Privacy Tier (Ainode Scoring)

Ainode Privacy Glossary · Auditor: Tomás Maria Vaz de Noronha

In short. Ainode's privacy-tier system grades each audited wearable into one of four bands based on the actual network flows we observe during forensic capture, plus a 6-dimension score. Tier A devices contact zero non-EU servers. Tier B contact only manufacturer firmware servers, predominantly EU-hosted. Tier C have disclosed flows to non-EU jurisdictions for documented purposes. Rejected devices send personal data to non-adequate countries without GDPR Article 46 safeguards.

Tier A — Zero non-EU traffic

Device contacts zero servers outside the EU. Zero non-EU traffic during 72-hour capture. Score typically 0–25 / 100. We have not yet published a Tier A wearable in our 8-device 2026-04 corpus — the bar is high. (Several lab-only candidates exist but have not been retail-launched.)

Tier B — Minimal disclosed flows

Device contacts manufacturer firmware servers + a small number of disclosed third-party services, all within the EU/EEA or in adequate countries. Score 25–40 / 100. Examples in our corpus: HeyCyan AI Glasses (idle telemetry only), Redmi Watch 5 Active (Xiaomi EU servers).

Tier C — Significant disclosed flows

Device transmits personal data to non-EU servers, but the flow is documented in the privacy policy or otherwise discoverable. Tier C is "transparent but not minimal." Score 40–70 / 100. Examples: SHR K3 Smart Ring (US servers), AuraBuds X6 Earbuds (firmware to non-EU). Our position: Tier C devices are sold with clear disclosure but better-privacy alternatives may exist.

Rejected — GDPR violations

Device transmits personal data (voice, location, biometrics) to non-adequate countries (typically China) without GDPR Article 46 safeguards. We flag these as outright Rejected. Examples: Aurafit Titan (voice → China), Nexa 2 (voice → China), AI Glasses 8MP/1200W (location/voice → China). See /reviews for the full list.