← Wearables
D

Halo Band

Serious concerns
Amazon · 🇺🇸 United States · Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: SDoC-BLE-only
Chipset: Unknown SiP (epoxy-potted BGA)
App: com.amazon.halo
Manufacturer: Amazon

⚠️ The bottom line

Amazon promised that the intimate photos you took in your underwear for body fat scanning would be deleted from their servers automatically. But the FTC caught Amazon keeping kids' voice recordings forever despite similar deletion promises with Alexa. There's no proof the body scan photos were actually deleted as claimed. Amazon said your voice recordings for mood analysis never leave your phone. But the app has permission to record audio AND send data to the internet in the background, plus it contains advertising trackers. There's nothing technically stopping the app from sending your voice data to Amazon's servers despite their promise.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
3/4 HIGH
Can I trust what they say?
Kids at risk
REPLACE Extreme risk. Look for alternatives or lock down hard.
10Contradictions
2Critical
5High
3Medium
5Sources
Findings by concern
Spying 4/4 EXTREME 6 findings
⚠️ criticalpolicy claims vs app permissions
Amazon said your voice recordings for mood analysis never leave your phone. But the app has permission to record audio AND send data to the internet in the background, plus it contains advertising trackers. There's nothing technically stopping the app from sending your voice data to Amazon's servers despite their promise.

What they claim: Amazon stated that Halo Tone voice samples are 'processed on-phone only' — encrypted via Bluetooth from band to phone, processed locally, then automatically deleted. Audio clips are 'not sent to the cloud'.

What we found: The Amazon Halo app requests both RECORD_AUDIO and INTERNET permissions simultaneously, plus FOREGROUND_SERVICE_DATA_SYNC for background data uploading. The app includes Amazon Analytics and Amazon Advertisement trackers. While RECORD_AUDIO is needed for the Tone feature, combining it with unrestricted INTERNET access, background sync services, and advertising trackers creates a technical capability to transmit audio data to Amazon's cloud, contradicting on-device-only processing claims.

⚡ highfirmware analysis vs regulatory findings
The Halo Band was packed with expensive sensors but sold for less than it cost to make. A US Senator pointed out the obvious: Amazon wasn't selling you a fitness band — they were buying your most intimate health data. Your body scans, voice emotions, heart rate, and sleep patterns were the real product.

What they claim: Amazon marketed the Halo Band as a health and wellness device priced at $69.99 (below manufacturing cost) with a $3.99/month subscription, positioning it as an affordable health tool.

What we found: Hardware teardown reveals sophisticated sensor array: MAX86141 optical heart-rate sensor, 2x AS6200 temperature sensors, ICM-20600 6-axis IMU, 2x MEMS microphones, 256Mbit Micron flash, custom SiP module — component costs alone likely exceed retail price. Senator Klobuchar's letter to HHS specifically cited below-cost pricing as evidence that the data was the product. Amazon collected 3D body scans in underwear, continuous voice emotional analysis, heart rate, skin temperature, and sleep patterns through a device sold at a loss.

⚡ highregulatory findings vs policy claims
When Amazon killed the Halo, they promised to delete everyone's health data. But at the same time, they were paying $30 million in fines for NOT deleting data they promised to delete from Alexa and Ring. Nobody checked whether Amazon actually deleted your body scans, voice recordings, and health data.

What they claim: When discontinuing Halo, Amazon stated 'remaining Halo health data will be deleted after August 1, 2023' and gave users a window to download their data.

What we found: Amazon discontinued Halo with ~3 months notice (announced April 26, ceased August 1, 2023). All devices bricked. No independent audit verified data deletion. Amazon's simultaneous FTC settlements for retaining Alexa recordings ($25M) and Ring surveillance data ($5.8M) demonstrate a pattern where claimed data deletion was not performed. Users who didn't download before the deadline lost all access with no verification Amazon actually deleted backend copies.

⚫ mediumapp permissions vs policy claims
Amazon needed camera access for body scan photos. But the app also had permission to read your stored photos and upload data in the background. That's more capability than just 'take a scan and delete it' — the app could technically access any photo on your phone.

What they claim: Amazon stated that body scan images are processed and 'automatically deleted from the cloud after processing,' with photos stored only on the user's device.

What we found: The Halo app requests CAMERA, READ_MEDIA_IMAGES, and READ_EXTERNAL_STORAGE permissions combined with INTERNET and FOREGROUND_SERVICE_DATA_SYNC. This gives the app persistent capability to access the camera, read stored images, and upload data in the background — a technical surface far exceeding the stated 'scan and delete' workflow.

⚫ mediumapp permissions vs policy claims
Amazon gave you a mute button for the microphone, making it look like you had control. But there's no mute button for heart rate, skin temperature, or movement data. The app runs constantly in the background, collecting biometric data from the moment you turn on your phone.

What they claim: Amazon marketed Halo as giving users control over their health data, with a physical mute button on the band for the Tone microphone feature.

What we found: The app requests BODY_SENSORS_BACKGROUND permission, allowing continuous collection of heart rate, skin temperature, and motion data even when the app is not in use. Combined with RECEIVE_BOOT_COMPLETED (auto-start on reboot) and WAKE_LOCK (prevent sleep), the app maintains persistent background biometric access. The physical mute button only controls the microphone — there is no way to pause heart rate, temperature, or motion monitoring without removing the band.

