A humanoid robot moving through your home or workplace is, among other things, a sensor platform. It carries cameras that see what is in front of it, microphones that pick up sound in the immediate environment, depth sensors that map spatial geometry in real time, and, in some designs, contact sensors in its hands and feet. All of this generates data — continuously, in high volume, covering spaces and activities that people have historically considered private. The industry's answer to questions about what happens to that data has so far been either vague, optimistic, or absent.
This is not a distant problem. Humanoid robots are already operating in workplaces. They are being marketed for home use. The data they collect is not incidental to their function — in many cases, it is the raw material from which they learn and improve. And the frameworks that govern what companies can do with that data are, at best, poorly matched to the reality of what these devices are.
What a Humanoid Robot Actually Sees
To understand the data question, it helps to be specific about what humanoid robots actually collect and why.
Modern humanoid robots typically carry multiple cameras — forward-facing for navigation and task execution, sometimes additional cameras on the hands for manipulation tasks. These cameras run continuously while the robot is operating. In a warehouse setting, that means persistent video coverage of a work environment. In a home setting, it means continuous imaging of a private living space, including the people, objects, and activities within it.
Depth sensors — typically structured light sensors or time-of-flight cameras — generate three-dimensional maps of the robot's surroundings. These spatial maps are essential for navigation: the robot needs to know where walls are, where objects are, and how to path-plan around them. But a sufficiently detailed spatial map of a home or facility is itself sensitive information. It tells you the layout of the space, what furniture or equipment is present, and potentially something about the activities of the people who live or work there.
Microphones, where present, pick up ambient sound for voice interaction and, in some designs, for situational awareness. In a home with a humanoid robot, this means a device with active audio capture is operating in the same space where private conversations happen.
The robot's own operational logs — what it did, when, in what sequence, with what outcomes — are a further data category. These logs are not sensitive in the way that video or audio are, but they do create detailed records of household or workplace activity patterns that, in aggregate, can reveal quite a lot about the routines and behaviours of the people in the space.
Why Companies Need the Data
It would be easy to frame this as companies collecting data they don't need for purposes that don't serve users. The reality is more complicated, and understanding that complication is necessary for thinking clearly about the problem.
Training data is the most important category. The core challenge in humanoid robotics right now is that these systems need enormous quantities of real-world interaction data to improve at manipulation, navigation, and task execution. Simulation can generate some of this, but real-world data — the actual sensor inputs and motor outputs from a robot doing real tasks in real environments — is more valuable for training models that will work in the real world. A company with a thousand robots deployed in homes and workplaces, all uploading operational data, has a significant training data advantage over a company with ten robots in a lab.
This creates a genuine tension. The same data collection that raises privacy concerns is also the mechanism by which the robot gets better. A company that collected no operational data would face a meaningful competitive disadvantage. The privacy trade-off is not simply a corporate choice to be exploitative; it reflects a real constraint in how these systems are currently developed.
Remote diagnostics and support are a second legitimate use. When something goes wrong with a robot — a task failure, a navigation error, an unexpected shutdown — the company needs information about what happened to diagnose and fix the problem. That information typically involves sensor logs, video from the moments before the failure, and operational data from the relevant time window. Without some version of this, manufacturers cannot maintain and improve their products in deployment.
Neither of these legitimate uses requires companies to retain raw video of private spaces indefinitely, share data with third parties, or use collected data for purposes beyond what users understand and consent to. But they do mean that some form of data collection is not a corporate imposition — it is a technical necessity, at least at this stage of the industry's development.
What the Policies Actually Say
Privacy policies for current humanoid robot products are, by and large, not written for devices of this kind. They tend to follow standard consumer electronics templates — language developed for smartphones and smart speakers, adapted and updated for devices with significantly greater sensor coverage, physical presence, and spatial intimacy.
The key questions that a well-constructed privacy policy for a humanoid robot should answer include: What data is collected? Where is it stored? How long is it retained? Who can access it? Is it shared with third parties, and under what conditions? Can users access, correct, or delete their data? What happens to the data if the company is sold, acquired, or shuts down? Are there uses of the data — for training, for research, for commercial purposes — that users are opting into by purchasing the device?
Few current policies answer all of these questions clearly. The data retention language in many policies is vague — data is retained "as long as necessary for business purposes," a phrase that provides almost no meaningful limit. Third-party sharing provisions are often broad. The training data question — whether your robot's operational data is being used to train the company's next-generation models — is addressed inconsistently, and in some cases not addressed at all.
