← Smart Home
D

Tuya IoT Platform (WB3S Module)

Serious concerns
Tuya · 🇨🇳 China · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
FCC ID: 2ANDL-WB3S
Chipset: Beken BK7231T / Espressif ESP8266
App: com.tuya.smart
Manufacturer: Tuya Inc. (Hangzhou)

⚠️ The bottom line

When you buy a cheap smart plug or light switch from a brand you've never heard of, there's a good chance it's actually powered by a Chinese company called Tuya. Your data goes to Tuya's servers, but the product packaging and app never tell you this. Over 116 million devices across thousands of brands hide this relationship. Tuya says you can choose where your data is stored — US, Europe, or elsewhere. But researchers found that Tuya devices secretly send data to Chinese servers no matter what region you pick. The fine print even admits they can't guarantee your data stays where you chose.

Legal jurisdiction
🇨🇳 China (headquarters)
National Intelligence Law read more →
Company must secretly hand data to Chinese intelligence on request
Data Security Law read more →
State can classify any data as 'important' and demand access for national security
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
4/4 EXTREME
Who gets my data?
Security
2/4 MODERATE
Is it actually secure?
Honesty
3/4 HIGH
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
10Contradictions
2Critical
6High
2Medium
6Sources
Findings by concern
Spying 3/4 HIGH 3 findings
⚠️ criticalregulatory findings vs policy claims
When you buy a cheap smart plug or light switch from a brand you've never heard of, there's a good chance it's actually powered by a Chinese company called Tuya. Your data goes to Tuya's servers, but the product packaging and app never tell you this. Over 116 million devices across thousands of brands hide this relationship.

What they claim: Tuya's FCC modular transmitter approval (2ANDL-WB3S) means the Tuya module appears inside 5,000+ branded products across 220+ countries. The FCC filing is under 'Hangzhou Tuya Information Technology Co., Ltd' — the end product carries only the OEM brand name.

What we found: Tuya's privacy policy (tuya.com) discloses extensive data collection including device identifiers, MAC addresses, IP addresses, usage patterns, location data, camera images, health data, and voice recordings. But consumers buying a branded smart plug from a retailer see only the OEM brand's privacy policy — they have no idea Tuya exists, let alone that their data flows to Tuya's cloud infrastructure on Alibaba Cloud, AWS, Azure, and Tencent Cloud.

⚡ highapp permissions vs firmware analysis
When you install the Tuya app to control a simple smart plug that just turns power on and off, the app asks for access to your phone's camera, microphone, and precise location — including tracking your location in the background. Your smart plug has no camera or microphone, so there's no legitimate reason for these permissions.

What they claim: The Tuya platform controls a vast range of simple devices — smart plugs, light switches, LED strips, and basic sensors — that have no camera or microphone hardware.

What we found: The Tuya Smart app requests CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION, and ACCESS_BACKGROUND_LOCATION permissions for ALL devices including simple smart plugs using the BK7231T or ESP8266 chipset (which have no camera or microphone capability). The same app with the same permissions bundle controls every Tuya device regardless of whether the hardware has these sensors.

⚫ mediumapp permissions vs policy claims
The Tuya app asks for access to your phone's motion sensors at the highest possible speed. This kind of data can reveal what you're typing, how you walk, and track your movements — far beyond what's needed to turn a light on and off. Tuya's privacy policy doesn't mention collecting this kind of data from your phone.

What they claim: Tuya's privacy policy describes collecting 'usage patterns' and 'sensor readings' from IoT devices, but does not disclose collection of high-frequency phone sensor data.

What we found: The Tuya Smart app requests the HIGH_SAMPLING_RATE_SENSORS Android permission, which enables access to the phone's accelerometer and gyroscope at maximum sampling rate (up to 400-800Hz). This level of sensor access can be used for keystroke inference, gait analysis, and continuous motion tracking. This permission is completely unnecessary for controlling smart plugs, lights, and switches.

Data Sharing 4/4 EXTREME 4 findings
⚠️ criticalpolicy claims vs firmware analysis
Tuya says you can choose where your data is stored — US, Europe, or elsewhere. But researchers found that Tuya devices secretly send data to Chinese servers no matter what region you pick. The fine print even admits they can't guarantee your data stays where you chose.

What they claim: Tuya's privacy policy states users can 'choose their data center region' for data storage, implying user control over where data resides.

What we found: Firmware analysis reveals hardcoded endpoints to Chinese servers (m1.tuyacn.com, a1.tuyacn.com, h1.tuyacn.com) alongside US and EU endpoints. Security research by the tuya-cloudcutter project confirmed that stock Tuya firmware phones home to Chinese cloud endpoints even when the user selects a non-China data center. The policy itself admits it 'does not guarantee data stays in the selected region'.

⚡ highapp permissions vs policy claims
The Tuya Smart app contains hidden advertising software from ByteDance — the company that owns TikTok. This means data about when you turn your lights on and off, your daily routines, and your device usage patterns could flow to TikTok's parent company. Tuya's privacy policy doesn't mention this by name.

