Got a tip for us?

iPadOS

AirTags and other accessories are locked to the phone they’re paired with. Apple calls this Find My Lock instead of Activation Lock, which is available for Apple devices, like iPhones and Macs. (See how Activation Lock protects a lost or stolen device.)

You can remove an AirTag from an Apple Account using the native Find My app but only on an iPhone or iPad linked to your iCloud account. You cannot use a Mac to remove a Find My item pairing; Apple has not explained why.

Go to the Find My app, tap the Items button, tap the AirTag, and at the bottom of the sheet with actions, tap Remove. Apple lets you know this means someone else can use it by pairing it. Apple also alerts you with shared items about others being unable to see it after removal.

If the AirTag is within Bluetooth range of the device you’re using to remove it from your Apple Account, it is automatically reset and ready to be paired with another device. Otherwise, it has to be physically reset after removal. Apple has instructions in a support document, but I found them a little difficult to follow in their formulation.

An AirTag remains connected to its paired device and unusable with another device until or unless it is removed from your Apple Account. Resetting it has no effect on pairing.

I highly recommend avoiding purchasing used AirTags or Find My items, as there’s no way for a seller to provide an assurance that the item has had its Find My Lock removed. At worst, only buy from a source that promises a full refund and free return, including shipping costs, if the item can’t be used.

I’ve sometimes found I have to restart my iPhone to re-pair an AirTag with it after removing it.

Here’s what I hope is a clearer sequence:

Reset your AirTag

  1. Remove the back cover: Holding the glossy white front, push down to twist the metal back panel counter-clockwise. It only needs to move a small distance before the cover pops off.
  2. Remove the battery: Inside, you’ll see its small coin cell battery. Remove the battery, making note of the right side up: the + sign on the battery will always face you.
  3. Press in a sequence: This next step may seem peculiar, because the back cover remains off. Put the battery back in place and then press down lightly. The AirTag makes a faint bleep. Repeat this four times: remove the battery so it makes no contact, put it back in, press it lightly, and wait for a sound. The fifth time you do this, the sound will be slightly different. That means the reset operation completed successfully.
  4. Reattach back cover: Now you can look at the cover to see the extended tabs and align those with the hole in the top. Press in and then rotate the cover clockwise against its top until it’s firmly in place.

The small size of the AirTag, its cover, and the battery within are all choking hazards for small children or pets. If you have either or have visitors with them, keep track of loose AirTags or parts.

Now you can pair with another iPhone or iPad.

Stop an AirTag transmitting

Removing an AirTag from an account stops it from relaying location data. However, if you want the device to stop sending any signal, remove the cover and the battery.

In a pinch, you can disable an AirTag’s or third-party item’s capability to transmit its signal by wrapping it in aluminum foil or putting it in a bag designed to block electromagnetic fields (a so-called Faraday cage). These items emit fairly weak Bluetooth signals, so the foil approach will, uh, foil attempts to track you if you can’t figure out how to remove the battery or you want to leave the device intact to give to law enforcement.

You can find advice all over the internet about how to disable the sound-producing part of an AirTag. I won’t link to any such advice, and I recommend you avoid it in nearly all cases. Why? Because the intent isn’t, as often stated on these webpages, how to keep an AirTag from bothering you. Rather, it’s clearly advice on producing a more effective electronic stalker. (Apple also may have made it harder to remove the sound-producing component in the 2nd-generation AirTag, but the company declines to discuss that.)

You might have a perfectly good reason to dampen the sound! But in some countries (or even certain cities, states, or regions within a country), unless an AirTag is continuously within your control, disabling the intended audio alert could run afoul of privacy and anti-stalking laws and get you into real trouble. (For when this sound occurs, see what an “AirTag Found Moving With You” alert means.)

Disclosing your location is a two-edged sword—or maybe a multi-bladed throwing star. It can be incredibly handy to let other people know where you are for travel, safety, timing, and even accountability. However, letting others know where you are means they know where you are, which even for close friends, family, and partners can feel like too much knowledge and the expectation of you sharing your position can feel invasive. (You also may feel it’s excessive that, when you launch Find My, you can see the precise location of everyone who has shared with you, even though they did so willingly!)

Apple tries to strike a balance with location sharing just as it does with nearly all other aspects of digital privacy that they mediate and let you choose your comfort level with.

Find My is the interface through which the location you share from an iPhone, iPad, Mac, or Apple Watch gets viewed, but it’s only partly the way in which you choose what is shared! That split is left over from when Apple introduced the previous standalone app, Find My Friends, and relied on preferences buried in Settings to manage all the details.

When you share your location, the other person cannot see your devices, but only your presence: the device marked as showing where you are. Only people in a Family Sharing group can see each other’s devices, and only if the person is sharing their location with them. Items don’t pick up Family Sharing settings. You can share them with up to five people.

Location has two interrelated components: how you share your location and how you choose to accept seeing other people’s locations. Let’s start with you.

You can use the native Find My app to view and change personal settings, even if you’re part of a Family Sharing group:

  • On an iPhone/iPad, watchOS 27, and macOS 27: Go to the Find My app > Me button.
  • In macOS 26 and earlier: In the Find My app’s People view, click Me and click the Info button.
  • In watchOS 26 and earlier: In the Find People app, tap the Me entry.

Here is what appears in the My Location section on all these devices:

  • Share My Location: A single tap, and you let yourself be seen by those you’ve shared with; another tap, and you run silent—your location isn’t sent again until it’s re-enabled.
  • Sharing From: Often called presence, this defines which devices are shared in Find My as being your location as a human if you own multiple devices. My Location reads This Device if you’re on the one defining your location; otherwise, it shows the name of that device. (See how Find My works.)
  • Location Label: At the top of the Me view, you see the current inferred address. However, Find My tries to offer something more descriptive. If you’ve defined your home or work location in Contacts or Phone, it should show Home or Work as the label. You can also create your own names for other addresses; see how to see someone’s location in Find My.

Share with someone

You can share your location in more than one way, and the interface is essentially the same with slight differences.

Here’s how to share in various ways across your Apple devices, from most universal to most specific; how to set the duration option is discussed after these instructions:

  • On an iPhone or iPad, or in macOS 26 or later:

— Find My app: Click or tap the add button at the upper-right corner of the list in whatever view you’re in. Enter names or select people. Click the checkmark button. Now choose a duration.

— Messages: In any conversation in Messages, tap or click the avatar or avatars. On an iPhone or iPad, tap the Plus button, choose Location, tap Share, choose the duration (see below), and tap the Send button. On a Mac, click Share My Location, choose a duration, and press Return to send.

Tip: If your recipient or group isn’t all Apple users, you can still send an image that embeds a link to a map; instead of Send or Share, the button reads Send Pin.

  • In macOS Sequoia or earlier:

— Find My app: In the Find My app, click the People button, then click Share My Location. Enter names or select people. Click Send, and choose a duration.

