What Sex Toy Apps Say They Collect: Four Brands' Labels
Of the four app-controlled toy brands whose store privacy labels we pulled, one declares that it collects your email address and ties it to your identity. It is Lovense, whose App Store label lists Contact Info under Data Linked to You, for product personalisation and app functionality (App Store listing, retrieved 3 Aug 2026). That is the same company whose 2025 security flaw let anyone turn a public username into the email address behind it, which we covered in our piece on the documented incidents in this category. Google’s form for the same app declares the name and email address as well (Google Play data safety detail, retrieved 3 Aug 2026). A label tells you such data exists and is tied to you. It does not tell you the data will one day be exposed, and someone reading that label in 2025 would have learned nothing about the flaw.
Research-based, not hands-on (how we review) · No affiliate links on this page, and nothing below was shown to any manufacturer before publication · We may earn a commission on Lovense products through our app-controlled vibrator guide, and Lovense is the brand that comes off worst below (disclosure)
Quick take: four brands, two stores, one afternoon of reading the filings. Here is what each one declares it takes, and the three findings this piece is built around, where a company’s own paperwork does not line up. The labels are worth reading, but not for the reason most guides imply. They are not a platform’s verdict on a manufacturer; both stores say in writing that they are unverified self-reports. Their use is that they are statements a company has put its name to, which you can then hold against everything else that company says.
What four brands actually declare
Apple’s App Privacy section and Google’s Data safety section are filled in by the developer, in the developer’s own words, from each store’s fixed vocabulary. Below is every entry in the App Store labels for four brands on the US storefront on 3 August 2026. Apple’s structure is purpose, then data category, then data type; the table keeps that order.
| App | Data Linked to You | Data Not Linked to You |
|---|---|---|
| Lovense Remote | Analytics: Usage Data (Other Usage Data). Product Personalization: Contact Info (Email Address). App Functionality: Contact Info (Email Address), Identifiers (User ID) | Analytics: Usage Data (Product Interaction). App Functionality: Diagnostics (Crash Data, Performance Data, Other Diagnostic Data) |
| We-Vibe App | nothing declared | Developer’s Advertising or Marketing: Usage Data (Product Interaction). Analytics: Usage Data (Product Interaction), Diagnostics (Crash Data, Performance Data). App Functionality: Usage Data (Product Interaction), Diagnostics (Crash Data, Performance Data) |
| Satisfyer Connect | nothing declared | Analytics: Usage Data (Product Interaction), Diagnostics (Crash Data) |
| FeelConnect 3.0 | Analytics: User Content (Other User Content). App Functionality: Identifiers (User ID) | Analytics: Usage Data (Product Interaction). App Functionality: Contact Info (Email Address), Diagnostics (Crash Data) |
Two of the four link something to your identity, which looks like a clean ranking until you read what sits in each bucket. Lovense links an email address. Kiiroo’s FeelConnect 3.0 links User Content, a category that on Apple’s form covers material a user creates inside the app (App Store listing, retrieved 3 Aug 2026). Neither of the other two links anything, but on Apple’s form Satisfyer’s declaration is genuinely the smallest of the four, while We-Vibe’s is the only one naming advertising and marketing as a purpose alongside analytics and app functionality (App Store listing, retrieved 3 Aug 2026).
Google’s form asks different questions, and its listing page publishes only a summary, so the picture changes again.
| Brand | Shared with third parties | Collected | Deletion |
|---|---|---|---|
| Lovense | Device or other IDs, for analytics | Name and email address, neither marked optional, for app functionality, analytics, “fraud prevention, security, and compliance”, and account management; crash logs and diagnostics; app interactions and photos and videos, all optional | You can request that data be deleted |
| We-Vibe | Device or other IDs, crash logs and diagnostics, for app functionality | Photos (optional), for app functionality | Data can’t be deleted |
| Satisfyer | App activity and crash logs, for analytics | App interactions, for app functionality, analytics and advertising or marketing; name, email address and user IDs; other user-generated content; other actions; photos; crash logs. All eight fields marked optional | You can request that data be deleted |
| FeelConnect 3.0 (Kiiroo) | No data shared with third parties | Crash logs only, for app functionality and analytics | You can request that data be deleted |
All four declare that data is encrypted in transit. Three of the four declare that the app may collect photos or videos, and each of those three marks it optional. The listing page shows only a summary; the table above is taken from the full breakdown, which Google serves at a separate address ending /store/apps/datasafety.
