Eufy says your fingerprint data stays on your lock and never goes to the cloud. But this is the exact same company that was caught lying about the same thing with their cameras — they said camera footage was stored locally too, but secretly uploaded it to Amazon cloud servers. They use the same app for both cameras and smart locks, so the same deceptive infrastructure could apply to your fingerprints.
critical
Eufy promised your video feeds were encrypted and secure. The New York Attorney General proved they were not — anyone who found the right web address could watch your camera feed without a password. Eufy paid $450,000 in penalties. If they failed to encrypt video properly, can you trust their encryption of your fingerprint data?
critical
Eufy says they can't access your biometric data. But the app has both biometric permissions AND full internet access, and Eufy was already proven in court to have secretly linked facial recognition data across different cameras via their cloud. If they did it with faces, the same app infrastructure could do it with fingerprints.
eufy told customers their baby monitor video stays on the device and is encrypted end-to-end. In reality, video was being uploaded to cloud servers without encryption, and anyone who figured out the URL could watch the feed. The New York Attorney General fined them $450,000 for this deception. This means footage of your sleeping baby may have been accessible to unauthorized people on the internet.
critical
eufy says they don't sell children's data for advertising. But their baby monitor app includes advertising tracking tools (Google Ad ID, ad attribution services) and shares data with advertising networks. Even though the tracked device belongs to the parent, the app's entire purpose is monitoring a baby — the advertising infrastructure has no business being in a baby monitor app.
critical
eufy doesn't tell you where your baby's data goes. But the company is Chinese-owned (Anker, based in Shenzhen), and researchers found data being sent to both Amazon cloud servers and Chinese servers. Chinese law allows the government to demand access to data held by Chinese companies. This means your baby's heart rate, blood oxygen levels, sleep patterns, and 24/7 video feed could potentially be accessed by the Chinese government, and eufy never told you this was possible.
Eufy sold their cameras by promising your video never leaves your home. A security researcher caught them secretly uploading face images to Amazon cloud servers. When confronted, they deleted their privacy promises from their website instead of fixing the problem.
critical
Eufy's app makes you log in with your fingerprint to see your cameras, suggesting tight security. But anyone on your Wi-Fi network could exploit a bug in the camera itself to take it over completely — no password, no fingerprint, no login needed. The app's security is like a deadbolt on a door with no walls.
high
Eufy promised military-grade encryption for your video feeds. In reality, anyone who knew the right web address could watch your live camera feed in a regular video player, with zero password or encryption. Eufy's own spokesperson denied this was possible while journalists were doing it.
Eufy told you your doorbell video and face data would never leave your home. They lied. Your face was being uploaded to Amazon's cloud servers without your knowledge. When caught, they quietly deleted their privacy promises from their website instead of fixing the problem.
critical
Eufy didn't just upload your face to the cloud — they used it to identify you on other people's doorbells too. If your neighbor had a Eufy doorbell, Eufy's servers could match your face across both cameras using a shared ID, without anyone knowing.
critical
Eufy said your doorbell video was protected by military-grade encryption. In reality, anyone who knew the right web address could watch your live doorbell feed using a free video player — no password, no decryption needed. Eufy denied this was possible while journalists were doing it.
Eufy promised that your face data and videos would never leave your device and would stay stored locally. In reality, the company was secretly uploading facial recognition images to cloud servers without telling you. They even had a hidden database that could match your face across different users's cameras. When caught, they quietly deleted their privacy promises from their website instead of admitting the truth. This is a direct lie about where your most sensitive biometric data goes.
critical
Eufy's privacy policy tells YOU that you're responsible for following biometric privacy laws when using their facial recognition and fingerprint features. Meanwhile, Eufy itself was breaking those exact same laws by secretly uploading your face data to the cloud. They put the legal burden on you while they were the ones violating your privacy. A court has allowed biometric privacy lawsuits against Eufy to proceed.
critical
Eufy released this fingerprint-and-face-scanning smart lock in late 2023 — a full year after being caught secretly uploading face data to the cloud, after being sued multiple times, and after researchers found critical hackable flaws in their system. Instead of fixing their security problems first, they launched a new device that collects even MORE sensitive biometric data into the same broken system. This shows the company prioritizes selling new products over protecting your data.
eufy's entire pitch was: no cloud. Your video stays on your device. Local storage only. Then a security researcher caught them uploading your face to Amazon's servers. Facial recognition thumbnails, sent to AWS, accessible via URL, no authentication required. Anyone with the link could see your face. Anker denied it. Then admitted it. Then called it "necessary for push notifications." A notification doesn't need your face. A notification needs text. They lied about the most fundamental promise they made — where your data lives — and got caught by one person with a network monitor.
critical
Military-grade encryption, they said. Researchers opened VLC, typed in a URL with the camera's serial number, and watched someone's living room. No password. No encryption. No authentication. Just a URL and a serial number. Anker denied it. Then admitted it "in some cases." Then quietly patched it. The camera serial number is printed on the box. Anyone who handled the package — the warehouse worker, the delivery driver, your neighbour — had what they needed to watch your feed. Military-grade encryption with a URL anyone can guess.
critical
Anker's apology tour went like this. November: denied everything. December: admitted cloud uploads but called them necessary. January: admitted unencrypted streams. February: apologised and promised independent security audits. Then: silence. No public audit results. No published findings. The pattern is always the same — deny until caught, apologise when cornered, promise transparency, then hope everyone moves on. A security camera company that lied about encryption and cloud storage is asking you to trust their promise of future audits. The audits you can't see.