— Messages: In any conversation in Messages, click the Info button in the upper-right corner. Click Share My Location and choose a duration. Press Return to send the location message.

  • On an Apple Watch:

— Find My app (watchOS 27) or Find People app (watchOS 26 or earlier): In watchOS 27 only, first tap People. Scroll to find Share My Location. Tap it to either dictate a name, choose a contact, or enter a contact’s phone number.

— Messages app: In the Messages app in watchOS 26 or later, choose a conversation, tap the add button, choose Location, tap Share, and choose a duration.

Note: When someone requests your location, as explained ahead in If You’re Asked to Reciprocate, you can’t use a single tap from an Apple Watch. You have to use one of the above methods.

Note: You can’t share your location with others or see their location in the Find Devices app on iCloud.com.

Choose how long it lasts

No matter which path, platform, or version you’re using from the above list, you’re asked to pick or set a duration: Always (formerly Indefinitely), End of Day, One Hour, or Custom. (These options are worded slightly differently across apps.) The Custom choice is new in the version 27 releases. Selecting that option lets you set a duration from 15 minutes to 30 days.

If you shared via Messages, you see a note in the conversation that says “You started sharing location with person name.” The recipient sees “Person name started sharing location with you.”

I’m guessing Apple switched in the version 27 releases to the simpler word “always” after years of using “indefinitely” because more people can easily parse “always.” Indefinitely has the ring of “inflammable” about it: does it mean forever or for a period of time? (Inflammable items are just as easy to set on fire as flammable ones.)

If you choose anything but Always/Indefinitely, a countdown clock appears when you view the details for that person’s entry in Find My: it reads “Sharing for X time units” in the version 27 releases and “X time units remaining in previous operating systems. Messages displays a map tile with an inset yellow countdown clock for the remaining time. In Apple Watch’s Find People app, the contact’s avatar is overlaid with a timer; tap the entry to see the remaining time as text.

Family Sharing is a separate switch

For greater flexibility, Apple also lets you use Family Sharing settings to enable to disable location sharing among group members. Go to Settings/System Settings > Family > Location Sharing to see family settings.

In Location Sharing, you see all the other members of your family sharing group and your current sharing status with them and theirs with you—sort of!

If you used this interface to share your location, or used the Automatically Share Location option (enabled by default) for new members, you see sharing enabled next to the group member. However, if you used the Find My app to start sharing your location, it may appear that you are not sharing with them! You’re just not “family” sharing with them! Yes, it’s as straightforward as a bent nail.

Under the Share Your Location With section, you can also see which of the group members are sharing with you. Again, this is dependent on how you shared. In the figure, you see “person name is sharing your location with you,” even though four members of my family group are sharing their locations with me. Oy!

See who can currently find you

Once you start sharing your location with other people, you might lose track of precisely who that is. Fortunately, you can see a list in a few different places:

  • Native Find My app: Use the Find My app’s People view or the Find People app on an Apple Watch (watchOS 26 or earlier). Everyone in the list who reciprocally follows you appears with location information; everyone else you share with has the label “Can see your location” beneath their name.
  • Find My settings: On an iPhone or iPad, go to Settings > Your Name > iCloud > Find My, and you can see Family (if you’re in a Family Sharing group) and Friends. This doesn’t show reciprocal sharing status, however.
  • Family settings: If you’re part of a Family Sharing group, Settings/System Settings > Family > Location Sharing reveals any group member with whom you’ve shared using Family Sharing settings. See that befuddling situation above in Share Location with Family.

We’re all quite rightly concerned about our private data stored on our most personal devices—the ones we carry with us all the time. Apple has done a stellar job in locking down access to an iPhone, iPad, Mac, or Apple Watch. But there’s still a fear: what if someone guesses our passcode or passphrase, or uses some new cracking technology to break in?

Apple offers an excellent option that can assuage some fears. You can remote erase your device by sending it an irreversible command that takes place immediately if it’s connected to the internet, or as soon as it’s next connected—if it ever connects again.

What happens when you erase a device in Find My?

  • A confirmation email is sent to your Apple Account email address.
  • When you erase a device remotely using Find My, Activation Lock remains on to protect it. Your Apple Account password is required to reactivate it.
  • If you erase a device that had iOS 15, iPadOS 15, or later installed, you can use Find My to locate or play a sound on the device. Otherwise, you won’t be able to locate or play a sound on it. You may still be able to locate your Mac or Apple Watch if it’s near a previously used Wi-Fi network.

Erase an iPhone or iPad

The last resort in some cases (or first in others) is a remote wipe, in which all the user data on an iPhone or iPad is erased.

An erased device that has Find My enabled before erasure and remains associated with an Apple Account cannot be unlocked without the account password due to Activation Lock.

The erase option lets you provide a phone number and message so that a person who found (or stole) your device can get in touch. The device is essentially useless to them without the password.

Once you erase a device (or if someone else has), Find My can find its location only if it’s an iPhone or iPad running iOS 15/iPadOS 15 or later. Before that release, erasing a device disables its ability to send Find My tracking data when connected to the internet.

You can remove a device from your Find My list; see how Activation Lock protects a lost or stolen device.

It’s a multi-step process to prevent accidental erasure; you can cancel at any stage until the last step:

The device will be erased immediately at the last step. If you’re using two-factor authentication, it is also removed from your trusted devices at once.

  1. Go to the Find My app 3ef46077881e8558ba33ff4dc013dbbe.
  2. Tap or click Devices at the bottom of the screen, then tap or click the name of the iPhone you want to erase.
  3. Tap or click Erase or Erase This Device.
  4. You’re warned that everything is about to be erased. Tap or click Continue.
  5. Optionally enter a phone number at which you can be reached after it’s erased, and tap or click Erase.
  6. Enter your Apple Account password and tap or click Erase. If this is another member’s device, accessible via Family Sharing, enter their Apple Account password.

If the device is online, the Erase action immediately wipes all your data. It’s fast because it throws away encryption keys that are used to secure your iPhone or iPad data—it doesn’t have to write zeros over all the data. If the device is offline, the erase begins as soon as it next comes online through any networking method.

What you actually lose

Wiping your device isn’t as bad for your stored data as it sounds. All iPhones and iPads are set by default to back up the unique data that’s stored on them, like settings, passwords, and documents created by or associated with apps. These backups can be either local to a Mac on a particular computer or remote to iCloud.

Apps are stored centrally, not in a backup, and restored from Apple’s servers; the same is true with synced books and purchased music, movies and TV programs. If you use iCloud Photos and Sync Library (for Music), that media is stored in the cloud and synced. (If you’re not using either, you probably sync music with a Mac or Windows system. This is a good time to check that you’re up to date with syncing.)