This is not unique to humanoid robotics. It reflects a pattern across consumer technology where data practices are complex, policies are written by legal teams optimising for maximum flexibility, and users are expected to accept terms they cannot meaningfully evaluate. But the stakes are meaningfully higher when the device in question is physically present in your home, capable of capturing continuous video and audio of private spaces, and operating in environments that contain children, medical information, and domestic routines that people have strong interests in keeping private.
The Workplace Dimension
Most early humanoid deployments are in workplaces rather than homes, and the data privacy questions in workplace settings have a different character. Workers generally have reduced privacy expectations compared to their own homes, and employers have legitimate interests in monitoring work performance and safety. But "reduced expectation" is not the same as "no expectation," and the workplace data questions raised by humanoid robots go beyond what existing employment law and practice have addressed.
A humanoid robot operating in a warehouse generates persistent video and spatial data of the work environment, including the people working in it. That data potentially captures worker behaviour, movement patterns, interaction with colleagues, and performance metrics in fine-grained detail. Depending on how it is analysed, it could be used for workforce monitoring in ways that go well beyond traditional management oversight.
This is not hypothetical. Several existing warehouse automation systems already generate worker performance data — pick rates, movement efficiency, idle time — that companies use for management and, in some documented cases, for automated disciplinary decisions. Adding humanoid robots to these environments adds additional sensor coverage and data collection to workplaces already under significant technological surveillance. The question of what data humanoid robots generate about workers, who controls it, and how it can be used is one that labour law has not yet caught up with.
The European Union's General Data Protection Regulation (GDPR) and, in the workplace context, emerging AI Act provisions create some constraints for European employers. In the United States, workplace privacy protections are thinner, and the legal framework for AI-driven workforce monitoring is less developed. Workers in many US states have limited legal recourse against employers using continuous monitoring technologies, including, in many cases, video surveillance.
The Home Setting: A Different Problem
The home context raises privacy concerns of a different order. A humanoid robot in a home is not operating under an employment relationship with a privacy policy defined by an employer. It is in a space where people have the strongest legal and normative expectations of privacy, where children are present, where medical conditions and personal relationships play out, and where the intimacy of domestic life has historically been protected by physical walls.
Several companies are actively developing humanoid robots for home use. 1X Technologies, the Norwegian company backed by OpenAI, is developing its NEO robot explicitly for domestic settings. Apptronik has described home assistance as a target market. The ambition is to build robots that can help with household tasks — cooking, cleaning, laundry, care for elderly or disabled household members. The value proposition is real. The data implications have received almost no public scrutiny.
A home humanoid robot generates a continuous, high-resolution record of domestic life. It sees what is in the home, who is there, what they are doing, and when. It potentially hears conversations. Over weeks and months of operation, this record becomes a detailed portrait of private life that would, in any other context, require a court order to obtain. The question of who owns that record, what the company can do with it, and what protections exist if the company is breached, sold, or compelled by law enforcement is not yet answered by any clear legal framework or industry standard.
What Adequate Governance Would Look Like
The data problems raised by humanoid robots are not unsolvable. They are engineering and policy problems that the industry and regulators could address if they chose to prioritise them.
On the technical side, on-device processing — running the AI inference that drives the robot's behaviour on local hardware rather than sending raw data to the cloud — can substantially reduce the volume of sensitive data that leaves the home or workplace. Several companies are investing in this approach, both for privacy reasons and because cloud-dependent robotics faces latency constraints that limit real-time performance. Where data must leave the device, encryption, minimisation (collecting only what is genuinely needed), and defined retention limits are standard practices in other sensitive data contexts that the robotics industry could adopt.
On the governance side, what is needed is something that doesn't yet exist: a data framework designed specifically for embodied AI systems operating in private spaces. Existing frameworks — GDPR, the California Consumer Privacy Act, sector-specific rules like HIPAA — provide partial coverage but were not built for this context. The gap is real. A robot operating in the home of an elderly person who uses home health services potentially implicates healthcare privacy law, consumer protection law, and general data protection law simultaneously, in ways that no regulator has worked through clearly.
Industry self-governance, in the absence of regulatory clarity, has a poor track record in consumer technology. The pattern — technology deployed at scale, data practices set by legal teams optimising for flexibility, regulatory attention arriving years after the practices are entrenched — is familiar enough to be concerning. In the humanoid robotics case, the data being collected is more sensitive than most of what preceded it.
The companies building these devices, and the investors backing them, would be better served by engaging seriously with the data governance question now — before a significant breach, a regulatory action, or a public incident makes it impossible to treat privacy as a technical afterthought. The trust required to put a robot in someone's home is harder to build than the robot itself, and considerably easier to destroy.