One marker in that breakdown carries more than it looks. Google lets a developer flag a data type as optional “only if all users – regardless of device or region – can either optionally provide information, opt-out, or opt-in to have the data collected” (Google Play data safety guidance, retrieved 3 Aug 2026). Satisfyer has flagged all three of its personal-info fields that way, which is a claim that anyone can use Satisfyer Connect without handing over a name, an email address or a user ID. Lovense’s name and email address carry no such flag. Play has no “Required” label to display: we opened the breakdown for these four apps plus WhatsApp and Spotify and found the word nowhere in any of them, so the honest reading is a claim made against a claim withheld rather than two opposing declarations.
The line with the most practical consequence is the last column. Only We-Vibe’s says the data cannot be deleted, and Google’s wording for that state is specific: the developer does not provide a way for you to request deletion (Google Play listing, retrieved 3 Aug 2026). It describes a missing button rather than a technical impossibility, and whatever rights you may have under a data protection law sit outside the label entirely.
Apple prints the disclaimer directly above the labels
The most common use of these labels is as reassurance, and that reading does not survive contact with the page they sit on. Apple prints “This information has not been verified by Apple” in the same block as the developer’s name, immediately above the label. Google’s version reads “The developer provided this information and may update it over time.” Neither company is being coy. These are declarations, not audits.
WIRED’s guide to this category, the strongest page ranking for this question, tells readers to do exactly what this piece does: “You can also take a look at the app’s privacy information prior to download in your phone’s app store. Look for language that states the app may collect data linked to your identity, including your contact information” (WIRED, 14 Dec 2025). We have given the same instruction ourselves, in the incidents piece. What neither we nor any page we read for this article had done is carry it out and publish the result, which is the only way to notice that three of these filings sit awkwardly beside another filing, or beside something else the same company published.
Where a company disagrees with itself
Kiiroo’s two forms answer the same question differently. Compare collection with collection, which is the like-for-like axis. Apple’s label declares User Content, Identifiers, Usage Data, Contact Info and Diagnostics. Google’s breakdown declares one category: crash logs (Google Play data safety detail, retrieved 3 Aug 2026). Diagnostics and crash logs match, so set those aside. Google’s rules do keep some kinds of data out of the section you can read, and they are worth naming rather than skipping. Two remove it from the declaration entirely: data processed only on the device, and data protected by end-to-end encryption. A third, ephemeral processing, still has to be entered on the form but is then withheld from the published section (Google Play data safety guidance, retrieved 3 Aug 2026). None of those routes reaches three of the four categories left over. Google bars the ephemeral one for anything used to build profiles, and an account email address is retained rather than discarded after use. An email address and a user ID that Apple’s form says are collected have by definition left the device, and neither is the content of an encrypted message; product interaction data is in the same position. Google’s form for the same app names none of those three categories. That leaves User Content, the one category where an exemption could genuinely apply, since the app carries messaging and video calls. Even there the two filings pull against each other: Google’s encryption exemption requires the data to be unreadable by any intermediary including the developer, while Apple’s label declares User Content collected for analytics. Data a company can analyse is data it can read.
Satisfyer’s shop page against Satisfyer’s own labels. The shop page says the Connect app “does not collect any information about your usage behavior” (Satisfyer US, retrieved 3 Aug 2026). The company’s own Play breakdown declares that it collects app interactions for app functionality, analytics and advertising or marketing, and that it shares app activity with other companies for analytics (Google Play data safety detail, retrieved 3 Aug 2026). Its App Store label separately declares Usage Data and Product Interaction for analytics (App Store listing, retrieved 3 Aug 2026). There is a reconciling reading and it deserves stating rather than burying: WIRED reports that the Connect app lets a user opt out of data collection before continuing into it, and that the app says it deletes logs every 60 days. If the marketing sentence describes the state after you decline, both can stand. What it cannot describe is the default, because a switch offered before entry is an acknowledgement that something is collected without it. A buyer reading only the shop page would not know there was a switch to look for.
We-Vibe’s Play form names a category its App Store form does not. The App Store label lists no user content of any kind; the Play summary lists photos and videos. That is a smaller finding than it first looks. Apple’s rules make disclosure optional for data that is user-provided, optional, confined to a non-core feature and not used for advertising, so a company can ship a photo feature and legitimately leave it off the Apple form. The same page also says that a feature letting users upload photos or videos means you need to disclose that data type, so Apple’s guidance pulls in both directions here (Apple App Store privacy details guidance, retrieved 3 Aug 2026). The gap is explainable; it is not explained. The durable observation is narrower and still useful: for the same product, Google’s form tells a buyer about a data category Apple’s does not.