If you erase your device, and then either recover it or obtain a new device, you can restore from your most recent backup. If you were syncing any items to your device through Photos, Music, or other apps or tools on a Mac, you can then sync them back to the device. For items stored in iCloud, the restore process downloads them again.

You can accelerate restoring an iPhone or iPad with Apple’s Quick Start. Place one of your iPhones or iPads near another and follow the steps provided. This streamlines setup. In a final step, you can choose to restore from an iCloud or other backup.

If any unique data was syncing from your iPad or iPhone to iCloud, Dropbox, Exchange, or another service, you should retain changes up to the moment the device disconnected from a cellular or Wi-Fi network. You will lose only changes made on the device between the last sync (push, fetch, or manual) for each account and the remote wipe.

Erase a Mac

The process of starting is nearly the same as with a mobile device:

Macs can’t be tracked after erasure. The device will be erased immediately at the last step. Two-factor authentication will also drop it from your trusted devices.

  1. Select the device in any Find My app and reveal its sheet.
  2. Tap or click Erase This Device.
  3. Review Apple’s warning. Click Continue.
  4. Enter a message that will be displayed to someone who has or finds the machine and click Erase.
  5. Enter your Apple Account password and tap Erase. If this is another member’s device, accessible via Family Sharing, enter their Apple Account password.

The selected Mac will now be erased. How long that will take depends on hardware features. Erasure is nearly instantaneous.

Be sure you always have a current backup that you can restore from in case your Mac dies, there’s a natural or house disaster (fire, flood, collapse), you lose it, or someone breaks it or steals it.

Find My lets you mark items as lost to help recover items you can’t find or that might be stolen. Marking something as lost puts the hardware into a special Lost Mode and lets you provide details to someone who finds it—or even to a thief you want to encourage to return it.

Apple labels the feature as Lost Device Type on the Find My sheet and Mark As Lost in macOS 26 and earlier when you Control-click/right-click a device in Find My for Mac’s device list. However, the option to turn the feature on is labeled Lost Mode.

This information is available differently (or not at all) based on the kind of thing that’s marked as lost:

  • Devices: For devices, you can enter text (such as offering a reward) and provide your phone number. Both appear on the device.
  • AirTags and other items: With a Find My item—like AirTags or a Pebblebee Card—you can provide your phone number or email address; Apple prefills the message “This item has been lost. Please call me.” This information appears on a webpage associated with the device, which a finder can retrieve as described in how to identify an AirTag you have found.
  • Audio hardware without a screen: AirPods (3rd generation), AirPods 4 with Active Noise Cancellation, AirPods Pro, and AirPods Max can provide contact info just as with a Find My item. (The 1st- and 2nd-generation AirPods, AirPods 4 without ANC, and Beats models that support the Find My network can’t be marked as lost.)

Because devices have screens, marking a device as lost puts the finder on notice that you know approximately where it is—they can see that from the lock screen. If your hardware is stolen, this is a way to tell a thief that you have their location and advise them to give it up.

With supported Apple audio hardware or a Find My item, it’s trickier, as a finder has to take additional steps to determine its status rather than looking at a screen or receiving an alert—although they will hear an item make a sound or sounds in certain circumstances: see what an “AirTag Found Moving With You” alert means for those cases.

Mark a device as lost

When a device is marked as lost, it is locked and can be unlocked only with a device passcode (iPhone, iPad, or Apple Watch) or an Apple Account password or a macOS account password (Mac). Apple Pay is disabled, and all associated cards are temporarily suspended.

Even though Apple audio hardware that can be marked as lost appears in the Devices list, the options for a lost set of earbuds or headphones are the same as a lost item, described later in this chapter.

In case you’re thinking of testing this on your Mac, be aware that your computer restarts instantly after you confirm Lost Mode. You might lose unsaved work in progress.

  1. Tap or click Lost Mode beneath Lost Device Type.
  2. Apple explains what will happen to the device in a screen labeled Lost Mode (iPhone, iPad, or Apple Watch), or “Lock this Mac?” Tap or click Continue to proceed or Cancel to back out.
  3. Enter a passcode if prompted and verify it. (This is unlikely, but it may happen. Make a note of the passcode so you aren’t locked out.)
  4. On devices other than Macs or supported audio devices, optionally set a phone number for a call back. On an iPhone, a finder can call only that number. On other devices, the call-back number is displayed. Tap or click Next.
  5. Optionally, for devices that offer it, enter a message that will appear on the device. In this step, the dialog shows that a passcode has already been set and will be used to lock the device. Tap or click Next.
  6. On the final screen for anything but a Mac, you see a summary of actions and information:
    • Notify When Found: Enable if you want device-based notifications on all your linked hardware.
    • Text you entered: The text of the phone number and messages you entered, if any, appears, but you can’t modify it.
    • Receive Email Updates: This adds email to notifications as part of how you’re alerted.

Despite Apple’s explicit promise when locking a Mac that “This message will be shown on your Mac when someone turns it on,” I can confirm in Tahoe and Golden Gate, it is not. I don’t understand why Apple doesn’t show the message, and why they document it incorrectly.

Tap or click Enable or Activate for anything but a Mac, where you tap or click Continue or Lock.

After you activate Lost Mode, the action is passed to the device if it’s online, and an email message (if enabled) is sent to the address for the Apple Account for the device, confirming what you’ve done. Devices with batteries will be placed in low-power mode. On an iPhone, emergency service calls remain available. Credit and debit cards associated with Apple Pay are disabled on the device.

When a device is locked, it appears in the Devices view with its icon overlaid with a white question mark in an orange circle. A Mac additionally shows a gray screen.

If Location Services has been turned off by you or someone with access to your devices, Lost Mode overrides that and re-enables it so you can track your device.

Turn Lost Mode off again

  1. Select the device in the Find My app.
  2. Tap or click Turn Off Lost Mode, except on an Apple Watch, where you tap the Lost Mode button and disable Lost Mode.
  3. Find My prompts you with a warning that explains the device will remain locked, but the information you entered (phone number and message) and its location history will be deleted. Tap or click Turn Off to confirm.
  4. When you recover the device, enter its passcode or password.
  5. Then, you can disable Lost Mode: Enter your passcode.

Whether you use Find My or start directly from your iPhone, iPad, or Apple Watch, your device will prompt you to re-enter your Apple Account password once or twice. If you have separate iCloud and media Apple Accounts linked, read the dialog carefully so you enter the correct password for each.

To unlock a Mac, despite Apple promising you can do so via Find My or via iCloud.com/find, the truth in testing in Tahoe and Golden Gate is that you can only unlock your Mac while in front of it, going through a separate procedure.

What happens to Apple Pay

In some cases, you may be prompted for two-factor authentication to finish regaining access; in many recent tests, I was not, but I don’t know why. For accounts using code-based verification, you will have to use a trusted device other than the one you have in hand or a trusted phone number to validate your sign-in. With a hardware security key, it’s already independent and can simply be used if you’re prompted; you may be asked to use code-based verification, however. If you’re prompted a second time for your Apple Account password, no second factor appears to be required.

