Cheap but Spying: Avoid These Smartwatches
- Low-cost smartwatches from unverified manufacturers often collect excessive user data and transmit it to insecure servers, according to a report by Živé.sk.
- The risk is highest with "no-name" brands sold through third-party marketplaces, where the hardware and software are often white-labeled.
- According to the Živé.sk analysis, these apps often request access to the microphone, camera, and call logs, even when such features are not required for the watch's primary...
Low-cost smartwatches from unverified manufacturers often collect excessive user data and transmit it to insecure servers, according to a report by Živé.sk. The publication warns that these budget devices frequently lack transparent privacy policies and may function as surveillance tools by requesting unnecessary permissions to access contacts, messages, and location data.
The risk is highest with “no-name” brands sold through third-party marketplaces, where the hardware and software are often white-labeled. These devices typically require the installation of companion apps that request broad system permissions on the user’s smartphone to function, Živé.sk reports.
According to the Živé.sk analysis, these apps often request access to the microphone, camera, and call logs, even when such features are not required for the watch’s primary health or notification functions. This data is then frequently sent to servers located in jurisdictions with weak data protection laws.
Privacy Risks in Budget Wearables
The primary security vulnerability lies in the companion applications required to sync the watch with a mobile device. Živé.sk notes that many of these apps are developed by companies that do not provide a clear legal entity name or a verifiable physical address in their privacy documentation.
The reporting highlights several specific technical concerns regarding these devices:
- Excessive Permissions: Apps requesting access to the full contact list and SMS history without a functional need for that data.
- Unencrypted Transmission: Data sent from the phone to the cloud often lacks strong encryption, making it susceptible to interception.
- Opaque Data Sharing: Lack of clarity regarding whether user health and location data is sold to third-party brokers.
Živé.sk suggests that the low price point of these devices is often offset by the monetization of the user’s personal information, which serves as a secondary revenue stream for the manufacturers.
Identifying High-Risk Devices
The report advises consumers to avoid smartwatches that lack a recognized brand name and are marketed primarily through aggressive social media advertisements or discount platforms. These products often mimic the design of premium brands like Apple or Samsung but operate on proprietary, unvetted software.
A key indicator of risk is the requirement to download an APK file directly from a website rather than through an official app store like Google Play or the Apple App Store. Direct APK installations bypass the basic security screenings provided by platform operators, according to Živé.sk.
Users are encouraged to review the permissions requested during the app setup process. If a basic fitness tracker asks for permission to read emails or access the device’s camera, it is a signal of potential data harvesting, the report states.
Comparing Budget and Established Ecosystems
While established brands also collect data, Živé.sk contrasts them with budget “no-name” devices based on the availability of legal recourse and transparency. Major tech companies are subject to regulations such as the GDPR in Europe, which mandates clear data deletion processes and explicit consent.
In contrast, budget manufacturers often operate outside these regulatory frameworks. This makes it nearly impossible for a user to request the deletion of their data or to determine exactly where their personal information is stored once it leaves the device.
