← All categories
Wearables
Strapped to your body 24/7. Knows your heart rate, sleep, location, and stress levels.
38 devices analyzed. Set your privacy comfort level to filter.
What we found
Meta Ray-Ban Smart Glasses: FTurns every wearer into a walking surveillance camera. Identifies strangers by name on the street.
OECD AI Incident Monitor (2025-10-24) documents that the LED recording indicator can be physically disabled or covered, enabling fully covert recording. Modified glasses have been sold and used for secret filming. A man in San Francisco used modified glasses to covertly record women at the University of San Francisco. The EFF analysis (2026-03) confirms the LED can be physically disabled. The "hardwired" safety feature provides no meaningful protection against deliberate misuse.
X6Play: FXplora promises "strict privacy and security measures" for your child's data, but the watch firmware has built-in spy features that can secretly take photos,...
Firmware contains intentional backdoor functions from Qihoo 360 code: REMOTE_SNAPSHOT (covert photography), WIRETAP_INCOMING and WIRETAP_BY_CALL_BACK (audio surveillance), SEND_SMS_LOCATION (location exfiltration), and REMOTE_EXE_CMD (arbitrary command execution). These are activated via RC4-encrypted SMS with a hardcoded 4-byte key in NVRAM. At 39C3 (Dec 2025), researchers revealed a universal cryptographic key identical across all devices, allowing any attacker with an IMEI to access children's communications. Over 1.5 million units affected.
VTech KidiZoom Smartwatch: FA camera on your child's wrist, from the company that already lost 6.4 million children's data.
Nov 2015: SQL injection breach exposed 6.4M children (names, birthdates, genders, photos, chat logs) + 4.9M parents. No encryption despite policy claiming otherwise. Unsalted MD5 passwords. Decryption keys stored next to encrypted photos. VTech unaware until journalist called.
Owlet Dream Sock: FBaby health monitor that FDA banned as an unapproved medical device. Still collecting infant biometrics.
The Owlet Dream app (com.owletcare.sleep) embeds 3 Facebook SDKs: Facebook Analytics, Facebook Login, and Facebook Share. These SDKs transmit device identifiers, app usage events, and potentially user data to Meta's advertising infrastructure — the world's largest ad surveillance network — directly from an infant health monitoring application.
WHOOP 4.0 Fitness Band: F$30/month subscription that owns your body data. No export, no delete.
Class action lawsuit (Lomeli v. Whoop Inc., August 2025) alleges WHOOP embedded Twilio's Segment tracker in its app, sharing sensitive health data (full names, email addresses, heart rate data, blood oxygen levels, sleep patterns, stress levels, video viewing history) with third parties. While WHOOP draws a legal distinction between 'selling' and 'sharing' data, the Segment integration transmitted identifiable health data to a third-party data infrastructure company without meaningful user consent.
Halo Band: FAmazon promised that the intimate photos you took in your underwear for body fat scanning would be deleted from their servers automatically.
FTC/DOJ found Amazon retained children's Alexa voice recordings indefinitely despite promises to delete them, resulting in a $25 million penalty (2023). This demonstrated a company-wide pattern of retaining data beyond stated deletion timelines. No independent audit verified Halo body scan deletion claims before the service was discontinued.
Spectacles (5th Gen AR): FSnap's entire bystander privacy defence is a tiny LED light on the frame of the glasses.
YouTube tutorials and eBay listings sell "Spectacles Black Out Kits" that cover or disable the recording LED, making covert recording trivial. The same problem plagues Meta Ray-Bans, where a mod fully disables the LED without affecting functionality. Snap has no hardware enforcement to prevent this — the LED is just a light, not a cryptographic kill-switch.
Kospet Tank M2: F$30 Chinese smartwatch with full GPS, heart rate, and blood oxygen — all sent to Shenzhen servers.
The app collects heart rate, HRV, blood oxygen, sleep stages, menstrual cycle data, exercise GPS routes, and weight/body composition — all highly sensitive biometric and health data. Accepting self-signed certificates means a man-in-the-middle attacker on public Wi-Fi could intercept all this biometric data in transit. FitCloudPro privacy policy itself acknowledges data is "unencrypted in transit" stating this is "temporary" — yet the app has been available since 2019.

Your privacy tolerance