Mark as Lost immediately disables Apple’s side of Apple Pay for a lost device, which prevents even someone with your passcode from using Apple Pay. (When they use the passcode, this disables Lost Mode, but you would be notified.) You may see a flurry of “card deactivated” emails and texts from your credit card companies and banks as well as an email alert from Apple.

To re-enable your cards for Apple Pay, you will be in one of two states:

  • Wallet sync active: With Wallet enabled for syncing—Settings/System Settings > Account Name > iCloud > See All—when you re-enter your Apple Account password after unlocking the device, your cards are re-synced and activated. This may result in a similar flurry of “card reactivated” messages.
  • Wallet sync inactive: Without Wallet sync, your device deletes all locally stored card information when Lost Mode is activated. You have to manually re-enter cards that you want to use for Apple Pay on that device.

Do the same from iCloud.com

The iCloud web app for Find My iPhone diverges slightly from the Find My app, and mobile devices have a different process than Macs.

Lost Mode activates immediately when you click Activate at the last step — there are no extra options or final review stage.

Here’s how to proceed for an iPhone, iPad, iPod touch, Apple Watch, AirPods Pro, or AirPods Max:

  1. Select the device.
  2. On the sheet that appears, click Lost Device Type.
  3. Read the disclosure of what will happen when it’s locked and click Next to proceed.
  4. In the unlikely event the device doesn’t have a passcode set, you have to invent one and set it at this point.
  5. Enter a phone number that will be displayed (optional). Click Next.
  6. Enter a message that will be displayed (optional). Click Activate.

You can unlock these devices using the same methods as when they are locked in a native Find My app.

Lost Mode restarts a Mac immediately when you click Lock at the last step.

Macs are handled slightly differently; here are the alternative steps:

  1. Select the Mac.
  2. Click Lost Mac.
  3. Click Next after reading the disclosure.
  4. You have an option to enter a message before you click Lock.

The Mac is now locked and powers down. See how to unlock a Mac you locked with Find My for how this appears and your next steps.

Pause sharing without telling anyone

In the version 27 releases, Apple added a way to pause sharing your location with someone without removing them from your sharing-with list—and without them knowing. Here’s how to pause sharing:

  1. Select a person with whom you’re sharing your location.
  2. Tap or click the More button, and choose Hide Location.
  3. Find My explains that you stop sending your location for the remainder of the day.
  4. The other party is not notified when you pause, stop or resume sharing. They see only that no location was found.
  5. Tap or click Hide to continue, or Not Now to keep sharing.

The Location field shows “Unhide Location” until the shown time. When I chose to Hide Location at 2:30 p.m., it displayed “tomorrow at 4:00 a.m.” as the end point. If you tap or click Unhide Location, there’s no confirmation step: your location is immediately shared again.

This addition is clearly another tool in the kit for deterring unwanted tracking in abusive situations, where someone’s partner or family member demands they leave tracking on. This allows someone being tracked to go off the radar without it being obvious. For more, see how to check whether someone is tracking you.

Stop sharing altogether

You can completely stop sharing with someone, which removes you from their People list in Find My. They can’t prevent or reverse these. Stop sharing in either of these ways:

  • In the info pane in a Messages conversation, tap or click Stop Sharing My Location or Stop Sharing.
  • In a native Find My app (or Find People in watchOS 26), tap or click Stop Sharing My Location, Stop Sharing Location, or Stop Sharing.

If you stop sharing, the person remains in your list. You can remove their entry, as below.

You can remove someone from your People list and stop sharing with them or seeing their location. This requires a native Find My app. Here’s how to remove someone:

  • In the version 27 releases, select the People view, select a person, then tap or click the More button. Tap or click Remove and confirm.
  • In earlier releases, select the People view and select the person. On an iPhone or iPad, tap Remove and confirm. On a Mac, click the Info button, then click Remove and confirm.
  • On an iPhone or iPad, you can instead swipe left on a name in the People list and tap the Remove button (iOS 27/iPadOS 27) or Trash button (earlier releases).
  • On a Mac, click the People button and Control-click/right-click the person’s entry. In macOS 27, choose Remove Friend; in earlier versions, choose Remove Name. The person is removed immediately without additional prompting.

Ask someone else to share

You can use the Messages app to request that someone share their location with you. This is handy for a less sophisticated user who doesn’t know how to initiate sharing, or in situations where you want to message someone and ask them to share at the same time: they can read your message and then tap to share without going through additional hoops.

You can prevent receiving these requests by disabling Allow Friend Requests in a native Find My app on the Me tab or pane.

On an iPhone, iPad, or Mac running Tahoe or later, in any conversation in Messages, tap or click the avatar at the top of the view; on a Mac running Sequoia or earlier, click the Info button at the upper-right corner. Tap or click Request Location. This creates a request within Messages. Tap the Send button or press Return to transfer the request, and the other person can opt to Share and choose a duration.

There’s an alternative method on an iPhone or iPad in a conversation in Messages: Tap the Plus button, choose Location, tap Request, and tap the Send button.

If you’re already sharing your location with someone who isn’t with you, you can also use a native Find My app, view the person’s details, and tap or click Send Request.

If you’re on the accepting side of that equation, Messages now mediates your response. When you select a duration, this generates another message; you can click or tap the Send icon or press Return to transmit.

When you are asked to reciprocate

The Find My app shows an entry for each person actively sharing their location with you in the People view. For time-limited sharing, their pictures are overlaid with a little clock.

When you share your location with someone else or vice versa, Find My posts an alert, but the party being shared with doesn’t have to accept it; the sharing party is just added to their Find My list.

However, if that person (you or someone else) isn’t someone the recipient already shares their location with, Find My prompts for reciprocation. (That is, if you share to someone and they don’t, they will be prompted to share with you; if they share to you and you don’t, you’ll be prompted to share with them.)

You can choose to mirror a shared location via a notification. Tap or click the notification, then choose the duration. If you ignore or dismiss the notification, you can also use the Find My app, where the notification appears in the People list with the same message. Similarly, tap or click Don’t Share or tap or click Share to choose a duration from the pop-up menu.

You can’t reciprocate on an Apple Watch.

If the person doesn’t follow you, you can use the same methods in Request Sharing from Someone to ask again.

Where to get help

There are many organizations beyond law enforcement eager to help people trapped in situations of domestic abuse or child subject to violence and an unsafe environment. For adults in the United States, that includes the National Domestic Violence Hotline; for children or those concerned about their welfare in the United States and Canada, the Childhelp National Child Abuse Hotline.

For those being stalked, one starting point is Safehope. It’s more likely you will need the help of police or federal authorities. Local police departments have their own paths to navigate, but for online or cyber stalking, it may be better to start with the FBI.

