Router privacy index 2026: industry-wide transparency failures exposed

Wi-Fi routers serve as the central gateway for every connected device in a modern household – from smartphones and laptops to smart TVs and security cameras. Yet Cybernews’ analysis of 25 leading consumer router brands for the US reveals a widespread privacy transparency failure: a severe lack of product-specific privacy policies. As seen throughout our study, in some cases, consumers have little to no opportunity to find a relevant policy before actually purchasing and setting up the device.
Because these blanket policies fail to clarify what the router hardware actually collects, not a single analyzed manufacturer explicitly states whether they track users' web browsing destinations. This creates legal ambiguity, which leaves critical telemetry, device fingerprinting, and traffic inspection practices largely unaddressed. And when a policy is silent, the resulting ambiguity can shift privacy risk onto the consumer.
- Pre-purchase transparency is blocked. Instead of standalone router policies, vendors often rely on broad corporate umbrellas. Because relevant privacy terms are often completely inaccessible until after purchasing, registering, or setting up the device, consumers cannot make informed privacy decisions before the purchase.
- Catch-all policy increases legal ambiguity. High-risk-scoring brands like D-Link (56pts), Omada (55pts), and Wyze (52pts) performed poorly largely due to overly vague, corporate-wide policies that create maximum legal ambiguity around network monitoring.
- Universal DNS opacity. All 25 analyzed vendors (100%) received a Not Specified rating for DNS request logging, failing to confirm or deny whether they record the domain names users visit. Given that DNS is one of the most revealing signals a router can log (it's basically a timestamped list of every site a user visits), providers seem rather too ambiguous about it.
- PII is more explicitly tracked. Brands are far more transparent about capturing user identity than network data. 84% explicitly collect email addresses, 84% capture account names, and 48% confirm collecting all four primary Personally Identifiable Information (PII) fields (name, email, phone, address).
- Pervasive geolocation exposure. Zero analyzed brands explicitly rule out tracking precise device location (7 confirm doing so outright, 6 do it conditionally, while 12 fail to specify), and 92% (23 of 25) either partially confirm or fail to disclose whether they harvest nearby Wi-Fi network identifiers (SSIDs/BSSIDs). Ultimately, this opens the door to highly invasive physical location tracking.
- Low-risk outliers result from stricter data handling practices. Asus (34pts), MSI Radix (38pts), and Google Nest (39pts) achieved the lowest risk scores by maintaining clearer hardware boundaries or making explicit non-collection disclosures.
Previous studies
The issue of router privacy has been examined from both policy and technical perspectives for years. Recently, Cybernews reported on Comcast’s Xfinity gateways and their use of Wi-Fi signals for in-home motion detection, while 2024 academic research by Junjian Ye et al. has identified ongoing security weaknesses in widely used consumer devices.
CNET also tackled the issue from a privacy-policy angle, reviewing over 30,000 words of documentation from seven major manufacturers to examine how they handle browsing data, personal information, and user controls. The conclusion highlighted a broader problem: even after digging through lengthy privacy policies, it’s incredibly difficult to understand what data a router or its related services actually collect. The disclosures are often vague, overly broad, or written to cover an entire company rather than specific networking products.
Motivated by these studies, we decided to investigate the topic independently, aligning our focus with prior industry research to conduct a comprehensive policy-disclosure analysis of 25 leading consumer router brands in the US.
Research approach
To evaluate the privacy transparency of the consumer networking market, Cybernews researchers initially identified 44 US router manufacturers. After screening for publicly available, more router-specific privacy documentation, 25 providers were selected for in-depth policy evaluation. Our analysis mapped disclosures across six critical privacy categories: browsing and web traffic, Personally Identifiable Information (PII), device inventory and mapping, location and spatial data, hardware fingerprinting, and security and smart telemetry.
