Learn › How tracking works

What your Google and Samsung accounts know

Last reviewed 2026-07-29

The account is the target, not the phone

A phone’s lock screen gets a lot of attention, but the account behind it is usually the bigger prize. This is different from stalkerware, which requires installing something on the device itself — account access instead comes down to who can sign in, and signing in usually takes more than just a password. Google accounts commonly have 2-Step Verification turned on, so a new sign-in also needs a second step: a code to a trusted phone number, a tap on an already-signed-in device, a security key, or a passkey — and Google may flag the attempt as a sign-in challenge it wants confirmed from a recognized device. Samsung accounts can have similar two-factor protections.

Two account hubs syncing streams of activity

That doesn’t put account access out of reach for someone close to you — it just means the realistic paths look different from “knows the password, walks right in.” What actually works for an intimate partner or ex: physical access to your unlocked phone or another device you’re already signed into (so they can approve the second-step prompt themselves); a device of theirs that was added as trusted at some point and never removed; control over the phone number your codes get sent to, including through SIM swapping; or a session you’re already signed into — a shared computer, a browser left logged in, a family device — that needs no authentication at all. The password alone, without one of those, usually isn’t sufficient on an account with 2-Step Verification on. If you’re trying to work out whether someone is watching you right now, start with Is someone tracking my phone? For hardening the accounts themselves, see Securing your accounts when someone knows you — this article is about what’s actually visible once someone is in.

Google: My Activity

Google’s My Activity is the closest thing to a running transcript of your signed-in life. Google’s support documentation states that My Activity lets you access and manage your search history and activity “in one central place from any device,” and that activity comes from your use of Google products, sites, apps, and devices whenever you’re signed in. You can view and filter that activity by date, product, and keyword, and it covers things like topics you’ve searched, articles you’ve read, and videos you’ve watched. The same page notes that My Activity does not store content or files like documents (unless directly uploaded, for instance in AI Mode) or emails — those live in Drive and Gmail themselves, not in the activity log.

Two things worth knowing about this on the audit side. First, Google’s guide to activity controls explains you can set auto-delete for your activity, or turn off saving for a category entirely, which stops new activity from being recorded going forward. For search and web activity specifically, Google’s help page on search history spells out the windows on offer: activity older than 3 months, 18 months, or 36 months. Second, some Google products save activity in places other than My Activity: your browser can separately hold search and browsing history, and — as covered next — location goes to Maps Timeline rather than the main activity feed.

Google Maps Timeline: what changed, and why it matters for an audit

Timeline (formerly called Location History) used to sit in the cloud with the rest of your Google Account data, which meant anyone with your password could open Google Maps on the web and see a synced, cross-device travel history. That’s no longer how it works. Per Google’s own Timeline support page, Timeline now saves your visits and routes “on each of your signed-in devices,” and because the data shown on your Timeline comes directly from your device, Timeline is not available in Maps on a computer — you need the Google Maps app itself to see it. The same page confirms Timeline is off by default and only active if you opt in.

This on-device shift is genuinely relevant to an account-access threat model: Timeline is no longer something you can browse by logging into maps.google.com from any browser. What Google’s page actually describes is narrower: if you turn on backup, Maps saves an “encrypted copy” of your Timeline data to Google’s servers, and “as long as you’ve turned on backup, you can import your data onto a different device, even if you lose or damage your device.” That’s a recovery feature for you, not a documented statement that anyone signed into the account can pull up your Timeline at will — but the underlying data isn’t purely on-device if backup is on, and the general principle holds: encryption protects data from outside breaches, not from someone who can complete a legitimate sign-in to the account itself. You’ll keep your Timeline based on your auto-delete settings, or until you delete it; you can turn off or delete all of it in My Activity, and delete parts of it in the Maps app. If you’re checking your own exposure, look at whether Timeline is on, whether backup is enabled, and what your auto-delete window is set to — details covered further in Location sharing.

Google Photos, Drive, and Gmail

My Activity deliberately excludes content — which is exactly what makes Photos, Drive, and Gmail separate risks. If someone has a signed-in session on your Google Account — through one of the paths described above, not just knowledge of your password — they can open Gmail and read your inbox, sent mail, and drafts, or open Drive and read anything stored there, the same way you would. Photos works the same way: whatever is uploaded or backed up to your account is visible to anyone with that access. None of this requires a special tool or technical skill — it’s the same interface you use.

Saved passwords: Google Password Manager

If you’ve ever let Chrome or Android save a password, it’s sitting in Google Password Manager, tied to your Google Account. Google’s support page explains that when you sign in to an Android device or Chrome browser, you can save passwords and passkeys with Google Password Manager, and use them to sign in to apps and sites “on all your devices where you’re signed in with the same account.” That means someone with a signed-in session on your Google Account doesn’t just see your Google activity — they can potentially see or use the login credentials you’ve saved for other sites and services, viewable at passwords.google.com or through Chrome’s settings. That access isn’t necessarily automatic, though: Chrome and Android offer an optional layer — biometric authentication, a fingerprint, face scan, or screen lock — before a saved password can be revealed, copied, or autofilled. It’s off by default, so whether it protects you depends on whether it’s been turned on. This is one of the more consequential things to check and clean up if you believe your Google Account itself was compromised, separate from your phone.

