Lists of "best spy apps" have been circulating for years with the same names, always with an affiliate link at the end. This text does the opposite: it explains what this category of software is from a security standpoint, why antivirus companies treat it as a threat, and what usually happens to those who buy it.
The legal aspect is straightforward and can be summed up in one sentence: monitoring an adult's cell phone without consent is... computer device intrusion, Article 154-A of the Penal Code, punishable by imprisonment from 1 to 4 years and a fine, also violates the confidentiality of communications guaranteed by Article 5, item XII, of the Constitution. The rest of this article deals with what almost no list mentions.
The category has a technical name: stalkerware.
Programs designed to run hidden on another person's device, collecting messages, location, calls, and screenshots, are classified by the security industry as... stalkerware — sometimes also called spouseware. This is not a derogatory nickname invented by critics: it is the detection category used in antivirus products, which remove these programs in the same way they remove any other malicious code.
There is even an international coalition formed by antivirus manufacturers and organizations that support victims of domestic violence, specifically dedicated to detecting and combating this type of software. This says a lot about the context in which it is used in practice.
Why does the installation require disassembling the device's safety features?
Official app stores do not accept apps that hide themselves from the user's device—this is an explicit policy rule of both Google Play and the App Store. The direct consequence: to install one of these programs, you have to leave the store.
The script is always similar, and each step breaks down a layer of protection:
- Download an APK file from any website, outside of the Play Store.
- Allowing the installation of unknown sources on Android.
- Disable Play Protect, which would block the app.
- Grant permission to accessibility — the same one that allows you to read everything that appears on the screen.
- Grant permission to device administrator, which makes uninstallation difficult.
On iPhones, the process is even more invasive: it generally requires the victim's iCloud credentials, or jailbreaking. In the end, you have two devices with compromised security and a program with full access running on one of them—controlled by a company you don't know.
Who really ends up with the data?
This is the point that these companies' marketing never highlights. The data collected They won't go to your cell phone.. They go to the company's server, and you can access them through a dashboard. In other words, the company then owns the material.
The sector has a poor track record of hacks, with the exposure of victims' content as well as the registration data of those who contracted the service — names, emails, and payment information of clients have already appeared in reported leaks. Those who installed the service thinking they were obtaining information ended up becoming part of a leaked database.
The typical business model: subscription, exaggerated promises, and a website that disappears.
Three characteristics are repeated in this market.
Cobrança recorrente
The model is a monthly, semi-annual, or annual subscription, with an aggressive discount upfront. Canceling is usually much more difficult than subscribing, and there are frequent reports of charges after a cancellation request.
Promessa maior que a entrega
Features advertised as "invisible," "no device access," or "only with a phone number" do not exist. Without physical contact with the device, or without account credentials, there is no installation. Anyone promising otherwise is selling something they will not deliver.
Fornecedor que desaparece
Several names that appeared on lists of this kind simply disappeared — websites were down or refused to connect. Since payment is upfront and the activity is legally fragile, there's no one left to complain to.
What to do instead
If you need to monitor a minor child, there is an official, free, and transparent tool: on Android, the Google Family Link; on the iPhone, the Usage Time, already built into the system. Both allow time limits, control over app installation, content filtering, and location tracking — and they are visible on the monitored device, which is exactly what makes them legitimate.
Google Family Link
AndroidIf the need is to manage a company's devices, the solution lies in a corporate device management system, with a written internal policy, acknowledged and signed by the employee, and restricted use only to devices provided by the company.
If the need is to resolve mistrust in a relationship, none of these tools will solve it. They only transform a personal problem into a criminal one.
How to know if something has been installed on your device.
Check three places on Android: permissions for accessibility, the list of device administrators ...and apps with permission to overlay other screens. Anything you don't recognize deserves investigation. Apps of this type often use generic system names to go unnoticed.
Indirect signs: battery draining much sooner than normal, unexplained high mobile data usage, overheating when the device is idle. If you find anything, change your passwords from another device and enable two-step verification before removing the program.
SEE MORE:
- App that takes a photo of who entered the wrong password on your phone.
- Application that unlocks your cell phone by voice
- Safe apps for chatting with people nearby.
