ADVERTISEMENT

Router privacy index 2026: industry-wide transparency failures exposed

router privacy index report
Cybernews research team
September 21, 2026 Updated: 29 minutes ago 15 min read
Key takeaways:

Previous studies

Research approach

Disclaimer

This index serves as a policy-disclosure analysis, not a technical audit of actual router behavior. It evaluates what providers publicly disclose in their privacy policies about data collection, retention, sharing, and related practices within the router ecosystem. It doesn’t directly test firmware, inspect network traffic, reverse-engineer mobile apps, monitor backend telemetry, or verify whether real-world data-handling practices fully align with published policy language.

Router privacy index: brand rankings

ProviderScore (from highest to lowest)Risk level
D-Link56High Risk
Omada (TP-Link)55High Risk
Amazon Eero53High Risk
Wyze52High Risk
Xiaomi Mesh52High Risk
Cudy52High Risk
TP-Link51High Risk
Netgear51High Risk
Ubiquiti Cloud51High Risk
Reyee (Ruijie)50High Risk
EnGenius50High Risk
Synology49Medium Risk
Mercusys49Medium Risk
Huawei49Medium Risk
Tenda49Medium Risk
Firewalla48Medium Risk
Zyxel47Medium Risk
AT&T Turbo Hotspot43Medium Risk
Linksys42Medium Risk
DrayTek Vigor41Low Risk
Actiontec40Low Risk
GL.iNet40Low Risk
Google Nest (Wifi)39Low Risk
MSI Radix38Low Risk
ASUS34Low Risk
  • Transparency penalty. A manufacturer that writes a highly detailed, scrupulously transparent privacy policy may explicitly list numerous technical data points it processes for diagnostics or network security. As a result of declaring these data types, it earns a higher score under our risk-exposure framework.
  • Possible ambiguity advantage. Conversely, a vendor that publishes a brief, 500-word policy that omits technical terminology may receive fewer Yes flags, even if its backend firmware telemetry gathers identical network information.

1. Catch-all policy problem

2. DNS blind spot

DNS request logging disclosures across 25 brands
Not Specified100% (25/25)
Confirmed No0%

3. Identity vs telemetry: transparency divide

ADVERTISEMENT
router privacy index pii chart
Personally Identifiable Information (PII) data points collected through vendor accounts and services
router privacy index dpi analysis chart
Breakdown of deep packet inspection (DPI) disclosures across 25 analyzed router brands
  • Personally Identifiable Information (identity) establishes who the user is. It may include information provided during account or router-app registration, such as a name, email address, phone number, or physical location.
  • Deep packet inspection and related network-monitoring techniques (telemetry) provide information about what the user or their devices do on the network. Depending on the implementation and whether traffic is encrypted, this may include identifying applications and services, classifying traffic, observing device activity, analyzing connection patterns, and inspecting the contents of unencrypted communications.

4. Geolocation tracking

  • Nearby Wi-Fi SSIDs/BSSIDs. We classified 19 providers as Not Specified, 4 as Partial (Xiaomi Mesh, ASUS, Cudy, and Omada), and 2 as Yes (D-Link and Amazon Eero). Zero providers were classified as No.
router privacy report wi fi chart
Disclosure breakdown for nearby Wi-Fi network identifiers (SSIDs/BSSIDs)
  • Precise location (device). We classified 7 providers as Yes (Wyze, AT&T Turbo Hotspot, D-Link, Huawei, Omada, Google Nest, and Ubiquiti Cloud), identified 6 that collect this data conditionally, with collection limited in scope or dependent on specific user configurations (Synology, Xiaomi Mesh, Reyee, TP-Link, ASUS, Linksys). Another 12 providers were classified as Not Specified, and none were classified as No.
router privacy index precise location
Disclosure breakdown for precise device location tracking

Privacy tips

  • Prefer routers that support local management and don’t require continuous cloud connectivity or a vendor account for core functions.
  • Check if the manufacturer has a privacy policy specifically written for its routers before you purchase. Avoid brands that force you to agree to a catch-all smart-home or eCommerce policy, as these can legally permit much broader data harvesting.
  • Disable unnecessary remote or cloud-based features, such as telemetry, remote administration, configuration backups, and unused integrations. Review optional security, filtering, and parental-control services carefully, as some may transmit DNS queries, URLs, device information, or other network metadata to the router vendor or third-party providers. Keep essential security features and automatic firmware updates enabled.
  • Don’t treat a VPN as a substitute for choosing a privacy-respecting router. A VPN can reduce what a router – and, by extension, any manufacturer cloud service receiving traffic-related telemetry from it – can infer about browsing destinations by encrypting traffic before it reaches the router. However, it doesn’t prevent the router from collecting local information, such as connected-device details, session timing and data volumes, or configuration and diagnostic logs. Also, the router still sees the IP address of the VPN server users connect to, even if it cannot see past it.
  • Consider using encrypted DNS on both your portable devices and your home router. Set up encrypted DNS (such as DNS over HTTPS (DoH) or DNS over TLS (DoT) directly on phones and laptops to protect your data on networks you don't control, such as public Wi-Fi. For your home network, change your router's DNS settings to use your preferred privacy-focused DNS provider – many routers now support encrypted DNS natively. This simplifies your overall setup and ensures that devices lacking built-in encrypted DNS support – like smart TVs, gaming consoles, and IoT gadgets – are automatically protected.
  • Periodically review the router's connected-device list, administrator accounts, DNS configuration, remote-access settings, and enabled services. Firmware updates or configuration changes can sometimes introduce or re-enable features that affect privacy.
  • Check if the router or hotspot manufacturer offers a firmware update that enables BSSID Randomization. This feature periodically changes the router's hardware identifier so it cannot be permanently tracked by Apple, Google, or the manufacturer.
  • Manually opt your router out of global Wi-Fi location databases. For example, to opt out of Google's and Apple’s, append _nomap to the end of the Wi-Fi network name (e.g., change MyWiFi to MyWiFi_nomap), but note that other companies may use different opt-out methods. These are voluntary conventions with no technical enforcement: providers that do not honor them may continue to collect or use Wi-Fi location data, and the handling of previously collected records varies by provider.

