It’s a real industry, with real marketing
Stalkerware isn’t a handful of rogue apps. It’s a commercial category — companies that build, sell, and support software designed to let one person quietly watch another person’s phone. Researchers at Citizen Lab, using marketing intelligence methods and content analysis, concluded that “many of the companies studied were actively promoting their software for the purposes of facilitating stalking and, by extension, intimate partner violence, abuse, and harassment,” based on an analysis of the marketing language and search terms those companies used to attract customers (Citizen Lab). This piece is about that business and the policy fight around it. For real cases and what happened to victims, see Stalkerware in the wild: documented cases — this article won’t retell them in detail.
Two pitches dominate the marketing. One is legitimate-sounding: parental monitoring or employee device management. The other is not: catching a cheating spouse. Citizen Lab’s researchers found that “consumer spyware companies’ blog and search engine optimization content revealed that most companies had extensive references to spousal monitoring,” and documented one vendor, mSpy, that “encoded concealed HTML text which advertised spousal spying on their website as a way to make their products more easily discoverable by people searching for ways to conduct intimate partner surveillance” (Citizen Lab). The same report notes that paid search ads from these companies “tended to favour the use of the tools for general spying, hacking, or tracking” rather than the family-safety framing shown on the apps’ own landing pages.
Researchers studying this space use the term “dual-use” apps for software that is “designed for some legitimate use case(s), but can also be repurposed by an abuser… because their functionality enables another person remote access to a device’s sensors or data, without the user of the device’s knowledge” — the same underlying capability can serve a parental-control app or a stalkerware app (Chatterjee et al., IEEE Symposium on Security and Privacy). Google’s own Play Store policy draws the line on more than just who consented: it also weighs whether the app conceals itself or skips notification, discussed below. What is stalkerware? and what parental control apps can and can’t see go deeper on telling the two apart.
What the app stores officially allow — and don’t
Both major mobile platforms have written policies that explicitly name this category, and it’s worth reading what they actually say rather than assuming.
Google Play defines stalkerware in its developer policy as “code that collects personal or sensitive user data from a device and transmits the data to a third party (enterprise or another individual) for monitoring purposes,” and states that apps “exclusively designed and marketed for monitoring another individual” — meaning parents monitoring children, or employers managing company devices — are “the only acceptable monitoring apps,” adding that “these apps cannot be used to track anyone else (a spouse, for example) even with their knowledge and permission, regardless if persistent notification is displayed” (Google Play Developer Program Policy). Apps that qualify as legitimate monitoring tools still have to clear a bar: they “must not present themselves as a spying or secret surveillance solution,” “must not hide or cloak tracking behavior,” must show “a persistent notification at all times when the app is running and a unique icon that clearly identifies the app,” and must disclose the monitoring function in the Play Store listing itself (Google Play Developer Program Policy). In other words: even a policy-compliant monitoring app on Android isn’t supposed to be invisible to the phone’s user.
Apple’s App Store doesn’t have a policy section labeled “stalkerware,” but its review guidelines rule out the core mechanics such an app would need. Guideline 1.1.6 bans “false information and features, including inaccurate device data or trick/joke functionality, such as fake location trackers,” and states that claiming an app is “for entertainment purposes” doesn’t excuse it (Apple App Store Review Guidelines). Separately, Apple requires apps to get “explicit permission from users via the App Tracking Transparency APIs” before tracking their activity, and its guidelines flag that developers who use an app “to surreptitiously discover passwords or other private data will be removed from the Apple Developer Program” (Apple App Store Review Guidelines). None of this is a specific “no stalkerware” clause — it’s a set of rules that a covert monitoring app would almost necessarily violate to do its job.
A product that genuinely worked as advertised — silent, undetectable, reading someone else’s messages and location without their knowledge — would not pass review on either store. That’s why so little of this industry actually lives there.
Most of it never goes through the app stores at all
This is the part that makes app-store policy only half the picture. Apple’s own analysis of sideloading risks states plainly that “the vast majority of stalkerware is distributed outside of first-party app stores” (Apple, “Building a Trusted Ecosystem for Millions of Apps”). On Android, that includes sideloading — downloading an APK file directly from the stalkerware company’s own website and installing it outside Google Play, which requires someone to turn on “install unknown apps” permissions. Apple’s analysis doesn’t rank how common sideloading is against other distribution methods, and installing an app doesn’t always require the installer to have physical access to the phone in hand.
On iPhones, the workaround has historically been different: abusing Apple’s enterprise-certificate program, which exists to let businesses distribute internal apps to their own employees without going through the App Store. In 2019, researchers found a spyware app called Exodus that had been “signed with an enterprise certificate issued to the developer by Apple,” letting it “bypass the tech giant’s app store to infect unsuspecting victims” — a technique Apple prohibits, and has shut down in the past by revoking the certificate, which also disables every other app signed with it (TechCrunch). An app-store ban only protects you if the app is actually trying to get into the app store. A lot of stalkerware isn’t.