Lovense is absent from this section only on the point this piece opened with: both its forms declare an email address. Its Play form also names photos, videos and a name that its App Store label does not. For the photos and videos that is the same gap as We-Vibe’s, and the same explanation is available: Google’s form marks both of them optional. It is not available for the name. Lovense declares that field for account management and for “fraud prevention, security, and compliance”, and Google’s form does not mark it optional, so the carve-out for optional data outside a core feature has nothing to attach to. None of these is an accusation of lawbreaking, and none is a security flaw. They are the same smaller thing: public statements a company made about its own product, filed with two platforms and printed on its own shop, that do not sit together comfortably. In a category where the question is how much you trust the maker, self-consistency is the cheapest signal available.
Three names on one listing
The entity publishing the app is usually not called what the brand is called. Lovense Remote lists HYTTO PTE. LTD. as seller and copyright holder. Satisfyer Connect lists Triple A Marketing GmbH, while the Satisfyer shop’s footer carries a third name, EIS Inc. FeelConnect 3.0 lists Feel Robotics B.V. as seller and FeelTechnology as copyright holder.
The We-Vibe listing carries three names on one page: the developer shown at the top of the privacy section is “We-Vibe”, the Information block names the seller as Standard Innovation Corp., and the copyright line reads WOW Tech Group. Standard Innovation is the company that settled a class action in 2017 over usage data collected by the We-Connect app, covered in our incidents piece.
This matters for a practical reason. The privacy policy you accept is that entity’s, and a request about your data goes to that entity rather than to the brand on the box. Which obligations attach to a Singapore private limited company, a German GmbH and a Dutch B.V. is a question for a lawyer rather than for us. The point here is narrower: the store tells you which one you are dealing with, and the box does not.
What to do with any of this
Reading a label takes about a minute, and the useful moment is before installing rather than after.
Open the store listing first. On iOS the App Privacy section sits partway down the product page; on Android it is Data safety, and “See details” opens the breakdown the summary leaves out. Read the seller name, because that is the company you are dealing with. Check the deletion line, the one entry describing something you can still act on. Then compare the label against what the brand’s own marketing says, which is the step that produced the Satisfyer finding above and needs no expertise at all.
Two limits are worth naming. These declarations describe what a company states, not what its software does; establishing the latter requires traffic analysis, a different exercise and one we have not performed. And a label is a snapshot, which Google says outright when it notes that developers may update the information over time. Everything above was retrieved on 3 August 2026 from the US storefronts, and every listing is linked so you can check whether it still says what it said.
FAQ
Do sex toy apps collect data about how you use the toy? All four we checked declare that they do. The App Store labels for Lovense Remote, We-Vibe, Satisfyer Connect and FeelConnect 3.0 each list Usage Data or Product Interaction. What differs is whether it is tied to your identity and what it is used for. On the App Store labels, We-Vibe’s names advertising and marketing alongside analytics while Satisfyer’s names only analytics and diagnostics; on Google Play, Satisfyer’s own breakdown declares app interactions collected for advertising or marketing as well.
Which app-controlled toy brand collects the most identifying data? On the App Store labels as filed, Lovense. Its Lovense Remote label is the only one of the four that lists an email address under Data Linked to You, declared for product personalisation and app functionality. Kiiroo’s FeelConnect 3.0 also links data to identity, but the category is User Content rather than contact details.
Are App Store privacy labels verified by Apple? No. On the listings we read, Apple prints the sentence “This information has not been verified by Apple” directly above the label. Google’s equivalent says “The developer provided this information and may update it over time.” Both are developer self-reports.
Who actually publishes these apps? Usually not a company named after the brand. On the US App Store the Lovense Remote listing names HYTTO PTE. LTD. as seller, Satisfyer Connect names Triple A Marketing GmbH, and FeelConnect 3.0 names Feel Robotics B.V. The We-Vibe listing shows three names at once: a developer of “We-Vibe”, a seller of Standard Innovation Corp., and a copyright line reading WOW Tech Group.
Related reading: What permissions those apps ask for → · Are sex toy apps safe? → · Can sex toys be hacked? →
This article is for adults 18+. It is general information about published documents, not legal advice.