Closeness Lab

Are Sex Toy Apps Safe? What the Record Shows

In March 2025 a security researcher reported two flaws to Lovense, one of the largest makers of app-connected sex toys. The first let anyone match a Lovense username to the email address behind it. The second let anyone holding that address take the account over without a password. TechCrunch verified the first one by opening a new account and asking the researcher to read its address back, which took about a minute (Whittaker, TechCrunch, 29 Jul 2025). The company asked for fourteen months to fix them.

Research-based, not hands-on (how we review) · No affiliate links on this page, and nothing below was shown to any manufacturer before publication · We may earn a commission on Lovense products through our app-controlled vibrator guide, and Lovense is the subject of the most serious case below (disclosure)

Quick take: three incidents in this product category, chosen because their causes differ rather than because they are the only ones. One was a company deciding to collect usage data, one was a bug in a company’s own systems, and one was an ordinary corporate email breach that had nothing to do with any device. Only one of the three involved a toy at all. They are not interchangeable, and neither are the things you can do about them. The single useful signal available to you before you buy is not whether a brand has had an incident, but what it did when someone told it.

Three incidents, three different causes

Coverage of this topic tends to gather every bad thing that has happened to a sex toy company into one pile labelled “smart toys are risky.” The pile is real. The lumping is the problem, because these three fail in structurally different ways, and the remedy for each sits with a different party. They are the ones with the clearest causal shape; if you want the wider list with dates and sources, we keep one at can sex toys be hacked.

What wentwrongCollection by designWe-Vibe · 2016A flaw in their systemsLovense · 2025An ordinary breachTenga · 2026Who canfix itThe courtsThe maker's engineering,and how it disclosesInternal security, sameas at any companyWhat you cancheck firstPrivacy policy, andwhether guest mode existsHow it treated theresearcher who told itNothing specificto the productCollection by designWe-Vibe · 2016Who can fix itThe courtsWhat you can checkPrivacy policy, whether guest mode existsA flaw in their systemsLovense · 2025Who can fix itThe maker's engineering, and how it disclosesWhat you can checkHow it treated the researcher who told itAn ordinary breachTenga · 2026Who can fix itInternal security, same as at any companyWhat you can checkNothing specific to the product
Three failures, three causes. The remedy sits with a different party each time and never with the buyer, which is why what you can check before buying differs case by case.

A company collecting on purpose. In September 2016 a Chicago woman identified in filings only as NP sued Standard Innovation, the Canadian maker of We-Vibe, in federal court in Illinois. Her complaint alleged the We-Connect app recorded which vibration settings were used and the dates and times of use, and, as the filing put it, “incredibly,” the email addresses of owners who had registered their devices, allowing the two to be linked and sent to servers in Canada (The Guardian, 14 Sep 2016). The following March the company settled for 3.75 million dollars without admitting wrongdoing, maintaining that users had “consented to the conduct alleged”; court documents put the number of Bluetooth We-Vibe buyers at roughly 300,000 (NPR, 14 Mar 2017). Nothing here was broken into. The design worked as built, and the dispute was over whether anyone had agreed to it.

A company’s own systems failing. The Lovense flaws above are a different animal. The researcher, who goes by BobDaHacker, reported them on 26 March 2025 through the Internet of Dongs project and received an award of 3,000 dollars through HackerOne. Lovense, which is said to have more than 20 million users, told them it had decided against a faster one-month fix because that would have required making customers update their apps, and asked for fourteen months instead. The researcher published after several weeks of disagreement about whether the bugs were fixed at all; three months is the usual grace period before disclosure. Cam models, who publish their usernames by profession, were the group most exposed by a bug that turned a username into a personal email address in under a second once scripted (Whittaker, TechCrunch, 29 Jul 2025). Nobody chose this behaviour. It was a defect, and defects are normal; what varies is the response.

