There is a category of device that does something no previous consumer technology has done: it builds a three-dimensional map of your home, in real time, every time you use it.
Augmented reality and virtual reality headsets need to understand the physical space around you to function. To prevent you from walking into walls, to anchor virtual objects to your real surfaces, to track your hands in space — all of these require the headset to scan and model your environment continuously. Apple Vision Pro and Meta Quest are currently the dominant consumer products in this category.
The privacy implications of this scanning are only beginning to receive serious attention, and the regulatory frameworks that apply are still catching up.
What Environmental Scanning Actually Captures
When you put on an AR headset, its cameras observe everything visible from where you’re wearing it: the layout of your rooms, the objects on your shelves, the artwork on your walls, the documents on your desk, the people in your home, the books in your bookcase.
The headset converts this visual information into a spatial map — a three-dimensional model of your environment that it uses for tracking and rendering. The depth, detail, and persistence of this map varies by device and by application.
This isn’t analogous to a phone camera that captures images when you choose to take a photo. The scanning happens automatically, continuously, as a prerequisite for the device working at all. You don’t have a capture moment to opt out of. The spatial map exists because you put the headset on.
The sensitivity of what’s in your home is easy to underestimate until you think about it concretely. A spatial map of someone’s home reveals: the layout of rooms (including security-relevant information about how many exits and entry points exist), what objects they own, what medications are on their nightstand, what books are on their shelves, what documents or screens are visible, who else was present and when.
Apple Vision Pro: The Privacy-First Approach
Apple has positioned Vision Pro with strong privacy claims, and some of those claims hold up to scrutiny.
According to Apple’s Vision Pro Privacy Overview, environmental scanning data is processed on-device by default. The spatial map your headset generates of your home is not, by default, transmitted to Apple’s servers. This is meaningful — Apple cannot be compelled to produce data they never received.
For eye tracking, Apple’s approach is particularly strong. Optic ID — the eye-based biometric for authentication — is encrypted and stored in the Secure Enclave, Apple’s dedicated security processor. Apple states that eye-tracking data is private and is “not shared with Apple, third-party apps, or websites.” Only your final selections (the equivalent of a tap) are transmitted when you interact with the interface.
The device also includes hardware-level protections: the LED indicators that show when cameras are active, and privacy controls that prevent third-party apps from accessing raw camera feeds directly.
Where it gets more complicated: Third-party apps on Vision Pro have different capabilities from the operating system itself. An app you install may request access to your environment in ways that the system can’t fully control. Developers who build for visionOS can access various levels of spatial data depending on what entitlements they’ve been granted.
The practical question is: what do the apps you install do with the spatial access you grant them? Apple’s app review process provides some constraint, but it doesn’t eliminate the possibility of apps using spatial data in ways users don’t anticipate.
Meta Quest: A Different Calculation
Meta, which makes the Quest line of VR headsets, operates under a fundamentally different business model and a different privacy philosophy.
Meta notified users in 2024 of its intention to collect additional data from Quest products. The data Meta collects or can access includes “your avatar’s lip and face movement” and “abstracted hand and body data.” The headset’s guardian system — which maps your play space to prevent collisions — captures detailed information about your physical environment.
Meta’s core business is advertising. The company has extensive experience using detailed personal data to build and refine targeting profiles. The data signals available from a VR headset — what you look at, how long you look at it, how your body moves — are potentially among the richest behavioural signals any platform has ever had access to.
Meta’s privacy policy for Quest devices permits using data for personalisation, advertising, and product improvement. Whether spatial environment data is used in advertising targeting isn’t explicitly disclosed, but the breadth of the data terms doesn’t exclude it.
The comparison with Apple is stark. Apple’s privacy commitments on Vision Pro are architecturally grounded: on-device processing means Apple doesn’t have the data to begin with. Meta’s commitments are policy-based: Meta holds the data and commits not to use it in certain ways. These are different categories of protection, even when stated with equal confidence.
