Back to Blog

Sign an Old Phone Out of Household Accounts After It Is Handed Down

A post-handoff audit for removing an old phone from email, cloud, utility, and smart-home sessions after a family transfer.

After handing down a phone, sign that device out from important account-security pages even if it was factory-reset. Review email, cloud storage, password managers, payment services, the mobile carrier, utilities, and smart-home apps. Then confirm the recipient has a separate account and cannot approve the former owner's sign-ins.

Understand the session that outlives the phone

A phone can appear in several places: the manufacturer's device list, a Google or Apple account, individual app sessions, a password manager, a carrier portal, passkey lists, push-approval devices, and trusted-device settings. Removing it from one list does not guarantee it disappears from all others.

Start with primary email because it can reset other accounts. Google's device access guidance explains how to review devices and sessions, inspect details, and sign out devices no longer used. Other providers have their own security pages. Type the official address or use a known app rather than following an unexpected security-message link.

A recent activity time does not by itself prove the recipient opened an account. Background synchronization or multiple sessions can make entries confusing. Compare device model, location, browser, and session details, then sign out any entry you cannot confidently assign.

Revoke access in layers

Review the former owner's manufacturer account first, including device finding, cloud backup, photo sync, messages, and payment wallet. Then open each critical service and remove the phone as an active session, trusted device, passkey holder, or push-approval target as appropriate.

Change passwords if the phone was handed over without a proper reset, if the unlock code was known to the recipient, or if account activity is uncertain. A password change may not revoke every token, so still use “sign out all sessions” or per-device controls where offered. Refresh backup codes and recovery contacts if they were stored on the handset.

Household services deserve their own list: internet provider, thermostat, alarm, cameras, door access, shared storage, grocery delivery, and utilities. Invite the recipient under their own account only when they need ongoing access. Do not sign the former owner back into a handed-down phone just to make a shared device work.

Verify both sides of the handoff

The recipient should see a clean setup under their own identity, with their own screen lock, recovery route, backups, and app-store account. The former owner should check that calls, messages, photos, notes, browser tabs, password prompts, and approval notifications no longer appear there.

From a trusted device, perform fresh sign-ins to the highest-value accounts. Confirm prompts arrive only on devices the owner controls. Keep purchase records and the device identifier needed for support, but do not retain the recipient's new unlock code.

Use the digital move-out account checklist when the phone handoff is part of a larger household change. Smart-home membership, location sharing, family plans, and subscriptions often survive beyond the physical device.

If an unknown session returns after removal, secure the account, review connected apps and forwarding, and contact official support. Avoid repeatedly approving prompts just to stop notifications. An unsolicited approval request should be denied.

How HomeCo helps

Create a HomeCo handoff with categories for manufacturer account, email, authenticator or passkeys, payments, carrier, household apps, reset verification, and follow-up session review. Record only status and device description, never passwords, recovery codes, or the new owner's screen lock.

Block the “handoff complete” task until both people confirm their side: the former owner sees no remaining access, and the recipient sees none of the former owner's data. Schedule a second session check after normal sync activity has had time to settle.

FAQ

Is a factory reset enough?

It is essential, but server-side device and session lists should still be reviewed. They provide another chance to spot stale or unknown access.

Why does the old phone still appear after sign-out?

Some account pages show recently used devices as signed out. Read the displayed status and provider explanation rather than assuming access remains.

Should the recipient reuse the former owner's app-store account?

No. Use the recipient's own account and intended family-sharing features. Shared primary identities create privacy and recovery problems.