CipherWatch All articles
Cybersecurity Explainers

Invisible Leashes: How Everyday Technology Has Become a Toolkit for Intimate Surveillance—and Why the Law Can't Keep Up

CipherWatch
Invisible Leashes: How Everyday Technology Has Become a Toolkit for Intimate Surveillance—and Why the Law Can't Keep Up

Photo: U.S. Government Accountability Office, Public domain, via Wikimedia Commons

Somewhere in the United States, right now, a person is watching a blue dot move across a map. That dot represents another human being—an estranged spouse driving home from work, a former partner visiting a therapist's office, a domestic abuse survivor who changed her address but not her phone settings. The watcher may be sitting in a parked car, or at a kitchen table, or in another state entirely. The technology enabling that surveillance is legal to purchase, trivial to deploy, and in many circumstances nearly impossible to detect.

Location tracking in America exists in a state of profound legal and technological contradiction. The same infrastructure that powers emergency 911 services, ride-sharing apps, and family-safety tools is routinely weaponized for control and intimidation. The consequences are not abstract: the National Domestic Violence Hotline has documented that technology-facilitated abuse, including location monitoring, appears in a significant percentage of the cases handled by its advocates. Yet the statutory frameworks meant to address stalking and harassment were written before GPS became a standard feature in every pocket.

The Technical Landscape: More Vectors Than Most People Realize

Understanding how intimate surveillance actually operates requires separating it into distinct technical categories, because the detection and mitigation strategies differ substantially between them.

The most visible category is consensual location sharing that has become coercive. Apple's Find My, Google's location-sharing features, and dedicated family-tracking apps such as Life360 are designed for mutual, transparent use. But in relationships where one party exerts control over the other, "consent" to location sharing may be anything but voluntary. A partner who demands that location sharing remain active at all times, monitors it obsessively, and reacts with anger or threats when the other person's location is unavailable is using a consumer safety feature as a surveillance mechanism. The technology itself cannot distinguish between these scenarios.

A second category involves stalkerware—commercial software explicitly marketed, often through barely-coded language, for covert device monitoring. These applications, once installed on a target's smartphone, can silently transmit GPS coordinates, call logs, text message content, and in some cases ambient audio to a remote dashboard accessible by the installer. A 2023 report by the Coalition Against Stalkerware noted that detections of such software on devices seeking security scans remained disturbingly consistent year over year, with the United States consistently ranking among the highest-affected countries globally.

Installing stalkerware on another adult's device without their knowledge is a federal crime under the Computer Fraud and Abuse Act, and potentially actionable under state wiretapping statutes as well. That legal reality does not appear to meaningfully deter its use in intimate-partner contexts, where the installer often has—or recently had—physical access to the device and where victims may not report the offense for fear of escalating danger.

A third category is the passive collection and sale of location data by data brokers, a problem that intersects with intimate surveillance in a less obvious but equally dangerous way. As CipherWatch has previously reported, the commercial data-broker ecosystem aggregates location histories derived from smartphone apps and sells or licenses that data with minimal restriction. Researchers and journalists have repeatedly demonstrated that a determined individual can purchase sufficiently granular location data to reconstruct a specific person's daily movements—identifying their home address, workplace, medical providers, and places of worship—without ever touching the target's device.

The Legal Gray Zone

Federal stalking law, codified at 18 U.S.C. § 2261A, prohibits conduct that causes substantial emotional distress or places a person in reasonable fear of death or serious bodily injury, including when carried out through electronic means. Most states have parallel statutes. On paper, covert GPS tracking of an intimate partner falls squarely within these prohibitions.

In practice, enforcement is inconsistent, prosecution is rare, and civil restraining orders—the most accessible remedy for most victims—do not prevent a determined abuser from continuing to monitor location data. Law enforcement agencies, particularly at the local level, frequently lack the forensic training to identify stalkerware on a victim's device, let alone document it in a manner that satisfies evidentiary standards. The result is a gap between what the law nominally prohibits and what victims actually experience.

The data-broker dimension compounds this problem. The Supreme Court's 2018 decision in Carpenter v. United States established that prolonged government collection of cell-site location information requires a warrant—a significant Fourth Amendment ruling. But Carpenter addressed government surveillance, not private actors. There is currently no comprehensive federal privacy statute restricting how data brokers collect, retain, or sell location information. The Federal Trade Commission has taken enforcement actions against specific brokers for deceptive practices, and several states—California, Virginia, and Colorado among them—have enacted consumer privacy laws with location-data provisions. For most Americans, however, meaningful statutory protection against third-party location data sales does not yet exist.

In 2024, the FTC moved to ban data broker Outlogic (formerly X-Mode Social) from selling sensitive location data, citing its proximity to domestic violence shelters and reproductive health clinics in the datasets it sold. The action was notable precisely because it was exceptional rather than routine.

What Victims and Potential Targets Should Know

Detection is the first challenge. Stalkerware is designed to be invisible, and a casual inspection of an app drawer will not reveal it. Several organizations offer more systematic guidance. The National Domestic Violence Hotline's Safety Net project provides resources specifically oriented toward technology safety planning. The Coalition Against Stalkerware maintains a list of security tools and organizations that assist survivors. For users with technical confidence, mobile security applications from established vendors can scan for known stalkerware signatures, though no scan is guaranteed to be comprehensive against novel or customized tools.

For individuals who suspect covert monitoring but cannot immediately replace a device, digital-safety advocates generally recommend against removing discovered stalkerware without a safety plan in place. Abusers who lose visibility into a victim's location may escalate to physical surveillance or direct confrontation. Planning for that possibility—including coordination with a domestic violence advocate, a trusted friend, or law enforcement—should precede any technical countermeasures.

For the data-broker dimension, several privacy-oriented services offer automated opt-out submissions to known brokers. While no service achieves complete removal, reducing the breadth of commercially available location history meaningfully raises the barrier for someone attempting to reconstruct a target's movements through purchased data.

Reviewing location-sharing permissions on a smartphone—found under Privacy settings on both iOS and Android—takes less than five minutes and can reveal applications that have been granted continuous background location access without the user's active awareness. Revoking those permissions does not remove stalkerware but does address the ambient data-collection layer.

A Structural Problem Without a Simple Fix

The uncomfortable reality of location tracking as an instrument of intimate surveillance is that the technology itself is largely neutral. The same features that provide genuine safety value—knowing that a child arrived at school, confirming that an elderly parent reached a medical appointment—are structurally identical to the features that enable control and harassment. Legislative responses that focus narrowly on specific applications or devices tend to lag behind the pace of technological change.

What is needed, advocates and legal scholars argue, is a combination of stronger baseline federal privacy protections governing location data at the point of commercial collection, meaningful resources for law enforcement to investigate technology-facilitated stalking, and continued public awareness that the most dangerous surveillance tool in many people's lives may already be installed on their phone—or embedded in the settings of an app they agreed to share with someone they once trusted.

All Articles

Related Articles

Backdoors, Warrants, and Whisper Networks: The High-Stakes Battle Over Encrypted Messaging

When the Scammer Sounds Exactly Like Your Boss: AI-Powered Social Engineering Has Entered a Dangerous New Era

When the Scammer Sounds Exactly Like Your Boss: AI-Powered Social Engineering Has Entered a Dangerous New Era

After the Breach: Decoding Your Rights Under America's Patchwork of Data Notification Laws

After the Breach: Decoding Your Rights Under America's Patchwork of Data Notification Laws