Bluetooth, Wi-Fi, and What’s Really Being Transmitted
Most parents know connected toys exist. Fewer know exactly how they connect — and almost none know what happens to the data once that connection is made. Understanding how AI toys connect to the internet is the first step toward making genuinely informed decisions about which devices belong in your home.
Today’s AI toys aren’t passive gadgets. They use Bluetooth, Wi-Fi, and companion apps to stay functional, and each connection method carries its own set of risks. Real-world security failures — including a 2015 breach that exposed the personal data of nearly 3 million children — show what happens when those risks are ignored.
This article breaks down how each connection type works, what data is actually being transmitted, what the law says companies are and aren’t allowed to do with it, and what practical steps protect your child.
The Three Ways AI Toys Connect to the Internet

Not all connected toys work the same way, and the connection method matters because it determines what risks are present. Most AI toys use one or more of the following three approaches.
Bluetooth
Bluetooth is a short-range wireless protocol. AI toys use it to pair with a parent’s smartphone or tablet, which then acts as a bridge to the internet. The toy doesn’t connect to your home Wi-Fi directly — it connects to an app on your phone, and the app handles internet access. This sounds contained, but Bluetooth carries a critical vulnerability that most parents are unaware of: many AI toys require no PIN or password to connect. Any Bluetooth-enabled device within range can attempt a pairing without your knowledge or approval.
Wi-Fi
Wi-Fi-connected toys link directly to your home network. This enables richer features — real-time voice recognition, cloud processing, content updates — but it also creates a direct path from your living room to external servers. Voice commands, behavioral data, and personal information can all travel this route, often with no visible signal that a transmission is occurring.
App-Based Connectivity
Almost every AI toy sold today requires a companion app. The app is where the toy’s intelligence actually lives: voice processing, profile management, and content delivery all run through it. The app layer is also where most data collection happens. When you install a toy companion app, you typically grant it access to your device’s microphone — and sometimes its location and camera as well. Those permissions remain active even when the toy is sitting in a box.
The Bluetooth Problem Parents Don’t Know About

Bluetooth is widely assumed to be safe because it operates over short distances. But the range is larger than most parents realize, and range alone doesn’t equal security.
Standard Bluetooth reaches approximately 10 meters (roughly 33 feet). Bluetooth Low Energy (BLE), which is used in many modern toys to extend battery life, can reach up to 100 meters in open conditions. That range covers your front yard, your driveway, and in many homes, the sidewalk outside your front door.
Research published in the Journal of Sensor and Actuator Networks identified several widely sold connected toys — including Furby Connect, i-Que Intelligent Robot, Toy-Fi Teddy, and CloudPets — as having unsecured Bluetooth connections that required no authentication. Anyone within Bluetooth range could connect to these toys and — depending on the toy’s microphone and speaker capabilities — potentially hear conversations or transmit audio into the child’s environment.
That’s not theoretical. At a cybersecurity conference at the World Forum in The Hague, an 11-year-old named Reuben Paul demonstrated a live hack of a cloud-connected teddy bear, exploiting the same Bluetooth authentication vulnerabilities that security researchers had flagged in commercial toys.
The BlueBorne Vulnerability
In September 2017, cybersecurity firm Armis disclosed a set of eight Bluetooth vulnerabilities known collectively as BlueBorne. In plain terms, the eight flaws covered:
two ways an attacker could take full remote control of an Android device,
one way to steal information from an Android device,
one man-in-the-middle attack on Android,
two equivalent flaws in the Linux operating system,
a man-in-the-middle attack on Windows,
and a remote code execution flaw in Apple’s iOS audio protocol.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that these vulnerabilities could allow a remote attacker to take full control of affected devices — without any pairing required and without any action by the device owner.
