This page has no affiliate links. Full disclosure below.

Checked 2026-10-10. This guide is research-based. We have not used these apps. It draws on privacy policies, Lovense’s EU Data Act statement, a We-Vibe app FAQ, and Apple App Store privacy labels. Published materials here include those policies and listings. If a document does not name a data type, silence is not treated as proof of collection.

This page stays with Lovense, We-Vibe, and LELO documents as published on 10 October 2026. It is not a security audit and not the product comparison in Lovense vs We-Vibe. App Store labels are filled in by the developer. On these listings, Apple says the details are not verified by Apple. When a label and a policy disagree, both are quoted.

Lovense’s privacy policy

The policy effective 10 October 2024 names HYTTO PTE. LTD. as controller unless it says otherwise. It covers the website, app, software, and other Lovense services. It says the company does not knowingly collect personal data from anyone under 18, or under a higher age of majority. (Privacy Policy of Lovense)

Categories it says it may collect: identifiers and contact details (name, alias, postal address, email, phone, account name, login credentials), including phone and email when you sign up for messaging, contests, surveys, or support; commercial records (products purchased, returned, or considered, payment information, billing and shipping addresses, purchase history); messages you send the company; internet activity (user content, browsing and search history, click-stream data, ads, and use of the sites or app); device and product-use data (activation times, model, operating system, firmware, connection logs, feature-usage statistics, error logs, crash reports); public posts such as comments, reviews, and forum posts, which other people can read; general fitness data only if you use fitness features, not for diagnosis or treatment, and the products are not medical devices; IP address and an approximate location such as country or region; session and persistent cookies, which may limit the services if you decline them. A heading, “Audio, Electronic, Visual, and Similar Information,” has no examples listed under it.

Private user-to-user chats are not collected, monitored, accessed, or stored in the ordinary course, except a valid legal request or an investigation of reported terms violations such as harassment, illegal content, or abuse. Those contents are not used for marketing, profiling, or training AI. For remote control and pairing, the policy separately says Lovense processes device identifiers, connection logs, session metadata, and, where applicable, the contents of associated communications. AI inputs and outputs may go to third-party providers, whose terms can allow use to run and improve their services, including training where the law allows it. Lovense says it does not use those inputs or outputs to train a provider’s general-purpose foundation models without separate consent where the law requires it, and it says not to put sensitive or health data into AI inputs. (Privacy Policy of Lovense)

The policy says Lovense does not sell personal data and does not “sell” or “share” it in the CCPA/CPRA sense except as described. It does describe sharing with group companies, service providers, AI and advertising partners, in a business sale, when the law requires it, and with consent. Content delivered to another person is then outside the company’s control. Retention follows the purpose, not one number for every field: account data while the account is active and for a period after; orders under tax and warranty rules; support messages for follow-up; security logs for investigations. You can request access, correction, deletion, restriction, or a portable copy, and you can refuse non-essential cookies. (Privacy Policy of Lovense)

The US App Store listing for Lovense Remote, developer HYTTO PTE. LTD., says data linked to you may include email (product personalization and app functionality), user ID (app functionality), and usage data (analytics). Data not linked to you may include product-interaction usage data and crash and performance diagnostics. Apple has not verified the label. (Lovense Remote on the App Store)

What the EU Data Act statement says a toy generates

The statement, last updated 21 August 2026, covers data from Bluetooth Lovense products and the apps. The toy has no persistent storage. Standalone, off, or in standby, nothing is generated for storage or sent to Lovense servers. The toy uses Bluetooth Low Energy and a proprietary protocol to the app. The app uses HTTPS to the servers. (Lovense EU Data Act Statement)

Named items: product model; firmware (current version only); device identifier including model, device ID, name, and BLE address; Bluetooth connection status; battery level; product configuration; feature-use events; product-to-account binding; session start and end; error codes; diagnostic logs. Diagnostic logs are generated by the apps, not the toy. Charging status is not obtained and not stored. Control commands are executed and not stored. Intensity and speed stay on the user’s device as the current setting only, with no history. Connection status, battery level, feature-use events, session information, errors, and diagnostic logs are listed at about seven days. The device identifier and account binding last until you unpair, remove the product, or delete the account. (Lovense EU Data Act Statement)

Purposes named: operate the product, support, maintenance, security, and legal duties. That generated data is shared only if you instruct a share, a public body shows an exceptional need under the EU Data Act, or the law requires it. Security named: SSL/TLS in transit, AES-256 at rest, Bluetooth security with the proprietary protocol, and limited access. You can ask to access, port, or delete it after an identity check. The statement does not describe a stored history of sensation patterns. (Lovense EU Data Act Statement)

