← Smartphones
D

Google Pixel 8

Google collects 20x more data than Apple. Location tracked even in airplane mode.
Serious concerns
Google · 🇺🇸 United States · WiFi + Cellular + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: A4RG9BQD
Chipset: Google Tensor G3 (Samsung 4nm) + Titan M2 security chip
App: com.google.android.gms
Manufacturer: Google
Model: Pixel 8

⚠️ The bottom line

Google says you can control what data they collect, but the most important data collection software on your Pixel phone — Google Play Services — has access to your location, texts, call history, contacts, camera, microphone, and body sensors, and you cannot turn it off or remove it. The "choice" they advertise does not apply to the biggest data collector on your phone. Even if you go through every privacy setting on your Pixel 8 and turn off everything you can find, your phone still sends data to Google every 4 minutes. It sends your phone number, device ID, location, and the WiFi networks near you — whether you are logged in or not. Academic researchers proved this happens even after you opt out.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
4/4 EXTREME
Who gets my data?
Security
4/4 EXTREME
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
12Contradictions
4Critical
5High
3Medium
10Sources
Findings by concern
Spying 4/4 EXTREME 6 findings
⚠️ criticalpolicy claims vs app permissions
Google says you can control what data they collect, but the most important data collection software on your Pixel phone — Google Play Services — has access to your location, texts, call history, contacts, camera, microphone, and body sensors, and you cannot turn it off or remove it. The "choice" they advertise does not apply to the biggest data collector on your phone.

What they claim: Google Safety Center states: "Whether you want to save, delete, or auto-delete your data, we give you the choice." Google privacy policy emphasizes user control over data collection and the ability to manage privacy settings.

What we found: Google Play Services (com.google.android.gms) runs as a privileged system process with 56 permissions including ACCESS_BACKGROUND_LOCATION, READ_SMS, READ_CALL_LOG, READ_CONTACTS, RECORD_AUDIO, CAMERA, BODY_SENSORS, READ_LOGS, and PACKAGE_USAGE_STATS. This service CANNOT be uninstalled, disabled, or permission-restricted by the user. It starts at boot (RECEIVE_BOOT_COMPLETED) and ignores battery optimization (REQUEST_IGNORE_BATTERY_OPTIMIZATIONS). The "choice" Google offers does not extend to the most invasive data collection channel on the device.

⚠️ criticalpolicy claims vs regulatory findings
Even if you go through every privacy setting on your Pixel 8 and turn off everything you can find, your phone still sends data to Google every 4 minutes. It sends your phone number, device ID, location, and the WiFi networks near you — whether you are logged in or not. Academic researchers proved this happens even after you opt out.

What they claim: Google privacy policy states data collection helps "maintain & improve" services and "develop new services." Privacy controls page suggests users can manage what data Google collects through account settings.

What we found: Trinity College Dublin research (Prof. Douglas Leith, 2021) found Google Pixel phones send ~1MB of telemetry to Google in the first 10 minutes of startup and ~1MB every 12 hours when idle. Data includes IMEI, SIM serial number, phone number, hardware serial number, location, cookies, local IP address, and nearby WiFi MAC addresses. Critically: "both iOS and Google Android transmit telemetry, despite the user explicitly opting out" and "this data is sent even when a user is not logged in (indeed even if they have never logged in)." Telemetry sent every 255 seconds (~4.25 min).

⚡ highapp permissions vs policy claims
Google Play Services can read, write, and send your text messages, see who you call and for how long, access all your contacts, and monitor outgoing calls. This is not a messaging app — it is a background system service that you never interact with directly, yet it has more access to your communications than any app you would actually choose to install.

What they claim: Google privacy policy describes data collection categories and suggests users can review and control what information is gathered. The policy frames data collection as necessary for service functionality.

What we found: Google Play Services requests READ_SMS, SEND_SMS, WRITE_SMS, RECEIVE_SMS, RECEIVE_MMS — full SMS access for a service marketed as a background platform component. It also requests CALL_PHONE, READ_CALL_LOG, WRITE_CALL_LOG, PROCESS_OUTGOING_CALLS — complete telephony surveillance capability. Combined with READ_CONTACTS, WRITE_CONTACTS, and GET_ACCOUNTS, this gives Google access to every communication channel on the device. These permissions are not disclosed prominently in the privacy policy as system-level collection capabilities.

⚡ highpolicy claims vs regulatory findings
Google says they collect data to make their services better for you, but your Pixel phone sends 20 times more data to Google than an iPhone sends to Apple. Google kept a massive database called Sensorvault tracking where every Android user went, which police could search to find everyone near a crime scene. Google only started changing this after years of public criticism.

What they claim: Google states in its privacy policy: "We collect information to provide better services to all our users." The framing positions Google as a service provider that collects data to help users.