Across 22 specific data points, each provider was assigned a cumulative score ranging from 0 to 66 based on policy explicitness. Data points were scored on a 0-to-3 scale: Yes (3) when the policy confirms collection (maximum exposure), Not Specified (2) when the policy is silent or vague, which is treated as a transparency failure rather than a neutral value, Partial (1) when collection is conditional or limited in scope, and No (0) when the policy explicitly states the data isn't collected or the feature is off by default.
To easily distinguish providers, these cumulative scores were then grouped into three relative-risk bands: High Risk, Medium Risk, and Low Risk.
This index serves as a policy-disclosure analysis, not a technical audit of actual router behavior. It evaluates what providers publicly disclose in their privacy policies about data collection, retention, sharing, and related practices within the router ecosystem. It doesn’t directly test firmware, inspect network traffic, reverse-engineer mobile apps, monitor backend telemetry, or verify whether real-world data-handling practices fully align with published policy language.
Router privacy index: brand rankings
The table below outlines the overall privacy risk scores and risk tiers for all 25 providers analyzed.
| Provider | Score (from highest to lowest) | Risk level |
| D-Link | 56 | High Risk |
| Omada (TP-Link) | 55 | High Risk |
| Amazon Eero | 53 | High Risk |
| Wyze | 52 | High Risk |
| Xiaomi Mesh | 52 | High Risk |
| Cudy | 52 | High Risk |
| TP-Link | 51 | High Risk |
| Netgear | 51 | High Risk |
| Ubiquiti Cloud | 51 | High Risk |
| Reyee (Ruijie) | 50 | High Risk |
| EnGenius | 50 | High Risk |
| Synology | 49 | Medium Risk |
| Mercusys | 49 | Medium Risk |
| Huawei | 49 | Medium Risk |
| Tenda | 49 | Medium Risk |
| Firewalla | 48 | Medium Risk |
| Zyxel | 47 | Medium Risk |
| AT&T Turbo Hotspot | 43 | Medium Risk |
| Linksys | 42 | Medium Risk |
| DrayTek Vigor | 41 | Low Risk |
| Actiontec | 40 | Low Risk |
| GL.iNet | 40 | Low Risk |
| Google Nest (Wifi) | 39 | Low Risk |
| MSI Radix | 38 | Low Risk |
| ASUS | 34 | Low Risk |
For the complete coded dataset, follow this link.
D-Link tops the list as the most vulnerable router vendor with a high-risk score of 56, followed closely by major consumer and enterprise brands like Amazon Eero, TP-Link, Netgear, and Ubiquiti Cloud, all of which sit in the 50-55 score range. The medium-risk category spans scores from 42 to 49 and includes Synology, Huawei, and Linksys. Conversely, ASUS proved to be the lowest-risk router, earning the overall score of 34 to anchor a low-risk group that also features Google Nest, GL.iNet, and DrayTek Vigor.
An important insight from this research is that a lower risk score doesn’t automatically prove a router collects less data in practice, nor does a high score guarantee malicious intent. Here’s how it plays out in practice:
- Transparency penalty. A manufacturer that writes a highly detailed, scrupulously transparent privacy policy may explicitly list numerous technical data points it processes for diagnostics or network security. As a result of declaring these data types, it earns a higher score under our risk-exposure framework.
- Possible ambiguity advantage. Conversely, a vendor that publishes a brief, 500-word policy that omits technical terminology may receive fewer Yes flags, even if its backend firmware telemetry gathers identical network information.
Main industry-wide privacy trends identified
Looking beyond the individual brand rankings, an overall analysis of the 25 privacy policies shows a clear lack of transparency across the consumer networking market. The industry is not simply divided between “privacy-friendly” and “malicious” companies. Instead, many router manufacturers are clear about collecting personal information for required cloud accounts, but are much less specific about how they handle sensitive data, such as network traffic, location information, and local device activity.
Reviewing the disclosures across all vendors reveals several common patterns, showing how vague privacy policies can create loopholes and leave households exposed to forms of data collection they may not fully understand.
