Sex Toy App Permissions: What Four Apps Ask For Now
On 5 August 2026 we opened the US Google Play listings for four companion apps and read the permissions each declares. All four ask for the camera, the microphone and precise location. Two of the four also read and write the phone’s calendar, and the write permission is described by Google in these words: “add or modify calendar events and send email to guests without owners’ knowledge.”
Research-based, not hands-on (how we review) · This page carries no affiliate links, and nothing below was shown to any manufacturer before publication · Lovense Remote declares the largest permission set of the four and is named throughout; we may earn a commission on Lovense products through our app-controlled vibrator guide (disclosure)
Quick take: the numbers people quote for this question come from one study published in February 2024 and never updated. It can be re-checked, the study says how, and none of the pages we read mentions that, so we did. Below is what four named apps declare today, taken from the listings on one dated afternoon, with the method written out so you can repeat it. The short version is that the intimate-sounding permissions have ordinary features behind them, and the one that does not is the calendar.
What four apps declare, 5 August 2026
Counts are of distinct permission descriptions shown on each app’s US English Play listing. The listing date is the app’s own “Updated on” stamp.
| App | Count | App updated | Package and source |
|---|---|---|---|
| Lovense Remote | 30 | 5 Aug 2026 | com.lovense.wear (Play listing, retrieved 5 Aug 2026) |
| FeelConnect 3.0 | 22 | 3 Aug 2026 | com.feeltechnology.feelconnect3 (Play listing, retrieved 5 Aug 2026) |
| Satisfyer Connect | 18 | 20 May 2026 | com.satisfyer.connect (Play listing, retrieved 5 Aug 2026) |
| We-Vibe, formerly We-Connect | 17 | 14 Jul 2026 | com.standardinnovation.weconnect (Play listing, retrieved 5 Aug 2026) |
Fourteen descriptions appear on all four listings. Six are the Bluetooth and networking machinery you would expect from a device that pairs with a phone and relays over the internet: pair with Bluetooth devices, access Bluetooth settings, view Wi-Fi connections, view network connections, full network access, receive data from Internet. Five more are housekeeping: control vibration, change your audio settings, prevent device from sleeping, reading the contents of USB storage, and modifying or deleting them. The remaining three are the ones worth naming, because they are on every app in the set: take pictures and videos, record audio, and precise location by GPS and network. Approximate location is on three of the four; We-Vibe’s app declares only the precise kind.
Beyond the shared fourteen, the sets diverge in a way that follows the counts. Satisfyer Connect and We-Vibe declare nothing the others do not. FeelConnect adds one of its own, downloading files without notification. Lovense Remote adds seven: find accounts on the device, create accounts and set passwords, retrieve running apps, modify system settings, control flashlight, allow Wi-Fi multicast reception, and a Google Play license check.
And the calendar pair — reading events including confidential information, and adding or modifying events and emailing guests — is declared by Lovense Remote and FeelConnect, and by neither of the other two. (Two of these apps are listed under names their buyers may not recognise: com.standardinnovation.weconnect is titled We-Vibe on Play and was long known as We-Connect, and com.feeltechnology.feelconnect3 is FeelConnect 3.0. We use the short forms below.)
The number everybody quotes, and what happens when you redo it
Almost every page answering this question traces back to one source: Surfshark’s analysis of ten adult toy apps, published 13 February 2024 and carrying no update stamp. Its findings are specific. Across the ten apps it found over sixty permission types, an average of 22 permissions per app and 6 classed as dangerous; Lovense Remote requested the most at 53 permissions and 13 dangerous ones, Satisfyer Connect and Love Spouse 28 each, and NaughtyKit the fewest at 6 and 2. Storage read and write showed up in 8 of the 10, camera in 7, and audio capture in 5 (Surfshark, 13 Feb 2024).