Bottom line: why this study matters

Detailed methodology and reference framework

  • Providers analyzed (25): Wyze, AT&T Turbo Hotspot, Synology, Xiaomi Mesh, Mercusys, Reyee (Ruijie), Firewalla, D-Link, DrayTek Vigor, Zyxel, EnGenius, Actiontec, Huawei, TP-Link, Amazon Eero, Asus, Netgear, GL.iNet, Tenda, MSI Radix, Cudy, Omada (TP-Link), Google Nest (Wifi), Linksys, Ubiquiti.
  • Excluded/screened vendors (19): GL.iNet (sub-entities), U-speed, UeeVii, DBIT, ZBT, MikroTik, Olax, Motorola, Ryoko Pro, WilFlyer, UOTEK, KuWfi, RoamWifi, TravlFi, JourneyGo, Starlink, Peplink, Cisco Meraki, Netis.
CategoryWhy it mattersData points tracked
Browsing and web trafficDirectly exposes personal habitsDNS requests, browsing/website interaction data, and network traffic content analysis (DPI)
Personally Identifiable Information (PII)Turns anonymous technical logs into a fully identified profileAccount name, user email address, phone number, and mailing/postal address
Device inventory and mappingReveals household members, tracks presence, flags device security risksConnected device MAC addresses, hostnames/device names, OS types, and local IP addresses
Location and spatial dataReveals precise physical location, tracks address changesPrecise device location, nearby Wi-Fi SSIDs/BSSIDs, IP geolocation
Hardware fingerprintingEstablishes a persistent signature to track a device across networks/ISPsRouter MAC address, serial number, public/WAN IP address, local/LAN IP address, firmware build
Security and smart telemetryReveals daily routines, smart-home patterns, and content-filtering historyThreat/filter logs, smart assistant states, network performance/diagnostic data

How we calculated scores

RatingScoreRationale
Yes3Policy confirms collection (maximum exposure)
Not Specified2Policy is silent or vague – treated as a transparency failure, not a neutral/missing value, since the user has no way to know what happens to their data
Partial1Collection is conditional, feature-dependent, or limited in scope
No0Policy explicitly states the data isn't collected, or the feature is off by default

Research disclaimers and study limitations

  1. Point-in-time scope. All policy evaluations represent a snapshot of publicly available terms at the time of the review in August 2026. Corporate privacy policies are living documents subject to revision without prior notice.
  2. Configuration and optional features. The scope of data collection depends heavily on how a router is used. A device managed strictly through an offline local web interface operates under a vastly different data-handling scope than one that uses a vendor cloud account, mobile app, or optional add-ons (e.g., parental controls or security subscriptions).
  3. Local vs cloud configuration. A router managed strictly through an offline local web interface (192.168.1.1) may operate under a vastly different data-handling scope than the same router linked to a vendor cloud account, remote management app, or security subscription.
  4. In-app and setup disclosures. Vendors may present additional terms, end-user license agreements (EULAs), or privacy toggles during initial router configuration that are not reflected in this study.
  5. Policy vs technical execution. This study evaluates published legal statements, claims, and disclosures. It doesn’t perform packet-capture inspection, reverse-engineer firmware binaries, or verify server-side telemetry destinations.
  6. Generic vs hardware-specific policies. Some scores in this index are elevated due to legal ambiguity rather than malicious data collection. Several providers don’t offer a dedicated privacy policy for their networking hardware. Instead, they use a single overarching privacy policy that covers their eCommerce store, mobile apps, and all smart devices combined.
  7. Open source firmware element. Some of the providers use fully or partially open-source firmware, which may have a positive impact on privacy and security by increasing transparency and allowing independent scrutiny of the software. However, the extent to which this affects privacy depends on factors such as how much of the firmware is open source and whether proprietary components or cloud services are involved. These aspects were not evaluated as part of this study.
ADVERTISEMENT