Before you change anything

What the check compares

Applore’s Needs your review check looks at every app installed on your phone and compares two things with a list of known stalkerware:

  • the app’s package name, the unique ID every Android app has, such as com.example.app
  • the app’s signing certificate, the digital signature its developer uses. A match here still counts if the app was renamed.

The list comes from the stalkerware indicators published by Echap under the CC BY 4.0 licence. It covers stalkerware, apps sold to secretly monitor another person, and a separate set of watchware, monitoring apps such as parental control or employee tracking tools that are usually installed openly.

The list is included in the app and refreshed with app releases after a person reviews the changes. It is not downloaded live. Echap states that its indicators are not a complete list of stalkerware and that there is no guarantee they are accurate, so Applore also looks for warning signs.

Behaviour signals Applore scores

For apps that do not match the list, Applore scores signals that monitoring apps often show. Each one on its own is common in normal apps too.

SignalWhat it means
Installed from outside an app storeIt was not installed by Google Play or another known app store, so someone may have installed it from a file.
Hidden iconIt has no icon in the app list, and no keyboard, widget or wallpaper that would explain that.
Icon switched offIts app icon exists but was deliberately disabled.
Accessibility accessIt can read what is on the screen and act for you.
Notification accessIt can read notifications, including message previews.
Device adminIt is a device administrator, which makes it harder to remove.
No battery limitsIt is allowed to keep running in the background.
Sensitive permissionsIt holds several of microphone, camera, background location, messages, call history, contacts or phone state.
Name like a system appIts name sounds like a system service, such as “update” or “sync”.
Developer test certificateIt is signed with a debug certificate that store apps do not use.
Scroll sideways to see the whole table.

Being installed from outside an app store is a gate, not evidence on its own. An app installed from a file with a visible icon reaches High only when another strong sign backs it up, such as a hidden icon, both accessibility and notification access, a system-like name or a developer test certificate. Applore skips system apps and itself.

What the levels mean

Every flagged app gets one of these levels, using the same words as the app:

Known monitoring appHighWorth a lookNot flagged

  • Known monitoring app: the package name or signing certificate matches the known stalkerware list, or a known monitoring app was installed from a file and hides its icon.
  • High: installed from outside an app store with strong warning signs, such as a switched-off icon, or a hidden icon together with accessibility, notification or device admin access.
  • Worth a look: some warning signs, or a known monitoring app installed from an app store. Review it when you have a moment.
  • Not flagged: no match and not enough signs. This is not proof that the app, or the phone, is fine.

Inside Applore, About this app explains each finding in plain words: what the app can see or do, where it came from, when it was installed and why it was flagged.

Monitoring apps and stalkerware

Family, parental and employee apps from Google Play are labelled monitoring apps, not stalkerware. They are usually installed openly and can be legitimate, but they can also be misused. An app installed from an app store can reach Worth a look at most, unless it matches the known stalkerware list. Monitoring apps and stalkerware explains the difference.

Flagged apps: a separate list

Applore also shows Flagged apps: installed apps that appear on a downloaded list of apps removed from app stores for harmful behaviour, mostly adware. This list is kept apart from Needs your review. It never raises an app’s stalkerware level and never sends a reminder on its own.

When checks run

Applore asks for your consent before it reads your list of apps for the first time. After that, checks run:

  • when you open Applore
  • in the background on a schedule, including a daily re-check of every installed app
  • when apps are added or updated, as Android reports those changes

Android’s battery saving can delay background checks, so a new app may not be checked straight away.

If Applore finds a Known monitoring app or High result, it reminds you later and again until you review it: after about an hour, later that day, the next day, then daily for a week and weekly after that. The reminder never names the app on the lock screen, and swiping it away does not clear the finding. A finding is resolved when the app is removed, or when you mark it as trusted with your App Lock PIN or pattern. Worth a look results show in the list without a reminder.

What Applore cannot do

Applore also cannot see which special access another app has been granted for some settings, such as usage access or drawing over other apps. It can only see that the app asked for it.

What is and is not sent

  • The check runs on your phone. The list of installed apps and the findings stay on the device.
  • No package names go to analytics. Analytics events about the check carry counts, not app names.
  • One exception, App Category. When you open App Category, package names are sent to Applore’s server to group apps by category. This is a separate feature, disclosed in the privacy policy.
  • The report leaves only if you share it. An evidence report is created on your phone and leaves it only through Android’s share sheet, to the place you choose. See sharing a record of what Applore found.

Get support

The Applore app includes support contacts for India, the United States and the United Kingdom, plus global options. If you live somewhere else, search for a domestic abuse helpline in your country. Support hotlines lists where to start. If you are in immediate danger, contact your local emergency number.

For the list of third-party data and licences Applore uses, see credits. All safety guides are on the safety hub.

Questions

Is the stalkerware check an antivirus?

No. Applore is not an antivirus and does not scan files or remove threats. The check compares installed apps with a public list of known stalkerware and scores warning signs such as a hidden icon or accessibility access. It flags apps that need your review, and you decide what to do. It can miss apps, so treat it as one check among several.

How often is the indicator list updated?

The list is included in the app and refreshed with app releases, after a person reviews the changes. Applore does not download it live, so one bad change in the public source cannot flag apps on your phone overnight. Keep Applore updated from Google Play to get the latest list.

Why did Applore flag an app I installed myself?

Some everyday apps share warning signs with monitoring apps. An app installed from a file rather than an app store, with accessibility or notification access, can reach Worth a look or High even when it is harmless. If you installed it and trust it, mark it as trusted. Applore asks for your App Lock PIN or pattern first, and flags the app again if its signing certificate changes.

Can Applore see apps in a work profile?

No. Android keeps apps in a work profile, or in another user on the same phone, separate from the main profile, and Applore cannot see them. The same applies to other separate profiles. To review those apps, open Settings inside that profile, or ask the organisation that manages the work profile.

Does a 'Not flagged' result mean my phone is clean?

No. Not flagged means Applore did not find a match with the known list or enough warning signs. New or unknown apps, tools that need a rooted phone and apps in a work profile can be missed. If you still have concerns, review Settings yourself and consider talking to a support service.

Sources

  1. Stalkerware indicators (repository and README), Echap, CC BY 4.0. Checked 2026-09-15.
  2. Use Google Play Protect to help keep your apps safe and your data private, Google Help. Checked 2026-09-15.
  3. Information for survivors, Coalition Against Stalkerware. Checked 2026-09-15.

Check your phone with Applore

A free check for known stalkerware, a guided Safety Check and a Quick exit. No ads on safety screens.

Free on Google Play · Android 8.0 and up

See how detection works