A breach with nothing to do with toys. In February 2026 Tenga told customers that an unauthorised party had reached the work email account of one employee, exposing names, email addresses and past correspondence that “may include order details or customer service inquiries.” The company later said a forensic review put the number affected at roughly 600 people in the United States, and that it had since enabled multi-factor authentication across its systems, though it would not say whether that account had any in place beforehand (Franceschi-Bicchierai, TechCrunch, 19 Feb 2026). This is a business email compromise. It would have unfolded identically at a stationery wholesaler. The only thing that makes it feel worse is the inventory, and the inventory is precisely the part that had no technical role in it.

Some of it is sorted better than that. Kaspersky’s guide, the most recently updated of the ranking pages we read when we checked this search on 30 July 2026, gives “frequent data breaches” and “vulnerabilities within the service’s infrastructure” their own consecutive paragraphs, links out to the Tenga and Lovense stories without naming either company, and follows with eight mitigations that do map back onto its own risk list, the first being a dedicated email address to limit what a breach can expose (Kaspersky, 13 Apr 2026). Where it lands short is the filing: Tenga sits under breaches suffered by “developers of intimate apps”, and the Tenga breach reached an employee’s inbox rather than an app, a server or a device. A company incident with no technical connection to the product at all is a third category, and it is the one we did not find on any page we read.

What the fear gets wrong

Ask people what worries them about a connected toy and the answer is usually a stranger taking control of it. With one exception, the documented harm has not been a stranger seizing a device in your home. The exception is a chastity lock rather than a vibrator, and we set it out with the rest of the dated record in can sex toys be hacked. Everything else has sat at the account and identity layer: an email address matched to a public username, an account opened without a password, an order history sitting in a compromised inbox. Two of those three are exposures a researcher demonstrated rather than harms anyone has shown occurred, and Lovense’s position is that there is no evidence of either being used. Say that plainly, because it cuts both ways: the exposure is what a company controls, and it is what a company should be judged on.

Svakom sold a vibrator called the Siime Eye with a camera built into the tip, reached over Wi-Fi rather than paired over Bluetooth. Its default password for the camera stream was 88888888, printed in a manual anyone could find online, so any buyer who left the default in place had a feed that anyone within Wi-Fi range could open; the model has since been discontinued (WIRED, 14 Dec 2025). That is the fear made possible by a design decision, though we found no reported case of anyone’s feed actually being opened by a stranger. It is also a product whose camera and Wi-Fi connection are not the architecture of a Bluetooth vibrator paired to a phone, which is the whole of why it does not generalise.

That is not a reassurance, because the identity layer is where the damage in this category actually lives. An email address tied to a sex toy account is a lever for harassment, for outing someone, or for a convincing extortion message, and none of those require touching a device. It does change what protects you. Nothing about how you store the toy or which room you use it in touches this risk. What touches it is which email address you signed up with, whether that address is reused elsewhere, and whether the account exists at all.

That last one is the underrated option. If you already own a connected toy and mostly use it in the same room, the app is often optional; many models keep their physical controls whether or not a phone is paired. And if you are still choosing, the question of whether you need an app at all comes before every other question, which is why it leads our guide to choosing a couples toy. Bluetooth pairing in the same room and internet relay across a distance are different architectures with different exposure, a distinction we go through in the app-controlled vibrator guide.

The signal worth checking before you buy

A brand large enough to be worth researching will have a defect sooner or later. Treating “has this company had an incident?” as the screening question rewards the companies nobody has bothered to examine, which is the opposite of what you want. Lovense was found out partly because it is big enough for a researcher to aim at, and partly because a project dedicated to this product category exists to route such reports.

The assessable question is what happened next, and here the record separates sharply. Lovense fixed the flaws within days of the story running, told TechCrunch they were “fully resolved,” and its chief executive said the company was “investigating the possibility of legal action” over what it called erroneous reports, without clarifying whether it meant the press or the researcher. The company also said there was no evidence any user data had been compromised. TechCrunch noted it was unclear how Lovense could know that, having itself reproduced the email disclosure bug, and said the company did not answer when asked what logs it had to determine it (Whittaker, TechCrunch, 1 Aug 2025).