⚫ mediumregulatory findings vs app permissions
The FTC issued rules saying companies can't collect body measurements, voice prints, and health data without proper consent. The Halo collected all of these. Amazon shut down Halo just weeks before these rules came out.

What they claim: Amazon collected 3D body scans in underwear, continuous voice emotional analysis, heart rate, skin temperature, and sleep data through the Halo Band.

What we found: The FTC's June 2023 biometric policy statement warns that collecting biometric data (voice prints, body measurements, health indicators) without adequate consent constitutes an unfair or deceptive practice under Section 5 of the FTC Act. The Halo app's permissions — RECORD_AUDIO, CAMERA, BODY_SENSORS, BODY_SENSORS_BACKGROUND, ACCESS_BACKGROUND_LOCATION, HIGH_SAMPLING_RATE_SENSORS, ACTIVITY_RECOGNITION — represent the most comprehensive biometric surveillance capability of any consumer fitness app. Amazon discontinued Halo weeks before this FTC policy was published.

Data Sharing 3/4 HIGH 2 findings
⚡ highpolicy claims vs app permissions
Amazon said they'd never use your health data for advertising. But the Halo app itself contains Amazon's own advertising tracker and requests access to your advertising ID — the identifier used to target you with ads across different apps. If health data truly wasn't used for marketing, why include ad trackers in a health app?

What they claim: Amazon's Halo privacy policy explicitly stated: 'We do not use Amazon Halo health data for marketing, product recommendations, or advertising. We do not sell Amazon Halo health data.'

What we found: The Amazon Halo companion app contains Amazon Advertisement and Amazon Analytics trackers alongside Google Firebase Analytics. The AD_ID permission is requested, providing access to the Google Advertising ID for cross-app ad targeting. Mozilla's Privacy Not Included review found that 'Amazon combines data on its users with data from third parties, for advertisement purposes.' Advertising SDKs and ad tracking IDs in a health app directly contradict claims that health data isn't used for marketing.

⚡ highapp permissions vs regulatory findings
Amazon said Halo health data was handled separately from your other Amazon data. But the app uses the same advertising trackers as Amazon Shopping and Alexa. Amazon also runs a pharmacy, clinics, and telehealth — all connected to your Amazon account. Separate privacy policies don't mean separate databases.

What they claim: Amazon's Halo privacy policy treated health data as separate from other Amazon services, with distinct terms for Halo data usage.

What we found: The Halo app includes Amazon Advertisement and Amazon Analytics trackers — the same tracking infrastructure across all Amazon services (Alexa, Ring, Kindle, Shopping). The AD_ID permission creates a cross-service identifier. Amazon simultaneously operated Amazon Pharmacy, One Medical, Amazon Clinic, and Halo — all collecting health data under separate policies but linked by the same Amazon account and advertising identity. Mozilla confirmed Amazon 'combines data on its users with data from third parties.'

Honesty 3/4 HIGH 2 findings
⚠️ criticalpolicy claims vs regulatory findings
Amazon promised that the intimate photos you took in your underwear for body fat scanning would be deleted from their servers automatically. But the FTC caught Amazon keeping kids' voice recordings forever despite similar deletion promises with Alexa. There's no proof the body scan photos were actually deleted as claimed.

What they claim: Amazon's Halo privacy page stated body scan images are 'automatically deleted from the cloud after processing' and stored only on the user's phone.

What we found: FTC/DOJ found Amazon retained children's Alexa voice recordings indefinitely despite promises to delete them, resulting in a $25 million penalty (2023). This demonstrated a company-wide pattern of retaining data beyond stated deletion timelines. No independent audit verified Halo body scan deletion claims before the service was discontinued.

⚡ highapp permissions vs firmware analysis
The Halo Band doesn't have GPS — it connects to your phone via Bluetooth only. But Amazon's app demanded permission to track your exact location in the background, even when you weren't using the app. A Bluetooth fitness band doesn't need to know where you are 24/7.

What they claim: The Amazon Halo Band is a BLE-only device (no Wi-Fi, no GPS, no cellular) that syncs exclusively via Bluetooth to the companion phone. Location is not a core device feature.

What we found: The Halo app requests ACCESS_BACKGROUND_LOCATION, ACCESS_FINE_LOCATION, and ACCESS_COARSE_LOCATION. A BLE-only wearable with no GPS has no legitimate need for background location tracking. While ACCESS_FINE_LOCATION is technically required on some Android versions for BLE scanning, ACCESS_BACKGROUND_LOCATION goes beyond this — it allows continuous GPS tracking even when the app is closed.

What happened to real people
Documented incidents involving Amazon products and user data.
Ring employees spied on customers through bedroom and bathroom cameras. Hackers live-streamed customers' videos. 8-year-old girl contacted by hacker through bedroom camera. $5.8M FTC settlement. [source]
Amazon admitted giving Ring footage to police without owner consent at least 11 times in 2022. 30,000 employees had access to customer videos. [source]
What your data is worth to governments
Jurisdiction: US (CLOUD Act).
Documented: Ring employees spied on customers through bedroom and bathroom cameras. Hackers live-streamed customers' videos. 8-year-old girl contacted by hacker through bedroom camera. $5.8M FTC settlement.
Documented: Amazon admitted giving Ring footage to police without owner consent at least 11 times in 2022. 30,000 employees had access to customer videos.
What is the CLOUD Act?
Sources