Furbo calls itself a "dog camera" but it records everything in your home — people, conversations, and activities — not just your dog. Its AI specifically watches for humans (person detection, home emergencies), making it a home surveillance system marketed under the friendlier label of "pet care.". Furbo says its microphone listens for your dog barking, but it actually captures every sound in your home — conversations, arguments, phone calls — and sends them to cloud servers for AI analysis. The "home emergency" feature proves Furbo is listening for human sounds, not just barking.
What they claim: Furbo is marketed as a "dog camera" and "smartest pet camera" — the branding, product name, and marketing all frame the device as a pet monitoring tool.
What we found: The app requests CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, and READ_PHONE_STATE permissions. The privacy policy admits collecting "video and audio information of individuals when they pass in front of the camera or speak when the Furbo Dog Camera is on." Person detection and home emergency alerts explicitly analyse human behaviour, not pet behaviour. The device captures continuous 1080p video and audio of entire living spaces 24/7.
What they claim: Furbo markets its microphone functionality as "barking detection" — listening specifically for dog barking sounds to alert owners. The Dog Nanny feature is described as monitoring pet activity.
What we found: The device has a built-in microphone array (not a single microphone) designed for far-field audio capture. The privacy policy confirms Tomofun collects audio when people "speak when the Furbo Dog Camera is on." The app requests RECORD_AUDIO permission. AI processing includes "home emergency detection" which requires analysing human voices and sounds (smoke alarms, glass breaking, crying) — meaning the microphone is actively listening to and analysing all household sounds, not just dog barking. All audio is sent to the cloud for AI processing.
What they claim: Furbo is a stationary indoor camera that sits on a shelf. It monitors a fixed location (your home). There is no functional reason for the app to track the user's real-time location.
What we found: The app requests both ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION permissions. Mozilla confirmed the app tracks user location. The privacy policy discloses collection of "real-time location when configured." The device itself has no GPS — it connects via home Wi-Fi only. Fine location tracking reveals when users are away from home, creating a valuable dataset about home occupancy patterns that could be exploited.
What they claim: The privacy policy states that for European users, personal information transfers use Standard Contractual Clauses and that Tomofun has "required contractual provisions for transferring personal information in place." The policy implies data stays within controlled jurisdictions.
What we found: Tomofun is a Taiwanese company backed by Foxconn. The app embeds JiGuang Aurora Mobile JPush (Shenzhen, China) and Huawei Mobile Services Core — both Chinese service providers. Data infrastructure uses Amazon AWS (S3, CloudFront). The privacy policy does not disclose specific countries where data is processed or stored. The combination of Taiwanese corporate ownership, Chinese SDK data flows, and US cloud infrastructure creates a complex international data routing that is not transparently disclosed.
What they claim: Tomofun states "We do not currently sell your Personal Information" in the CCPA section of their privacy policy.
What we found: The same privacy policy admits that identifiers, internet activity, geolocation, and commercial information fall under California definitions of "sharing" and "sale" for cross-contextual advertising. The policy also states Tomofun "may disclose your personal information to third parties for marketing purposes." Mozilla Privacy Not Included review confirmed Tomofun collects data from third-party marketing partners about user preferences and interests.
What they claim: Furbo is marketed as a premium pet camera primarily for Western markets (US, EU). The privacy policy mentions data processing safeguards and GDPR compliance with Standard Contractual Clauses for European data transfers.
What we found: The app embeds JiGuang Aurora Mobile JPush (Chinese push notification SDK) and Huawei Mobile Services Core tracker alongside Google Firebase Analytics, Google CrashLytics, and MixPanel — totalling 5 trackers. JiGuang (Aurora Mobile) is a Chinese mobile developer services company based in Shenzhen. These Chinese SDKs are not disclosed to users, and the privacy policy does not mention data flows to Chinese service providers despite Tomofun being a Taiwanese company backed by Foxconn.
What they claim: Furbo is a pet camera that lets you see, talk to, and toss treats to your pet. Core functionality requires camera streaming, audio, and internet connectivity.
What we found: The app requests 34 permissions including READ_PHONE_STATE (device identity/phone number), SYSTEM_ALERT_WINDOW (draw over other apps), ACCESS_ADSERVICES_AD_ID and ACCESS_ADSERVICES_ATTRIBUTION (advertising tracking), AD_ID (Google advertising identifier), WRITE_EXTERNAL_STORAGE, READ_EXTERNAL_STORAGE, and RECEIVE_BOOT_COMPLETED (auto-start on phone boot). None of these are needed for viewing a pet camera or tossing treats. The advertising permissions confirm the app's secondary function as a data collection tool.
What they claim: Furbo's Product Security Statement claims the company maintains security standards. Mozilla confirmed Furbo "meets minimum security standards" for encryption, strong passwords, security updates, and vulnerability management.
What we found: CVE-2020-24918 (critical) allows unauthenticated remote code execution as root via a buffer overflow in the RTSP authentication parser. CVE-2021-32452 allows command injection via the webserver. CVE-2023-28704 (CVSS 8.8) allows unauthenticated command injection via Bluetooth. Somerset Recon also found predictable device IDs enabling enumeration of all Furbo devices, and a broken password reset mechanism allowing full remote access to any Furbo account without user interaction.
What they claim: Furbo markets features like "barking detection" and "smart alerts" as pet care features, implying the camera locally monitors your pet. The product is positioned as a simple pet camera that tosses treats.
What we found: Firmware analysis reveals no local API — all video is processed through Tomofun's cloud infrastructure. AI features (barking detection, person detection, home emergency alerts) all require cloud processing. The privacy policy confirms AI analyses "Content data" for "sound and motion detection" and uses footage for "research and development" to "test and refine AI algorithms." The Dog Nanny subscription (.99/month) adds additional cloud AI processing.
What they claim: The privacy policy provides CCPA and GDPR rights sections stating users can request deletion of their personal information. Tomofun claims GDPR compliance with a designated Data Protection Officer (dpo@furbo.com).
What we found: The same privacy policy states that post-account closure, content is "retained indefinitely for legal defense and crime prevention." Phone records are retained up to 6 years. The policy does not define what constitutes "content" subject to indefinite retention, meaning all captured video/audio of your home could be kept forever even after you stop using the device and request deletion.