1. Catch-all policy problem
The single largest factor driving higher risk scores among top-tier brands is legal ambiguity rather than proven technical surveillance. Many vendors don’t publish a dedicated, standalone privacy policy for their networking hardware, and in some cases, potentially relevant policies are difficult or impossible to locate publicly without owning, registering, or setting up the device. Instead, they apply a broad corporate policy that simultaneously covers their online store, mobile applications, cloud ecosystems, and smart home hardware (such as cameras or smart plugs).
Because these blanket documents state that the company may collect precise location data, browsing interactions, or audio/video telemetry for certain ecosystem services but fail to exclude router hardware from these practices, some routers accumulated multiple Not Specified or Yes ratings in our study. For example, Synology (49pts) and Wyze (52pts) treat router devices under the same privacy umbrella as their mobile software and other cloud-based services.
This makes it difficult for buyers to make informed decisions based on a vendor’s documentation alone, undermining the purpose of transparency. Modern routers can technically support the collection of highly sensitive information, yet broad (and hard to find) privacy policies often fail to clarify which of these capabilities are actually used, under what conditions, and for which products.
This ambiguity also complicates privacy evaluation. In this research, sensitive data practices couldn’t be assumed to be inapplicable to a router when the governing policy left that possibility open. As a result, a high privacy-risk score may reflect either extensive data collection in practice or insufficiently specific disclosure about how the hardware’s capabilities are used.
More broadly, consumers face the same problem: they may be unable to distinguish between genuinely extensive data collection and a lack of clear, product-specific disclosure.
2. DNS blind spot
Across the entire dataset, 25 out of 25 providers were rated Not Specified for DNS request logging. None explicitly stated that it doesn’t log DNS requests, and none clearly disclosed how long such records would be retained if collected.
DNS (Domain Name System) functions like an address book for the internet, translating text domain names, such as example.com, into IP addresses that devices can use. Depending on the network configuration, a router may act as a DNS proxy or forwarder, relaying these requests to an upstream DNS resolver. DNS queries can reveal which domains household devices look up and when, depending on where and how the queries are observed, while deep packet inspection (DPI) may expose additional information about network traffic.
Although DNS data doesn’t necessarily identify specific pages viewed or prove that a person intentionally visited a site, a detailed history can still reveal sensitive patterns. For example, repeated connections to health portals, financial services, religious organizations, or political websites may support inferences about medical concerns, finances, beliefs, or affiliations. In some circumstances, traffic patterns may also indicate household routines, such as approximate waking, working, and sleeping hours.
The lack of disclosure about DNS handling in routers’ privacy policies creates significant privacy concerns, particularly when a provider also collects Personally Identifying Information, such as a customer’s name, email address, or home address. If DNS activity were collected and linked to that information, it could enable the creation of a detailed, identifiable profile of household behavior. While users can often change their upstream DNS provider, the router’s firmware still processes these requests and may be capable of logging them before forwarding.
The reviewed policies largely fail to clarify whether DNS data is collected for telemetry, whether it remains stored locally on the device, or whether logging is conditionally activated by features such as parental controls or security filters. However, a Not Specified rating should not be interpreted as evidence that such logging actually occurs – it indicates that the reviewed policies do not clearly address the practice.
| DNS request logging disclosures across 25 brands | |
| Not Specified | 100% (25/25) |
| Confirmed No | 0% |
3. Identity vs telemetry: transparency divide
Router vendors are remarkably clear about collecting personal account details, but opaque about what their hardware captures on the local network.
Because some modern consumer routers heavily promote cloud management and/or smartphone app onboarding, creating a centralized account has become standard practice. Identity details are typically required to create logins for these remote apps. While local router management may not require this personal data, it’s rarely clear whether a remote account is strictly mandatory or if local management options exist. This critical information is usually inaccessible before purchase.
