Eufy told customers that their facial recognition data and video stayed on their device and never went to the cloud. Independent researchers proved this was false — face data was being secretly uploaded to Amazon servers, and anyone with the right URL could watch your camera feeds without a password. Eufy denied it for months before finally admitting the truth. Eufy advertised "military-grade encryption" for their cameras, suggesting your video was completely secure. In reality, anyone who found the right web address could watch your live camera feed using a free video player — no password needed. There was no encryption at all on these streams.
What they claim: Eufy privacy policy states: "the applicable biometric assessment process is conducted entirely on your device. We do not store or have access to this biometric data." Marketing materials consistently claim "local storage only, no cloud."
What we found: Security researcher Paul Moore discovered in November 2022 that Eufy cameras connected to HomeBase were uploading facial recognition thumbnails to AWS cloud servers (s3.amazonaws.com). The Verge independently confirmed that live video feeds were accessible via unencrypted cloud URLs without any authentication. Anker denied the findings for months before admitting in January 2023 that cameras did not offer end-to-end encryption as promised.
What they claim: Eufy promotes facial recognition as a privacy-respecting feature, with BionicMind AI engine processing faces "entirely on your device."
What we found: The HomeBase 3 has 16GB eMMC storage and a quad-core processor capable of on-device AI processing for facial recognition, person detection, and pet detection. However, Paul Moore proved that facial recognition thumbnails were being uploaded to AWS (s3.amazonaws.com) despite the hardware being fully capable of local processing. The hardcoded endpoints (security-app.eufylife.com, mysecurity.eufylife.com, s3.amazonaws.com) confirm cloud connectivity infrastructure exists. The device has the hardware to do it locally but the software chose to upload it anyway.
What they claim: Eufy privacy policy claims biometric processing is "conducted entirely on your device" and they "do not store or have access to this biometric data." The system is marketed as a local-only security solution.
What we found: The eufy Security app (com.oceanwing.battery.cam) requests ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, and AD_ID permissions — advertising tracking identifiers that have no function in a local-only security system. The app also requests ACCESS_BACKGROUND_LOCATION, allowing continuous location tracking even when the app is not in use. Combined with the proven cloud uploads of facial recognition data, these permissions indicate a data collection apparatus inconsistent with "local only" claims.
What they claim: The eufy Security app requests 49 permissions including CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION, ACCESS_BACKGROUND_LOCATION, READ_PHONE_STATE, ACTIVITY_RECOGNITION, and FOREGROUND_SERVICE_MICROPHONE.
What we found: For a device that is a Wi-Fi-connected security hub (HomeBase 3), the companion app requests permissions far beyond what is needed to view and manage camera feeds: ACTIVITY_RECOGNITION (tracking user physical activity), READ_PHONE_STATE (accessing phone call status and device identifiers), ACCESS_BACKGROUND_LOCATION (continuous GPS tracking), FOREGROUND_SERVICE_MICROPHONE (persistent microphone access), and WRITE_SETTINGS (modifying system settings). The HomeBase 3 itself has no GPS, microphone, or phone capability.
What they claim: Eufy privacy policy states: "We do not sell personal information to third parties." Data handling is described as privacy-focused and local-first.
What we found: The same privacy policy discloses sharing personal data with "ad networks and advertising partners, business and marketing partners, third-party providers." The app includes ACCESS_ADSERVICES_AD_ID and AD_ID permissions for Google advertising identity tracking. Transaction details are shared with Riskified for fraud prevention. For Expert Monitoring subscribers, video data is shared with Rapid Response Monitoring Services Inc. The Cisco Talos research (CVE-2022-25989) showed the HomeBase could be tricked into sending traffic to attacker-controlled servers via DHCP manipulation.
What they claim: Eufy privacy policy claims data "is encrypted during transfer using industry-standard protocols (such as TLS 1.3 and ECDH key exchange with AES-256)."
What we found: CVE-2021-3555 demonstrated a pre-authentication buffer overflow in the RTSP server of Eufy cameras on the local network — the video stream interface had no authentication. The Verge confirmed that camera feeds were accessible via unencrypted cloud URLs. Paul Moore showed facial recognition thumbnails uploaded to AWS were not encrypted end-to-end. The gap between policy encryption claims and observed encryption in practice represents a systemic pattern rather than an isolated incident.
What they claim: Eufy marketing materials prominently featured "military-grade encryption" and "end-to-end encryption" as core selling points for their security camera system.
What we found: The Verge confirmed that Eufy camera feeds could be accessed remotely via VLC media player using unencrypted cloud URLs. No authentication was required to view the streams. Anker admitted in January 2023 to The Verge that Eufy cameras were "not natively end-to-end encrypted" and could produce unencrypted video streams via the web portal.
What they claim: Anker initially denied all findings about cloud uploads and unencrypted streams when confronted by Paul Moore and The Verge in November-December 2022.
What we found: The Verge documented a months-long pattern of Anker providing "deliberately unclear and often misleading answers" about Eufy camera security. Anker only admitted the truth in January 2023 after The Verge threatened to publish a story about the company stonewalling. Paul Moore initiated a GDPR lawsuit against Eufy/Anker for violating European data protection regulations. The company eventually admitted cameras were "not natively end-to-end encrypted" — a direct reversal of their marketing claims.
What they claim: Eufy HomeBase is marketed as a secure central hub for the entire home security system, protecting all connected cameras and sensors.
What we found: Cisco Talos discovered CVE-2022-21806 (CVSS 10.0): a critical remote code execution vulnerability in the Eufy HomeBase 2 that allowed complete takeover via network packets. CVE-2022-25989 allowed authentication bypass via DHCP packets, redirecting all device traffic to an attacker. CVE-2022-26073 allowed forced device reboots, disabling the security system entirely. Since all Eufy cameras connect through the HomeBase, a single exploit compromises the entire home security system. The HomeBase 3 is the direct successor to the vulnerable HomeBase 2.
What they claim: Eufy privacy policy states the User Experience Improvement Program is optional and collects "diagnostic and usage data" to improve products.
What we found: The eufy Security app requests RECEIVE_BOOT_COMPLETED (auto-starts when phone boots), REQUEST_IGNORE_BATTERY_OPTIMIZATIONS (prevents Android from limiting background activity), KILL_BACKGROUND_PROCESSES, FOREGROUND_SERVICE (persistent background operation), and WRITE_SETTINGS (modify system settings). These permissions enable persistent, always-on data collection that goes well beyond a voluntary "improvement program." The app effectively resists being shut down by the operating system.