QuietField LLC

A QuietField reference

What a phone can and cannot detect.

A plain account of the limits of consumer surveillance detection — what an ordinary smartphone can establish about the recording devices around you, what it cannot, and why the difference is physics and platform policy rather than effort.

We make a detection app. That is a conflict of interest, and it is exactly why this document leads with the limits. Every constraint described here applies to our app precisely as it applies to everyone else’s.

The short version

If you read nothing else.

  • A phone can tell you what is broadcasting nearby. It cannot tell you what is there. Those are different questions, and only the first one has an answer.
  • Nothing a phone receives says whether a device is recording. No radio signal in common use encodes capture state. Any product claiming otherwise is inferring, guessing, or lying.
  • A Bluetooth match identifies a manufacturer, not a device. Company identifiers cover a company’s entire catalogue — a match narrows the field, it does not name the thing.
  • The hardware that actually threatens you is usually the hardware a phone cannot see. Wired cameras, cellular loggers, analog transmitters and covert audio bugs carry no Bluetooth at all.
  • Direction and distance are estimates from signal strength. Bluetooth does not give an ordinary phone a bearing. A radar-style display is an illustration, not a compass.
  • No alert is not a guarantee of safety. A quiet sweep means nothing answered. It does not mean nothing is there.

01 — The raw material

What a phone actually has to work with.

Detection is bounded by the sensors on the device and by what the operating system will let an app do with them. Both boundaries are narrower than people assume.

Bluetooth Low Energy radio

The workhorse. An app can act as a receiver and read the advertising packets that nearby devices broadcast to anyone in range. It can read what is advertised. It cannot interrogate a device that does not advertise, and it cannot see Bluetooth Classic devices at all.Usable

Wi‑Fi radio

Far less useful than people expect. On iOS an app cannot scan the airwaves for nearby networks or devices; there is no public interface for it. Once joined to a network an app can enumerate other devices on that same network. A camera on a different network, on a hidden network, or on a cellular connection is invisible.Sharply limited

Camera and flashlight

An optical method rather than a radio one. A lens reflects light back along the axis it came from, so a bright light held near the camera can produce a small, sharp, unusually bright point where a lens is pointed at you. Real, but weak: it needs a dim room, a direct line of sight and a favourable angle, and it flags jewellery, glass and polished metal.Heuristic only

Microphone

A phone can hear a room. It cannot hear a recorder. A device that is recording emits no characteristic sound, and nothing in the audio of a room reveals that something in it is capturing.No detection value

Magnetometer

The compass sensor. It measures magnetic field strength, which is a property of ferrous metal and magnets — not of cameras. It responds identically to a hinge, a screw, a speaker magnet and a structural bracket. See §05.No detection value

Cellular baseband

Entirely off limits. No app on iOS gets access to the baseband radio, which is why nothing on the App Store can honestly claim to detect a cell‑site simulator.No app access

What is simply not present

A phone has no software‑defined radio and no general RF spectrum receiver, so the wide swath of spectrum where analog transmitters and wireless bugs actually live is unreachable. It has no thermal camera. It has no general‑purpose infrared view.Absent

02 — The signal itself

What a Bluetooth advertisement actually contains.

Almost every consumer detection claim rests on this one packet. It is worth knowing what is in it, because the answer explains most of the limits further down.

A Bluetooth Low Energy device that wants to be discoverable broadcasts a short advertising packet on a repeating interval. Any receiver in range can read it — no pairing, no permission from the broadcasting device. That packet may contain a local name, a list of advertised service identifiers, a small block of service data, a block of manufacturer‑specific data, a transmit‑power value, and an appearance code.

The manufacturer data block is the one that matters. Its first two bytes are a company identifier assigned from a central industry registry. That is the number nearly every scanner in this category keys on, and it is worth being precise about what it means: it identifies the company, not the product. A company that sells camera glasses, a gimbal, a microphone and a drone typically uses the same identifier across all of them. A match tells you a device from that manufacturer is broadcasting nearby. It does not tell you which one.

The address in the packet is not a stable identity either. Modern devices broadcast rotating private addresses by design, specifically so they cannot be followed over time, and iOS never hands an app a hardware address at all — it substitutes an identifier that is unique to that app and that pairing and that can change. This is good privacy engineering and it is working as intended. It also means a scanner cannot reliably say “this is the same device I saw an hour ago” unless the device is broadcasting something that gives it away.

Two further constraints are worth stating plainly. Devices that use only classic Bluetooth rather than the Low Energy variant — a great many audio devices among them — are invisible to an iOS app entirely; there is no interface that surfaces them. And an iPhone cannot itself broadcast manufacturer data, which is why testing a detector honestly requires a second, non‑Apple device.