What they claim: Tuya's privacy policy lists categories of third-party service providers but does not specifically name Pangle or ByteDance as a data recipient.

What we found: Exodus Privacy analysis of the Tuya Smart app (v7.2.6) identifies Pangle — ByteDance's (TikTok parent company) advertising SDK — as an embedded tracker. Pangle collects device identifiers, usage data, and serves targeted advertising. The privacy policy generically refers to 'service providers' without naming them, hiding the fact that IoT device usage data flows to TikTok's parent company.

⚡ highregulatory findings vs policy claims
Tuya promises to delete your data if you ask under California privacy law. But Tuya is a Chinese company required by Chinese law to hand over data to the government when asked. These two promises directly contradict each other — Chinese law overrides California privacy rights for data stored on Chinese servers.

What they claim: Tuya's privacy policy provides CCPA rights for California residents and GDPR-style rights for EU users, implying strong privacy protections and user control over data.

What we found: Tuya Inc. is headquartered in Hangzhou, China, and is subject to China's Data Security Law (June 2021) which requires Chinese enterprises to 'support, assist and cooperate with law enforcement' on data concerning national security. VOA investigation found that Dark Cubed tested 10 Tuya devices and every one connected to servers in China. Tuya is backed by Tencent, which has documented ties to Beijing. The CCPA deletion rights are meaningless if Chinese law simultaneously requires data retention and disclosure.

⚫ mediumregulatory findings vs policy claims
Tuya shows off impressive security certifications on its website. But when cybersecurity experts actually tested 10 Tuya devices, every single one failed basic security checks. They all connected to Chinese servers and some exposed private camera images to anyone on the same Wi-Fi network.

What they claim: Tuya's data privacy center promotes security certifications and compliance with international standards including SOC 2, ISO 27001, and GDPR.

What we found: Dark Cubed cybersecurity firm examined 10 Tuya-powered home devices and found: every device had at least one network connection to servers in China, all failed basic security checks, and provided complete visibility into private images to anyone on the network. This directly contradicts Tuya's marketing of security certifications and their privacy center's claims of robust data protection.

Security 2/4 MODERATE 2 findings
⚡ highregulatory findings vs firmware analysis
Tuya claims its devices are secure with encryption, but researchers found that during setup, your Wi-Fi password is sent completely unprotected — anyone nearby with the right tools can grab it. The default password for the device's setup network is literally '12345678'.

What they claim: Tuya's data privacy center promotes 'end-to-end encryption' and security certifications for its IoT platform.

What we found: A&O IT Group discovered that Tuya-powered smart plugs transmit Wi-Fi SSID and password in plaintext during device setup. The default access point password is '12345678' as documented in the user manual. Security researcher rb9.nl found that the BK7231T/BK7231N SDK's AP configuration handler has an out-of-bounds memory write via UDP port 6669 that allows overwriting factory-burned secrets (UUID, auth key, PSK) with no authentication.

⚡ highfirmware analysis vs regulatory findings
When a security flaw is found in Tuya's software, it doesn't just affect one brand — it affects every single device using Tuya's platform across thousands of brands. Three serious vulnerabilities have been found that could let attackers crash or take over these devices. Most people don't even know their device runs Tuya software, so they'd never know to look for security updates.

What they claim: Tuya's FCC modular approval and platform approach means identical firmware runs on 116+ million devices across 5,000+ brands.

What we found: CVE-2026-28519 (heap-based buffer overflow in DnsServer, CVSS 8.7) and CVE-2026-28520 (off-by-one buffer overflow in WiFiMulti, CVSS 8.6) affect the arduino-TuyaOpen SDK used across the entire Tuya ecosystem. CVE-2024-32268 allows remote denial of service without authentication. Because Tuya provides the firmware SDK to all OEM manufacturers, a single vulnerability affects every branded device simultaneously. Most consumers don't know their device is Tuya-based, so they have no way to find or apply security patches.

Honesty 3/4 HIGH 1 finding
⚡ highapp permissions vs policy claims
The Tuya Smart app — which you download to control a $10 smart plug — asks for permission to read your blood pressure, heart rate, blood oxygen levels, sleep patterns, and body fat percentage. There is no reason a light switch app needs to know your body temperature or bone mass.

What they claim: Tuya is marketed as a smart home IoT platform for controlling lights, plugs, switches, and sensors. The privacy policy mentions health data collection but does not explain why a smart home app needs it.

What we found: The Tuya Smart app (com.tuya.smart v7.2.6) requests 27 health-related Android permissions including READ_BLOOD_PRESSURE, READ_HEART_RATE, READ_OXYGEN_SATURATION, READ_SLEEP, READ_STEPS, WRITE_BODY_FAT, WRITE_BODY_TEMPERATURE, WRITE_BONE_MASS, and WRITE_EXERCISE_ROUTE. These are extreme permissions for an app whose primary function is turning lights on and off. The same app controls all Tuya devices regardless of category.

Sources