IoT Privacy White Paper - Xiaomi

3.6 Xiaomi/Mi Home And Privacy

Introduction

Xiaomi/Mi Home is the smart device management platform for your home. Xiaomi/Mi Home enables you to interact with smart devices conveniently through your mobile phone, and enables you to control your smart devices under one platform.

1) Linkage Control, Easy to Use

Even users without previous experience of smart devices can quickly master the connection and operation of smart devices, allowing for such devices to become interconnected.

2) Customize as You Wish

Set up smart scenes according to your own habits.

3) Device Sharing, Fun Delivery

Sharing devices with family and friends lets everyone experience the fun of technology together.

Data Collection and Usage

1) Smart Device Connections

In order to provide you with Xiaomi/Mi Home services and to enable you to securely connect to and manage your smart devices, we will collect your Wi-Fi information, location information, account login information, information related to your mobile phone and smart device, and information associated with your Mi Account and smart device.

This information will be used to provide you with various functionalities, including pairing with and connecting to smart devices, discovering nearby devices, and device management. Specific examples involving the above information are set out below:

  • Account Login Information: Mi Account (the account ID may be the Xiaomi ID, phone number or email address), nickname, and profile picture information, as well as cookies (including Mi Account, serviceToken, country code, app store channel, and time zone) to log in to your account.

  • Mobile Phone related Information: Hardware-based identifiers (MAC address, Android ID), phone model, OS version, OS language, country or region, app store version, screen size and resolution, CPU, and display device related information. Based on the type of smart device you wish to connect to, we will collect the following information:

    • Smart devices connected via Wi-Fi: Wi-Fi Information (SSID, BSSID, MAC address of Wi-Fi, Wi-Fi password), MAC address of the device, and device ID.
    • After establishing a local connection via Bluetooth, smart devices connected via Wi-Fi: Wi-Fi information (SSID, BSSID, MAC address of Wi-Fi, Wi-Fi password), MAC address of the device, and MAC address of Bluetooth on the device.
    • Smart devices connected via Bluetooth: MAC address of Bluetooth on the device, and device ID.
    • Smart devices connected via Zigbee: MAC address of the device, and device ID.

2) Using Smart Devices for Home Management

We will collect information that you provide relating to room settings for smart devices in order to facilitate smart home management. This will allow you to enjoy greater convenience when using smart devices (for example, when using multiple smart lights, being able to quickly identify that a light is in a bedroom instead of the living room).

3) Device Sharing

We provide support for you to share smart devices with others through Mi Accounts. Sharing a smart device with others allows them to also control the device. In order to provide this service, we will collect your Mi Account ID, the Mi Account ID which you use to share, and shared device information (including the device ID, device name, device verification key, and sharing status of device). Such information equips us with the ability to enable you to share device control and usage with the accounts of other Mi users as well as to display the device's sharing status on the My Devices page in the Xiaomi/Mi Home app.

4) App and Smart Device Updates

To ensure you are able to continue enjoying the latest Xiaomi/Mi Home services, we will use your Xiaomi/Mi Home app version and phone model in order to provide you with updates to the Xiaomi/Mi Home app. We will also collect a list of your connected smart devices and associated firmware version information in order to provide you with smart device updates so that you can use the latest version of the service.

5) Smart Linkage Scenes

We provide support for you to configure certain rules to establish smart connections between devices under specific conditions. In order to enjoy this feature, we may collect your location information, smart scene rule settings, and designated device status so as to enable specific device functions to be executed according to the commands you give. For example, enabling a light to turn on whenever a sensor detects someone passing by. This functionality cannot be enabled without your explicit consent and configured rules.

6) Provision of Content-related Support

We provide support for content-related services. For example, articles and audio content playback are available in certain regions only. To help you make better use of smart devices, we will provide you with selected articles on such devices. When you view these articles, we will not collect any information from you.

If you have connected a smart device (such as the Mi AI Smart Speaker) that plays media content to Xiaomi/Mi Home, you can select and control the music or content to be played on the corresponding support page. We will collect the smart device type registered with your account to make corresponding smart device control functions available to you.