Third-Party Apps and the Access Gap
Both Vision Pro and Quest allow third-party developers to build applications. These applications can, with appropriate permissions, access various kinds of spatial and environmental data.
A game that needs to map your play space will access your floor plan and nearby objects. An AR interior design app will access detailed views of your rooms. A productivity app that overlays notes on your physical desk will access what’s on that desk.
In each case, the question isn’t just what the operating system does with your environment data. It’s what each individual app’s developer does with whatever access you grant them. Third-party app developers have their own privacy policies, their own data practices, and their own business incentives. A developer building an AR app may share environment data with analytics services, advertising networks, or AI training pipelines — practices that are disclosed, if at all, in privacy policies that few users read.
The permission model for spatial data on these platforms is still maturing. The categories of access — “environment,” “room layout,” “scene understanding” — don’t map cleanly onto how most users think about privacy. When a user grants an app access to “your environment,” they may not fully understand that this means the app can observe and potentially transmit a detailed model of their home.
The Regulatory Gray Zone
Environmental scanning exists in a privacy regulatory space that current law wasn’t designed to address.
GDPR in the EU protects “personal data” relating to an identified or identifiable person. A spatial map of someone’s home, associated with an account, arguably qualifies. But the GDPR’s categories of special data — health data, biometric data, genetic data — don’t explicitly include home layout information. How regulators will categorise and enforce against spatial data collection is still being established.
In the US, there is no federal privacy law equivalent to GDPR. Several state laws include provisions around biometric data — facial geometry, fingerprints — but again, spatial map data doesn’t fit cleanly into these categories.
This regulatory gap means that consumer protection currently depends largely on manufacturer commitments rather than enforceable legal obligations. Apple’s on-device processing architecture provides structural protection regardless of regulatory gaps. For platforms where data is transmitted off-device, the regulatory uncertainty leaves users more exposed.
What’s Visible in Your Background
A specific practical concern: what a headset’s cameras can see while you’re using it isn’t limited to the floor and walls.
Documents on a desk are readable if a camera passes over them. Prescription bottles, medical devices, financial statements, identity documents, personal correspondence — all of these become part of the environmental data captured during normal use. This is true even if the app you’re using has no interest in documents: the spatial mapping process captures whatever is visible.
For users who work from home, or who store sensitive documents in the same spaces where they use AR/VR devices, this is a meaningful consideration. The exposure isn’t hypothetical — it’s a direct consequence of the cameras being active while you use the device.
Practical Steps for Users
Given the current state of these devices and their privacy protections, a few practical approaches:
Use AR/VR in spaces you’re comfortable being mapped. A living room or dedicated play space is different from an office where sensitive documents are present. The camera doesn’t distinguish between these contexts.
Review the privacy policies of apps before granting spatial access. The system permission for environmental access is binary — you grant or deny it. But what the app does with access depends on its own practices.
Understand that Meta and Apple have different structural models. On Vision Pro with Apple’s default settings, your home map stays on your device. On Meta Quest, the data practices are policy-governed rather than architecturally enforced.
Keep sensitive materials out of camera view. This is a simple environmental control: if you don’t want something visible to a headset camera, don’t have it visible where you use the headset.
Be cautious about headsets with third-party cameras attached. Accessories that add camera functionality to headsets may have different, weaker privacy protections than the primary hardware.
The Longer Arc
AR/VR is still at an early stage. The devices are expensive, relatively niche, and used for limited periods. The privacy implications of spatial scanning are correspondingly limited in scope today.
As headsets become cheaper and usage increases — and as mixed-reality computing becomes more integrated with daily life — the amount of environmental data captured will grow substantially. The norms and regulations that govern this data need to be established before the data collection is ubiquitous, not after.
The decisions Apple and Meta have made about their devices now — on-device processing versus policy-governed cloud processing — will shape the default expectations for an entire product category. Understanding those decisions is the foundation for making informed choices about which devices to bring into your home.