← All categories
Operating System
10 devices analyzed. Set your privacy comfort level to filter.
What we found
ChromeOS: FIn 2015, Google signed the Student Privacy Pledge — a promise not to collect children's data for non-educational purposes.
EFF's 2015 FTC complaint found Chrome Sync was enabled by default on school Chromebooks, uploading students' entire browsing history, bookmarks, saved passwords, and open tabs to Google servers. The 2020 New Mexico AG lawsuit and 2025 Schwarz v. Google lawsuit allege the same practice continues a decade later — three lawsuits over ten years for the same violation.
Apple iOS / macOS: DPrivacy. That's iPhone. Unless you count the analytics they send when you opt out, the Siri recordings contractors listened to, or the iCloud data they hand to law enforcement.
Under Standard Data Protection (default for all users), only 14 of 25+ iCloud categories are E2E encrypted. Most sensitive categories — iCloud Backup, Photos, iCloud Drive, Notes, Reminders, Voice Memos — use "in transit & at rest" encryption where Apple holds decryption keys. E2E requires manually enabling Advanced Data Protection — estimated under 10% adoption. Apple has never published ADP adoption figures.
Windows 11: DYou paid for the OS. It sells you ads, ignores your privacy settings, and screenshots everything you do. Hardened version costs extra.
March 6, 2026: Hagenah released TotalRecall Reloaded, injecting payload into AIXHost.exe to extract screenshots, thumbnails, OCR text, and CSV metadata from the redesigned encrypted Recall. Beaumont confirmed March 19, 2026: "yep, you can just read the database as a user process" in plaintext, "no AV or EDR alerts triggered." Multiple VBS Enclave CVEs: CVE-2025-47159 (kernel privilege escalation), CVE-2025-48811 (missing integrity check), CVE-2025-53717 (CVSS 7.0). DEF CON 33 (Aug 2025): Akamai researchers demonstrated malware running inside VBS enclaves invisible to detection.
HarmonyOS: DHuawei said it only makes "general-purpose products." It tested a system that scans crowds for Uyghur faces and alerts police.
In 2018, Huawei worked with Megvii to test an AI camera system detecting Uyghur faces in crowds, triggering a "Uyghur alarm" for police. A confidential document was hosted on Huawei's own European website — deleted only after IPVM contacted them. Huawei filed a patent (July 2018) with Chinese Academy of Sciences listing "race (Han, Uyghur)" as pedestrian attribute. World Uyghur Congress filed criminal charges in France for genocide, human trafficking, aggravated servitude. Antoine Griezmann terminated his sponsorship. Up to 2 million Uyghurs detained in camps.
OneUI (Android Skin): DSamsung's Gallery app scanned your face every time you opened your photo library.
Nearly 50,000 Samsung Galaxy users filed Illinois BIPA claims alleging Samsung collected facial biometric data through the Gallery app without informed consent. Samsung pushed for individual arbitration for all claimants, then refused to pay its share of arbitration costs. A federal judge had to order Samsung to engage in the arbitration proceedings it had demanded.
Android / Google Play Services: DGoogle knows where you are, even when you tell it not to. It settled for $391 million over that. Then kept doing it.
A federal jury in Rodriguez v. Google awarded $425.7 million after finding Google continued collecting data from third-party apps even after users turned off "Web & App Activity." Class of 98 million users. $247M attributed to Android device members. Google's defence was that users should have known the opt-out wouldn't actually stop tracking.
MIUI / HyperOS: DXiaomi told 500 million users their private browsing was private.
Forbes investigation (May 2020): Cybersecurity researchers Gabriel Cirlig and Andrew Tierney found the Xiaomi Redmi Note 8 transmitted every URL visited, every search query, and every news article viewed — even in incognito mode — to servers in Singapore and Russia, with domains registered in Beijing. Tracking code found in firmware of Mi 10, Redmi K20, and Mi MIX 3. When confronted with video proof, Xiaomi denied it.
ColorOS: DResearchers at two European universities bought OPPO phones, turned off every analytics option they could find, and watched what happened.
University of Edinburgh and Trinity College Dublin researchers found that OPPO/Realme/OnePlus devices transmit IMEI numbers, MAC addresses, GPS coordinates, phone numbers, app usage, and call/SMS history to backend servers — even when users have opted out of all analytics and personalization, have not created an account, and are not using cloud services. Published in PLoS ONE (2023).

Your privacy tolerance