A baby monitor is one of the most intimate surveillance devices that exists. It watches your child sleep. It records sounds in your home around the clock. It observes a room where family life is at its most unguarded.
For most of history, that data went nowhere. It was analog RF transmission between two devices in the same house. The monitor did its job, and no one outside the room ever saw or heard anything.
Modern smart baby monitors have changed that architecture completely. Today’s popular monitors — Nanit, Owlet, Eufy, Miku, Cubo AI — are networked devices that route footage through cloud servers, store recordings for later review, and offer apps that let parents check the nursery from anywhere in the world.
That convenience comes with a structural change that is worth understanding before you point a camera at your sleeping infant.
Where Your Nursery Footage Actually Goes
When you use a cloud-connected baby monitor, the video from your nursery does not travel directly from the camera to your phone. It routes through the manufacturer’s servers — or in many cases, through a third-party cloud provider (often Amazon Web Services or Google Cloud) contracted by the manufacturer.
The footage lives on those servers according to whatever retention policy the company has set. Some companies store short event clips for 24–72 hours in free tiers. Premium plans extend that to weeks or months. In all cases, the video is accessible to:
- You, via the companion app
- The manufacturer’s engineering and support staff, typically for troubleshooting purposes
- Potentially the manufacturer’s data analytics teams, for product improvement
- Law enforcement, with a warrant or in circumstances the company deems an emergency
- Anyone who gains unauthorized access to either the company’s systems or your account credentials
That last category is not theoretical.
The Scale of Known Vulnerabilities
In 2023, Cybernews reported a significant vulnerability in the Meari SDK — a platform used by hundreds of baby monitor and IP camera brands. The flaw allowed anyone with a free account to receive data from other users’ devices. All apps built on the platform shared the same hardcoded cryptographic keys, which meant the vulnerability was structural, not an isolated bug, and affected over a million devices simultaneously.
The Eufy cloud controversy — which the company settled in 2025 — centered on footage being accessible outside users’ local networks despite marketing language implying local-only storage. Security researchers demonstrated that thumbnail images from cameras, including baby monitors, were accessible via Eufy’s cloud servers without authentication. Eufy subsequently revised its privacy commitments, but the incident revealed a fundamental gap between how these devices were marketed and how they actually functioned.
Earlier documented cases include parents discovering their Nest camera audio was being picked up and the stream accessible, reports of voice communications coming through baby monitors from unknown third parties (an indicator of account compromise), and multiple cases where default credentials on cheaper devices were left unchanged, giving anyone with the brand’s documentation access to a live feed.
The pattern is consistent: cloud-connected cameras, including baby monitors, are a persistent target precisely because they offer live video access to private spaces, and the security baseline varies enormously across manufacturers.
What Data Smart Baby Monitors Actually Collect
The modern smart baby monitor is not just a camera. It is a sensor array. Current-generation devices collect:
Video: Continuous or event-triggered recording, typically in HD or higher resolution. Often infrared-capable for night vision.
Audio: 24/7 ambient audio, with sound alert triggering. Many devices do voice analysis to distinguish crying from other sounds.
Movement data: Acceleration and breathing rate for wearable sock monitors like Owlet. This is classified as health data in some jurisdictions.
Sleep analytics: Sleep duration, room temperature, humidity, time spent in different positions (for some camera-based systems that use AI to infer this from video).
Account and usage data: When you check the feed, how often, for how long. Which features you use.
The health data category deserves particular attention. Owlet’s Dream Sock and similar products track pulse oximetry and heart rate. These are medical measurements. In the US, they are not protected by HIPAA because Owlet is a consumer device company, not a covered healthcare entity — the same regulatory gap that affects fertility apps and general health tracking apps.
If Owlet or a similar company were acquired, experienced a breach, or changed its terms, the physiological data of thousands of infants could flow to parties with no particular obligations toward protecting it.
The “Emergency” Disclosure Exception
Most baby monitor companies’ privacy policies include a clause permitting disclosure of recordings to law enforcement without a warrant in circumstances deemed an emergency. The language varies: “imminent threat to life,” “child safety emergency,” “as required by law or to protect safety.”
This is not inherently malicious. There are scenarios where rapid law enforcement access could save a child’s life. The problem is that “emergency exception” in practice has a loose definition, and once an exception exists in the terms, its application is governed by the company’s judgment rather than a legal standard.
