Loading...

Eyezy: what the app does and when its use is legal.

Advertising - SpotAds

Before installing a monitoring program on someone's cell phone, there's a question almost no one asks: what does this installation do to... you. The focus is usually entirely on the target device, but whoever hires and installs the service assumes real risks—legal, financial, and security-related. This guide addresses that aspect.

What do you need to do to install?

On Android, the process is always the same, regardless of the product brand:

  1. Holding the unlocked target device in your hands for several minutes.
  2. Download an APK file outside of the Play Store.
  3. Disable Google Play Protect and allow installation from unknown sources.
  4. Grant permission to accessibility, access to notifications, location, contacts and, in some cases, microphone.
  5. Register the program as the device administrator.
  6. Create an account on the service and provide your credit card information.

There is no installation in this format on the iPhone. What is offered is access via iCloud — requiring login, password, and the two-step verification code, which is sent to the person's own device.

Risk 1: the legal risk, which is the most serious.

Installing it on an adult's cell phone without their knowledge is computer device intrusion, Article 154-A of the Penal Code: imprisonment from 1 to 4 years and a fine. The penalty increases to 2 to 5 years when the content of private communications is obtained, and increases by one to two-thirds if the material is disclosed to third parties.

Add to this the civil liability for violation of privacy and, in the case of a former partner, the possibility of being charged with stalking — article 147-A of the Penal Code — with aggravating circumstances when the victim is a woman.

The responsibility lies with the installer. Having purchased a license from a known supplier doesn't change anything.

Risk 2: You've turned off your own ecosystem's defenses.

The step of disabling Play Protect and allowing unknown sources is exactly the vector used by banking trojans. Many "installers" distributed by third-party websites, which mimic well-known products, carry embedded malware.

Advertising - SpotAds

If you did this on your own device for testing purposes, it has been exposed. It's worth reverting both settings and running a manual scan with Play Protect.

Risk 3: the financial one

The model is a recurring subscription. Two common pitfalls: the advertised price is usually the annual plan price divided by twelve, charged all at once; and cancellation often requires contacting support that responds slowly, with renewals triggered mid-process.

On websites that imitate well-known brands, the situation is worse: they charge for something but deliver nothing, and the only recourse is to dispute the offer with the bank.

Risk 4: the data goes to a third party.

All captured material — messages, location, photos — is sent to the company's server and is accessible through a web panel. You are entrusting someone else's intimate content, and your own account access, to a provider you do not control.

Data leaks in this sector have occurred more than once, exposing both the data of the monitored individuals and the identity of those who contracted the service. It's an asymmetrical risk: the leak reveals exactly what was intended to remain hidden.

Risk 5: the evidence is useless

Material obtained through unauthorized access is inadmissible evidence and tends to be removed from the case file. In family law cases, the printout is usually discarded—and by including it, the party documents their own criminal conduct in the case file.

What to do instead?

Younger son

O Google Family Link It's free, official, and doesn't require disabling any protections: time limits per app, bedtime, installation approval, content filters, and location. On iPhone, the Usage Time It serves the same function.

Google Family Link

Android
4,6(5.2 million reviews)
100 million+ downloads
Varies
View on the Play Store

Enterprise

An MDM solution contracted on behalf of the company, applied to company devices, with a policy signed by the employee. This is the correct instrument and does not generate criminal exposure.

Advertising - SpotAds

Relationship

There is no legal tool, and let's say it bluntly. Conversation, individual or couples therapy, and a lawyer when there are property or custody issues. It's worth remembering that divorce in Brazil does not require proving fault—proving infidelity, in most cases, does not alter the division of assets or custody.

If you have already installed

  1. Remove the program: revoke accessibility permission, unregister it from the device's Administrators list, and uninstall it.
  2. Cancel the subscription and confirm with the bank that the recurring payments have stopped.
  3. Reactivate Play Protect and the protections you disabled on both devices.
  4. Do not use or share the material obtained — disclosure increases the penalty.
  5. If there is an ongoing conflict, seek legal advice before taking any further steps.

Frequently Asked Questions

Can I install it without using my phone?

Not on Android. On iPhone, it depends on the person's iCloud credentials and two-step verification code.

Does the person find out?

Frequently. Battery life, heat, data usage, and accessibility and administrator lists give it away.

Is it a crime even within marriage?

Yes. The criminal code does not make exceptions based on emotional ties or marital property regimes.

What if I install it on my own phone?

It's allowed on your device. But consider what it means to send all your content to a third-party server.

Is there a free and legal alternative?

For child supervision and locating lost devices, yes: the native Android and iOS tools are available at no cost.

In summary

Installing this type of program requires disabling the device's protection, providing a credit card for a recurring subscription, and entrusting intimate data to a third-party server—all to produce evidence that is inadmissible in court and criminal exposure that is. Legitimate use has its own free tool and requires none of this.

Advertising - SpotAds

How to use it in practice

  1. Combine before configuring. With a teenage child, an agreement on what will be monitored is worth more than any restriction—and survives discovery better.
  2. Review the agreement every few months. Limits that don't match age become a source of conflict and challenges.
  3. Enable installation approval. It prevents new apps from appearing without your knowledge, which is half the problem.
  4. Set a limit per application, not just a total limit. Allowing free study time and restricting short video time works better than a single limit.