Connected third-party apps and services

Beyond Google’s own products, your account can also be linked to apps built by other companies — the ones you signed up for with “Sign in with Google,” or that you granted some level of access to your Google data. Google’s documentation explains that linked apps can request different kinds of access: your basic profile (name, email, photo), permission to view and copy data such as contacts, photos, or YouTube playlists, or in some cases permission to manage — edit, create, or delete — data in your account. Critically, Google states that “linked apps can only access the data and services that you authorize them to,” and that you can review or remove any linked app’s access at any time from your linked apps page. If you’re doing an audit, this list is worth checking specifically for anything you don’t recognize or no longer use — an old app with standing access to your contacts or Drive is easy to forget about.

Google Takeout: the “everything” export

If you want to see the fullest possible picture of what’s tied to your account — more complete than any single settings page — Google Takeout is the tool Google itself points to. According to Google’s support page, Takeout lets you select which products to include in a download archive, and Google products you actively use are automatically pre-selected; you can deselect anything you don’t want. The important safety implication cuts both ways: it’s a legitimate way for you to see and preserve everything associated with your own account (useful if you’re documenting what a shared or formerly shared account contains), but it’s also exactly what someone with account access could use to pull a comprehensive copy of your data in one action. It isn’t necessarily invisible after the fact, though — Google states that “when your archive is created by using one of these options, we’ll email you a link to its location,” typically the same day. An export you didn’t request should show up as that email, unless it was deleted before you saw it. If you’re worried about someone else’s access, that email, along with recent linked-app activity and sign-in history, is worth checking.

Samsung account: the parallel hub on Galaxy phones

If your phone is a Galaxy device, there’s a second account layered on top of your Google Account, with its own separate password and its own reach. Samsung’s own explainer describes a Samsung Account as an “integrated account designed to facilitate easy access to Samsung apps and services,” listing Samsung Health, Samsung Wallet, Galaxy Store, and Samsung Cloud as services it unlocks, and stating it “helps you find lost Samsung devices with Samsung Find.” Samsung’s account setup support page adds that the account also handles backing up and restoring data between devices and recovering your ID or password. In practice, this means a Samsung account holder has a second login, independent of the Google one, that reaches into device-finding, cloud backups, health data, and payment services.

Samsung Cloud: what’s actually stored there

Samsung Cloud isn’t one bucket — its categories matter for an audit, because they’re not all reachable the same way. Per Samsung’s own support documentation:

Samsung’s page also notes a retention limit: data stored in Samsung Cloud is deleted if it hasn’t been used in more than 12 months, with Samsung providing advance notice before that deletion happens.

Samsung Health

Samsung Health data is covered separately under Samsung’s consumer health privacy commitments. Samsung’s Consumer Health Data Privacy Statement lists the categories of health data Samsung may collect through services like Samsung Health, including bodily functions and vital signs, reproductive or sexual health information you provide, and information contained in medical records you choose to store in the service. Samsung’s sustainability and privacy page separately states that health data such as weight, blood pressure, heart rate, and body composition collected by Samsung Health “is all encrypted and securely stored through the Knox security platform,” and that it is “not shared with anyone without your permission,” with an exception for the minimum data needed for a service you’ve opted into with a partner. Whoever holds your Samsung account credentials and opens the Samsung Health app can see this data the same way you do — encryption at rest protects against outside breaches, not against someone signed in as you.

Find My Mobile / Samsung Find: remote powers

Samsung’s device-finding service — now branded Samsung Find, previously Find My Mobile — gives an account holder real remote control over a Galaxy device, not just its location. Samsung’s own support page lists the remote options available from the Samsung Find website once a device is selected, including Ring, Lock, Erase data, Notify me when it’s found, Track location, and Extend battery life. The same page states plainly that “a Samsung account login is required to use Samsung Find” — meaning anyone who can sign in to your Samsung account, not just you, can trigger these actions on your device. Family and child location tracking are separate from those website remote options: Samsung’s page states that tracking people in a Family group is a feature of the Samsung Find app specifically, “not available on the Samsung Find website at this time.” Inside the app, you can share your location with a Family group for 1 hour, 24 hours, or indefinitely, and there’s a Child location sharing toggle that, once turned on by a guardian, requires the child to accept the request on their own device.

The practical implication: if you share a Samsung account with a partner, family member, or ex, they may be able to see your device’s location, lock it, or factory-reset it remotely — powers that go well beyond a typical “find my phone” feature. If that’s a live concern, changing your Samsung account password and reviewing who’s listed under any family or guardian sharing is worth doing alongside the account-security steps in Securing your accounts when someone knows you.

Auditing both accounts

For Google, start at your Google Account’s My Activity and step through each activity category, then check Google Maps Timeline settings in the Maps app to see whether Timeline and backup are on, and what your auto-delete window is. From there, review your linked third-party apps for anything unfamiliar, and check Google Password Manager for saved logins tied to other accounts you may need to rotate separately.

For Samsung, open Settings → Samsung account on the device (or sign in at Samsung’s account portal on a computer) to review linked devices and account details, per Samsung’s account setup guide. From there, check the Samsung Cloud sync and backup categories under Settings → Accounts and backup, following Samsung’s Cloud support documentation to see what’s actually stored. Finally, review the family and guardian sharing list under Samsung Find, since that’s the setting that determines who else can see your location or trigger a remote lock or wipe, as described on Samsung’s Find support page.

Neither audit tells you everything with certainty — Google’s own documentation is explicit that My Activity doesn’t capture content stored in Gmail, Drive, or Photos, and Samsung’s Cloud portal only shows summaries, not full file contents, without restoring to a device. What both audits reliably tell you is which categories exist, whether they’re on, and who else — through a shared password, a trusted device, a family group, or a still-connected app — might have a door into them. If your device itself also needs a deeper security pass, The complete Android security guide covers the rest of the phone.