We-Vibe: shop policy, app FAQ, App Store label

The US site policy is a Lovehoney Group shop policy. For we-vibe.com/us the controller is Lovehoney Group US Trading Ltd. It has no heading for the We-Vibe App. The shop list includes name, postal address, email, telephone, IP address, age or date of birth, gender, anniversary, relationship status, card details, orders, and support or competition messages. Full IP addresses are stored seven days, then deleted or anonymized. Log data is analyzed in anonymized form. Google or Apple login passes along email and name. That list is the website, not the app. (We-Vibe US privacy policy)

The app FAQ PDF, filename date 2 September 2023, says the app does not ask for name or address, creates an anonymous token on first launch, and does not require an account. Email is only for the newsletter. It does not track location. On Android 11 or lower, location services must be on for Bluetooth, and location data is not collected, stored, or processed. Communications are end-to-end encrypted, with DTLS for data, SRTP for media, and WebRTC. A PIN is under Privacy settings. You can unpair. A factory reset after a forgotten PIN deletes partner connections, paired toys, settings, and saved patterns. During a partner session, the FAQ says Android blocks screenshots and screen recording, and iOS cannot. A partner must accept “Request Control,” and either person can take control back. (We-Vibe App FAQ PDF)

The US App Store listing shows only “Data Not Linked to You”: product interaction for advertising or marketing, analytics, and app functionality, plus crash data for analytics and app functionality. (We-Vibe App on the App Store) A shorter care article repeats PIN, unpair, and WebRTC, and says We-Vibe does not control the phone OS, the network, or other apps. (How safe is the We-Vibe App?)

LELO’s policy sentence and a shorter label

LELO’s privacy policy is dated 31/07/2025. LELOi AB and the relevant group company are the controller. A website account asks for email, first name, last name, and gender. An order adds shipping and billing details, phone, and cardholder data. (LELO privacy policy)

If you connect a device to the LELO app, the policy says LELO might collect, through the app or third-party services in the app, email, first and last name, IP address or domain, location, and device operating-system or IT-environment parameters, including Bluetooth sharing permission. “Might” is the verb. That sentence does not list vibration settings, session recordings, or photos, so this guide does not add them. (LELO privacy policy)

Newsletter signup is voluntary. Mobile opt-in information is not shared with third parties or affiliates for marketing. Data might be shared inside the LELO group, with service providers in the EU, UK, or US, with payment and logistics companies for an order, and with authorities when the law requires it. Retention lasts for the purpose or a legal period. LELO describes encryption and says it cannot guarantee those measures will fully prevent unauthorized access. (LELO privacy policy)

The US App Store listing for the LELO app shows “Data Not Linked to You”: crash data and other diagnostic data for app functionality. No “Data Linked to You” section appeared. Apple has not verified the label. Quotes here are from lelo.com/privacy-policy. The listing links to a different URL, which was not the page quoted. The policy’s “might collect” list and the diagnostics-only label do not match. (LELO on the App Store)

App features, as distinct from this paperwork, are covered in app-controlled toys for long-distance use. The We-Vibe FAQ says iOS cannot block screenshots. (We-Vibe App FAQ PDF)

FAQ

Does Lovense keep intensity settings on its servers?

The Data Act statement says intensity and speed stay on the user’s device, current setting only, with no history, and that control commands are not stored. Battery level and session times are listed at about seven days. Account data in the privacy policy uses a separate, purpose-based schedule. (EU Data Act Statement)

Why does an older Android phone ask We-Vibe for location?

The app FAQ says Android 11 or lower needs location services on to start Bluetooth, and that location data is not collected, stored, or processed. It says the app does not track location. (We-Vibe App FAQ PDF)

Does LELO’s App Store label list a name?

The listing (as of 10 October 2026) shows diagnostics not linked to you, and no “Data Linked to You” section. The privacy policy says a Bluetooth connection might include name, email, IP or domain, and location. The documents use different lists. (App Store, privacy policy)

Can a partner be cut off from control?

We-Vibe’s FAQ says a partner must accept a control request and that you can take control back, unpair, or use a PIN. Lovense’s policy says content already delivered to another person is then outside the company’s control. (We-Vibe FAQ, Lovense)

Does a fitness mention make the toy a medical device?

No. Lovense’s policy says the products and fitness features are not medical devices and that the data is not for diagnosis or treatment.

Sources accessed 2026-10-10

This is not medical advice. Nothing here diagnoses, treats, or prevents a health condition. Policies change. Read the current version before you connect a toy or create an account.

This content is general information, not medical advice. If you have a health condition, allergy (for example to latex or certain lubricants), pain or are pregnant, ask a healthcare professional.