If the person you are worried about may be watching your device, use one they cannot see. Removing a tracker or turning off sharing can be noticed, and advocates warn that it can make a situation worse rather than better, so it is worth talking to someone before you act.

In a TidBITS article, Evaluating Wireless Security Needs: The Three L’s, Adam Engst laid out the three factors he considered relevant to determining one’s risk when it comes to Wi-Fi security. He called them the three L’s: likelihood (the probability that someone will violate your security), liability (the cost—financial or otherwise—that you’d incur if a security breach happened), and lost opportunity (what you lose in terms of time and convenience by implementing stronger security). That article is still well worth a read almost two decades later.

Times, technologies, and threats change, but some people still face greater risks than others. If you can assess your own level of risk soberly, you’ll be able to take appropriate measures—neither too weak nor too strong.

The risk for most people

Years ago, it made more sense for nearly all Mac owners to consider their susceptibility to outside attack: how likely were you to visit sketchy sites, download applications that might contain Trojan horses, be infected by malware by visiting a site or running software, or even configure a network sharing setting that allowed people on the internet to scan and find weaknesses they could use to potentially copy data from your Mac, or worse. iPhone and then iPad users had fewer risks because of how iOS and iPadOS were constructed and locked down, but external attacks remained the central problem for them.

That profile changed considerably by the late 2010s. The biggest risk that most Apple users have faced since then—no matter their specific Apple hardware—comes from phishing and social engineering.

Phishing describes when someone impersonates a person, group, or website in the hopes you will click through and be infected by malware or enter login credentials. Phishers want your personal data, preferably financial information, such as your credit card number, expiration date, and verification code. They try to offer credible-looking security warnings and fraudulent webpages where you enter payment information or credentials they can use to access your bank and other accounts.

Social engineering is when people attempt to convince you to do something harmful to your device—and compromise your security and privacy. A common scam is that you visit a website and are redirected to another site (via malicious advertising or injected code) that claims your computer, phone, or tablet is infected and urges you to call a number. Calling that number leads you to a boiler room in which the other parties try to get you to install remote access software and sign up for expensive, hard-to-cancel tech services—or worse.

There are also more general attackers, who want to fool you into installing Mac apps that appear to be legitimate, but actually encrypt your personal files and hold them for ransom (ransomware). iOS and iPadOS don’t allow this vector because of how apps are installed and files managed. And even after over a decade into what remains rampant use of ransomware, that scourge hasn’t found a foothold on Mac.

From the mid-2020s, I would also argue that governments of democracies have increasingly chosen to enact laws or stretch the limits of existing ones to intrude into our private spaces, including accessing data that they would never previously have considered due to pushback from both ends of the political spectrum and, in some countries, a strong libertarian philosophy on the primacy of privacy.

Even if you don’t believe you fit in a category where the government of the place you reside would target you personally, you should assume your risk is elevated in any country that is sweeping away previous protections in the vague interests of “protecting children” even when no children are involved and “national security” when no national security interests are shown.

The high value of privacy violations

Some unwanted software doesn’t mess up a device or steal data, but installs adware that can display rogue ads (overlaying ones served by webpages), hijack web searches, and redirect affiliate clicks through portals controlled by the operators to make money illegitimately off you from advertisers. Other software is more insidious, tracking your location to sell it to companies that target you with ads—it’s a kind of malware, even if it doesn’t subvert the device.

The most obvious vector is a Mac, where you can install third-party software that isn’t vetted by Apple. But given that you can install extensions in Safari for the iPhone, iPad, or Mac, and that Apple has routinely failed to catch App Store apps that violate user privacy or include adware components, you can be at risk on any platform. Fortunately, so far, I have heard of no iPhone or iPad examples.

To step up protections, you can engage any or all of the following security or software integrity steps that reduce the area of attack on you that could succeed:

  • Two-factor authentication (2FA): This extra step for logging in deters attackers who have phished or otherwise obtained your password. Apple requires 2FA for Apple Accounts (with a few legacy exceptions), limiting access to iCloud-synced information, purchases, email, and much more. Most non-Apple services offer code-based 2FA (sent via SMS) or other ways to validate a password login. To compromise your account, someone has to obtain your SMS messages, your trusted devices, or your authentication app.

Some phishers perform a “two-step” attack in which they convince you not only to enter your account name and password on a site, but then also relay that information in real time to the actual site you intended to access. This causes the real site to send you a confirmation code (or the fake site requests that you generate one). The attackers capture that code when you enter it. However, that scam works only for brief periods, as short as one minute.

  • Passkey: Upgrade accounts at websites that support passkeys, a secure method of logging in that’s deeply embedded on iPhones, iPads, and Macs, and supported by Google and Microsoft. The secret part of a passkey is never transmitted over the internet, and a passkey is phishing-resistant. You can sync and share passkeys when using recent operating systems and password managers. I’ve shifted from tolerating passkeys to preferring them to a password-and-second-factor combo. See where Apple stores your passwords and passkeys.

Sounds great, right? But passkeys are, in every case I’m aware of, a supplemented to two-factor-protected accounts, not a replacement. Until you can make a passkey replace a regular login (with some kind of recovery option), they’re only as secure as the next-weakest link in the chain.

  • Hardware security key: Another form of 2FA, a relative of a passkey, is a hardware security key. These small physical objects plug into a USB or Lightning port or can connect via NFC to iPhones or iPads. The hardware key has embedded encryption circuitry that generates a unique, highly secure login key for each site you use it with. These keys are built on a standard nearly identical to the technology underlying passkeys, and most websites that support passkeys can accept a hardware security key and vice versa. (These keys also rarely fully replace access to an account yet, meaning a flaw in password and two-factor authentication could compromise access.)
  • Apple Pay: Avoid sites that don’t let you pay by Apple Pay, which prevents your credit-card number from being transmitted directly.
  • Install financial apps: Financial apps and their associated notifications make it more likely you will know immediately if any part of your financial life has been manipulated without permission. I’ve noticed a trend since 2024 for financial apps that support Face ID or Touch ID to let you log in from a desktop browser using a QR code or a push notification from the app. You then verify via biometrics, so you’re never entering any credentials in a browser.

Apple already blocks the direct installation of unsigned software on a Mac—apps that were released by people without an Apple Developer account or who bypassed Apple’s minimally involved signing system. By not allowing the easy installation of unsigned software, Apple prevents most malicious software from running at all. See how Gatekeeper decides which Mac apps can run.

  • Continuous backups: The technology for making constant, secure online backups of documents and creating local clones and backups obviates risks more present now than in the past when those options were slow, expensive, or not feasible due to cost or bandwidth limitations. Having such backups in place gives you a point to revert to if you have data corruption or loss.
  • End-to-end encryption (E2EE) for iCloud: Apple’s Advanced Data Protection lets iCloud users put media, notes, reminders, and iCloud Drive files under the gold standard of end-to-end encryption, which requires possession of a device and the means to unlock to access data. Because we may store details that can be used to exploit us in these various kinds of media, E2EE is another leg up on attackers. See how to turn on Advanced Data Protection.

