← IoT Privacy Database

Petcube Camera

Petcube · Camera / Doorbell

✓ Reviewed

2.2Surveillance
Index
Policy — what its policy permitsD
Evidence — what research provesA

Interactive Wi-Fi pet camera with two-way audio and cloud-recorded video (short clips, 256-bit AES at rest, TLS in transit); cloud/account-dependent with no meaningful offline mode. Petcube's privacy policy explicitly refuses to sell/rent personal data and grants marketing opt-out plus GDPR erasure, but records audio/video, has the companion app collect geotag/city-level location, and shares cookie data with third-party advertising partners for targeted ads. IOActive (advisory dated April 2015, publicly released May 2018) disclosed serious security negligence in the original device — SSH private keys shared across all users, no isolation, server-side command execution, shared TLS certificate — now over a decade old, remediated, with no known exploitation. Mozilla's *Privacy Not Included review of the current Play 2/Bites 2 line is otherwise clean (no known incidents in last 2 years, meets minimum security standards).

Why this rating

POLICY 58 (start 100): -15 sensitive-collection (records audio+video; companion app collects geotag/city-level location); -15 broker-disclosure (shares cookie data with third-party advertising partners for targeted ads per policy v2.4); -7 policy-vagueness (post-deletion retention = "commercially reasonable time for backup, archival, and/or audit"); -5 forced-arbitration (JAMS). NOT deducted: sells-data (policy explicitly refuses to rent/sell), no-opt-out and no-deletion-right (marketing opt-out + GDPR erasure both offered), indefinite-retention (30-day logs / 5-yr surveys are bounded), law-enforcement-loose (discloses only "in response to a lawful request"). No bonuses (cloud-only, no local-processing mode, no independent audit, no explicit data-minimization commitment). Source: Petcube Privacy Policy v2.4, eff. 2021-09-17 (verified directly). EVIDENCE 95 (start 100): device IS studied (independent research exists — not unstudied). -5 security-negligence (IOActive advisory dated April 2015, publicly released 2018: shared-SSH-key + rsync.sh command-execution flaw + shared TLS cert on the original device; -10 halved for >5-yr age). No confirmed data-sale, breach, regulatory action, or law-enforcement-pipeline incidents found (adversarial search of FTC/class-action/breach databases returned nothing on Petcube); Mozilla PNI reports no known incidents in the last 2 years and that the line meets minimum security standards (measurement-clean, applied as no further deduction rather than a bonus). Confidence medium: IOActive targeted the original Petcube Camera (2014); Mozilla's review covers the current Play 2/Bites 2 line; the brand-wide policy specifics were independently verified against Petcube Privacy Policy v2.4.

What it is

Manufacturer
Petcube
Category
Camera / Doorbell
Model years
2014–present
Market status
Current
Companion app
Petcube app (iOS/Android)

The evidence 3

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Security research · IOActive · 2015-04

    Advisory dated April 10, 2015 (publicly released by IOActive May 2018). IOActive found the original Petcube Camera distributes two SSH private keys ('logger'/'updater') shared by all Petcube users, with no isolation between users; a server-side rsync.sh script (the logger/updater shell) provides no effective security and can be overwritten to achieve command execution; a TLS certificate is also shared across all devices. Rated as compromising user security and privacy.

    Why it matters here: Supports the -5 security-negligence deduction on the evidence axis (historical flaw in the original device, halved for >5-yr age; remediated, no known exploitation).

  2. Primary policy · Petcube · 2021-09-17

    Effective 2021-09-17. States 'We will not rent or sell your information to third parties outside Petcube, except as noted in this Policy'; grants marketing opt-out and GDPR right to erasure. However shares cookie data with third-party advertising partners for targeted ads, records/stores audio-video, collects geotags/city-level location, retains post-deletion data for a 'commercially reasonable time for backup, archival, and/or audit,' and provides JAMS arbitration.

    Why it matters here: Primary source for the policy-axis deductions (sensitive-collection, broker-disclosure, policy-vagueness, forced-arbitration) and for the non-deductions (no sale, opt-out, erasure). Verified directly against the live policy.

  3. Privacy review · Mozilla Foundation · 2023

    Independent review: shares only aggregated/de-identified data (Mozilla: 'This doesn't worry us much at all'), records audio/video, location tracked only in the app (device: no), users can request deletion; meets Minimum Security Standards (encryption in transit and at rest, strong passwords, security updates, vulnerability management) with 'No known incidents in the last 2 years.'

    Why it matters here: Independent, relatively clean assessment supporting the high (studied) evidence score and confirming recent absence of incidents; note it covers the current Play 2/Bites 2 line.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database