7) Device Sharing

You can share your smart devices with other users through Mi Accounts to allow someone else to control your devices. We may collect your Mi Account ID, the ID you provide relating to the account with which you share access, and shared device information (including device ID, device name, device verification key, and sharing status of device). This information allows us to give you the ability to share device control and usage with the accounts of other Mi users as well as to display the device's sharing status on the My Devices page in the Xiaomi/Mi Home app.

8) User Feedback

You may use feedback feature when encountering problems during daily use. We may collect your We may collect your contact information (phone number or email address you provided), uploaded logs (includes error information). This information will only be used for solving the given problems.

9) Data Analysis

We collect the usage time and frequency of each function in Xiaomi/Mi Home app plug-in for statistical analysis of your usage and status of these functions. Such data is collected only if the user has previously agreed to join the User Experience Improvement Program.

Privacy by Design

Xiaomi/Mi Home supports the sharing of smart devices, and strictly controls device sharing permissions. When you share a device with others in Xiaomi/Mi Home, the shared party will only be granted viewing permissions and permissions to control basic functions. You remain the sole device owner at all times, and have the ability to cancel the sharing at any time.

You can also create your device's smart linkage function in the Xiaomi/Mi Home app. For example, when the door and window sensors recognise that someone has returned home, the smart light at home will light up. These functions are implemented by Xiaomi/Mi Home, so even if you link smart devices from different manufacturers, you do not have to worry about your personal information being shared with different manufacturers.

Due to security restrictions of the Android and iOS system, Xiaomi/Mi Home needs to obtain mobile phone location permission when scanning and connecting to Bluetooth and Wi-Fi smart IoT devices. Xiaomi/Mi Home will only ask the user for location permissions when the user is using such scanning or connecting functions in relevant pages. If the user does not agree to enable location permissions, they are still able to use the basic functions of Xiaomi/Mi Home other than those of scanning and connecting to smart devices.

figure

figure

Appendix 6: Data Inventory for Xiaomi/Mi Home

TypeType of DataIdentification QualifierPurposeData Transmission Encryption MeasuresData Storage Encryption MeasuresData Retention Policy
IdentifiersMi Account ID
Identified
App Functionality
Device Functionality

HTTPS

No Encryption

Per user's request
MAC
Identified
App Functionality
Device Functionality

HTTPS

HTTPS

No Encryption

Per user's request
Android ID
Identified
App Functionality
Device Functionality

HTTPS

AES-128

Per user's request
Facebook ID
Identified
App Functionality
Device Functionality

HTTPS

AES-128

Per user's request
Device ID
Identified
App Functionality
Device Functionality

HTTPS

HTTPS

No Encryption

AES-128

Per user's request
Contact InformationCountry
Identified
App Functionality
Device Functionality

HTTPS

No Encryption

Per user's request
User ContentUser Information
Identified
App Functionality
Device Functionality

HTTPS

AES-128

Per user's request
Usage DataProduct Interaction
Identified
Analytics

HTTPS

AES-128

Per user's request
DiagnosticsCrash Data
Identified
Analytics

HTTPS

AES-128

Per user's request
Performance Data
Identified
Analytics

HTTPS

AES-128

Per user's request
Other DataPhone Number
& Email Address
Identified
App Functionality
Device Functionality

HTTPS

AES-128

Per user's request
Other Account Login Information
Identified
App Functionality
Device Functionality

HTTPS

No Encryption

Per user's request
Mobile Phone related Information
Identified
App Functionality
Device Functionality

HTTPS

No Encryption

Per user's request
Wi-Fi Information
Identified
App Functionality
Device Functionality

HTTPS

No Encryption

Per user's request
Device Sharing related Information
Identified
App Functionality
Device Functionality

HTTPS

No Encryption

Per user's request
Smart Linkage Scenes Information
Identified
App Functionality
Device Functionality

HTTPS

AES-128

Per user's request
Feedback Information
Identified
Analytics

HTTPS

AES-128

Per user's request