If you're really concerned, and want to make sure you're safe, I recommend doing the following:
- back up all your personal files (photos, videos, documents, etc.) that you've put on the phone
- once you're sure everything's safely backed up, log out of your Google account on your phone
- from a computer, log in to your Google account
- enable and set up 2-step verification
- do a factory reset on your phone
- step through setting up the phone
- do fresh installs of all apps you want
- restore backups through such things as WhatsApp
- restore your photos and other files
You're good to go! Or should be. Don't give anyone your login credentials for Google (and, hence, your phone). Don't give your unlocked phone to anyone. Don't leave a computer browser logged in to Google. Etc.
If you need help with any of that, let us know.
If I've missed, or misstated, anything, someone will hopefully correct me.