← All categories
Smartphones
The device that knows everything. The question is who else does.
12 devices analyzed. Set your privacy comfort level to filter.
What we found
Spark 40: FEvery Tecno phone sold in Africa — roughly one in two smartphones on the continent — ships with a hidden tracker called Athena.
NowSecure researcher Buchodi found Athena and oneID frameworks embedded at system level in Tecno Spark 40 (KM5) firmware. Collects GPS location, per-app network usage (~60 apps), foreground app in real-time, camera activation events — bound to permanent device identifiers. No user disclosure, no consent prompt, no opt-out. Removing com.hoffnung package causes bootloop.
Hot 50: FInfinix promises to "fully respect your privacy." Every Infinix phone ships with the same hidden Athena tracker found in Tecno — logging your GPS, your apps,...
NowSecure found identical Athena/oneID telemetry frameworks across all Transsion brands. Collects GPS location, per-app usage, camera events, foreground app — bound to permanent device identifiers. No disclosure, no consent, no opt-out. Removing com.hoffnung bricks the phone. Infinix is Transsion's second-largest brand.
S23: Fitel sells $48 phones to people who can't afford anything else.
Same Athena/oneID telemetry framework found across all Transsion brands. itel targets the sub-$60 market — users least able to afford privacy alternatives. GPS, app usage, camera events collected with no consent. Removal bricks phone.
NaviX Ultra: FThe phone's AI can see everything you do in every app — your WeChat messages, your bank balance, your shopping.
Doubao uses INJECT_EVENTS permission for full system-level access — reads screen content of every app, simulates clicks, swipes, and inputs. WeChat, Meituan, and Alipay blocked the predecessor Doubao phone within 72 hours because this resembled cheat tools. A security executive told Nikkei Asia: Doubao "has been granted excessively broad permissions, so extensive that it can open virtually any app."
Samsung Galaxy S24: DAds in the operating system. Samsung reads your texts to "understand your relationships."
Samsung Members app (com.samsung.android.voc) requests BODY_SENSORS, USE_FACE, MANAGE_IRIS, RESET_IRIS_LOCKOUT, USE_IRIS, USE_FINGERPRINT, BIOMETRICS_PRIVILEGED, and FINGERPRINT_PRIVILEGED permissions — giving it deep access to biometric hardware and data. The app also contains 3 third-party trackers (Adobe Experience Cloud, Google Analytics, Google Tag Manager) that could theoretically exfiltrate biometric-adjacent data. While Samsung claims biometrics stay on-device, the combination of biometric access + embedded trackers + internet permission creates a pipeline where biometric usage patterns could be correlated with advertising profiles.
Google Pixel 8: DGoogle collects 20x more data than Apple. Location tracked even in airplane mode.
Google Play Services (com.google.android.gms) runs as a privileged system process with 56 permissions including ACCESS_BACKGROUND_LOCATION, READ_SMS, READ_CALL_LOG, READ_CONTACTS, RECORD_AUDIO, CAMERA, BODY_SENSORS, READ_LOGS, and PACKAGE_USAGE_STATS. This service CANNOT be uninstalled, disabled, or permission-restricted by the user. It starts at boot (RECEIVE_BOOT_COMPLETED) and ignores battery optimization (REQUEST_IGNORE_BATTERY_OPTIMIZATIONS). The "choice" Google offers does not extend to the most invasive data collection channel on the device.

Your privacy tolerance