What Someone Else in Your Account Would Reach

Someone who signs in as you does not see a snapshot of today. They see the entire history from the first message, whatever the app has retained about you, the billing screen, and — this is the part people miss — the controls that let them change the email and password and keep you out of it permanently. A conversation account is not like a social feed where the interesting material scrolls away. Everything is on one continuous surface, ordered by date, searchable.

Worth knowing before it matters, because most of the containment is a five-minute settings pass you can do now and cannot do afterwards.

The inventory

The full message history, back to the beginning. Not a recent window. Whatever the operator retains is what the signed-in session can page through, and in this category that is usually all of it.

The profile the app assembled. Any facts you supplied or the app inferred and stored — a name, a job, a relationship situation, things you said were troubling you. In some apps this is a visible list you can edit, which means it is also a visible list somebody else can read in one screen instead of scrolling for an hour.

Anything you sent that was not text. Images, voice notes, and the transcripts of voice conversations if the app keeps them.

The account surface itself. Email address on file, the plan you are on, payment status, the store or provider the subscription came through, and often the sign-up date.

An export, if the app offers one. Where a download-your-data button exists, an intruder can press it, and the result is one portable file instead of a session that ends when you change the password.

The destructive powers. Change the email, change the password, delete the account, delete individual messages. Someone hostile can lock you out; someone merely curious can leave traces you will never reconstruct.

The two intrusions are not the same problem

A stolen credential is remote and silent. It comes from password reuse, a breach somewhere else, or a message that got you to type your password into the wrong page. Nothing on your phone shows it happening. The defences are all account-side: a unique password, a second factor, a recovery inbox that is itself well defended, and using a platform identity where the app supports one — what sign in with Google or Apple links together explains why that removes an entire class of failure.

An unlocked device is local and much more common. The app is already signed in; there is no credential to guess. This is the household version, and it is not solved by anything in the account settings — it is solved by the screen lock, by notification previews, and by knowing what the app’s presence reveals even before it is opened, which is the subject of what a shared device exposes.

Confusing the two leads people to add a second factor and then hand over an unlocked phone. Address whichever one actually describes your situation.

The containment pass

Five things, in the order that pays best.

Look for a sessions or devices screen and end everything you do not recognise. This is the only control that evicts an intruder who is already in. A password change alone sometimes leaves existing sessions alive.

Make the recovery inbox stronger than the app. Whoever controls that inbox can reset the password whenever they like, so the app’s own security is capped by the inbox’s. If the inbox has a weak password and no second factor, fixing that is worth more than anything you do inside the companion app.

Use a unique password, from a manager, filled by autofill rather than pasted. The clipboard is a system-wide surface that other apps have historically been able to read, so handing a credential straight to the field is better than copying it.

Turn off notification previews for this app specifically. It costs nothing, it does not disable notifications, and it removes the most frequent real-world leak.

Decide whether you want the history to exist. If the app allows deleting older conversations, the material you delete is material that cannot be read by anyone who gets in later. That is the only defence in this list that shrinks the inventory rather than guarding it.

The controls that mostly do not exist

Worth knowing so you do not go looking for them.

There is usually no login history. Mainstream email and platform accounts show you recent sign-ins with location and device. Companion apps rarely do. That means an intrusion can be entirely invisible after the fact, and it is why the sessions screen — where one exists — is the whole game.

There is rarely a per-conversation lock. A few apps offer a passcode on the app itself, which is genuinely useful on a shared phone; most do not, and none should be relied on as a substitute for the device lock.

Second factors are inconsistently supported in this category. If the app has one, switch it on. If it does not, the platform identity route is the closest available equivalent, because the second factor then lives on an account that definitely has one.

If you think someone has already been in

Work the eviction steps first: sessions, then password, then recovery inbox, then billing. Do it from a device you trust. Then check whether the email address on the account is still yours, because a changed email is the sign that the intrusion was hostile rather than nosy, and it converts this into a support problem rather than a settings problem.

After that, treat the content as read rather than at risk. That is a different question with a different response, and it is the same question a breach forces — the ordered version of it is in when a companion app is breached, what to do first. If what follows is somebody using the material as leverage, stop reading here and go to if someone threatens to publish your conversations instead.