The sentence that carries the rest of this document

Nothing in an advertising packet describes what a device is doing. The packet exists so that things can find each other and connect. It is a connectivity mechanism. It was never designed to disclose activity, and it does not.

03 — The honest ceiling

What can honestly be detected, and how sure you can be.

Four things, in descending order of how much confidence the underlying mechanism can actually carry.

Drones

The only one of the four that is a genuine protocol read rather than an inference. Most drones now broadcast a standardised Remote ID message under ASTM F3411, an aviation transparency standard, and that message is designed to be received and understood. When a phone reads a validly formatted Remote ID broadcast, it is reading a disclosure the aircraft is required to make.Strongest available — a real standard

Bluetooth trackers

Tracking tags broadcast continuously so that the finding network can hear them, and the companies that make them tend to make nothing else. A registered company identifier belonging to a single‑purpose vendor is about as strong as a manufacturer match ever gets.Strong — single‑purpose vendor

Camera glasses

Detected the same way, with a weaker ceiling. The companies that make camera eyewear also make phones, headsets, speakers and accessories under the same identifier. A match is a good reason to look around. It is not proof that the device is eyewear, and it says nothing whatever about whether the camera is on.A strong clue, not proof

Camera lenses, optically

The lens‑glint method described in §01. It is the weakest technique in honest use, and it is worth being blunt about that: it misses real cameras routinely — wrong angle, no reflection at that moment, too much ambient light, a lens too small or too recessed — and it flags harmless reflective objects. It is a way of looking more carefully. It is not a test that returns an answer.Heuristic aid only

04 — The scope statement

What cannot be detected, and why.

Each of these is a structural limit rather than an engineering backlog. None of them is waiting on a better app.

Whether anything is recording

The most claimed capability in this category and the least supported. No radio signal in common use encodes capture state, so there is nothing for a receiver to read. A device that is advertising is present; that is the entire content of the finding. Treat any product that claims to know when recording starts as claiming something it cannot demonstrate.

A microphone

The trap here is worth spelling out. The Bluetooth audio devices a phone can reliably see are the benign ones — headphones, earbuds, speakerphones, hearing aids. The devices that actually threaten — UHF and cellular bugs, wired recorders, proprietary wireless microphone links — either carry no Bluetooth or advertise nothing that distinguishes them. The set of devices that are simultaneously detectable, threatening and distinguishable from a user’s own earbuds is empty.

A specific device, or a person

Company identifiers cover whole catalogues, and addresses rotate by design. A scanner can report a category and a confidence. It cannot report an identity, and it cannot follow a device across time or place.

A bearing, or a real distance

Distance is inferred from received signal strength through a path‑loss model, which is noisy by nature and thrown off by reflection, orientation, obstruction and differences in transmit power. An ordinary phone gets no direction information from a Bluetooth advertisement at all. A radar-style display is an illustration of proximity, not a bearing.

Anything not broadcasting

A wired camera. A cellular data logger. An analog transmitter. A device that is powered off, or asleep, or broadcasting under an identifier no one has catalogued yet. No signal, no finding — and this category includes most purpose‑built covert hardware.

A cell‑site simulator

iOS gives no application access to the baseband radio. Nothing distributed through the App Store can do this, whatever it says on its listing.

Anything reliable, in the background

Broad Bluetooth scanning while an app is suspended is best‑effort on iOS. The platform does not reliably deliver new device discoveries to a backgrounded app running this kind of scan. A quiet phone in your pocket is not a monitored room.

No alert is not a guarantee of safety.

A quiet sweep means nothing answered. It does not mean nothing is there. Everything above is a reason a real device might not answer.

05 — Named plainly

Methods that do not work.

These appear across a large number of detection apps. They are worth understanding because they explain why the category has a credibility problem, and because knowing them makes you a harder person to sell to.

The magnetometer “camera detector”

Uses the compass sensor and reports a hit when the local magnetic field changes. Magnetic field strength is a property of ferrous metal and magnets. It is not a property of cameras. The sensor responds the same way to a door hinge, a screw, a speaker magnet, a bracket behind drywall and a fridge. A tour of a room with this feature on produces hits everywhere, which reads as sensitivity and is in fact noise.

“Infrared detection”

Phone cameras are filtered against infrared, and no consumer phone offers a general‑purpose infrared view. What some phones can do — and it varies by handset and by camera, so treat it as a maybe rather than a method —, in a fully dark room, is faintly show the glow of an active infrared illuminator — the kind a night‑vision camera uses. That is a narrow and real effect, and it is the camera doing it, not the app. It finds only cameras that are actively illuminating in the dark, and it is not a general camera test.

