Learn › Take back control

Factory reset: what it fixes and what it doesn't

Last reviewed 2026-07-29

Read this before you touch the reset button

A factory reset can feel like the obvious move if you suspect stalkerware on your phone. It’s also irreversible, and it can work against you at the wrong moment. Resetting the device destroys evidence — the app, its install date, any files tied to it — right when you might need that evidence for police, a lawyer, or a protective order. It can also alert whoever installed the monitoring: the Coalition Against Stalkerware warns that removing stalkerware or making significant changes “may be detected by the abuser and could increase the abuse and harassment” (Coalition Against Stalkerware). Safety first and documenting it and getting help cover how to preserve proof and make a safety plan before changing anything. If the device might become evidence in a custody or protective-order case, that caution applies doubly. Reset only once your plan says it’s the right time.

With that said, here’s what actually happens when you do reset.

What a reset removes

Apple’s own instructions describe erasing an iPhone as securely removing your personal information, content, and settings, restoring the device to factory settings (Apple Support). Google describes an Android factory reset the same way: it erases all your data from the phone, and while data stored in your Google Account can be restored, all apps and their data are uninstalled (Google Support).

For ordinary consumer stalkerware — installed as a regular app, which covers most of what people find — that wipe takes it with everything else. TechSafety.org’s Safety Net Project, the National Network to End Domestic Violence’s technology-abuse program, says plainly: “In most cases, a full factory reset can remove the stalkerware.” Its Cell Phone Safety Plan says the same. The Coalition Against Stalkerware calls a reset “almost as effective” as replacing the phone entirely (stopstalkerware.org).

None of these sources call it guaranteed. TechSafety.org warns that rooting an Android phone or jailbreaking an iPhone strips out the manufacturer’s built-in security protections and makes the device more vulnerable, and that on iPhones, most stalkerware can’t even be installed unless the device is jailbroken in the first place (TechSafety.org). That’s the honest scope of the exception: a rooted or jailbroken phone is more exposed, not a device where deeper survival after a reset has been documented — which is why a scan beforehand, and honesty about what a scan can’t rule out, matters more than guessing what kind of software you’re dealing with.

What survives a reset

Your accounts. A reset erases the device, not your Apple Account or Google Account, and not the password to either. If someone has your password, they still have it after the phone is wiped. TechSafety.org recommends going further than the reset alone: change your account passwords from a separate, safe device, and consider creating a new Apple or Google Account rather than reusing the old one so there’s no path back in.

A compromised backup. This is the one people miss. Restoring from an iCloud, Google, or computer backup made while the phone was compromised can reinstall the exact problem you just erased. TechSafety.org’s guidance is explicit that reinstalling apps or files from a backup “can re-load it onto the device,” and its Cell Phone Safety Plan separately warns against reconnecting a reset device to an old backup. Set the device up as new instead.

eSIM data, if you choose. An eSIM can be kept or erased as a choice during the iPhone erase process — Apple’s support page confirms you can choose to erase your eSIM or keep it (Apple Support). Either way, the reset doesn’t touch your carrier account — someone with access to your phone bill or carrier login can still see call logs there, separate from anything on the device.

Hardware trackers. A factory reset only affects the phone’s own software. An AirTag, Tile, or similar tracker hidden in a bag or vehicle is a separate physical object; resetting your phone does nothing to it.

MDM on a supervised device. This is the sharpest edge case. Apple documents that an iPhone or iPad enrolled through Automated Device Enrollment is automatically supervised, and organizations can set a “Prevent unenrollment” option so a supervised device can’t be unenrolled by the user at all (Apple’s deployment documentation). On a device like that, erasing it doesn’t necessarily remove the management: because supervision and enrollment are tied to the organization rather than to whatever’s on the device’s storage, a device assigned to an organization through Automated Device Enrollment may come back under the same MDM when it’s set up again after an erase. The MDM profiles guide covers checking Settings → General → VPN & Device Management for what’s installed before you reset anything. Android has a parallel case, though the mechanics differ from Apple’s: Google’s Android Management API documentation states that its WIPE command factory-resets a company-owned device, while on a personally-owned device it deletes the work profile instead (Google’s Android Management API documentation) — an admin-issued command, not the same thing as a user tapping reset in Settings, which on a personal device only affects what’s on the phone itself.

Doing it right, once it’s safe

  1. From a device the other person has never used, change your Apple or Google Account password and review connected devices.
  2. Back up only what you need — photos, contacts — and skip anything that might carry a compromised app’s data forward.
  3. On iPhone: Settings → General → Transfer or Reset iPhone → Erase All Content and Settings.
  4. On Android: Settings → System → Reset options → Erase all data (factory reset); wording varies by phone maker.
  5. When the phone restarts, choose to set up as new rather than restore from the old backup.
  6. Sign in with a new or freshly secured account, not the old credentials, if you have any doubt about who else has access to them.

A reset is a real fix for the device in your hand. It was never going to fix the account, the carrier, or the person on the other end of any of it — those need their own, separate steps.