← IoT Privacy Database

SwitchBot Hub

SwitchBot · Smart Plug / Light

✓ Reviewed

1.5Surveillance
Index
Policy — what its policy permitsA
Evidence — what research provesB

Cloud bridge/IR-blaster (Hub Mini/Hub 2/Hub Plus) that links SwitchBot sensors, cameras, and locks to the internet and voice assistants; the Hub hardware itself has no onboard camera, microphone, or GPS, but its purpose is to route ecosystem device data through SwitchBot's cloud. Requires a SwitchBot account and internet for remote/cloud features. Vendor (Wonderlabs) is Shenzhen-based. The published privacy policy (updated 2025-12-05) states data is not sold, keeps fingerprint/facial data on-device, uses geofencing rather than storing precise location, grants access/update/delete rights, and commits to data minimization, but is vague on retention and uses a discretionary law-enforcement disclosure standard under a PRC jurisdiction. No deep independent privacy audit of the Hub exists; two confirmed CVEs affect the required companion app (one critical, CVSS 3.1 9.1; one medium, CVSS 5.9).

Why this rating

POLICY 92 = 100 -7 policy-vagueness (no comprehensive retention timeline, only e.g. "30 days" for operation logs, and broad reserved use to "improve our products, add new features... determine what new features to prioritize") -5 law-enforcement-loose (discloses "if we believe the disclosure is consistent with the requirements of any applicable law or legal process", a discretionary standard, compounded by PRC jurisdiction) +4 data-minimization-commitment ("we undertake to follow the principle of data minimization"). No no-deletion-right deduction: the cited policy grants users the right to "access, update, delete and protect this information." No deduction for sells-data ("We do not sell your personal information"), sensitive-collection (Hub has no onboard camera/mic/GPS; fingerprint/facial data stored on-device only; location via geofence, not stored), broker-disclosure (shares with service vendors/Google Analytics, not data brokers), or no-opt-out (opt-out/withdraw-consent present). No local-processing bonus applied because the Hub's core function is cloud bridging. Grade A on the policy axis reflects the written commitments; the evidence axis is the real-world check. EVIDENCE 80 = 100 -10 security-negligence (CVE-2024-48786, CVSS 3.1 base 9.1 CRITICAL per CISA-ADP, CWE-863 incorrect authorization, remote sensitive-info disclosure via the firmware-update process, app v5.0.4) -10 security-negligence (CVE-2025-53649, CVSS 4.0 5.9 / CVSS 3.1 5.1 MEDIUM, CWE-532 insertion of sensitive info into log files, app V6.24-V9.12, fixed in V9.13). The methodology deducts a flat -10 per security-negligence incident regardless of CVSS tier. Both CVEs are independent third-party findings (GitHub Advisory Database / JPCERT-CC JVN), so the device is NOT unstudied and an evidence score above 60 is permitted; but there is no Hub-specific privacy research and no independent positive audit to add a bonus. No confirmed data sale, major breach, regulatory action, or class action found - confidence medium.

What it is

Manufacturer
SwitchBot
Category
Smart Plug / Light
Model years
2020-present (Hub Mini, Hub 2, Hub Plus)
Market status
Current
Companion app
SwitchBot

The evidence 3

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Vendor policy · SwitchBot / Wonderlabs, Inc. · 2025-12-05

    Vendor policy: does not sell personal information ("We do not sell your personal information") and commits to data minimization; keeps fingerprint/facial data on-device and uses geofencing instead of storing precise location; grants users the right to access, update and delete their information; but retention is vague (only a 30-day operation-logs example) and law-enforcement disclosure is discretionary ("if we believe the disclosure is consistent with the requirements of any applicable law or legal process").

    Why it matters here: Primary source for the policy-axis deductions (retention vagueness, law-enforcement-loose) and the data-minimization bonus; its explicit delete right is why no no-deletion-right deduction is taken.

  2. Cve · NIST NVD / GitHub Advisory Database (GHSA-5h9p-4mfg-hmh4) · 2024-10-11

    SwitchBot app (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware-update process (CWE-863 incorrect authorization; CVSS 3.1 base 9.1 CRITICAL per CISA-ADP - the vendor firmware server lacks proper access control). Affects Hub users, who provision and update firmware through this app.

    Why it matters here: Confirmed security-negligence incident in the required companion app used to provision and update the Hub; critical CVSS.

  3. Cve · NIST NVD / JPCERT-CC (JVN#59585716) · 2025-07-29

    SwitchBot app for iOS/Android V6.24-V9.12 inserts sensitive user information into log files (CWE-532; CVSS 4.0 5.9 / CVSS 3.1 5.1 MEDIUM), exposing it to an attacker with access to application logs; fixed in V9.13.

    Why it matters here: Second confirmed security-negligence incident in the app that controls the Hub; supports evidence-axis deduction.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database