Network scanners sold as camera finders

Enumerating devices on the Wi‑Fi network you are joined to is a legitimate thing to do and can occasionally surface a camera on a guest network. As a way of clearing a room it is close to useless: anything on a separate network, a hidden network, or a cellular connection simply is not on your list, and a covert camera is unlikely to be sitting on the network handed to guests.

Any claim of completeness

“Detects all hidden cameras.” “Know what is watching.” “Military grade.” Given everything above, a completeness claim is not enthusiasm. It is a statement that the seller either has not understood the constraints or is content for you not to.

06 — The fixable part

The standards gap.

Everything above tops out at “a clue” for one reason: there is no standard by which a recording device announces itself. That is not a law of physics. It is a gap.

The shape of a solution is already on the record. In June 2026 the G7 data protection and privacy authorities published a compendium on smart glasses. In it, the Berlin Group’s position is recorded directly: for miniaturised devices, transparency should be provided by non‑visual means, “such as broadcasting a signal.” The same document acknowledges that in some situations it is practically impossible to obtain the consent of bystanders captured in the background of a recording. A regulator has described, in writing, precisely the mechanism a detector would consume.

The standards work has not followed — not because nobody is doing it, but because of where it has been pointed. The IETF working group closest to this problem, Detecting Unwanted Location Trackers, is chartered around location‑tracking accessories; its programme of work does not extend to devices whose purpose is to record. That group is active and its drafts are current: the threat model was revised on 6 August 2026. So the gap is one of scope rather than of neglect. Transparency for trackers is being specified. Transparency for cameras and glasses is not being specified by anyone.

So the situation is this: the transparency signal that would make detection reliable has been described by regulators, is technically unremarkable, and does not exist. In its absence, everyone in this category — ourselves included — is reduced to fingerprinting manufacturers and reporting a probability. That is the honest state of the art, and it is a policy failure rather than an engineering one.

We think that is the part worth arguing about, and we would rather be measured against a standard that exists than sell certainty that does not.

07 — Practical

How to actually check a room.

If you are in a hotel room, a short‑term rental or a changing room and you want to satisfy yourself, this is the order that actually helps. An app belongs late in it, not first.

Work out the sight lines first. Stand where you would undress or sleep and look back. A camera has to see you, which means it has to be somewhere with a clear view of that spot. That narrows a room to a handful of places before you have touched anything.

Look hard at the objects that face the bed. Smoke and carbon monoxide detectors, alarm clocks, chargers and plug adapters, air purifiers, speakers, decorative boxes, power outlets, and anything that seems oddly placed or newer than everything around it. Two smoke detectors in one small room is worth a second look.

Turn the lights off and sweep with a bright light. Hold the light close to your eye and move slowly across the room at and below eye level. You are looking for a small, sharp, bright point that appears at one angle and disappears at another. Check from several positions — a lens only reflects back along its own axis.

Touch things that should be cold. A device that is powered and processing gives off heat. A warm charger with nothing plugged into it, or a warm decorative object, is worth explaining.

Then run a Bluetooth scan. It will tell you what is broadcasting nearby, which is useful and incomplete. Treat a finding as a reason to look somewhere specific, and treat a clean scan as telling you nothing.

If you find something, leave it in place. Photograph it where it sits, note the position, and contact the platform you booked through and local police. Removing or dismantling it destroys the thing that would establish what it was and how long it had been there.

08 — Provenance

Sources and disclosure.

Where the claims in this document come from, and what our interest in it is.

Bluetooth advertising structure and company identifiers — the assigned‑numbers registry maintained by the Bluetooth Special Interest Group.

Drone Remote ID — ASTM F3411, the standard specification for remote identification and tracking of unmanned aircraft.

Platform constraints on scanning, background execution and baseband access — Apple’s published developer documentation for Core Bluetooth and for network and radio access on iOS.

Regulatory position on non‑visual indication for miniaturised recording devicesSmart glasses: Compendium of G7 data protection and privacy authorities approaches, published by the CNIL, June 2026, and the Berlin Group position recorded within it. Primary document (PDF).

Standards status for device‑tracking transparency protocols — the IETF Detecting Unwanted Location Trackers working group charter and its threat‑model draft, checked on the IETF datatracker on 3 September 2026 (revision 05, 6 August 2026).

Disclosure

QuietField LLC makes QuietCheck, a paid iPhone app that does some of the detection described in §03. We therefore have a commercial interest in people caring about this subject, and you should read this document with that in mind.

What we would ask you to weigh against it: this page argues that the most valuable capability in our category cannot be delivered by anyone, ourselves included, and it names the weakest technique in our own product as the weakest technique in our own product. We would rather be trusted about the limits than believed about the claims.

This document is free to quote and to cite. If something here is wrong, we would like to know — corrections are welcome at info@quietfieldllc.com and we will publish them.

First published 3 September 2026. Reviewed 3 September 2026.