As a result, 48% (12 out of 25) of providers we analyzed explicitly confirm collection across all four PII data points: user email, account name, phone number, and mailing address. Often, this data is collected when customers create a cloud app account, support services, or a similar profile. The breakdown below shows how many vendors confirm collecting each data point individually.
In Network Traffic Content Analysis (deep packet inspection), 20 out of 25 providers (80%) failed to specify whether their routers perform DPI on local traffic. Only 2 providers (Google Nest and Ubiquiti Cloud) explicitly state No. 3 vendors (Amazon Eero, MSI Radix, and AT&T Turbo Hotspot) collect data conditionally, depending on user configurations.
To understand why this lack of transparency is concerning, it’s necessary to examine how these two distinct categories of data can interact.
- Personally Identifiable Information (identity) establishes who the user is. It may include information provided during account or router-app registration, such as a name, email address, phone number, or physical location.
- Deep packet inspection and related network-monitoring techniques (telemetry) provide information about what the user or their devices do on the network. Depending on the implementation and whether traffic is encrypted, this may include identifying applications and services, classifying traffic, observing device activity, analyzing connection patterns, and inspecting the contents of unencrypted communications.
Individually, these categories reveal different things, but their significance increases when they are linked. PII can associate a real person or household with an account, while telemetry can produce a detailed record of activity associated with that account or network. Combining them can transform network observations into an identifiable behavioral profile. For example, connecting a named account holder with the applications used, devices present in the home, patterns of network activity, or services accessed.
This creates what can be called the "transparency divide": vendors openly admit to collecting the identity data required to build a user profile, but 81% don’t clearly state whether their hardware is actively monitoring local network traffic to fill that profile in the cloud with highly personal behavioral data.
4. Geolocation tracking
While DNS queries reveal significant information about a user's digital life, other router-related data, such as nearby Wi-Fi SSIDs/BSSIDs and precise device location information, can pinpoint the user's physical movements with high accuracy. The reviewed policies varied substantially in how clearly vendors addressed these data categories.
- Nearby Wi-Fi SSIDs/BSSIDs. We classified 19 providers as Not Specified, 4 as Partial (Xiaomi Mesh, ASUS, Cudy, and Omada), and 2 as Yes (D-Link and Amazon Eero). Zero providers were classified as No.
- Precise location (device). We classified 7 providers as Yes (Wyze, AT&T Turbo Hotspot, D-Link, Huawei, Omada, Google Nest, and Ubiquiti Cloud), identified 6 that collect this data conditionally, with collection limited in scope or dependent on specific user configurations (Synology, Xiaomi Mesh, Reyee, TP-Link, ASUS, Linksys). Another 12 providers were classified as Not Specified, and none were classified as No.
These findings indicate that disclosure of location-related data collection was limited and inconsistent across providers.
This is notable because routers and related devices are not always stationary: travel routers, mobile hotspots, mesh devices, and portable satellite terminals may move with their users. Where such devices persist in these databases, repeated observations can reveal movement over time rather than a single fixed location. Wi-Fi access points also broadcast identifiers such as BSSIDs, which can be associated with geographic locations through Wi-Fi positioning databases. When BSSIDs, nearby Wi-Fi network information, or device-location data are combined with such databases, they may support relatively precise location estimation.
In practice, many users are unlikely to be familiar with these technical mechanisms and may therefore be unaware that data generated by their router or related network devices could be used to infer or track their geographic location.
Privacy tips
To protect personal information and maintain strict control over network privacy, it’s useful to keep some of these practices in mind when selecting and configuring network equipment:
- Prefer routers that support local management and don’t require continuous cloud connectivity or a vendor account for core functions.
- Check if the manufacturer has a privacy policy specifically written for its routers before you purchase. Avoid brands that force you to agree to a catch-all smart-home or eCommerce policy, as these can legally permit much broader data harvesting.
- Disable unnecessary remote or cloud-based features, such as telemetry, remote administration, configuration backups, and unused integrations. Review optional security, filtering, and parental-control services carefully, as some may transmit DNS queries, URLs, device information, or other network metadata to the router vendor or third-party providers. Keep essential security features and automatic firmware updates enabled.