While contemporary estimates placed the total number of Bluetooth devices in use at over 8.2 billion, Armis Labs confirmed that BlueBorne vulnerable devices numbered over 5.3 billion. This confirmed figure makes BlueBorne one of the most widely applicable Bluetooth attack vectors in history, directly impacting users of the Android, Windows, Linux, and iOS operating systems—systems that form the technical backbone of almost all consumer smart products.* (www.csoonline.com)
What made BlueBorne particularly concerning for connected toys is that unlike phones and laptops, toys rarely receive automatic security updates. A phone running an unpatched operating system can be updated within hours of a fix being released. A Bluetooth-connected toy sitting in a child’s bedroom may never receive that patch at all.
*Full technical documentation of the BlueBorne vulnerabilities is available in the CISA alert and the original Armis Labs research.
What Wi-Fi-Connected Toys Actually Transmit

Wi-Fi-connected AI toys don’t just respond to your child’s questions — they transmit data to process those questions. The voice recognition that makes these toys seem intelligent is almost never performed on the device itself. It happens in the cloud, which means every word your child speaks to the toy travels over your home network to an external server before a response comes back.
Depending on the toy and its privacy policy, transmitted data can include:
- Voice recordings of your child’s speech
- Transcripts of conversations with the toy
- The child’s name, age, and preferences entered during account setup
- Device identifiers and IP address, which can indicate your home’s approximate location
- Usage patterns — how often and how long the child plays with the toy
The key issue isn’t necessarily that this data is transmitted — cloud processing is how these toys work. The issue is what happens to that data once it reaches the manufacturer’s servers, how long it’s retained, and who else it’s shared with.
What the Law Actually Says About Your Child’s Data
This is where parents are often surprised — because the legal protections are stronger than most people realize. The laws protecting children’s data are not limited to America, and they are not optional for toy manufacturers that sell into your country.
United States — COPPA
The Children’s Online Privacy Protection Act requires companies to obtain verifiable parental consent before collecting personal information from children under 13, to clearly disclose what data is collected and how it is used, and to delete that data on request. The VTech breach in 2015 resulted in a $650,000 FTC fine precisely because VTech violated COPPA.
COPPA was significantly strengthened in 2025 — its first major update since 2013. The amended rule, which took effect in June 2025, now explicitly classifies voiceprints and other biometric identifiers as personal information. That matters directly for AI toys: a child’s voice recording is no longer just “data the toy collects,” it’s now legally treated with the same protection as a name or a photograph. The amended rule also requires companies to get separate, specific parental consent before sharing a child’s data with third parties for advertising — closing the loophole where one blanket sign-up screen used to cover everything.
For a full breakdown of what COPPA requires and where it falls short, see our article on children’s online privacy and what COPPA actually covers.
Europe — GDPR
The EU’s General Data Protection Regulation gives children’s personal data special protected status. Companies must obtain parental or guardian consent before processing a child’s data, and they are prohibited from using that data in ways detrimental to the child’s interests. The second-largest fine ever issued under GDPR — handed down in 2022 — was for a children’s privacy violation. The EU’s Digital Services Act goes further and bans platforms from delivering targeted advertising to users they know are children.
United Kingdom — UK GDPR and the Age Appropriate Design Code
The UK has its own version of GDPR, and alongside it, the Age Appropriate Design Code applies specifically to apps, games, connected toys, and devices. It requires that privacy settings for children default to the highest level of protection — companies cannot set privacy defaults to “low” and rely on parents to change them.
South Africa — POPIA
South Africa’s Protection of Personal Information Act, which came into full effect in 2021, provides some of the strongest child data protections globally. Under Sections 34 and 35, processing of a child’s personal information is prohibited by default unless prior consent has been obtained from a parent or legal guardian — and that consent must be given before any data is collected. POPIA defines a child as anyone under the age of 18, a higher threshold than the GDPR’s approach. Companies that transfer a South African child’s personal information to a foreign third party without adequate protections face fines of up to R10 million.
The practical implication: if a toy company collects your child’s data without your explicit prior consent, they may be in breach of the law — not just in one country, but in several at once. Knowing this gives you legitimate grounds to demand answers from any manufacturer before you buy.
