To the public, mobile monitoring software looks like a tidy category — parental-control tools that keep children safe, compliance apps that keep businesses secure, sold through polished websites and subscription dashboards. Underneath that surface is a far messier industry: one being squeezed simultaneously by data breaches, aggressive regulators, and the operating systems the software runs on. This is a look at the real financial architecture and technical pressures shaping mobile surveillance in 2026 — and why the whole sector is being forced to abandon covert tracking in favor of transparent, consent-based monitoring.
The short version: brute-force background surveillance is a declining business. It’s breaking under OS restrictions, it’s a legal liability, and it’s a security risk to the very people who deploy it. The money and the momentum are moving toward overt, API-driven, transparent systems — and understanding why is useful whether you run a business, build software, or just want to know what you’re actually buying.
The Financial Landscape: High Margins, Short Lifespans
The market divides into two very different segments, and conflating them badly overstates the covert end. The employee monitoring software market — legitimate, largely enterprise, consent-based — is the large one, valued at roughly $4.5 billion and growing at around 12% a year, driven by remote and hybrid work. By contrast, the niche of consumer “
stalker ware” and hidden-surveillance utilities is comparatively tiny, estimated at roughly $145–170 million globally. Both sit inside a much larger consumer-security and endpoint-software landscape worth tens of billions — but that broad figure shouldn’t be mistaken for the size of the covert-tracking business, which is a small and shrinking slice.
The unit economics
A consumer tracking subscription typically retails from around $18 per month up to roughly $100 a year per
license. Because the software leans on the device’s own hardware to do its work, the vendor’s main cost is running cloud servers and dashboards — so gross margins on a single
license can exceed 80%. On paper, that looks like a highly profitable model.
The 90-day churn problem
The profitability is undercut by brutal retention. The average lifetime of a consumer tracking customer is often no more than about 90 days. People tend to buy these tools in a moment of acute stress — a family crisis, a sudden suspicion — and cancel once the crisis passes or the software stops working after a system update. That churn forces vendors to spend heavily and continuously on marketing just to replace the customers they lose, which is why this corner of the industry is so aggressively advertised.
The Dark Underbelly: Risks Buyers Rarely Consider
The honeypot problem: your target’s data on someone else’s server
The single biggest structural risk of covert tracking is what happens to the data. To show call records, messages, locations and captures on a customer’s dashboard, the app must continuously mirror everything it collects into a central cloud database. That database is an extraordinarily attractive target — and the track record is grim. Over the past decade, multiple monitoring platforms have suffered catastrophic breaches, spilling the private messages, images, and live locations of people who never consented to being tracked in the first place.
The implication is stark: someone who installs covert tracking software isn’t just watching their target — they’re handing that person’s entire digital life to a third-party server that may have weak security. The 2018 SpyFone breach, which exposed the data of thousands of monitored people, is one of several cautionary examples.
Regulators are now banning companies outright
The Federal Trade Commission has moved from mild settlements to permanent bans. In 2019 it acted against Retina-X Studios — maker of MobileSpy, PhoneSheriff and TeenShield — barring further sales unless the company could ensure its apps were used only for legitimate purposes. Then in 2021 it went further, permanently banning SpyFone and its CEO from the entire surveillance business — the first outright industry ban — and ordering the deletion of all illegally collected data. In December 2025, the FTC denied the CEO’s petition to reopen that order, leaving the ban firmly in place.
The FTC’s line is now explicit: a monitoring product that facilitates covert tracking without verifiable consent, or that lets its icon be hidden from the device’s owner, can be treated as illegal — with permanent bans and forced data deletion as the consequences.
The sideload barrier
Because Google Play and the Apple App Store enforce strict rules against unnotified monitoring, the most covert tools can’t use mainstream distribution at all. They’re pushed to direct-download APK files on external mirrors — which now trigger prominent “Harmful file blocked” and “Play Protect signature mismatch” warnings in the browser and OS. Getting a non-technical customer past those red screens takes onboarding guides and constant support, adding friction and cost to every install.
The Technical Squeeze: The Operating System Is Fighting Back
Even setting aside law and security, modern mobile operating systems are increasingly built in ways that break persistent background tracking.
Android’s Doze Mode and aggressive battery optimization are the clearest example. When a monitoring process polls GPS constantly, scrapes chat apps, or repeatedly captures the screen, the OS flags it as an anomalous power drain. Once the device sits idle for a while, the system enforces deep execution limits and can terminate the process entirely — at which point the app quietly stops syncing. To the customer, the software simply looks broken, driving refunds and support tickets. Keeping such an app alive requires manually excluding it from the phone’s power-saving settings, a fragile workaround that each OS update can undo.