By using Apple and industry technologies and safeguards and keeping backups current, you can dramatically reduce your likelihood of risks while also curtailing the liability that results. Even if you’re infected by ransomware—an unlikely event—and don’t want to pay, you might lose no files by reverting to a snapshot before the attack; or if someone guesses or obtains an account login, you’re alerted as they try to log in, so you can change the password, or they’re blocked entirely without a second factor or hardware element.

The change in our general risk profile over time, however, comes with one big flashing red light. I noted a couple of times above that most people only need to take certain default strong, reasonable measures. However, if you’re someone in particular fields of work or who engages in political advocacy, you may face targeted attacks that evade basic measures that suffice for everyone else.

A human-rights reformer in an incipient dictatorship needs to take more safeguards than a suburban online shopper in Ohio. But identity theft can sometimes lift that Ohioan—or you—into a much higher category of risk, because someone decides your assets or information are valuable to them, and they’ve acquired credentials or personal information that will let them attempt to crack your security shell.

What about children?

If your minor child has their own iPhone, iPad, or Mac, you might assume they are at very low risk. After all, their device probably contains nothing but games, educational software, a school-provided office suite, and a browser playing videos from Disney+.

But no! Sad to say, children are at greater risk than adults, all else being equal, because they’re less experienced and more trusting—and because, let’s face it, there are a lot of creeps out there who stalk children online.

If you travel to a country with severe laws or a propensity to jail people without legitimate charges, you should raise your risk profile before you travel and while there.

If you’re at higher risk, you should consider taking the most stringent measures available. Check the following criteria to see if they apply:

  • You work in the financial, legal, medical, or government sector: If you use Apple hardware for work, you are likely subject to regulatory requirements and have been briefed on them. (You might even have had to take a course on compliance!) You may be required to engage additional security, like using a VPN, blocking ports for USB/Thunderbolt and SD Cards (see the Mac settings worth changing), enabling FileVault on a Mac, and turning on Advanced Data Protection in iCloud. You may also need to enable hardware security keys for your Apple Account. If you don’t take these steps, and it’s discovered, your devices are lost or data intercepted, or online accounts are compromised, you could be sanctioned, fired, fined, or even charged with a crime, depending on the employer and locality.
  • Your device contains unusually sensitive data: This could be old love letters you don’t want your partner to see, confidential business information from your employer (even if they’re not in the financial, legal, etc., categories above), records of a delicate medical condition, or anything else that could cause you serious problems (like loss of your job, insurance, or marriage) if it were to get out.
  • You’re famous: Congratulations! You already know the price of this on social media and when dining, traveling, or walking around, depending on how well-known you are. But you’re also more of a target online, because of the obsession so many sites and people have with secrets about people who are seen to be famous.
  • You’re a journalist: Sadly, reporters are frequently targeted by criminals, people they’re writing about, and governments. For instance, Ronan Farrow reported that Harvey Weinstein hired an Israel-based private-intelligence firm to dig up dirt on him while he was researching his watershed story on Weinstein’s history of alleged and proven sexual crimes.
  • Wealthy in real terms or cryptocurrency: People with more than a little money are regular targets, especially if they have significant Bitcoin or other cryptocurrency holdings. Having an expensive house doesn’t mean much in the current real-estate market; it’s more likely that you have elevated risk if there’s coverage or securities filings that disclose your wealth, stock grants, or other assets.
  • Rough travel: You frequent any of the internet’s seedier neighborhoods, such as sites that traffic in online gambling, porn, or pirated content (like software, television shows, or movies).
  • Secret or pseudonymous identity: You have an online identity, separate from your real-life identity, that you need to keep private. A number of times in recent years, someone whose job or political position has prevented them from having a public persona have been outed for writing under another, typically fictitious name.
  • Heated online interactions: You engage in controversial discussions that might result in people being exceptionally angry with you.
  • Careless co-users (Mac): Specific to a Mac, you share it with less-sophisticated family members who may not be as careful as you would be about downloading files from unknown sites, clicking links in email messages, and using good passwords. While you can set them up with their own macOS accounts—you should!—some of their actions can affect the entire Mac and your online accounts.
  • People in particular professions and of genders other than male: It’s a sad fact of modern life that being a responsible journalist, being an advocate for vulnerable people, believing the Earth is round and evolution legitimately established in the fossil record, or having the temerity to be a gender that someone else has chosen to be angry about online can cause reactionary individuals and groups to target you.
  • You live in a country that has reduced privacy protections: Various countries have fought with Apple over allowing back-door access to iCloud data. The United States asserts the right to login to examine incoming tourists’ and students’ social media and other accounts. Many countries now think that any checkpoint, traffic stop, or other incidental encounter gives them carte blanche to demand all your data.

Now for the good news! A decade ago, my advice to you would have likely been far more extensive and stringent than for the average user. These days, however, Apple’s and other companies’ baseline security is more accessible, easier to use, and more effective.

My general advice is to do everything suggested here as the baseline, and build a bit from there.

Take a hard look at Lockdown Mode

Some people are pinpoint targeted by spyware, software that can hijack their devices, often without a single click, using previously unknown exploits. These attacks are worth a lot of money and thus typically deployed in a targeted fashion by governments and criminal syndicates against journalists, members of minority groups in a given country, human-rights activists, and opposition politicians.

To help counter these kinds of intrusions, Apple offers a Lockdown Mode you can invoke that highly restricts many forms of inbound messages and traffic. For the full rundown, see how to turn on Lockdown Mode and who needs it.

If you fall into the above categories, your biggest risks will come from how your Mac is set up, rather than your iPhone or iPad. Here’s how you could improve your Mac security:

  • Upgrade your Mac to Golden Gate: Golden Gate supports all Apple silicon Macs. A few older Intel models can upgrade to the previous release, macOS 26 Tahoe, which you should do. If you can’t run Tahoe or Golden Gate, you’re not getting the latest and best security. Consider upgrading your Mac if that’s important to you. (See which Macs can run it.)
  • Allow FileVault: Apple enables FileVault by default when you upgrade to macOS 26 or 27 and on new computers running it. Leave it on (see FileVault). Also, power down your Mac whenever it’s not in use; never leave it idle and running for more than a brief period. (A FileVault-like feature is part of iOS/iPadOS and cannot be disabled or configured.)
  • Block device and card insertion: Thunderbolt and USB devices and SD Cards plugged into your Mac can be blocked from interacting with the operating system without authentication. See the Mac settings worth changing.
  • Never make local, unencrypted copies of your data: All local copies should be on encrypted volumes that are unmounted after backup or shutdown when you regularly shut your Mac down; all hosted backups, if any, should only be with firms that offer strong, user-owned encryption. Time Machine lets you set up backups on an encrypted drive or add an encryption key for networked backups. All online backup services worth considering put the encryption key for your archived data solely in your hands.

