← Smart Home
C

Roku Smart Home

Notable issues
Roku · 🇺🇸 United States · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: Roku Smart Home
Manufacturer: Roku

The bottom line

Roku makes 80% of its money from advertising. Now they sell cameras, doorbells, and smart plugs. Your security camera data feeds into the same infrastructure that serves you TV ads. Roku knows what you watch AND when you're home. An advertising company now has cameras inside and outside your house. 576,000 Roku accounts breached. Then 15,000 more. Attackers used stolen passwords to log in and make purchases on victims' accounts. Roku had no two-factor authentication until after the breaches forced it. The company that wants cameras in your home couldn't secure the accounts those cameras connect to.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
0/4 N/A
Is someone spying on me?
Data Sharing
1/4 LOW
Who gets my data?
Security
2/4 MODERATE
Is it actually secure?
Honesty
1/4 LOW
Can I trust what they say?
ACCEPTABLE Moderate concerns. Standard privacy hygiene applies.
2Contradictions
0Critical
2High
0Medium
2Sources
Findings by concern
Data Sharing 1/4 LOW 1 finding
⚡ highmarketing vs third party research
Roku makes 80% of its money from advertising. Now they sell cameras, doorbells, and smart plugs. Your security camera data feeds into the same infrastructure that serves you TV ads. Roku knows what you watch AND when you're home. An advertising company now has cameras inside and outside your house.

What they claim: Roku Smart Home promotes simple, affordable home monitoring

What we found: Roku's primary business is advertising — 80% of revenue comes from advertising and data licensing on its streaming platform. Roku Smart Home cameras, doorbells, and sensors feed into the same data infrastructure used for ad targeting. Roku's privacy policy allows combining smart home data (who's home, activity patterns) with streaming data (what you watch) to build comprehensive household profiles.

Security 2/4 MODERATE 1 finding
⚡ highprivacy policy vs regulatory
576,000 Roku accounts breached. Then 15,000 more. Attackers used stolen passwords to log in and make purchases on victims' accounts. Roku had no two-factor authentication until after the breaches forced it. The company that wants cameras in your home couldn't secure the accounts those cameras connect to.

What they claim: Roku describes data collection as necessary for product functionality

What we found: In 2023, Roku disclosed a data breach affecting 576,000 accounts, followed by a second breach in 2024 affecting another 15,000 accounts. Attackers used credential stuffing to access Roku accounts and make fraudulent purchases. Roku responded by enforcing mandatory two-factor authentication — but the breaches exposed how much personal data Roku had accumulated across its streaming and smart home ecosystem.

Sources