The obvious move is to redo it and see what changed. Surfshark makes that possible and none of the pages we read mentions that it does: its methodology names Exodus Privacy’s public reports as the extraction source, and it publishes its full working dataset as a spreadsheet (Surfshark research dataset, retrieved 5 Aug 2026). We downloaded it on 5 August 2026. It lists all ten apps by Play URL, and three of those package identifiers are three of our four: com.lovense.wear, com.satisfyer.connect and com.standardinnovation.weconnect.
Two things do not transfer, and both have to be said before any comparison means anything.
The first is the headline number. Surfshark counted permission names declared inside the app; the public Play listing shows Google’s human-readable descriptions, where several underlying permissions collapse into a single line or into none. Their 53 for Lovense Remote and our 30 are not the same measurement, and subtracting one from the other produces a number that means nothing.
The second is the wording. Surfshark’s sheet does print both units in the same cell, with entries reading Dangerous - CAMERA take pictures and videos, which is what makes an item-level comparison possible at all. But Google has since reworded its own strings. “read the contents of your shared storage” is now “read the contents of your USB storage”; “have full network access” is now “full network access”; “prevent phone from sleeping” is now “prevent device from sleeping”; “access approximate location only in the foreground” is now “approximate location (network-based)”. Match the two datasets by description and you will get the wrong answer in both directions. The comparison only works if you match on the manifest name, which is the first half of each cell.
There is a third problem, and it decides what can honestly be claimed in either direction. An item is comparable only if its manifest name carried a human-readable description in 2024 — and Surfshark’s sheet lists plenty that did not. Twenty-two of Lovense Remote’s fifty-three entries are a bare name with no description: FLASHLIGHT, CHECK_LICENSE, RECEIVE, AD_ID, POST_NOTIFICATIONS and so on. Seven of Satisfyer Connect’s twenty-eight and seven of We-Vibe’s twenty-six are the same.
That trap is live in the table above. Lovense Remote’s unique permissions today include “control flashlight” and a Google Play license check. Both look like recent additions and neither is: FLASHLIGHT and CHECK_LICENSE are both in its 2024 row, just without a description attached. Our own data caught us on that one.
So the rule has two halves. An addition is readable when the manifest name is described in 2024 and its cell is blank — or, more strongly, when the name is absent from the entire sheet. A removal needs one more test, because a description missing from Play today could mean the app dropped it or that Google stopped surfacing that string, and Google plainly did stop surfacing several: BLUETOOTH_CONNECT and BLUETOOTH_SCAN are in the 2024 data for all three apps and appear on none of the four listings today, which no Bluetooth toy app can have done. The test for a removal is whether Play still renders that same description for some other app. If it does, an absence means something; if it does not, it means nothing.
On that basis, here is what has changed across the three apps in both datasets.
Lovense Remote has gained the calendar. No calendar permission appears anywhere in the February 2024 data, for any of the ten apps, described or not. com.lovense.wear now declares both reading calendar events including confidential information and adding or modifying them.
And it has gained accounts. The same argument, and the same strength: the 2024 sheet contains no account permission of any kind for any of the ten apps. Lovense Remote today declares both finding accounts on the device and creating accounts and setting passwords, and it is the only one of our four that declares either. That matters more than it looks, because the features those permissions serve are the ones the next section is about.
Satisfyer Connect has gained location. In 2024 it is the only one of the ten apps declaring no location permission of any kind. Its listing today declares both approximate and precise.
We-Vibe’s app has gained “read phone status and identity” — a permission Google classes as dangerous, held in 2024 by Lovense Remote and by neither of the other two here.
Two smaller movements, both meeting the test. “reorder running apps” is rendered today for Lovense Remote and Satisfyer Connect: Satisfyer has gained it since 2024 and We-Vibe’s app has dropped it. “approximate location (network-based)” is rendered today for three of the four: We-Vibe’s app has dropped that too, keeping only the precise kind.