The detection arms race, and why it’s lopsided
If stalkerware mostly lives outside the app stores, the next line of defense is device-level scanning — antivirus apps and Google’s own Play Protect. Here the record is mixed at best. In 2025 testing by the Electronic Frontier Foundation and AV-Comparatives that covered 17 stalkerware products, several vendors caught nearly everything: “Malwarebytes detected 100% of the stalkerware products we tested for. ESET, Bitdefender, McAfee, and Kaspersky detected all but one sample” (EFF). Google’s own built-in scanner did not fare as well: “Google Play Protect and Trend Micro had the lowest detection rates in the 2025 test, at 53% and 59% respectively” (EFF).
Part of the reason is that stalkerware developers actively engineer around Play Protect specifically. EFF notes “the poor performance of Google Play Protect is unsurprising: because it is the anti-virus solution on so many Android phones by default, some stalkerware includes specific instructions to disable detection by Google Play Protect as part of the installation process” (EFF). That’s a useful thing to check for yourself: if Play Protect is switched off on a phone and nobody who uses that phone remembers turning it off, that’s worth paying attention to — though a clean scan from any tool, including DeSpy, is one data point, not proof a phone is clear.
The breach pattern isn’t a coincidence
One of the more consistent findings about this industry is that stalkerware companies get hacked, and often. TechCrunch has documented a running series of these incidents: a 2022 leak that let the outlet build a public lookup tool because a “network of nine spyware apps” had exposed “every Android device that was compromised” through a shared security flaw (TechCrunch; EFF); a 2024 breach that exposed millions of mSpy customers (TechCrunch); and a 2025 breach at Catwatchful that spilled “the spyware app’s full database of email addresses and plaintext passwords” along with “phone data from 26,000 victims’ devices” (TechCrunch).
These companies’ business model depends on siphoning a victim’s private data to a server the victim doesn’t know exists. People whose phones were compromised by stalkerware are often victimized twice: once by whoever installed it, and again when the company holding their data gets breached. Stalkerware in the wild: documented cases walks through several of these company-level failures in detail.
Who’s pushing back, and how
The clearest coordinated response is the Coalition Against Stalkerware, a working group “founded in November 2019” that brings together antivirus companies, digital rights groups, and domestic-violence organizations (Coalition Against Stalkerware, “About”). It defines stalkerware as “software, made available directly to individuals, that enables a remote user to monitor the activities on another user’s device without that user’s consent and without explicit, persistent notification to that user in a manner that may facilitate intimate partner surveillance, harassment, abuse, stalking, and/or violence” (Coalition Against Stalkerware). Notably, it does not treat “physical access to the device,” “unlocking the device,” or knowing someone’s login as equivalent to consent — closing a loophole that stalkerware marketing often leans on (Coalition Against Stalkerware). It also draws a line between off-the-shelf stalkerware and nation-state spyware like Pegasus, noting the latter involves “considerably more sophisticated” methods than what an individual abuser can buy (Coalition Against Stalkerware).
Where the law actually stands
There’s no single federal law in the United States that says “stalkerware is illegal” — and it’s worth being precise here, because the legal exposure falls on how the software is used and marketed, not on a blanket ban of an app category.
The Federal Trade Commission has used its general consumer-protection authority — Section 5 of the FTC Act, which lets it act against “unfair or deceptive acts or practices” — to bring enforcement actions against stalkerware companies specifically. An FTC report on its privacy enforcement work lists “developing and marketing ‘stalkerware,’ in which purchasers surreptitiously install monitoring software on their partners’ phones without their knowledge or consent” as squarely within the conduct it has pursued under that authority (FTC). In one such case, the FTC’s December 2021 order banned SpyFone and its CEO from the surveillance business, over allegations the company sold apps that let purchasers “surreptitiously monitor photos, text messages, web histories, GPS locations, and other personal information on the phone on which the app was installed without the device owner’s knowledge” (FTC).
Beyond the FTC, state and federal wiretap statutes can apply to installing software that intercepts someone’s calls, messages, or location without consent, and how those laws apply depends heavily on the state, the relationship between the parties, and the specific facts — talk to a domestic-violence advocate or attorney about your situation rather than relying on a general answer. The FTC actions described above targeted monitoring installed and used without the device owner’s knowledge; legitimate parental-control and enterprise device-management tools sit in the same technical space and remain lawful when disclosed to the person using the device.
What this means if you’re trying to figure out your own phone
None of this changes the practical steps: check what’s actually installed, treat unexplained battery drain or data use as a prompt to look closer (not proof of anything), and don’t assume an app being on the Play Store or App Store means it’s harmless — or that an app being absent from both means you’re safe from it. If you think you’re currently being monitored, Safety first: before you remove anything is worth reading before changing settings or deleting anything, since tipping off whoever installed it can be its own risk. The industry’s business model depends on staying invisible to the person it’s watching — understanding how it operates and where the rules actually apply is part of taking that advantage away.