What a scan genuinely can find
- Known stalkerware. Commercial monitoring apps have recognizable package names and signatures. When one is installed and visible to the scan, detection is reliable and the finding is strong evidence.
- Monitoring-shaped configuration. Apps holding the permission combinations surveillance needs — accessibility services that can read the screen, notification access that can read your messages, device-admin rights that resist removal, sideloaded apps you never knowingly installed. Each is checkable, factual, and explainable.
- Account-side signals. With a Google account export: devices signed into your account, third-party apps granted access to your mail or files, app passwords, and active location sharing — often more revealing than anything on the phone itself.
- Public indicator matches. Files and artifacts matching published indicators from security research (the same class of indicators used by tools like Amnesty International’s Mobile Verification Toolkit).
What no consumer scan can see
- What it can’t reach. Without deep system access, parts of a phone are simply not inspectable — other apps’ private data, some deleted content, some system areas. On iPhone, scans work mostly from backups, which contain a lot but not everything.
- Threats without signatures. Renamed or brand-new stalkerware, custom tools, and sophisticated commercial spyware may match no known indicator. Absence of a match is not absence of a threat.
- Monitoring that isn’t on the phone. Someone reading your email from their own laptop, a shared iCloud account, a family-locator app doing exactly what it was configured to do — no phone-side scan can see any of it. (This is why checking your accounts comes first.)
- Who did it. A scan can show what is present, not who installed it or why. Attribution is a human and legal question, not a technical output.
How to read a “nothing found” result
“Nothing found” means: in the parts of the device and accounts this scan could examine, none of the signals it knows about were present. That is genuinely reassuring — most monitoring by non-experts uses exactly the tools scans catch. But it is not a certificate of cleanliness, and it never outweighs strong real-world evidence. If someone still keeps knowing things they shouldn’t, trust that observation: consider the account-side checks again, other devices (tablets, laptops, smart home), physical trackers, and — where the stakes justify it — a professional forensic examination.
Questions to ask any scanning tool (including ours)
- Does it say what it checked and what it couldn’t check?
- Does it show its evidence, or just a verdict?
- Does it distinguish “known spyware found” from “suspicious capability found”?
- Does it warn you about removal risks before telling you to delete things?
- Does it ever claim a phone is “clean”? (If yes, be skeptical of everything else it says.)