← Security Cameras
D

Furbo 360° Dog Camera

Serious concerns
Tomofun · 🇨🇳 China · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: 2AIBVTFFBV2
Chipset: Ambarella S2Lm (ARM Cortex-A9)
App: com.tomofun.furbo
Manufacturer: Tomofun

⚠️ The bottom line

Furbo calls itself a "dog camera" but it records everything in your home — people, conversations, and activities — not just your dog. Its AI specifically watches for humans (person detection, home emergencies), making it a home surveillance system marketed under the friendlier label of "pet care.". Furbo says its microphone listens for your dog barking, but it actually captures every sound in your home — conversations, arguments, phone calls — and sends them to cloud servers for AI analysis. The "home emergency" feature proves Furbo is listening for human sounds, not just barking.

Legal jurisdiction
🇨🇳 China (headquarters)
National Intelligence Law read more →
Company must secretly hand data to Chinese intelligence on request
Data Security Law read more →
State can classify any data as 'important' and demand access for national security
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
2/4 MODERATE
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
10Contradictions
2Critical
5High
3Medium
6Sources
Findings by concern
Spying 4/4 EXTREME 4 findings
⚠️ criticalpolicy claims vs app permissions
Furbo calls itself a "dog camera" but it records everything in your home — people, conversations, and activities — not just your dog. Its AI specifically watches for humans (person detection, home emergencies), making it a home surveillance system marketed under the friendlier label of "pet care."

What they claim: Furbo is marketed as a "dog camera" and "smartest pet camera" — the branding, product name, and marketing all frame the device as a pet monitoring tool.

What we found: The app requests CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, and READ_PHONE_STATE permissions. The privacy policy admits collecting "video and audio information of individuals when they pass in front of the camera or speak when the Furbo Dog Camera is on." Person detection and home emergency alerts explicitly analyse human behaviour, not pet behaviour. The device captures continuous 1080p video and audio of entire living spaces 24/7.

⚠️ criticalfirmware analysis vs policy claims
Furbo says its microphone listens for your dog barking, but it actually captures every sound in your home — conversations, arguments, phone calls — and sends them to cloud servers for AI analysis. The "home emergency" feature proves Furbo is listening for human sounds, not just barking.

What they claim: Furbo markets its microphone functionality as "barking detection" — listening specifically for dog barking sounds to alert owners. The Dog Nanny feature is described as monitoring pet activity.

What we found: The device has a built-in microphone array (not a single microphone) designed for far-field audio capture. The privacy policy confirms Tomofun collects audio when people "speak when the Furbo Dog Camera is on." The app requests RECORD_AUDIO permission. AI processing includes "home emergency detection" which requires analysing human voices and sounds (smoke alarms, glass breaking, crying) — meaning the microphone is actively listening to and analysing all household sounds, not just dog barking. All audio is sent to the cloud for AI processing.

⚡ highapp permissions vs firmware analysis
The Furbo app tracks your phone's exact location even though the camera just sits on your shelf at home. This means Furbo knows when you leave the house and when you come back — information that has nothing to do with watching your dog but could tell burglars when you're away.

What they claim: Furbo is a stationary indoor camera that sits on a shelf. It monitors a fixed location (your home). There is no functional reason for the app to track the user's real-time location.

What we found: The app requests both ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION permissions. Mozilla confirmed the app tracks user location. The privacy policy discloses collection of "real-time location when configured." The device itself has no GPS — it connects via home Wi-Fi only. Fine location tracking reveals when users are away from home, creating a valuable dataset about home occupancy patterns that could be exploited.

⚫ mediumpolicy claims vs app permissions
Your home videos flow through a complex international network — a Taiwanese company backed by Foxconn, with Chinese tracking software in the app, and Amazon cloud storage in the US — but the privacy policy never clearly tells you which countries your data passes through.

What they claim: The privacy policy states that for European users, personal information transfers use Standard Contractual Clauses and that Tomofun has "required contractual provisions for transferring personal information in place." The policy implies data stays within controlled jurisdictions.

What we found: Tomofun is a Taiwanese company backed by Foxconn. The app embeds JiGuang Aurora Mobile JPush (Shenzhen, China) and Huawei Mobile Services Core — both Chinese service providers. Data infrastructure uses Amazon AWS (S3, CloudFront). The privacy policy does not disclose specific countries where data is processed or stored. The combination of Taiwanese corporate ownership, Chinese SDK data flows, and US cloud infrastructure creates a complex international data routing that is not transparently disclosed.

Data Sharing 3/4 HIGH 3 findings
⚡ highpolicy claims vs regulatory findings
Tomofun says they don't sell your data, but in the same document they admit your information qualifies as being "shared" and "sold" under California law for advertising. They also share your personal data with marketing companies. They are technically telling the truth while doing exactly what they deny.

What they claim: Tomofun states "We do not currently sell your Personal Information" in the CCPA section of their privacy policy.

