In early August, Sapna Maheshwari published a New York Times feature on Nanit (paywalled; Techmeme entry here, headline: “Aw, It’s Baby’s First A.I. Surveillance System”). Nanit’s flagship product is a camera mounted directly above the crib. HD video streams to Nanit’s servers, machine learning logs the exact moment the baby’s eyes open and close, and the app rolls it all up into charts: a nightly sleep score from 0 to 100, a sleep-efficiency percentage, minutes to fall asleep, number of times a parent got up in the night.
When Bruce Schneier linked to the piece, his post title needed three words: “Spyware for Babies.”
That sounds harsh. Look at the scale first, then decide.
This is not a niche gadget
Nanit says it has one million daily active users and over $100 million in annual revenue (the company’s own figures, as reported by the Times). In December 2025 it closed a $50 million growth round led by Springcoast Partners, with Upfront Ventures and JVP participating.
The press release is plain about where the money goes: a “Parenting Intelligence System” rolling out in 2026 that moves beyond sleep to track breathing patterns, movement signatures, motor skill milestones, speech and language development, and “trends that may predict metabolic, emotional, or cognitive challenges.” Two numbers in the release say more about the direction than the feature list does (both are company-reported, with no independent verification): Nanit claims over 5 billion hours of infant sleep data from more than one million babies across 100+ countries, and says more than 70% of its active camera users keep using the product past age four. CEO Anushka Salinas, in her own words: “We envision a future where people can track and access their comprehensive health data from birth to 100 years old.”
Birth to 100. The baby monitor as a category is nearly ninety years old (Zenith’s Radio Nurse shipped in 1937), and for most of that time it was a transmission device: a microphone by the crib, a speaker by the parent, and if the baby cries you hear it. Nanit’s business is a different species. The device is an intake point; the product is a data platform. One detail the Times dug up makes the intent explicit: the consultancy that did Nanit’s branding wrote in its own case study that the central challenge was “how to introduce this novel technology to the parenting market while transcending the negative connotations of ‘surveillance.’”
What the privacy policy lists
To judge a product like this, the privacy policy beats the marketing page, because the policy is written for regulators. I read Nanit’s in full (last updated February 10, 2026). The collection list comes in three layers.
About parents: name, email, phone number, payment information, IP address, and the name of your home WiFi network. About the child: name, profile photo, gender, date of birth, plus whatever care logs parents enter by hand. About the nursery: video and audio recording, temperature, humidity, and computer-vision analysis of breathing motion during sleep.
Under purposes, alongside providing the service, sits a standard clause worth reading word by word: “legitimate interests” cover “direct marketing, research and development,” including “custom audiences advertising” and cross-device tracking. Custom audiences is a routine ad-industry mechanism: an advertiser uploads its customer list (emails, phone numbers) to an ad platform, the platform matches those against its own user base, and the matched people get targeted ads (Meta’s documentation describes the matching flow). Cross-device tracking stitches your phone, tablet, and laptop activity into a single profile. Nanit’s policy doesn’t name which platform it works with, but both practices are listed in black and white. To be precise about scope: the policy does not say the videos or sleep measurements themselves feed the ads. What it does establish is that personal information collected by a tool that helps your baby sleep enters the targeted-advertising pipeline.
Nanit does say it does not sell personal information, but the sentence has a second half. The policy’s position is that its practices don’t meet the CCPA definition of “sale”, while conceding that the third-party analytics tools it uses “may be construed as a ‘sale.’” The CCPA defines sale more broadly than everyday usage: transferring personal information to a third party for “monetary or other valuable consideration” counts, and money doesn’t have to change hands. So the accurate reading of the disclaimer is this: Nanit argues its practices fall short of the statutory definition, while acknowledging that data does flow to third-party analytics and advertising services.
Two more items. The policy gives no concrete retention period, only that data is kept “as long as you use our Services or as necessary to fulfill the purpose(s) for which it was collected.” It also states outright that it does not honor browsers’ Do Not Track signals. I looked for a clause restricting the use of video and audio for training AI models. There isn’t one.
The security is decent; security is not privacy
To be fair: the measures on Nanit’s security page are serious by consumer-product standards. Video is encrypted with 256-bit AES. Streams are push-only: Nanit’s servers push video to your device, and nothing can pull video directly off the camera. Two-step verification is mandatory, not optional. The company states that general employees cannot access customer video streams, and recordings are stored in the cloud only if you opt into an Insights subscription.
All of that answers one question: can outsiders get in? The core privacy question is a different one: what does the company itself do with the data? Encryption stops hackers. It does not stop a business model. Product pages tend to blur these two questions together; parents evaluating the product should keep them apart.
There is a third question that gets less attention: whether the data is even accurate. The Times reports that the camera logs visits and crying episodes that never happened. And Columbia pediatrician Rebekah Diamond’s worry in the piece cuts deeper than accuracy: “Parents are losing a little bit of the muscle of their own confidence and decision-making.” When a score tells you every morning how last night went, you slowly substitute it for your own observation, even if you have no idea how the score is computed.
Why regulation doesn’t catch this
US privacy law mostly idles on this product category, and the reasons are worth taking apart.
