Share this article

Third-Party Trackers Are Pulling Your Data Off Ring's Android App

A new report from the Electronic Frontier Foundation details the personally identifiable information pulled from your Ring app.

Updated Sep 13, 2021, 12:13 p.m. Published Jan 31, 2020, 10:00 a.m.
Credit: Ring promotional screenshot
Credit: Ring promotional screenshot

Ring, the home security company owned by Amazon, promises to watch the world around you and keep your property safe. But the doorbell app is also surveilling its users, sending personally identifiable information out to third-party vendors, according to a new report from the Electronic Frontier Foundation (EFF), the San Francisco civil liberties nonprofit.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

Bill Budington, the senior staff technologist who wrote the report, tested the Ring for Android version 3.21.1 app and found it was sharing data such as users private IP addresses, full names, email address, information about whether bluetooth is enabled and even sensor data from the device being used to access the app.

Budington identified four main companies receiving this information, including Branch, which calls itself a “deep linking” platform (meaning it takes people to specific web pages or products). Facebook also received information such as a person's time zone and was alerted when the app was opened. AppsFlyer, a big data firm, received information such as when users engage with the Neighbors section of the app, as well as what marketplace the app you installed is from and when it was first launched. Mixpanel, a business analytics company that tracks user engagement with apps, received the most identifiable data including the number of locations where a user has Ring devices installed, and user names and emails.

Analytics companies take these discrete forms of data and combine them with other internet user data to create a cohesive picture of device usage.

"This increases the risk of exposure, since Ring hasn't vetted for the security of these trackers," says Budington. "It also means that unaccountable marketers have access to customer data, and can follow their actions around as they use their mobile devices. It was revealed that a few Ring employees were fired for directly spying on customers and, again, these trackers, whose business model is to follow users, are not subject to the same level of scrutiny."

This is the most recent in a long line of revelations involving Ring. For example, it partnered with more 400 police departments in sharing device images, accidentally exposed the data of more than 3,000 users including login details and names of Ring devices (which are often labeled with terms like “bedroom”), and created neighborhood-wide panopticons in which neighbors are surveilling neighbors and paying for the privilege to do so.

Considering Amazon has a patent for “surveillance as a service” (delivery drones perform aerial surveillance at the property of an “authorized party”) along with its facial recognition technology, it’s worth considering how services you use to watch the world are also watching you.

Decentralization may provide one option when it come to alternative models that are less exploitative of user data.

"It's possible to envision a privacy-centric marketing technique that allows users to have targeted ads without a big, centralized database of users information," says Budington. "The Brave browser has experimented with providing these ads via a locally stored database so that you own that data and can clear it when you like. One thing we can be sure of is that the tracking industry isn't interested in these solutions so long as [it] can make big money out of slurping up as much data as [it] can."

UPDATE (Jan. 31, 16:21 UTC): This post has been updated to include comments from the author of the report.

UPDATE (Jan. 31, 18:5 UTC): This post has been updated to specify the IP addresses shared were private IP addresses.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Solana’s Drift Launches v3, With 10x Faster Trades

Drift (b52_Tresa/Pixabay)

With v3, the team says that about 85% of market orders will fill in under half a second, and liquidity will deepen enough to bring slippage on larger trades down to around 0.02%.

What to know:

  • Drift, one of the largest perpetuals trading platforms on Solana, has launched Drift v3, a major upgrade meant to make on-chain trading feel as fast and smooth as using a centralized exchange.
  • The new version will deliver 10-times faster trade execution thanks to a rebuilt backend, marking the largest performance jump the project has made so far.