When Security Failed: Two Cases Every Parent Should Know
The VTech Breach (2015)
In November 2015, Hong Kong-based electronic toymaker VTech suffered what security experts described at the time as the largest known breach of children’s data on record. The U.S. Federal Trade Commission confirmed that the breach exposed the personal information of approximately 2.25 million parents and nearly 3 million children. Compromised data included children’s names, dates of birth, genders, and photos, along with parents’ names, email addresses, home addresses, and passwords.
The FTC’s investigation found that VTech had not encrypted the data it collected and had violated COPPA by gathering children’s personal information without proper parental consent. VTech paid a $650,000 settlement and was required to submit to independent privacy audits for 20 years. No settlement restores data that has already been exposed.
My Friend Cayla (2017)
The My Friend Cayla doll, manufactured by Genesis Toys, used Bluetooth to connect to a companion app and relayed children’s speech to external servers for voice processing. Germany’s Federal Network Agency banned the doll in February 2017, classifying it as an illegal surveillance device. The agency’s president stated that items capable of transmitting data without detection compromise privacy — and that this applied with particular force to children’s toys.
Security researchers found that the doll required no authentication to pair via Bluetooth, meaning any Bluetooth-enabled device within approximately 10 meters could access its microphone and speaker without restriction. Consumer advocacy groups in the United States filed a complaint with the FTC, and major retailers including Toys R Us, Target, and Walmart removed the doll from their shelves.
The App Layer: Where Data Collection Really Begins

Before your child speaks a single word to their AI toy, the companion app has already begun collecting data. When you install and set up most toy apps, you agree to a privacy policy that may permit the manufacturer to:
- Store voice recordings for extended or indefinite periods
- Share data with third-party partners, including advertising and analytics companies
- Use collected conversation data to train and improve AI models
- Transfer data to servers in other countries, where different privacy laws apply
Most parents don’t read these policies before setup. The ones who do often find the language deliberately broad. The most useful question to ask isn’t “what does this app do?” — it’s “what does this app’s privacy policy permit it to do?”
Before any connected toy comes home, our article on 5 critical questions to ask before buying an AI toy gives you a framework for evaluating exactly these privacy practices.
What to Look for on the Box Before You Buy

You don’t need to be a cybersecurity expert to make a smarter purchasing decision. The information you need is usually on the box or in the product listing — you just need to know what to look for. Before buying any connected toy, find answers to these six questions.
Does the Bluetooth connection require a PIN or password?
Look for the words “secure pairing,” “PIN required,” or “authenticated connection” in the product description or technical specifications. If no authentication method is mentioned, that is a warning sign. Toys that connect to any nearby device without a code are the ones that have historically been exploited.
Does it connect via Wi-Fi directly, or only through the companion app?
A toy that connects through an app on your phone has one layer of control — you can delete the app. A toy that connects directly to your home Wi-Fi network becomes a permanent resident on your network until you manually remove it. Know which type you are buying before it comes home.
What companion app does it use, and who makes it?
Search the app name in your app store before buying the toy. Check the developer name, read the reviews, and look at what permissions the app requests. If the app asks for location, contacts, or camera access and the toy has no obvious need for those functions, that is worth questioning before you install it.
Does the manufacturer release security updates?
Check the manufacturer’s website or the app store listing for the companion app. If the app hasn’t been updated in over a year, that manufacturer is likely not actively patching security vulnerabilities. A toy with no security update history is a toy that will become increasingly vulnerable over time.
Where is the data stored, and what law governs it?
The toy’s privacy policy will state where data is stored and processed. If your child’s data is sent to servers in a country with weaker privacy laws than POPIA or the EU’s GDPR, those stronger protections may not apply once the data crosses borders.
Can you request deletion of your child’s data?
Under POPIA, COPPA, and GDPR, you have the right to request that a company delete your child’s personal information. Check the privacy policy for a section on data deletion or the right to erasure. If the privacy policy has no deletion process described, the company is likely not compliant with the laws that apply to your family.