- Don’t treat a VPN as a substitute for choosing a privacy-respecting router. A VPN can reduce what a router – and, by extension, any manufacturer cloud service receiving traffic-related telemetry from it – can infer about browsing destinations by encrypting traffic before it reaches the router. However, it doesn’t prevent the router from collecting local information, such as connected-device details, session timing and data volumes, or configuration and diagnostic logs. Also, the router still sees the IP address of the VPN server users connect to, even if it cannot see past it.
- Consider using encrypted DNS on both your portable devices and your home router. Set up encrypted DNS (such as DNS over HTTPS (DoH) or DNS over TLS (DoT) directly on phones and laptops to protect your data on networks you don't control, such as public Wi-Fi. For your home network, change your router's DNS settings to use your preferred privacy-focused DNS provider – many routers now support encrypted DNS natively. This simplifies your overall setup and ensures that devices lacking built-in encrypted DNS support – like smart TVs, gaming consoles, and IoT gadgets – are automatically protected.
- Periodically review the router's connected-device list, administrator accounts, DNS configuration, remote-access settings, and enabled services. Firmware updates or configuration changes can sometimes introduce or re-enable features that affect privacy.
- Check if the router or hotspot manufacturer offers a firmware update that enables BSSID Randomization. This feature periodically changes the router's hardware identifier so it cannot be permanently tracked by Apple, Google, or the manufacturer.
- Manually opt your router out of global Wi-Fi location databases. For example, to opt out of Google's and Apple’s, append _nomap to the end of the Wi-Fi network name (e.g., change MyWiFi to MyWiFi_nomap), but note that other companies may use different opt-out methods. These are voluntary conventions with no technical enforcement: providers that do not honor them may continue to collect or use Wi-Fi location data, and the handling of previously collected records varies by provider.
Bottom line: why this study matters
Our router privacy index highlights a widespread transparency gap in the consumer market. In some cases, router-specific privacy policies are difficult to locate, and it’s not always clear whether the policy we found is the only one that applies or whether additional policies govern the router or related services.
None of the 25 brands we analyzed clearly disclose whether they log DNS requests, and most rely on broad privacy policies that blur the distinction between hardware and app data. Only 6 out of 25 brands (24%) scored as low-risk, and even these scores do not indicate strong privacy protections. They simply reflect fewer red flags based on the documentation available.
Because the baseline level of disclosure is so low, consumers cannot rely on vendor policies alone to understand how their network data is handled. The practical response we recommend is to treat every router as potentially logging more data than its vendor explicitly discloses and to approach setup, updates, and account choices with that possibility in mind.
Detailed methodology and reference framework
Our initial search identified 44 US router vendors. However, 19 providers were excluded from the final scoring index due to a lack of distinguishable product disclosures suitable for standardized evaluation.
- Providers analyzed (25): Wyze, AT&T Turbo Hotspot, Synology, Xiaomi Mesh, Mercusys, Reyee (Ruijie), Firewalla, D-Link, DrayTek Vigor, Zyxel, EnGenius, Actiontec, Huawei, TP-Link, Amazon Eero, Asus, Netgear, GL.iNet, Tenda, MSI Radix, Cudy, Omada (TP-Link), Google Nest (Wifi), Linksys, Ubiquiti.
- Excluded/screened vendors (19): GL.iNet (sub-entities), U-speed, UeeVii, DBIT, ZBT, MikroTik, Olax, Motorola, Ryoko Pro, WilFlyer, UOTEK, KuWfi, RoamWifi, TravlFi, JourneyGo, Starlink, Peplink, Cisco Meraki, Netis.