Set aside whether the fix was adequate, which nobody outside the company can judge. A vendor that floats legal action against disclosure is telling you something about the next report, from the next researcher, that it does not yet know about. That is a forward-looking signal, and it is available for free before you spend anything. Standard Innovation, for its part, settled and agreed to change its practices while admitting nothing, which is a weaker signal than an apology and a stronger one than a threat.

Two searches give you this. Put the brand name next to “vulnerability” or “disclosure” and read what the company said rather than what it did wrong, and check whether it runs a bug bounty or a security contact page at all. A company with no route for receiving bad news is a company that will receive it in public.

How to check an app yourself

Published research on this goes stale fast. The most quantified survey we found, Surfshark’s analysis of ten of the most-downloaded adult toy apps on Google Play, found they requested 22 permissions on average and six classed as dangerous, ranging from thirteen dangerous permissions for Lovense Remote down to two for NaughtyKit, with Lovense Remote requesting 53 permissions in total (Surfshark, 13 Feb 2024). That was February 2024 and carried no update stamp when we checked it. Treat the figures as a snapshot of a moment, and run the check yourself instead:

Two limits worth naming

A privacy policy describes intent, and no reader, us included, can confirm it matches what a server does. And an absence of reported incidents is not a clean record; it is frequently just an absence of researchers, which is why the response to disclosure carries more information than the disclosure count. If long-distance features are the reason you are considering an app in the first place, the trade is real and worth making deliberately, and we cover what those features actually buy in our long-distance intimacy guide.

FAQ

Can a smart sex toy be hacked and controlled by a stranger? It is the fear people name first, and it is not the shape of the documented cases. Those have been about accounts and identity: a flaw that let anyone match a Lovense username to its registered email address and then take the account over without a password, a lawsuit alleging We-Vibe’s app logged usage data and linked it to email addresses, and a breach of a Tenga employee’s inbox holding correspondence that, in the company’s words, may include order details. One discontinued product did fit the description: Svakom’s Siime Eye had a camera reachable over Wi-Fi behind a default password printed in its manual, a design quite unlike a Bluetooth vibrator paired to a phone. One case does fit it exactly: in January 2021 an attacker locked users of the Qiui Cellmate chastity device and demanded bitcoin to release it. That device is a lock with no manual release, which is why it is the exception rather than the pattern; the full dated list is in can sex toys be hacked. For a Bluetooth vibrator, remote seizure is possible in principle but is not where the record sits.

Which sex toy app is the most private? Nobody can answer that honestly from the outside, because what a company declares and what its servers do are different things. What you can compare is disclosed behaviour. WIRED’s reporter found Satisfyer Connect lets you decline data collection before entering the app and states it deletes logs every 60 days, and that We-Vibe and Svakom both offer a guest mode, while Lelo retained the reporter’s in-app browsing history with no way to clear it. Those are the vendors’ own claims, not test results.

Does the app collect data even if I deny it permissions? Denying permissions does not by itself prevent it. Turning off camera, microphone, contacts and location stops the app reaching those parts of your phone, but none of that stops the app recording how you use the app itself: when you log in, what you tap, which settings you pick. A privacy expert quoted by WIRED puts it as switching off device permissions not definitively preventing an app from collecting behavioural data. Permissions and data collection are two separate things, and the app store’s data safety declaration covers the second one.

Should I avoid app-connected toys altogether? Only if the app is not buying you anything. If you want long-distance control, the app is the product and there is no version of it without a server in the middle. If you mainly use the toy in the same room, a model with physical controls removes the entire category of risk at no real cost, which is worth knowing before you pay extra for connectivity you will not use.

Related reading: Can sex toys be hacked? The documented cases → · How to choose a couples sex toy → · Long-distance sex toys for couples → · We-Vibe Sync 2 → · Keeping intimacy alive long-distance → · How we review →

Sourcing: we have not tested these apps, inspected any traffic, or audited any vendor’s servers, and no claim here rests on our having done so. Everything above comes from court filings, from reporting by outlets that verified their own findings, and from what the companies have said on the record; where a company’s statement is the only evidence, we say so. For adults 18+. General information, not security, legal or medical advice.