Ring (an Amazon company, not a baby monitor but architecturally similar) disclosed footage from over 2,000 accounts to law enforcement without warrants in a two-year period before 2023, when policy changes required a warrant or owner consent. The company had created an infrastructure for “emergency” disclosure that was being applied routinely.
The same infrastructure can exist in baby monitor systems. You do not know whether it does because it is not disclosed.
The AI Analysis Question
Several smart baby monitors use AI to process video and audio. Nanit uses computer vision to track sleep positions. Miku uses radar sensing and audio AI. Cubo AI uses image recognition to alert parents if the baby’s face is covered.
This AI processing requires computational resources, and the question is where that computation happens. On-device processing means the AI runs locally and footage does not need to leave the camera to be analyzed. Cloud processing means footage is transmitted to servers for analysis.
Most current consumer monitors, for cost and power reasons, do cloud-side processing. That means continuous video of your nursery is being actively analyzed by AI systems operating on the manufacturer’s cloud infrastructure.
The manufacturer typically claims this is done securely and that the footage is used only for your feature results. The privacy policy may or may not address whether this analysis data — separate from the raw video — is used for model training or quality improvement. Read carefully: language about “improving our services” is a common catch-all for training use.
Practical Steps to Reduce Exposure
You can significantly reduce the privacy risks of smart baby monitoring without giving up the safety benefits.
Choose local-first options:
Some monitors offer a true local-only mode. Eufy’s non-WiFi models connect directly to a parent unit without internet routing. Infant Optics DXR models work on DECT frequencies, entirely offline. What you lose is remote access from outside your home — but you gain certainty that no footage is being transmitted beyond your network.
Use a dedicated monitor account with a strong, unique password:
If you use a cloud-connected monitor, the account protecting it should have a unique password not used anywhere else and two-factor authentication enabled. The most common avenue for unauthorized monitor access is credential compromise, not sophisticated hacking.
Audit network segmentation:
A baby monitor on the same network as your laptop, phone, and work computer creates a path between all of them if the monitor is compromised. Many modern routers support network segmentation — an IoT VLAN or guest network that isolates smart devices from your primary devices. The monitor can still reach the internet for its cloud features, but a compromised monitor cannot access your other devices.
Read the privacy policy before you buy:
Look for explicit commitments on:
- Whether footage is used to train AI models
- How long recordings are retained after deletion
- Whether there is an emergency disclosure policy and how broadly it is written
- What happens to your data if the company is acquired
The absence of clear language is itself informative.
Storing Your Baby’s Information Privately
Beyond live video monitoring, new parents accumulate a substantial amount of sensitive data about their child: health records, vaccination schedules, medical notes, milestone documentation, birth photos, videos of early development.
This information deserves the same care as the monitor footage — perhaps more, because it will be relevant for years or decades, long after the manufacturer of your baby monitor has been acquired, pivoted, or shut down.
The distinction worth making is between data that lives in a consumer product (where the monetization model determines how your data is treated) and data that lives in a private archive (where the privacy model is the product). Milestone photos, medical documents, and family videos stored in an app like daftei remain encrypted at rest with AES-256, transmitted securely over TLS 1.3, and never analyzed or used for AI training — a meaningfully different architecture from a consumer device company’s cloud.
The Underlying Question
The smart baby monitor market is built on a compelling emotional premise: see your child, hear your child, know that they are safe, from anywhere in the world. That premise is genuinely valuable.
The question is whether the cloud infrastructure required to deliver it needs to be built the way it currently is — with relatively weak disclosure about what is collected, where it goes, and who can access it — or whether companies building for parents might apply a higher standard.
Parents researching monitors rarely think to ask about cryptographic key management or third-party data sharing agreements. They are thinking about their child’s safety. The companies building these products know that, and it shapes the trade-offs they make.
The technology to build a smart baby monitor that offers remote viewing without storing footage on a company’s servers exists. Local processing, peer-to-peer encrypted transmission, no cloud intermediary. A handful of products approach this. The mainstream market has not converged on it because remote access features are easier to build with cloud infrastructure, and most buyers do not ask the privacy questions.
Until they do, the questions remain worth asking.