The analysis mapped disclosures across 6 critical privacy categories encompassing 22 specific data points:
| Category | Why it matters | Data points tracked |
| Browsing and web traffic | Directly exposes personal habits | DNS requests, browsing/website interaction data, and network traffic content analysis (DPI) |
| Personally Identifiable Information (PII) | Turns anonymous technical logs into a fully identified profile | Account name, user email address, phone number, and mailing/postal address |
| Device inventory and mapping | Reveals household members, tracks presence, flags device security risks | Connected device MAC addresses, hostnames/device names, OS types, and local IP addresses |
| Location and spatial data | Reveals precise physical location, tracks address changes | Precise device location, nearby Wi-Fi SSIDs/BSSIDs, IP geolocation |
| Hardware fingerprinting | Establishes a persistent signature to track a device across networks/ISPs | Router MAC address, serial number, public/WAN IP address, local/LAN IP address, firmware build |
| Security and smart telemetry | Reveals daily routines, smart-home patterns, and content-filtering history | Threat/filter logs, smart assistant states, network performance/diagnostic data |
How we calculated scores
Each data point was evaluated based on policy explicitness and assigned a numeric exposure/risk score.
| Rating | Score | Rationale |
| Yes | 3 | Policy confirms collection (maximum exposure) |
| Not Specified | 2 | Policy is silent or vague – treated as a transparency failure, not a neutral/missing value, since the user has no way to know what happens to their data |
| Partial | 1 | Collection is conditional, feature-dependent, or limited in scope |
| No | 0 | Policy explicitly states the data isn't collected, or the feature is off by default |
Not Specified is assigned 2 points because this index measures both disclosed data collection and policy transparency. When a privacy policy is silent, vague, or does not clearly distinguish router-specific practices from broader company-wide data handling, a consumer cannot reliably determine whether that data type is collected, under what conditions it is collected, or whether it is limited to optional features. The study, therefore, treats Not Specified as a meaningful transparency failure: less severe than an explicit Yes, but more concerning than a clearly stated No or a limited Partial disclosure.
Cumulative scores range from 0 (minimum disclosed exposure) to 66 (maximum exposure/ambiguity). For easier discussion and comparative distinction, the scores were then divided into relative risk bands: High Risk (50+), Medium Risk (42-49), and Low Risk (≤41).
Note that these cutoffs are intended to distinguish lower-, mid-, and higher-scoring providers within this sample, not to imply that a Low Risk provider is risk-free or that the thresholds would automatically apply to other router datasets.
Research disclaimers and study limitations
- Point-in-time scope. All policy evaluations represent a snapshot of publicly available terms at the time of the review in August 2026. Corporate privacy policies are living documents subject to revision without prior notice.
- Configuration and optional features. The scope of data collection depends heavily on how a router is used. A device managed strictly through an offline local web interface operates under a vastly different data-handling scope than one that uses a vendor cloud account, mobile app, or optional add-ons (e.g., parental controls or security subscriptions).
- Local vs cloud configuration. A router managed strictly through an offline local web interface (192.168.1.1) may operate under a vastly different data-handling scope than the same router linked to a vendor cloud account, remote management app, or security subscription.
- In-app and setup disclosures. Vendors may present additional terms, end-user license agreements (EULAs), or privacy toggles during initial router configuration that are not reflected in this study.
- Policy vs technical execution. This study evaluates published legal statements, claims, and disclosures. It doesn’t perform packet-capture inspection, reverse-engineer firmware binaries, or verify server-side telemetry destinations.
- Generic vs hardware-specific policies. Some scores in this index are elevated due to legal ambiguity rather than malicious data collection. Several providers don’t offer a dedicated privacy policy for their networking hardware. Instead, they use a single overarching privacy policy that covers their eCommerce store, mobile apps, and all smart devices combined.
- Open source firmware element. Some of the providers use fully or partially open-source firmware, which may have a positive impact on privacy and security by increasing transparency and allowing independent scrutiny of the software. However, the extent to which this affects privacy depends on factors such as how much of the firmware is open source and whether proprietary components or cloud services are involved. These aspects were not evaluated as part of this study.