← Trackers
D

Pixel Tag

Serious concerns
Google · 🇺🇸 United States · Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
Manufacturer: Google

⚠️ The bottom line

The reassurance is that your phone will tell you if a stranger's tracker is following you. The standard that promise rests on has a published threat model, and it is candid. Mix trackers from two manufacturers and you slip through the gaps between their brand-specific detection — rated high impact, mitigation: none available. Use a GPS tracker instead of a Bluetooth one and you are outside the system altogether, which the document notes is exactly what attackers do in rural areas where the crowd network is thin. And anyone who can pick up your phone can switch the background detection off. The alert is real. It is also the version of the problem that was easiest to solve. Every anti-stalking alert on every tracker works by asking one question: does this belong to you? If the answer is yes, nothing happens. So the protection holds against a stranger slipping a tag into your bag, and dissolves in the situation that actually kills people — the partner who set up your phone, who pays for the family plan, whose name is on the account. The tag is registered to them, or to the account you share, and by the standard's own logic that makes it legitimate. The IETF threat model writes it down plainly: the target is tracked by their own tag, without any warning. The alert was built for the pickpocket, not the person you live with.

Legal jurisdiction
🇺🇸 United States (headquarters)
⚠CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
⚠FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
●Geofence warrants read more →
Police can demand location data for everyone near a crime scene
D
Parent company: Google (Alphabet)
PRISM participant since 2009, CLOUD Act jurisdiction (US), $170M COPPA violation (YouTube Kids) +1 more
4 structural risks · 38 products →
Grade raised from C to D due to parent company risks
Spying
0/4 N/A
Is someone spying on me?
Data Sharing
1/4 LOW
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
2/4 MODERATE
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
3Contradictions
2Critical
1High
0Medium
5Sources
Findings by concern
Data Sharing 1/4 LOW 1 finding
⚡ highmarketing vs third party research
The billion-device network Google is selling the Pixel Tag on was not assembled by a billion people deciding to help. Find Hub switches itself on when you add a Google Account to an Android phone. That is the whole consent step. Code found in the Find Hub app shows Google preparing to widen it further — turn on Location, pair a set of earbuds, check where your other phone is, or just stop using a device, and your phone gets enrolled, with two days to say no. It was one day in an earlier build. Your phone is a node in a location network for other people's belongings, and the notice arrives after the decision.

What they claim: Google presents Find Hub as a network users join, and sells the Pixel Tag on the strength of its reach across more than a billion Android devices.

What we found: The Find Hub network is switched on automatically when a Google Account is added to an Android device — participation is the default state, not a choice the user makes. Android Authority's teardown of the Find Hub app found Google preparing to widen automatic enrolment to further triggers: enabling Location access, syncing a Fast Pair accessory, pulling recent location data from another device, or simply ceasing to use a linked device. Each would give the user 48 hours to opt out, raised from 24 hours in earlier builds. Those expanded triggers are unreleased code found in a teardown, not shipped behaviour; the Google Account default is current behaviour today.

Security 3/4 HIGH 1 finding
⚠️ criticalmarketing vs third party research
The reassurance is that your phone will tell you if a stranger's tracker is following you. The standard that promise rests on has a published threat model, and it is candid. Mix trackers from two manufacturers and you slip through the gaps between their brand-specific detection — rated high impact, mitigation: none available. Use a GPS tracker instead of a Bluetooth one and you are outside the system altogether, which the document notes is exactly what attackers do in rural areas where the crowd network is thin. And anyone who can pick up your phone can switch the background detection off. The alert is real. It is also the version of the problem that was easiest to solve.

What they claim: Google and Apple present DULT — the joint Detecting Unwanted Location Trackers standard — as the cross-platform protection that makes consumer trackers safe, with unknown-tracker alerts on both iOS and Android.

What we found: The IETF DULT threat model draft records that "Attackers may use a mix of Tags from different manufacturers (e.g., Apple AirTags, Tile, Samsung SmartTags) to exploit gaps in vendor-specific tracking protections", and that "Many detection systems are brand-dependent, making them ineffective against mixed Tag deployments" — rated high impact, with no effective mitigation available. GPS trackers fall outside the detection model entirely, and the draft notes attackers are "especially likely to use GPS trackers in rural areas and areas with low Crowdsourced Network saturation." An attacker with access to the target's phone "might intentionally disable background Unwanted Tracking detection on a Target's Device." A USENIX Security 2025 evaluation by Gerhardt et al. tested the reliability of unwanted-tracking notifications on iOS and Android and participants' ability to locate a hidden tracker, choosing AirTag precisely because it carries among the strongest protections on the market.

Honesty 2/4 MODERATE 1 finding
⚠️ criticalmarketing vs third party research
Every anti-stalking alert on every tracker works by asking one question: does this belong to you? If the answer is yes, nothing happens. So the protection holds against a stranger slipping a tag into your bag, and dissolves in the situation that actually kills people — the partner who set up your phone, who pays for the family plan, whose name is on the account. The tag is registered to them, or to the account you share, and by the standard's own logic that makes it legitimate. The IETF threat model writes it down plainly: the target is tracked by their own tag, without any warning. The alert was built for the pickpocket, not the person you live with.

What they claim: Unknown-tracker alerts warn you when a tracker you do not own is travelling with you.

What we found: The IETF DULT threat model documents the "Tracking Using Target's Own Tag" case, in which "the Target is effectively tracked by their own Tag without any warning" because the protocol assumes the registered owner is legitimate. Where one person set up both phones, or the account is shared across a family plan, the tracker is owned — so no alert is ever generated. The draft records this as a gap the protocol does not close.

What happened to real people
Documented incidents involving Google products and user data.
Jorge Molina jailed 6 days for murder via geofence warrant based on Google Sensorvault location data. Lost job, car, reputation. Charges never filed. [source]
PRISM participant since 2009. NSA collects stored communications. FBI conducts warrantless 'backdoor searches' of American data using names and email addresses. [source]
Google received 180 geofence warrants per week by 2019. Each warrant searches tens of millions of accounts. Supreme Court hearing constitutionality (Chatrie v. United States). [source]
What your data is worth to governments
Google complied with 235,000 government data requests in H1 2024. That's +530% over 10 years. Google has been a confirmed PRISM participant since 2009. Under this programme, the NSA collects stored communications. The company is legally prohibited from telling you. Jurisdiction: US (CLOUD Act, FISA Section 702, Patriot Act).
Documented: Jorge Molina jailed 6 days for murder via geofence warrant based on Google Sensorvault location data. Lost job, car, reputation. Charges never filed.
Documented: PRISM participant since 2009. NSA collects stored communications. FBI conducts warrantless 'backdoor searches' of American data using names and email addresses.
What is PRISM? · What is the CLOUD Act? · Transparency report
Sources