And one 2024 finding this method cannot re-check at all: Lovense Remote was the only app of the ten declaring background location, and Play’s description list does not distinguish background from foreground, so its absence proves nothing either way.
Counted individually, that is eight permissions added and two dropped across the three apps: a calendar pair and an account pair on Lovense Remote, a location pair and a task-list permission on Satisfyer Connect, a device-identity permission gained on We-Vibe’s app, and the same task-list permission plus approximate location dropped there. One more qualifies on the strongest test and we have left it out: “read Google service configuration” is absent from the whole 2024 sheet and renders today on two of the four. It is Play Services plumbing rather than a product decision, which is a judgement call, so we are naming it rather than quietly dropping it. Nothing here is a total; it is what the two datasets can be made to say to each other.
The intimate-sounding permissions have ordinary explanations
It would be easy to write the camera and the microphone up as sinister, and it would be wrong. Lovense’s own Play description explains both. Media Sync “let[s] music, sounds, or videos drive your toy’s vibrations”, which needs a microphone. Burn After Reading lets photos and videos sent in the app expire, which needs a camera. The listing also advertises Control Link and Control Roulette, features for handing control to another person or to a stranger for a limited time, which is what the account and networking permissions are for (Lovense Remote Play listing, retrieved 5 Aug 2026).
Two things follow, and they point in opposite directions.
The first is that these permissions are attached to features, so a reader deciding whether to grant them is really deciding whether they want those features. Controlling a toy over Bluetooth needs none of them. If you are not sending photos in the app, not driving vibration from music, and not handing control to a stranger, declining the camera, the microphone and location costs you nothing you were going to use.
The second is that this makes the unexplained ones stand out. Nothing on either listing advertises a feature that would need to read your calendar, still less to create events and email the guests. It may be a library the app depends on rather than a deliberate product decision — that is common, and it is the most likely explanation. But it is declared, a reader can see it, and neither company explains it where the permission is shown. Two of these four apps manage without it.
What permissions do not tell you
There is a second half to this question and permissions are not it.
Denying the camera stops the app reaching the camera. It does not stop the app recording that you opened it, which toy you paired, which pattern you chose or how long the session ran, because none of that comes from your phone’s hardware — it is the app’s own record of its own use. That is governed by a different declaration, the Play data safety section, and we went through what four brands say there, including three places a company disagrees with its own filings, in what sex toy apps say they collect.
The written policies do not close the gap either. A content analysis published in April 2026 examined the privacy policy documentation and product descriptions of 146 smart sex toys across fourteen brands, and reported that among the policies available, critical data storage and transmission details were “frequently omitted or ambiguous”, leaving them misaligned with the privacy claims made in the same companies’ marketing (Sun, Gómez Ortega, Rostami and Lampinen, CHI 2026). We are quoting the authors’ own summary of their findings rather than a reading of the full paper, and saying so.
So the picture is three declarations that do not reconcile: what the app can reach, what the company says it collects, and what the policy says it does with it. The permission list is the only one of the three you can verify in a minute, which is a reason to look at it and not a reason to think it settles anything.
How to check any app yourself, in about a minute
- Note that the store name may not be the app name you know.
com.standardinnovation.weconnectis titled “We-Vibe” on Play, andcom.feeltechnology.feelconnect3is “FeelConnect 3.0”. Search by package identifier, not by brand. - Open the app’s Play listing in a browser, at
play.google.com/store/apps/details?id=plus the package name. The package name is in the address bar of the store page. - Scroll to the bottom and open “About this app”, then “App permissions”, then “See more”. That dialog is the full declared list. It is the same data we counted above.
- Read the four categories separately from the rest. Camera, microphone, location and calendar are the ones that reach beyond the toy. Bluetooth, networking and vibration control are the job.
- Then open the data safety section, which answers a different question, namely what the company says it collects and shares, and treat any distance between the two as worth noticing rather than as a contradiction.
