Echoes of Privacy: Uncovering the Profiling Practices of Voice Assistants

Authors: Tina Khezresmaeilzadeh (University of Southern California), Elaine Zhu (Northeastern University), Kiersten Grieco (Northeastern University), Daniel Dubois (Northeastern University), Konstantinos Psounis (University of Southern California), David Choffnes (Northeastern University)

Volume: 2025
Issue: 2
Pages: 71–87
DOI: https://doi.org/10.56553/popets-2025-0050

Download PDF

Abstract: Many companies, including Google, Amazon, and Apple, offer voice assistants as a convenient solution for answering general voice queries and accessing their services. These voice assistants have gained popularity and can be easily accessed through various smart devices such as smartphones, smart speakers, smartwatches, and an increasing array of other devices. However, this convenience comes with potential privacy risks. For instance, while companies vaguely mention in their privacy policies that they may use voice interactions for user profiling, it remains unclear to what extent this profiling occurs and whether voice interactions pose greater privacy risks compared to other interaction modalities. In this paper, we conduct 1171 experiments involving 24530 queries with different personas and interaction modalities during 20 months to characterize how the three most popular voice assistants profile their users. We analyze factors such as labels assigned to users, their accuracy, the time taken to assign these labels, differences between voice and web interactions, and the effectiveness of profiling remediation tools offered by each voice assistant. Our findings reveal that profiling can happen without interaction, can be incorrect and inconsistent at times, may take several days or weeks to change, and is affected by the interaction modality.

Keywords: privacy, profiling, persona, voice assistant

Copyright in PoPETs articles are held by their authors. This article is published under a Creative Commons Attribution 4.0 license.