so the “what now?” is never left as an exercise for the reader.

Optional: bring your Google account into the picture

If you supply a Google export of your own account data, DeSpy can correlate account-side signals with what it found on the device: which devices are signed in to your account, third-party access to your mail, and location sharing. Like everything else, the export is analyzed locally and never leaves your computer.

3 Built-in privacy controls

A spyware scanner that can't spy on you.

A tool people reach for in their most vulnerable moment has to be beyond suspicion. These protections aren't settings you have to find — they're how DeSpy is built.

100% local analysis

Extraction, detection, scoring, and reporting all run on your computer. There is no cloud upload — ever — and DeSpy works offline once installed.

No account required

No name, no email, no sign-in. Registration stores only a one-way device hash — a fingerprint that can't be reversed into anything about you.

Personal media excluded by default

Photos, videos, audio, and documents are never collected unless you make the explicit opt-in choice. The default is always “leave my personal files alone.”

Consent before collection

Before anything runs, the scan explains what it is about to collect from the phone. Nothing is touched until you've seen the list and agreed to it.

Evidence you can prove

SHA-256 hashing at acquisition seals every artifact, and reports preserve their evidence references — so findings stay verifiable long after the scan.

Survivor-safety by design

Removing stalkerware can alert the person monitoring you. That's why reports place safety warnings before removal steps. Read more in Safety first.

Masked numbers, redacted logs

Phone numbers are masked in report content, and DeSpy's own logs are privacy-redacted and stay local. Even the diagnostics respect your privacy — and never upload.

Keep learning

DeSpy's job is evidence; understanding is yours to keep. These companions go deeper:

See what your phone has to say — privately.

DeSpy is in private beta. Apply to test it, run a scan on your own terms, and get a report that respects both your intelligence and your privacy.

Stylized illustration of a secure vault flanked by device silhouettes, representing evidence kept private on your own computer.