To view your device’s location, those of people in a Family Sharing group, or your items, use the Find My app on an iPhone, iPad, Mac, or Apple Watch, or the Find Devices app in watchOS 26 or earlier or on iCloud.com. By activating Find My, you’re signed in to the app on all those operating systems and on iCloud.com. Each view in the iPhone, iPad, and Mac Find My app provides access to a different category of location-finding.

The map in each view includes typical actions, such as zooming in and out, switching to satellite view, and switching to 2D view. The icons, such as the Choose Map and 3D view buttons, appear the same as in Apple Maps.

Those Find My views are separate apps on an Apple Watch running watchOS 26 or earlier: Find People, Find Devices, and Find Items. If I mention a view, find the app in watchOS 26 or use Find My in watchOS 27.

You can add a Find My widget to the Home screen or Notifications Center to see people and devices without opening the app.

The three status labels

For each category—People, Devices, and Items—Find My shows the last time a location was updated in the list: to the right of the item on an iPhone/iPad and under the item on a Mac, Apple Watch, and (for devices) on iCloud.com. It also displays this information in the detail view for the selected item.

Here’s what the status messages mean:

  • Live: Devices can provide a continuous stream of location information in the right circumstances. You can watch someone walk down a street or see their train move across the landscape. (Frankly, a little creepy, even though it’s done with permission?)
  • Now: If live updates aren’t possible due to battery, location, connectivity, or operating system version, Now is the second-best. It indicates an update within the last minute.
  • Time duration: Find My shows X minutes ago or a specific date and time for the last location update.

Selecting an entry

Starting with the version 27 releases, you select an entry by tapping or clicking it. This reveals slightly more information, such as a Directions button or a Play button to play a sound. Tap or click the More button to reveal the sheet of actions for that category.

Before the version 27 releases, Apple had two distinct methods for selecting an item from the people, devices, or items list: one for the Find My apps on iPhone, iPad, and Apple Watch; another for the Mac Find My app.

In iOS 26, iPadOS 26, and watchOS 26 and earlier, tapping an entry selects it and causes its sheet to appear. In macOS 26 and earlier, click the item, then click the Info button to reveal the sheet. macOS 26 and earlier also let you Control-click/right-click an entry to reveal several menu items; macOS 27 limits these to just Remove and, for People, Add to Favorites or Remove from Favorites.

What iCloud.com cannot do

You can’t track people or items on iCloud.com, only devices (via the Find My link, which takes you to the Find Devices app). However, iCloud.com’s Find Devices web app is useful for one purpose: when a device is missing or stolen, and the person whose device it is lacks access to Find My on any of their devices. See how to find a lost iPhone or Mac.

Because of the fraught nature of putting your devices or services on them directly in the path of the entire internet, it’s almost always the case that you can share files more easily, with more control, and more securely using a cloud-based sharing service, with a lot of provisos that I describe along with each service.

Each of these services partitions access, so you know precisely what you are letting someone view or download, and whether they can modify, delete, or upload files. You can set a time limit that a link will work, and usually restrict whether something can be downloaded or just viewed online. You may also be able to tell when they access or view files and see exactly what changes they make, if they have permission to modify files.

All the major tech companies offer them, and you may already have free access to substantial storage, or already be paying for a subscription plan or higher level of storage for other purposes.

All these services encrypt data at rest and use encrypted transport (HTTPS, primarily) for uploads, downloads, and link creation. However, if someone can access your account, they can view, delete, modify, download, and add files without restriction.

If you want to share files in a truly secure, end-to-end manner, however, the gold standard is end-to-end encryption (often abbreviated E2EE). With E2EE, the ecosystem you use generates and retains keys only at endpoints, on devices under your control. (Sometimes you’re involved in generating them, but usually the key creation and management is silently handled by the software.)

iCloud.com was never protected by E2EE before December 2022; after that, it became optional for some services if you enabled Advanced Data Protection (ADP). With ADP, iCloud Drive and other items synced, shared, and available via iCloud.com are protected by E2EE for you and with people with whom you share—so long as they also have ADP enabled. See how to turn on Advanced Data Protection.

Layer your own encryption on top

If you or your shared partners don’t have ADP enabled or can’t turn it on, you can layer E2EE on top of standard secure cloud services, because data that’s encrypted before transfer and stored in these locations remains encrypted, and is only decrypted by endpoints that have the keys.

That is, if you have an encrypted disk image and upload it, that integral encryption isn’t stripped off. If someone downloads the disk image, they still have to break the encryption applied to that data to access what’s inside.

But you can be more sophisticated than a disk image. Software that handles its own encryption—say, the password-management app 1Password—can safely hold and sync its separately encrypted data on a sync service. Someone stealing your 1Password vault has stolen trash.

As of 1Password 8, the app works only with its own syncing system. It used to work with Dropbox and iCloud.

Beyond software that uses E2EE for its internal format are packages that allow generic file sync by effectively tunneling the end-to-end encryption across a sync service! From your perspective, the files are readily available; to everyone in between you and your devices, including the sync services, it’s just a bunch of garbage-looking data. This is a nifty workaround.

I can’t recommend a service, as I don’t use any, but there are two options you can test for this purpose that are Mac compatible:

  • Cryptomator is an open-source solution to create an encrypted package, called a vault. It’s free to use on Mac, Windows, and Linux. The Android and iPhone/iPad apps have a one-time €19.99 (about US$23) purchase price to cover development costs.
  • VeraCrypt is also free, open-source software for creating virtual encrypted disks or partitions. However, the project supports desktop operating systems only: Linux, macOS, and Windows.

Cloud sync services usually reduce data transfer required by syncing only changed portions of files. (Unix folks call it the diff after a command-line tool; delta encoding is a more exact technical term.)

With encrypted files you upload, large portions of the file or the entire file change whenever it’s modified, resulting in a lot of data synced. However, Apple’s bundle form of disk images and some third-party software breaks large files into smaller ones to solve this problem. Only those sub-portions are changed, resulting in less syncing.

Encrypted messaging with others

Apple enabled E2EE with Android users for messaging over RCS, an industry standard Google championed. However, be sure to check when you start messaging with someone using RCS that their Android device has RCS encryption enabled. You can see whether it’s enabled in Messages: an Encrypted label appears at the top of the conversation, or inline if the encryption method changes. (If you had an ongoing conversation with someone over RCS, upgraded your device, and they have encryption enabled, an inline message in the conversation would appear.)

If you want to use E2EE to exchange data with others, you can use options like GPG Suite ($23.90 per year, 30-day trial, Mac only), which manages public-key encryption data for you, and lets you exchange encrypted files via email with anyone else who uses PGP- or GPG-compatible software. (PGP is a decades-old implementation of public-key encryption; GPG is the GNU, free-software version.)