The legal price for those who install
The conversation usually revolves around who is being monitored, but the legal exposure falls on whoever installs the system. Article 154-A of the Penal Code deals with the invasion of another person's computer device to obtain, alter, or destroy data without the owner's authorization, and the penalty increases when the content of private communications or trade secrets is obtained.
In addition to this, there are other layers to consider. The Brazilian Internet Bill of Rights protects the confidentiality of communications, the LGPD (Brazilian General Data Protection Law) deals with the personal data of third parties, and the Constitution considers evidence obtained illegally to be inadmissible, meaning that the capture, besides being risky, tends to be useless in legal proceedings. In civil cases, a claim for compensation for moral damages is also possible.
In the context of family conflict, the effect is even worse: secret monitoring is often interpreted as controlling behavior and can weigh against the person who practiced it in custody disputes or requests for protective measures. It's a risk paid for a long time to obtain information that is rarely confirmed.
What these tools simply cannot deliver
Discounting the advertising, the list of limitations is long. None of them read messages protected by end-to-end encryption in transit, because the content only exists in plain text within the devices at both ends. Therefore, vendors rely on recording the screen or keyboard, which is fragile, heavy, and visible.
None of them work without physical access to the device or without the person's account credentials. None of them survive a system update well, because manufacturers close off precisely the paths they use. And none of them can hide the extra battery and data consumption caused by constantly sending information.
There is also no remote installation via phone number, despite what the ads suggest. When that's the promise, the real product is something else entirely: recurring subscription, collection of your data, or malicious software on your own cell phone.
How to secure the device so that no one can install anything.
The defense is inexpensive and works for everyone, regardless of suspicion. The idea is to eliminate the three conditions that any surveillance program needs: a few minutes with the phone unlocked, powerful permission granted without attention, and an account protected only by a password.
- Use a screen lock with a six-digit password or PIN, not a pattern lock, which is easy to spot.
- Do not lend your unlocked device, even for a short time, to anyone who insists on keeping it alone.
- Enable two-step verification on your main accounts and in the messenger app.
- Review the accessibility menu and the device administrator list monthly.
- Keep your system updated and Play Protect turned on, with periodic scanning enabled.
- Check the list of devices linked to your accounts and disconnect any that you don't recognize.
- Hide notification content on the lock screen.
If the suspicion is concrete and there is personal risk involved, there is a better order of action: do not confront before documenting, seek legal advice, and consider changing passwords from another device, because tampering with your own phone may alert whoever installed the malware.
Business scam signs and mistakes people make when seeking them out.
This marketplace has a repetitive script. A page with generic testimonials, video demonstrations that never show the actual installation, a money-back guarantee that nobody can claim, customer service only via message, and a daily price advertised to disguise the annual subscription. By the time the customer complains, the domain has already changed its name.
- Payment requested in cryptocurrency, instant transfer, or gift card.
- System protection must be disabled before installation.
- It promises to work without touching the target device, which is technically impossible.
- Website without company identification, address, or legal representative.
- This program requests accessibility access, device administrator privileges, and permission to install other applications.
The fundamental mistake is believing there's a technical shortcut to a relationship problem. In legitimate cases, such as monitoring a minor child, the answer lies in official supervision tools that are transparent and visible to both parties, not in a hidden program purchased from an anonymous seller.
What are the most frequently asked questions about this topic?
Se for o celular que eu paguei, posso monitorar?
Paying the bill does not transfer ownership of the data of the person using the device. Between adults, consent is what separates legitimate supervision from the legally permitted invasion of privacy, even if the phone line is in your name.
É possível descobrir quem instalou?
Not always by the device itself. The installation log may indicate the date and time, which often helps to reconstruct the event, but attributing authorship with probative value is the work of an expert, not an application.
Formatar resolve?
Yes, a factory reset removes that type of program. The important thing is not to immediately restore an app backup made while the device was compromised, and to change the passwords afterward, preferably from another device.
Ferramenta de segurança detecta esse tipo de programa?
Many systems detect and classify this category as an unwanted application. However, manual review by accessibility and device administrators remains the most reliable method because it doesn't rely on signature detection.
