Govee Smart Lighting
Govee · Smart Plug / Light
✓ Reviewed
Index
App-controlled RGB/RGBIC smart lighting (strips, bulbs, bars, ceiling/floor lamps) managed through the Govee Home app with a cloud account. Wi-Fi models route features through the vendor's (Chinese) cloud; many models also support local Bluetooth/LAN control (Home Assistant govee_light_local integration, introduced HA 2024.2 — per-device LAN Control toggle, no cloud) and work offline once configured. Many light bars/strips include a built-in high-sensitivity microphone for music-reactive ("music mode") lighting; there is no camera or GPS in the device. The Android app requires precise location permission for Bluetooth device setup and also requests camera/NFC access at the app-permission level. Govee's privacy stance is decent on paper (erasure rights, retention minimization, no-sale-without-authorization) but split across a thin US main policy (which carries the no-sale commitment yet omits retention/deletion/law-enforcement) and fuller region-gated GDPR/PIPEDA/APPI versions (which carry retention/erasure/law-enforcement terms). No independent privacy research, regulatory action, breach, or confirmed data sale specific to Govee lighting was found — treated as unstudied.
Why this rating
POLICY 84 = 100 -15 sensitive-collection (Govee Home requires precise Android location for BLE setup plus camera/NFC beyond a light's need; many models embed a mic for music-reactive mode — built-in microphone independently confirmed) -7 policy-vagueness (thin/old US main policy omits retention, deletion and law-enforcement terms that appear only in region-gated GDPR/PIPEDA/APPI versions) -5 unilateral-change ("we may update this Privacy Policy from time to time") +4 data-minimization (GDPR policy retains data "only as long as necessary"; separate US main policy commits to "never sell, rent or share...without authorization" — both verified) +7 local-processing (LAN/Bluetooth local control on many models; native Home Assistant govee_light_local integration confirmed — applied model-dependently). Not deducted: sells-data (explicit no-sale commitment verified in US main policy, unconfirmed otherwise), broker-disclosure/forced-arbitration (none — GDPR policy has no arbitration clause), law-enforcement-loose (standard "valid requests by public authorities...required by law" language), no-opt-out/no-deletion-right (GDPR/PIPEDA policies grant access + erasure + withdraw-consent), indefinite-retention (GDPR policy retains only as necessary). EVIDENCE 60 = unstudied cap: no independent privacy research, regulatory action, confirmed breach, or confirmed data sale specific to Govee lighting (independent breach/lawsuit/FTC searches returned nothing). Community/automated concerns exist (broad precise-location permission surfaced Jan 2024; unencrypted BLE broadcast) but the BLE finding targets Govee thermo-hygrometers, not lighting, so it is not cited as a lighting incident. No incident deductions and no independent-audit bonus apply (both citations are vendor/developer self-disclosures). Confidence low. Grade derivation left to orchestrator.
What it is
- Microphone
- Requires a cloud account
- Works offline
- Manufacturer
- Govee
- Category
- Smart Plug / Light
- Model years
- 2017-present
- Market status
- Current
- Companion app
- Govee Home
The evidence 2
Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.
-
Vendor's own GDPR-region policy (Last Updated 2022-09-30): retains personal data 'only for as long as is necessary,' grants rights to access/update/delete, to request erasure ('delete or remove Personal Data when there is no good reason for Us to continue processing it') and to withdraw consent, and discloses to public authorities only 'if required to do so by law or in response to valid requests by public authorities'; it contains no arbitration clause. This GDPR version lists standard sharing situations (service providers, affiliates, business partners, business transfers) and does NOT itself contain a no-sale promise. The 'never sell, rent or share your information...without your own authorization' commitment appears instead in Govee's separate, thinner US-facing main policy (us.govee.com/pages/privacy-policy, verified), which in turn omits the retention, deletion and law-enforcement terms.
Why it matters here: Primary source for POLICY scoring — supports retention-minimization and erasure/withdraw-consent (no deduction); the divergent thin US policy (which carries the verified no-sale commitment but omits retention/deletion/law-enforcement) drives the policy-vagueness deduction. Vendor self-disclosure, not independent research — does not lift the unstudied evidence cap. Not an incident.
-
Developer's own Google Play Data safety label: the app collects device or other IDs, crash logs, diagnostics and app-performance data, and shares data with third parties for analytics (also collects optional name/email/address/phone and user-generated content). The Data safety label itself does NOT list location, camera or NFC. Separately, the Android app's runtime permissions require precise location for Bluetooth (BLE) device setup — a source of user concern since Jan 2024 — and the app also requests camera and NFC access; these are app permissions, not entries in the Data safety label.
Why it matters here: Supports the sensitive-collection deduction (precise-location permission beyond a light's need) and the analytics-sharing concern. Official self-disclosure / permission manifest, not independent research — does not lift the unstudied evidence cap. Not an incident.
Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.