This is the core reason the covert model is failing: the platform itself now treats persistent background surveillance as the anomaly it’s designed to shut down.
What’s Replacing Covert Tracking
The industry is pivoting away from invisible background hacks toward transparent, intelligent, API-driven systems. Three shifts stand out.
On-device AI that flags risks instead of streaming everything
Rather than piping a raw firehose of every keystroke, image, and audio clip to a dashboard, newer safety tools run machine-learning models on the device itself. A tool like Bark, for instance, doesn’t show a parent a stream of private conversations — its local code scans for contextual warning signs and surfaces an alert only when it detects markers of something like cyberbullying or self-harm. The everyday content stays private; only genuine safety flags rise to the surface. It’s a fundamentally different bargain than total surveillance.
Open-API cloud aggregation for business
Instead of a fragile local app fighting the OS to stay alive, modern enterprises increasingly use the official APIs of the platforms they already run on — Microsoft 365, Google Workspace, Apple Business Manager. Administrators review security logs and activity through sanctioned cloud-to-cloud interfaces, with no need to sideload background profiles onto endpoints at all. It’s more robust, more lawful, and doesn’t degrade every time the OS updates.
Overt transparency as the operating model
Sociological and workplace research points the same way: hidden monitoring creates toxic dynamics — it damages trust, prompts people to abandon or work around their devices, and drives up employee turnover. The industry response is to design monitoring to be explicitly visible. Rather than a trap to catch bad behavior, it functions as an agreed-upon structure: for a child, a digital safety net they know about; for an employee, an objective tool for mapping productivity and protecting company data, applied with notice and consent.
What This Means If You’re Choosing a Tool
The through-line for a buyer — parent or business — is that the covert approach is a dead end on every axis that matters: it’s increasingly illegal, it exposes your target’s data to breach, and it breaks itself against modern operating systems. The durable choice is transparent monitoring used with the knowledge and consent of the person being monitored — which, not coincidentally, is also the approach that builds the trust monitoring is supposed to protect.
For a business, that means monitoring company-owned devices with clear written notice and a policy employees have seen, ideally through platform-native tools. For a family, it means monitoring a child openly, scaled to their age. If you’re comparing options on that basis, our monitoring software comparison lays out where the main tools stand, including where rivals do a job better.
Frequently Asked Questions
How big is the monitoring software market?
It depends which segment. The legitimate employee monitoring software market is worth roughly $4.5 billion and growing about 12% a year, driven by hybrid work. The niche of covert consumer “stalker ware” is far smaller — estimated at around $145–170 million globally — and under heavy legal and technical pressure. Both sit within a much larger endpoint-security landscape, but that broad figure shouldn’t be confused with the size of the covert-tracking business.
Is employee monitoring legal?
Monitoring company-owned devices is generally lawful when employees are given clear notice and, depending on the jurisdiction, consent. What regulators treat as illegal is covert surveillance without consent — the FTC has permanently banned companies like SpyFone from the surveillance business for exactly that. The safe and durable approach is transparent monitoring, on company hardware, under a policy employees have seen.
Why do monitoring apps stop working after a while?
Usually because the operating system shuts them down. Modern Android battery optimization and Doze Mode detect the constant background activity that tracking requires, flag it as an anomalous power drain, and terminate the process when the device is idle. The app then stops syncing and appears broken. Keeping it running requires manually exempting it from power-saving settings, and each OS update can undo that — a core reason the covert model is failing.
What are the risks of using covert tracking software?
Three big ones. Legally, covert tracking without consent can break the law and has led to outright regulatory bans. Security-wise, these apps mirror everything they collect to central servers that have repeatedly been breached — exposing the monitored person’s data. And technically, modern operating systems increasingly break the software, so it fails unpredictably. Transparent, consent-based monitoring avoids all three.
What’s replacing traditional monitoring apps?
Three approaches: on-device AI that flags only genuine safety concerns rather than streaming all activity; open-API cloud aggregation that uses the official interfaces of platforms like Microsoft 365 and Google Workspace instead of fragile background apps; and a general shift toward overt, consent-based monitoring, which research shows works better than hidden surveillance because it preserves trust rather than destroying it.
Sources
- Federal Trade Commission — SpyFone surveillance-business ban and 2025 petition denial
- Harvard Journal of Law & Technology — FTC
stalker ware
- enforcement, including Retina-X
- Coalition Against Stalkerware — on covert monitoring and its harms
- Android Developers — Doze Mode and background execution limits