- Deny first, then see what breaks. Android will prompt when a feature actually needs something. A permission you never granted cannot be misused, and an app that works fine without it has told you the permission was optional.
If you have not bought yet, the prior question is whether you want an app-connected device at all, which we put first in our guide to choosing a couples toy. If the security record is what you are weighing, the dated list of what has actually happened is in can sex toys be hacked.
Limits of this snapshot
Four apps is four apps, and the four were chosen because this site already covers those brands, not by any sampling method. Surfshark looked at ten and found a wider spread than we did.
These are Android listings for a US English store. Play listings vary by region, iOS reports permissions differently, and a company can change what it declares with any update; one of these four was updated the same day we read it. One counting trap, since the numbers are the point: most of these descriptions begin with a lower-case letter and one does not (“Google Play license check”), so a filter that assumes lower case silently loses it. Our first pass did exactly that and reported 29 for Lovense Remote instead of 30. Everything above is a snapshot with a date on it, which is why the date is in the table and the method is written out. If you repeat it and get different numbers, the numbers changed; that is the point of publishing the method rather than only the result.
We have not decompiled any app, inspected any traffic, or verified that any app’s behaviour matches what it declares, and nothing above rests on our having done so.
FAQ
What permissions do sex toy apps ask for? We read the US Google Play listings for four companion apps on 5 August 2026 and counted the distinct permission descriptions each declares: Lovense Remote 30, FeelConnect 3.0 22, Satisfyer Connect 18, and the app listed as We-Vibe (formerly We-Connect) 17. Fourteen descriptions are common to all four, and among them are taking pictures and videos, recording audio, and precise location by GPS and network. Two of the four, Lovense Remote and FeelConnect, also declare reading calendar events including confidential information, and adding or modifying calendar events and sending email to guests without owners’ knowledge.
Why does a vibrator app need my camera and microphone? Because of the social features, not the toy. Lovense’s own Play listing advertises Media Sync, which lets music, sounds or videos drive the toy’s vibrations, and Burn After Reading for photos and videos sent in the app. Those explain a microphone and a camera. They are also optional: controlling a toy over Bluetooth needs neither. That is why declining both is usually free, and why a permission with no advertised feature behind it, the calendar on two of these four apps, is the one worth asking about.
Are the numbers in the Surfshark study still accurate? They are from 13 February 2024 and carry no update stamp, but they can be re-checked, and Surfshark says how: it extracted from Exodus Privacy’s public reports and publishes its full dataset as a spreadsheet. The counts do not transfer — Surfshark counted permission names declared inside the app, Google Play shows human-readable descriptions, and their 53 for Lovense Remote and our 30 are different units. Individual permissions do transfer if you match on the manifest name, because Google has reworded several of its own descriptions since 2024, and only where that name carried a description in 2024 at all — twenty-two of Lovense Remote’s fifty-three did not, which is why its flashlight permission looks new and is not. Doing that on the three apps in both datasets: Lovense Remote has added calendar read and write plus two account permissions, Satisfyer Connect has added location where it declared none at all, and We-Vibe’s app has added the dangerous-class permission to read phone status and identity while dropping approximate location. A removal needs one further test — whether Google still renders that description for some other app today.
Does denying permissions make the app private? It closes one door of two. Denying the camera stops the app reaching the camera; it does not stop the app recording that you opened it, which toy you paired, or how long the session ran, because that is the app’s own data rather than your phone’s. Permissions govern what an app can reach on the device. What a company says it collects is a separate declaration, in the Play data safety section, and we went through what four brands declare there in a companion piece.
Related reading: What sex toy apps say they collect → · Are sex toy apps safe? → · Can sex toys be hacked? → · How to choose a couples sex toy → · How we review →
Sourcing: the permission counts were extracted by us from the four Play listings linked in the table on 5 August 2026, and the method is written out above so the count can be repeated or corrected. Store listings can be changed by the developer at any time and vary by region. For adults 18+. General information, not security or legal advice.