WatchGuard
An anti-theft alarm for Android that runs entirely on the phone. No Google Services, no cloud account, no telemetry. Your watch is the key: when the phone leaves it, the phone locks itself down and starts screaming.
How it behaves
Something sets it off, the phone turns hostile, and evidence leaves the device.
Trigger
- The paired wearable leaves Bluetooth range, after a grace period (30 s by default)
- The SIM is pulled — polled every three seconds
- Too many wrong lockscreen PINs
Response
- A random six-digit PIN is set on the lockscreen
- Lock Task Mode kills the power menu, navigation and recents
- Alarm at maximum volume; the volume observer re-raises anything a thief turns down
- Continuous vibration and flashlight strobe
Evidence
- Front-camera photos, stored app-private
- GPS and network location for as long as the alarm runs
- Email with the photo and an OpenStreetMap link, retried with backoff until the network is back
- SMS in parallel, if you configured numbers
It stops when the wearable comes back into range, or when you long-press the alarm screen and enter the Recovery PIN.
Getting it running
This is the part to read before you decide you want it.
It needs Device Owner, set over ADB, before you ever open the app
Device Owner is what lets it hold the screen, block the power menu and refuse a factory reset. Android only grants it on a device with no accounts on it at all, so in practice this means a fresh phone or one you are willing to wipe. Remove every account, then:
adb shell dpm set-device-owner me.watchguard.app/.admin.WatchGuardAdmin
Check it took:
adb shell dumpsys device_policy | grep "Device Owner"
Add your accounts back afterwards.
-
Build and install
./gradlew assembleDebug adb install app/build/outputs/apk/debug/app-debug.apk
Android 13 or newer. Tested on stock Android, GrapheneOS and LineageOS.
-
Set the Recovery PIN — and write it down
It is the universal way out of an alarm, and it gates the dangerous settings.
-
Pair the wearable and pick a grace period
Tap the device card to scan. Thirty seconds stops the alarm firing every time you walk to the kitchen without your phone.
-
Turn on protection
Basic Observation, Bluetooth Guard, or both. Optionally add SMTP and SMS under Alarm Notifications, and the grouped restrictions under Advanced Hardening. Then turn USB debugging back off.
Two ways to lock yourself out
Restart Protection without a Recovery PIN you remember. It sets
DISALLOW_FACTORY_RESET. Forget the PIN and you own a phone you
cannot reset.
GrapheneOS revokes the Network permission per app by default, so
the SMTP test fails with EPERM until you grant it. Test the email
path before you rely on it.
What it does not do
Straight from the repository's own limitations, because finding this out during a theft is worse than reading it now.
- Holding the power button for ten seconds cuts the hardware. Nothing in software stops that — the alarm re-triggers on boot instead.
- Outside Lock Task Mode, a long-press on power cannot be blocked persistently.
- SMTP credentials are stored app-private in plaintext. The trust boundary is your lockscreen.
- Pulling the SIM blocks outgoing SMS, but email still goes out over Wi-Fi.
- On GrapheneOS, escrow tokens are disabled, so the random-PIN lock degrades to a plain
lockNow(). The hardening rules still apply. - It is not a replacement for full-disk encryption, a strong PIN and a short lock timeout.
Threat model: opportunistic physical theft — a pickpocket, a phone left on a table. Not someone with chip-off equipment, not a supply-chain attacker, and not anyone who already has your Recovery PIN.