What goes wrong most often?

  • Expecting to read WhatsApp conversations: end-to-end encryption prevents this, for any tool.
  • Disabling Play Protect to install files from outside sources is the most common vector for banking trojans.
  • Don't believe promises of monitoring based solely on a phone number; it doesn't exist.
  • Installing hidden software on an adult's cell phone is a crime under article 154-A, punishable by 1 to 4 years imprisonment.

Before installing: what's already on the device

To find a lost device, Find My Device and Find My iPhone are free and come standard: they sound an alarm even when the device is on silent, show it on a map, and remotely lock and erase it. It's worth checking today if they are activated — once lost, you can't configure them anymore.

Play Protect, integrity, and apps that won't open.

There is a technical side effect that almost never appears in the advertising for this type of software: it breaks the mechanism that other applications use to trust the device.

Android has an integrity check. Before opening, sensitive applications ask the system if the device is in a healthy state—original system, without superuser privileges, with the store's protection active. If the answer is negative, they simply refuse to function.

Who depends on this in practice:

  • Banking and payment institution applications.
  • Contactless payment wallets.
  • Government applications with digital signatures and official documents.
  • Video services that reduce quality or block playback.
  • Some games have an anti-cheat system.

The result is a familiar sequence: the person disables the store's protection to install, then discovers that the bank stopped opening, searches the internet, finds a tutorial to "bypass the verification," and sinks to another level. On the iPhone, the equivalent path requires jailbreaking, which removes the isolation between applications and is even more destructive.

It's worth stating the obvious: a device that needs to have its defenses disabled to run software is, by definition, more exposed to everything else — including programs that nobody installed on purpose.

Battery and data: the bill your device pays

Software that logs background activity consumes energy and data, and this cannot be hidden because the system itself measures it.

An app that sends data needs to keep the processor awake, read sensors, capture screen or position data, and upload everything to a server. On a typical device, this manifests as a noticeable drop in battery life and overheating while at rest, with the phone becoming warm on a table with no one using it.

Where the system displays the account.

  1. In Settings, under Battery, view the battery usage per app over the last 24 hours. Compare this to the device's standard usage.
  2. In the network section, check the background data usage per application. Constant uploads to the cloud leave a mark on this number.
  3. In recent Android versions, the indicator at the top of the screen lights up when the camera or microphone is in use. If it lights up for no reason, it means something is running.
  4. In the Privacy section, the permissions panel shows which apps accessed your location, camera, and microphone, and when.

None of these numbers alone proves the presence of a specific software. Taken together, and outside the norm, they indicate that something is working in the background all the time.

System updates often break everything.

This type of software relies on vulnerabilities and permissions granted under very specific conditions. Each Android and iOS update adjusts the permissions model, and the consequence is predictable.

  • Accessibility and screen overlay permissions will now require manual reconfirmation.
  • Access to background location becomes a separate choice, which the system asks about again.
  • Applications that have been inactive for a long time have their permissions automatically revoked.
  • Notifications about "apps running in the background" become more visible.

Therefore, the support services for these devices often advise postponing updates. This advice trades device security for product continuity, and the cost of this trade-off falls on the phone owner, who ends up running a system without known bug fixes.

Complete removal, in the correct order.

Uninstalling the icon rarely solves the problem, because the important part isn't in the icon. The sequence below works for Android and also covers cases where there's no visible shortcut.

  1. Revoke accessibility first. Settings, Accessibility, installed services. Turn off anything you don't recognize. Without this step, the app can defend itself against uninstallation.
  2. Remove administrator privileges from the device. In Settings, look for Device Administration. As long as this privilege exists, the uninstall button will be unavailable.
  3. Uninstall from the full list of applications., including system settings, and not the home screen. Generic names like "Synchronization Service" or "System Update" deserve attention.
  4. Reactivate store protection. and run a full scan.
  5. Update the system up to the latest version available.
  6. If doubt persists, restore to factory settings. And restore only photos and contacts, without restoring the list of applications from the old backup — restoring everything brings the problem back.

On iPhone, the verification process begins in Settings, General, VPN, and Device Management. The most significant finding is an unknown profile there, and removing it will take down a large part of the setup.

Accounts and passwords: what changes next?

Removing the app doesn't end access. Much of the monitoring on iPhones doesn't even require installation: it works with cloud account credentials, which remain valid after any device wipe.

  1. Change the main account password on the device from here. another device.
  2. Enable two-step verification, preferably using an authenticator app instead of an SMS code.
  3. Open the list of connected devices and end any sessions you don't recognize.
  4. Check the recovery email and recovery phone number. An unfamiliar address there can restore access to the intruder even after a password change.
  5. Check the automatic forwarding rules in your email inbox. It's the most common and least checked hiding place.
  6. Check location sharing and family sharing, which continue to work with the old permissions.

Done in that order, access is effectively cut off. Done in reverse, the password change only serves as a warning to the other side.

Read also

Advertising - SpotAds

Author's Photo

Andre Luiz

Studying IT. I currently work as a writer on the luxmobiles blog. Creating diverse content relevant to you daily.