eWeLink Privacy: What Data Does the App Actually Collect?
A plain-English breakdown of what eWeLink's own privacy policy discloses about device data, permissions, third-party SDKs, and where the data goes.
A plain-English breakdown of what eWeLink's own privacy policy discloses about device data, permissions, third-party SDKs, and where the data goes.
Aqara or Xiaomi drops a model. Here's what actually happens to the unit already running on your Zigbee2MQTT or ZHA network, and what really can break it.

The 'Tuya sends data to China' claim traces to a 2021 report. Here's what Tuya's own current documentation says about where your data actually goes.

Xiaomi open-sourced ha_xiaomi_home. Here's what its local mode really requires, why most readers outside China won't get it, and what to use instead.

Aqara's June 2026 cloud CVEs chain into an account-takeover path. Here's how the chain works, who's exposed, and why local Z2M/ZHA setups sit outside it.

CVE-2026-50090 is a CVSS 9.3 OAuth redirect bypass in Aqara's cloud. If you run Zigbee2MQTT, ZHA, or local HomeKit, you are not in scope. Here is why.

A 16 June Mijia outage broke the app for tens of millions. Here's why local Home Assistant automations kept running and what determines if yours would too.

What data does the official ha_xiaomi_home integration send to Xiaomi's cloud? Token storage risks, LAN mode limits, and who true local control works for.

Aqara's March 2026 privacy policy update explicitly addresses local mode data collection. Here's what it says, what it doesn't cover, and how to verify it.