Five Additional Things Parents Can Do Right Now
Review the companion app’s permissions before installing
Check what permissions the app requests on first install. Microphone access is expected for a voice-enabled toy. Location, contacts, and camera access are worth questioning. You can review and revoke individual permissions on both Android and iPhone without uninstalling the app.
Read the data sharing section of the privacy policy
You don’t need to read the entire document. Find the section titled “How We Share Your Information” or equivalent. If it refers to “third-party partners” without naming them, that language is deliberately broad and worth noting before you proceed.
Turn off Bluetooth when the toy isn’t in use
If the toy doesn’t have a physical power switch that fully cuts wireless functions, switch off Bluetooth on the paired device when the toy isn’t being played with. This closes the connection window that allows unsolicited pairing attempts.
Keep the app and any firmware updated
Security patches are delivered through app updates and, for some toys, firmware updates. Enable automatic updates for any app connected to a child’s toy. Check whether the toy manufacturer also releases firmware updates, and how to apply them.
Put connected toys on a separate Wi-Fi network
Most modern routers allow you to create a guest or secondary network. Placing connected toys on a separate network limits what a compromised device can reach — it cannot access your laptop, your phone, or other devices on your main network.
Frequently Asked Questions
Can an AI toy spy on my child?
It depends on the toy. Toys with unsecured Bluetooth connections — those that require no PIN to pair — can be accessed by any Bluetooth-enabled device in range. In documented cases, security researchers have used this vulnerability to both listen through and speak through children’s toys. Most reputable manufacturers have improved their security practices since the high-profile incidents of 2015 to 2017, but it’s still worth verifying for any toy you’re considering.
Does turning the toy off stop data transmission?
Not always. Some connected toys have a standby or sleep mode that keeps wireless functions active. A physical power switch that cuts power entirely is the most reliable way to stop all wireless activity. Check the manufacturer’s documentation to confirm what the off switch actually does on your specific model.
Are Wi-Fi-connected toys more dangerous than Bluetooth toys?
Both carry risks, but they’re different in nature. Bluetooth risks are proximity-based — someone needs to be physically close to the toy to exploit an unsecured connection. Wi-Fi risks are broader and can involve external server breaches, third-party data sharing, and manufacturer-level security failures, as demonstrated by the VTech breach in 2015.
What data do AI toy companion apps typically collect?
This varies by manufacturer, but commonly collected data includes the child’s name, age, and gender entered at setup; voice recordings and conversation transcripts; device identifiers; IP addresses; and usage data. The privacy policy for each app will list what is collected — look for the “information we collect” section, and pay particular attention to what the app collects automatically versus what you actively provide.
Is it illegal for a toy company to sell my child’s data?
In many jurisdictions, yes — without verifiable parental consent first. Under COPPA in the United States, GDPR in Europe, UK GDPR in the United Kingdom, and POPIA in South Africa, companies must obtain prior parental consent before collecting or sharing children’s personal information. Violations can result in significant fines. However, enforcement depends on complaints being made and regulators taking action. Reading the privacy policy before installing the companion app remains your most reliable personal protection.
The Bottom Line
AI toys are not passive objects. They are connected devices with microphones, wireless radios, and companion apps — and like all connected devices, their safety depends on how responsibly they were built and how they are configured in your home.
The legal protections around your child’s data are real, increasingly strong, and not limited to any one country. But those laws only work when parents know they exist — and when toy manufacturers are held to account for following them.
The families caught in breaches like VTech in 2015 had no idea the risk existed until after their children’s data was already in someone else’s hands. Awareness is the most effective protection available. Knowing what questions to ask before a toy comes home, and knowing what the law requires of the companies building these products, puts you in a position that most parents never get the chance to be in.
Ask the questions before the toy comes home. Check the permissions before the app is installed. The toy may be smarter than it looks — but so are you.