What we found: Google Pixel phones send 20 times more telemetry data to Google than iPhones send to Apple (Trinity College Dublin, 2021). Google collected data from 1.3 million Australian accounts through deceptive dual-setting design (ACCC, A$60M penalty). Google maintained Sensorvault — a database of location history for all Android users — which was the primary target for law enforcement geofence warrants covering every user near a crime scene. Google only began moving away from Sensorvault in Dec 2024, years after it was publicly criticised.

⚫ mediumpolicy claims vs regulatory findings
Google made a big announcement about storing your location data only on your phone, but they still collect your location through Google Search, Maps, YouTube, Chrome, and your IP address. This is the same pattern that got them fined in Australia — making one change to look privacy-friendly while continuing to collect the same information through other channels you might not think about.

What they claim: Google announced in December 2023 that Location History would move to on-device storage with end-to-end encryption, and default auto-delete would be set to three months, positioning this as a major privacy improvement.

What we found: While Location History moved on-device effective December 2024, Web & App Activity and other Google services continue to collect location-adjacent data server-side. Google search queries, Maps directions, YouTube viewing location, Chrome browsing, and IP-based location all still flow to Google servers. The ACCC case proved Google has a pattern of using one visible setting as a decoy while collecting the same data through less visible channels. The 5th Circuit ruled geofence warrants unconstitutional, but Google had maintained Sensorvault for years before acting.

⚫ mediumfirmware analysis vs app permissions
Google promises 7 years of security updates for the Pixel 8, but hackers and forensic companies found ways to break into the phone before Google could fix the problems. At the same time, Google Play Services permanently has access to your camera, microphone, and location — creating a built-in security risk that no update can fix because it is part of how the phone is designed to work.

What they claim: Google markets Pixel 8 as receiving 7 years of security updates and being the "most personal, helpful and secure phone" with monthly security patches.

What we found: Despite monthly security patches, three high-severity Pixel-specific vulnerabilities (CVE-2024-29745, CVE-2024-29748, CVE-2024-32896) were actively exploited before patches were available. Meanwhile, Google Play Services maintains RECORD_AUDIO, CAMERA, ACCESS_BACKGROUND_LOCATION, and READ_LOGS permissions — creating a permanent attack surface that even patched devices cannot eliminate. The combination of privileged system access and demonstrated zero-day exploitation means the "most secure phone" label is misleading when Google itself maintains the largest privileged access footprint on the device.

Data Sharing 4/4 EXTREME 3 findings
⚠️ criticalpolicy claims vs regulatory findings
Google was fined $60 million in Australia because they tricked people about location tracking. When you turned off "Location History" thinking Google would stop tracking your location, a hidden second setting called "Web & App Activity" kept collecting your location data anyway. This hidden setting was turned on by default. A court found Google deliberately designed it this way.

What they claim: Google implied that the "Location History" setting was the primary control for whether Google collected location data from Android devices, giving users the impression they could stop location tracking by disabling this one setting.

What we found: The ACCC sued Google and won. The Federal Court of Australia found that between January 2017 and December 2018, Google misled 1.3 million Australian users. A second setting — "Web & App Activity" — was enabled by default and also collected personally identifiable location data. Google was ordered to pay A$60 million. This was a deliberate dual-setting design where disabling the obvious setting still left location collection active through a less obvious one.

⚡ highfirmware analysis vs policy claims
Google says their special Tensor chip means your Pixel 8 processes things privately on the phone itself. While a few features do work offline, the most-used AI features like Google Assistant and Google Photos still send your data to Google servers. Your phone also constantly connects to Google advertising servers even when you are not using it.

What they claim: Google promotes Tensor G3 as enabling "on-device AI" for privacy-preserving features, marketing the chip as a reason Pixel phones are more private because processing happens locally rather than in the cloud.

What we found: While features like Call Screen and Live Translate run on-device, core AI features including Google Assistant, Google Photos face/object recognition, Google Lens, and search suggestions still route through Google cloud servers. The device maintains persistent connections to play.googleapis.com, app-measurement.com, firebaseinstallations.googleapis.com, and pagead2.googlesyndication.com (Google ad network). The "on-device AI" marketing creates a false impression that the phone operates independently when it continuously sends data to Google servers.

⚫ mediumapp permissions vs policy claims
Google says advertising is separate from their core services, but their advertising servers are baked directly into the Pixel 8 operating system through Google Play Services. Ad tracking runs at the system level with access to your location and device identifiers, and no ad blocker or privacy app can stop it because it runs with special system privileges.

What they claim: Google privacy policy describes advertising as a service that "helps fund our services" and states ads are shown based on user activity, with the implication that advertising data collection is separate from core device functions.