What we found: The same privacy policy admits that identifiers, internet activity, geolocation, and commercial information fall under California definitions of "sharing" and "sale" for cross-contextual advertising. The policy also states Tomofun "may disclose your personal information to third parties for marketing purposes." Mozilla Privacy Not Included review confirmed Tomofun collects data from third-party marketing partners about user preferences and interests.

⚡ highapp permissions vs policy claims
The Furbo app secretly contains Chinese tracking and notification software (JiGuang and Huawei services) that is never mentioned in the privacy policy. Your data may be flowing to Chinese companies without your knowledge, even though Furbo markets itself as a premium Western product.

What they claim: Furbo is marketed as a premium pet camera primarily for Western markets (US, EU). The privacy policy mentions data processing safeguards and GDPR compliance with Standard Contractual Clauses for European data transfers.

What we found: The app embeds JiGuang Aurora Mobile JPush (Chinese push notification SDK) and Huawei Mobile Services Core tracker alongside Google Firebase Analytics, Google CrashLytics, and MixPanel — totalling 5 trackers. JiGuang (Aurora Mobile) is a Chinese mobile developer services company based in Shenzhen. These Chinese SDKs are not disclosed to users, and the privacy policy does not mention data flows to Chinese service providers despite Tomofun being a Taiwanese company backed by Foxconn.

⚫ mediumapp permissions vs policy claims
A pet treat-tossing camera app doesn't need to know your phone number, draw over other apps, track you for advertising, access your files, or automatically start when you turn on your phone. But Furbo's app demands all of these, revealing that data collection is a core part of the product, not just a side effect.

What they claim: Furbo is a pet camera that lets you see, talk to, and toss treats to your pet. Core functionality requires camera streaming, audio, and internet connectivity.

What we found: The app requests 34 permissions including READ_PHONE_STATE (device identity/phone number), SYSTEM_ALERT_WINDOW (draw over other apps), ACCESS_ADSERVICES_AD_ID and ACCESS_ADSERVICES_ATTRIBUTION (advertising tracking), AD_ID (Google advertising identifier), WRITE_EXTERNAL_STORAGE, READ_EXTERNAL_STORAGE, and RECEIVE_BOOT_COMPLETED (auto-start on phone boot). None of these are needed for viewing a pet camera or tossing treats. The advertising permissions confirm the app's secondary function as a data collection tool.

Security 2/4 MODERATE 1 finding
⚫ mediumfirmware analysis vs regulatory findings
Furbo claims to be secure, but security researchers found that anyone nearby could take complete control of the camera — watching your home, listening to conversations, and even dispensing treats. One vulnerability allowed hackers to access ANY Furbo account without knowing the password. Three separate critical vulnerabilities were found across multiple years, suggesting systemic security failures.

What they claim: Furbo's Product Security Statement claims the company maintains security standards. Mozilla confirmed Furbo "meets minimum security standards" for encryption, strong passwords, security updates, and vulnerability management.

What we found: CVE-2020-24918 (critical) allows unauthenticated remote code execution as root via a buffer overflow in the RTSP authentication parser. CVE-2021-32452 allows command injection via the webserver. CVE-2023-28704 (CVSS 8.8) allows unauthenticated command injection via Bluetooth. Somerset Recon also found predictable device IDs enabling enumeration of all Furbo devices, and a broken password reset mechanism allowing full remote access to any Furbo account without user interaction.

Honesty 4/4 EXTREME 2 findings
⚡ highfirmware analysis vs policy claims
Every video and sound from your home goes to Furbo's cloud servers for AI analysis — nothing happens locally on the camera. Furbo uses your home footage to train their AI systems. What's marketed as a simple pet treat-tosser is actually streaming everything to the cloud for processing.

What they claim: Furbo markets features like "barking detection" and "smart alerts" as pet care features, implying the camera locally monitors your pet. The product is positioned as a simple pet camera that tosses treats.

What we found: Firmware analysis reveals no local API — all video is processed through Tomofun's cloud infrastructure. AI features (barking detection, person detection, home emergency alerts) all require cloud processing. The privacy policy confirms AI analyses "Content data" for "sound and motion detection" and uses footage for "research and development" to "test and refine AI algorithms." The Dog Nanny subscription (.99/month) adds additional cloud AI processing.

⚡ highpolicy claims vs regulatory findings
Even if you stop using Furbo and ask them to delete your data, they keep your home videos and audio recordings forever "for legal defense." This directly contradicts your right to have your data deleted under privacy laws like GDPR and CCPA.

What they claim: The privacy policy provides CCPA and GDPR rights sections stating users can request deletion of their personal information. Tomofun claims GDPR compliance with a designated Data Protection Officer (dpo@furbo.com).

What we found: The same privacy policy states that post-account closure, content is "retained indefinitely for legal defense and crime prevention." Phone records are retained up to 6 years. The policy does not define what constitutes "content" subject to indefinite retention, meaning all captured video/audio of your home could be kept forever even after you stop using the device and request deletion.

Sources