HIPAA applies to “covered entities”: health plans, healthcare providers, healthcare clearinghouses, and their business associates. Nanit collects breathing and sleep data that looks a lot like medical data, but it is a consumer electronics company, not a covered entity, so HIPAA does not reach it. The trigger is who holds the data, not what the data is: the same measurements in the hands of a hospital would fall under HIPAA’s rules, while for data coming off a camera above a crib, the constraints that remain are the company’s own privacy policy, the FTC’s authority over unfair or deceptive data practices, and a patchwork of state privacy laws. That is a much thinner net.
COPPA looks on-point and also misses. Its core mechanism is verifiable parental consent: it exists to stop companies from collecting data online from children behind their parents’ backs. Per the FTC’s own FAQ, COPPA covers information collected online from the child; information about a child that an adult volunteers is out of scope. With a baby monitor, the parent buys the camera, installs it, and types in the birth date, which on the FTC’s reading is adult-volunteered information. Whether the statute could still reach what the camera itself records automatically is a fact-specific question that turns on details like whether the service counts as directed to children; I won’t pretend to settle it here. What is clear is that COPPA assumed the parent is the gatekeeper of the child’s privacy; it did not anticipate a structure where the parent hands the data over. And the actual data subject, the baby, cannot invoke any rights personally: for years, whatever rights state privacy laws provide are exercised on the child’s behalf by the parent, the same person who installed the camera. If the camera stays in use, by the time the child is old enough to object, the file may already run the length of a childhood.
Three questions parents can ask
At the practical level, I think evaluating any product in this category comes down to three questions.
One: where is the data processed? On-device analysis with nothing uploaded and cloud processing are two different risk classes. Nanit is cloud-based; non-WiFi local monitors such as eufy’s exist, where the camera talks directly to a dedicated parent screen and the video never touches the internet. Settle this before buying.
Two: how does the company make money? Hardware plus subscription is one model; data monetization is another. Don’t judge by the marketing. Judge by whether the privacy policy contains marketing, advertising, and third-party-sharing clauses. As shown above, Nanit’s contains all three.
Three: what does leaving cost? Can you delete the data? (Nanit takes deletion requests at privacy@nanit.com. Read the 45-day language carefully: the policy promises to inform you within 45 days if it declines to act on a request, not to complete every deletion within 45 days.) The policy states the company can revise it at any time, so today’s promises don’t bind tomorrow’s version. And if the company is merged, acquired, or sells its assets, the data can transfer as part of the deal. That last part is not speculation; the clause is in Nanit’s policy. Both points belong in any evaluation of a startup’s data promises.
One more general habit: read the feature list as a collection list. A new “insight” on the product page (breathing monitoring, language development, mood trends) may need a new stream of data behind it, and whether it actually does is something to check feature by feature against the vendor’s documentation and privacy policy. Unless the vendor states that a new feature uses only existing data and runs on-device, treat a feature upgrade as a possible collection upgrade.
Infant data differs from adult data in two basic ways: the subject cannot consent, and nothing about it is resettable. A leaked password can be changed; as NIST puts it about biometrics, “changing compromised passwords is easy, but changing your biometric information is not.” A person’s breathing patterns, sleep curves, and language development from day one are in the same category: no reset button, and once leaked, the remedies are thin. When Nanit’s CEO says “from birth to 100,” she is describing the center of the fundraising story as much as a product vision — the 5 billion hours of sleep data sit right there in the $50 million press release. The hardware is the least of it. What the category leader has made the default is a file that starts on day zero, with consent given by someone else. And defaults are the hardest thing to renegotiate.
References
- Aw, It’s Baby’s First A.I. Surveillance System (The New York Times, 2026-08-02, Sapna Maheshwari; via Techmeme) — core feature facts: 0–100 sleep score, eye open/close logging, company-reported 1M daily users and $100M+ revenue, branding consultancy quote, false-positive detail, Dr. Diamond quote
- Spyware for Babies — Schneier on Security — where I found the story; only the title is cited in the text
- Nanit Privacy Policy — collection list, data purposes, CCPA “sale” language, retention wording, DNT, deletion requests and the 45-day notice-if-declined wording, policy revision and merger/transfer clauses
- Nanit Privacy & Security — encryption, push-only video streaming, mandatory two-step verification, employee access limits, Insights subscription and cloud storage
- Nanit Raises $50M… (PR Newswire, official press release, December 2025) — funding details, Parenting Intelligence System, 5 billion hours of data, 70% of active users continuing past age four, CEO quote
- HHS: HIPAA covered entities — HIPAA’s scope (health plans, healthcare providers, healthcare clearinghouses, and their business associates)
- FTC: Privacy and Security Enforcement — FTC’s Section 5 authority over unfair or deceptive practices involving consumers’ personal data
- FTC: Complying with COPPA FAQ — COPPA covers only information collected online from the child; verifiable parental consent mechanism
- California Civil Code §1798.140 (CCPA/CPRA) — statutory definition of “sale” (monetary or other valuable consideration)
- Meta Business Help Center: About Hashing Customer Information — custom audiences list upload and matching mechanism
- NIST: Facing the Facts to Keep Our Biometrics Secure — unlike passwords, compromised biometric information cannot be changed
- Slate: Zenith’s Radio Nurse Was the World’s First Baby Monitor — origin of the baby monitor category (1937, one-way audio)
- eufy: Non-WiFi Baby Monitors — example of local, non-connected monitors
- Democratic Underground forum transcription — used to verify NYT quotes verbatim (branding consultancy, false positives, Diamond quote)
- The Hustle: Even babies are living in an AI-powered surveillance state — cross-check of NYT reporting; none of its exclusive figures cited in the text