What we found: Google Play Services connects to pagead2.googlesyndication.com and www.googleadservices.com — Google advertising infrastructure — as hardcoded endpoints at the firmware level. The service contains Google Analytics, Firebase Analytics, Google CrashLytics, and Google Tag Manager trackers. Combined with ACCESS_BACKGROUND_LOCATION, READ_PHONE_STATE, and GET_ACCOUNTS, the advertising system has access to persistent device identifiers and real-time location data through a system process that cannot be blocked by ad blockers or privacy tools.

Security 4/4 EXTREME 3 findings
⚠️ criticalpolicy claims vs regulatory findings
Google Assistant was secretly recording people without being activated and sending those recordings to human contractors who listened to them. The leaked recordings included people having private conversations in their bedrooms, discussing medical conditions, and women experiencing violence. Google paid $68 million to settle the lawsuit. 153 of the leaked recordings were made without anyone saying "Hey Google."

What they claim: Google Assistant privacy disclosures stated that voice interactions were processed to improve service quality, with users understanding their data would be handled by automated systems.

What we found: In July 2019, a Dutch contractor leaked over 1,000 Google Assistant recordings to Belgian news outlet VRT. Contractors identified people by their home addresses and heard bedroom conversations, medical discussions, and recordings of women in distress. 153 conversations should never have been recorded at all — triggered without the "Hey Google" wake word. Google settled a class action for $68 million. The Hamburg DPA invoked GDPR Article 66 urgency procedure to halt Google voice data processing.

⚡ highfirmware analysis vs regulatory findings
Google calls the Pixel 8 their most secure phone, but forensic companies like Cellebrite found ways to break into locked Pixel phones and steal your data. Three serious vulnerabilities let attackers bypass security features, and Google only fixed them after an outside security project (GrapheneOS) reported the problems — Google did not find these issues themselves despite their security marketing.

What they claim: Google markets the Pixel 8 as having "the most helpful and secure phone" with the Titan M2 security chip providing hardware-level protection and 7 years of security updates.

What we found: Forensic companies including Cellebrite exploited Pixel firmware vulnerabilities CVE-2024-29745 (bootloader information disclosure, HIGH severity) and CVE-2024-29748 (firmware privilege escalation, HIGH severity) to extract data from locked Pixel devices. CVE-2024-32896, a related zero-day confirmed by Google as actively exploited, allowed interruption of factory reset wipes. These exploits were weaponized specifically against Pixel devices. GrapheneOS discovered and reported these vulnerabilities while developing duress PIN features — Google did not discover them internally.

⚡ highapp permissions vs firmware analysis
Google built a special security chip (Titan M2) to protect your data from hackers, but Google Play Services has special system-level access that bypasses all the security controls your phone shows you. It can read system logs, monitor which apps you use, and access device admin functions — and you cannot see or control these permissions. The security chip protects you from everyone except Google.

What they claim: The Pixel 8 includes the Titan M2 security chip for hardware-level protection of sensitive data, and Google markets Android as having a robust permission model that gives users control over what apps can access.

What we found: Google Play Services has BIND_DEVICE_ADMIN, INTERACT_ACROSS_USERS, READ_LOGS, DUMP, and PACKAGE_USAGE_STATS — system-level permissions that bypass the normal Android permission model entirely. It can read system logs (including other apps activities), access device admin functions, interact across user profiles, and monitor which apps you use and for how long. These privileged permissions are not subject to user consent and are not visible in the normal permission management interface. The Titan M2 security chip protects against external attackers but cannot protect users from Google itself.

What happened to real people
Documented incidents involving Google products and user data.
Jorge Molina jailed 6 days for murder via geofence warrant based on Google Sensorvault location data. Lost job, car, reputation. Charges never filed. [source]
PRISM participant since 2009. NSA collects stored communications. FBI conducts warrantless 'backdoor searches' of American data using names and email addresses. [source]
Google received 180 geofence warrants per week by 2019. Each warrant searches tens of millions of accounts. Supreme Court hearing constitutionality (Chatrie v. United States). [source]
What your data is worth to governments
Google complied with 235,000 government data requests in H1 2024. That's +530% over 10 years. Google has been a confirmed PRISM participant since 2009. Under this programme, the NSA collects stored communications. The company is legally prohibited from telling you. Jurisdiction: US (CLOUD Act, FISA Section 702, Patriot Act).
Documented: Jorge Molina jailed 6 days for murder via geofence warrant based on Google Sensorvault location data. Lost job, car, reputation. Charges never filed.
Documented: PRISM participant since 2009. NSA collects stored communications. FBI conducts warrantless 'backdoor searches' of American data using names and email addresses.
What is PRISM? · What is the CLOUD Act? · Transparency report
Sources