If you trust other parties to manage the process, you can use iMessage or Signal. In early 2021, Apple quietly overhauled iMessage’s innards to make it more robust, but still needs to publish its spec and allow outside auditing. The company quickly had to patch major exploits found in their update in September 2021, making an even better case for allowing more eyes on the problem.

In May 2025, people were baffled that they couldn’t type “Dave & Buster’s” and similar ampersand-containing names into Messages. Turns out, Messages transformed the ampersand into something that triggered the protection! Apple fixed it, but it showed it worked?

Despite Apple’s lack of full transparency, iMessage remains trustworthy. Signal is created by an organization devoted to privacy, and has proven itself a great way to avoid interception.

What if you’ve lost your Apple hardware and it’s in a place where it can’t reach a Wi-Fi network and either has no active cellular data plan or can’t reach a cellular base station? What if it’s stolen, and the thief has disabled network access through Control Center? What if you stuck an AirTag or other Find My item on your backpack and left it where you can’t remember—or it was taken from you at an unknown time?

Apple’s solution is anonymity-preserving crowdsourcing that relies on the billion active devices their customers use worldwide, running recent-enough versions of iOS, iPadOS, and macOS to participate. The system relies on devices that can’t connect with the internet or a paired device to begin transmitting an anonymized, encrypted Bluetooth network signal that other Apple hardware can pick up.

A user's iPhone 17 Pro shows a screen that reads

Find My crowdsourcing causes every supporting device or item to emit a Bluetooth beacon that incorporates an encrypted hardware identifier.

This ID changes at regular intervals to prevent the privacy or safety nightmare of a third party tracking you, your devices, or your items through a persistent ID. Even Apple doesn’t really know where your devices and items are when using crowdsourcing!

When a device or item sends this beacon varies between Apple devices and Find My items:

  • iPhone, iPad, Mac, or Apple Watch: Find My must be enabled on the device (including the Find My network option), and it must be unable to make a connection to the internet.
  • AirTags and other Find My items as well as Apple and Beats audio hardware: If the audio hardware is within Bluetooth range of its paired device, it acts like a device, relaying its location through it. When beyond that range, it broadcasts a Bluetooth beacon as if it were a Find My item.

While 2nd-generation AirTags have minimum operating system requirements to appear in Find My apps, there is no such issue for the Bluetooth signals they broadcast. Any device that can relay a 1st-generation AirTag’s location can relay that of a 2nd-generation AirTag. (See AirTag 2 vs AirTag.)

The original AirPods rely solely on Bluetooth-based location tracking. When within Bluetooth range, they appear in the Find My app under Devices. However, they don’t work with the crowdsourced network. You can’t mark those audio devices as lost, and you can find those devices only within range of their paired iPhone or iPad.

What Apple can and cannot see

This broadcast is recognized by anyone’s iPhone, iPad, or Mac running at least iOS 13/iPadOS 13 or macOS 10.15. If a device owned by another person has an internet connection, it encrypts a package containing the beacon’s name and location information obtained or inferred, and uploads it to Apple.

That information is stored in a very particular way:

  • Apple doesn’t track what IP address or device uploaded it.
  • Apple doesn’t know to which device or Find My item any Bluetooth ID is associated—only your hardware retains that.
  • Apple doesn’t have encryption keys to extract location information.

It’s a beautiful system, in that no one—not Apple, the other equipment’s owner, or anyone sniffing in the area near your device—can determine who the hardware belongs to.

In the right circumstances using an iPhone, iPad, or Mac native version of the Find My app (see Precision Finding), you trigger retrieval of this location and timestamped location:

  • The Find My app uploads a cryptographic secret that Apple can match against the encrypted bundles they have of Bluetooth ID and location.
  • Apple’s servers transmit matching entries to the requesting device.
  • Using a locally stored encryption key that only your devices possess, the bundles are unlocked to determine the last location found.

What you get back

Find My provides this information in two different ways depending on the hardware you’re using:

  • iPhone, iPad, Mac, or Apple Watch plus audio hardware: The current location appears as expected in the Devices view of a native Find My app. If the device has an internet connection (direct or via a paired device for audio hardware), its location is a directly provided one; if it’s not connected to the internet, the Find My location appears when you use a Find My app.
  • AirTags and other items: The current or last-tracked location of a Find My network item, whether from a paired device or anyone else’s Apple device, is always shown in the Items view of the Find My or Find Items app. If you mark these devices as lost, you have more options: see what someone sees when they find your lost device.

In contrast to the Find My Device service, the Find My network is almost entirely one-way: you can determine where something is, but an owner can’t send a signal to the device unless it’s within Bluetooth range of an owner’s device. It also can’t be locked or erased as with internet-based Find My actions; See how to play a sound on a lost device or AirTag.

There are two actions you can perform as the owner of a Find My item:

  • When marking an item as lost, you can provide a phone number that Apple also stores securely. Someone finding the item can retrieve that data from Apple.
  • When you are near enough to connect to an item from one of your devices via Bluetooth, you can play a sound on it. This is particularly useful for finding a lost item in a classroom, home, or car, or for being notified of one nearby.

If someone’s iPhone or iPad detects that a Find My item or a Google Find Hub item is moving along with them—determined by Bluetooth proximity and across time—they are offered the opportunity to play a sound. That signal is sent via Bluetooth. (The same is true for an Android device detecting an Apple Find My item.) See what an “AirTag Found Moving With You” alert means.

Apple Designed the Find My Network To Deter Stalking

You might conclude that the design of the AirTag and other Find My items is both great for finding your own lost or stolen stuff—and a way someone might deploy tracking against you.

Fortunately, Apple included design elements in their Find My network for AirTags and third-party gear to try to protect the privacy of those who might be under observation without their knowledge, or who wind up accidentally transporting them. I dig into this in depth in Understand Stalking via Tracking.

Industry-Wide Anti-Stalking Standard Launched

Apple developed their system independently, though it offers a license and access to third parties. Facing criticism from a range of politicians and groups about stalking by tracker, Apple and Google—joined by several smaller firms—released a plan for interoperable industry support for identifying trackers across networks that went into effect in operating system and item updates in 2024. For more, see Active Stalking and an Industry Alliance.

You can also enable separation alerts. This feature notices when any Find My device or item is no longer in proximity to your iPhone or iPad. This might happen if you leave an iPhone in a coffee shop or it slips out of your pocket in a movie theater or you forget you put your iPad in an airplane seat’s unhygienic publication pocket. I explain separation alert management in Notifications for Devices and Items.

Google’s Find Hub offers a competing, non-interoperating ecosystem. Apple and Google don’t share location data with each other’s networks. But Android phones, iPhones, and iPads detect unwanted trackers across both ecosystems. See how to check whether someone is tracking you.