Dev.to
7/20/2026

A Practical Privacy Threat Model for Consumer Companion Robots
Short summary
A practical framework for privacy threat modeling consumer companion robots, treating them as distributed systems spanning physical sensors, companion apps, vendor clouds, and third parties. The method maps data flows across five components and categorizes data by harm potential rather than implementation. For each flow, developers should assess local processing feasibility, sensor indicators, retention policies, and control testability.
- •Companion robots are distributed systems: physical device, app, cloud, and third parties all create privacy exposure
- •Data should be categorized by harm type: ambient media, identity, behavioral, home data, telemetry, sensitive context
- •Each data flow needs four checks: local feasibility, visible indicators, retention limits, and testable controls
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



