Fing
fing.comFing is a network scanner and cybersecurity monitoring product for home users and IT professionals. The single available policy document is a 2022 GDPR-oriented privacy policy that is reasonably transparent about data collection and user rights, and states that Fing does not sell personal data. However, it is over four years old relative to the analysis date, is silent on nearly all AI/ML processing despite the product marketing being explicitly AI-centric, discloses broad advertising-partner data sharing, and names no security certifications. No terms of service, DPA, or security page was retrievable, so ownership, retention specifics, and enterprise carve-outs cannot be verified. Business users should treat it as moderate risk and seek contractual protections before processing sensitive network data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The privacy policy describes what data users submit (MAC addresses, IP addresses, account details) but does not address ownership of user-submitted data or prompts in any terms-of-service sense. No terms of service was available to establish ownership, so this remains unresolved.
Output Data Ownership
The document is a privacy policy and does not address ownership of any results, scans, or outputs generated by the product. No terms of service was retrievable to clarify this. Silence on output ownership is itself a gap.
Training Data Usage
Despite the product being marketed as powered by a decade of machine learning, the privacy policy never mentions using user inputs to train or improve models. It does reserve broad rights to use data to 'improve our products and services' and to anonymize and share data with third parties. The absence of any explicit statement on model training, combined with these broad improvement rights, leaves training use ambiguous.
Data Retention & Deletion
Retention is described only generically as 'as long as necessary,' with no specific retention schedule except a one-month cap on call recordings. Users can request erasure by email or letter (with ID verification), so a deletion pathway exists, but there is no deletion SLA or defined timeline.
Third-Party Data Sharing
The policy states Fing does not sell personal data and generally does not share it outside Fing, but it then discloses sharing with a broad range of processors and, notably, advertising partners including device identifiers and hashed email addresses. This advertising-related sharing goes beyond what a network-scanning utility strictly requires, though it is disclosed. International transfers to jurisdictions without adequate protection are also acknowledged.
Opt-Out Rights
The policy provides concrete opt-out mechanisms: users can turn off device recognition, oppose direct marketing at any time by email or via any newsletter, and withdraw consent at any time. These are explicit and actionable opt-out rights, though opting out of advertising-partner sharing specifically is less clearly addressed.
Compliance & Certifications
The policy claims compliance with GDPR and references the Irish Data Protection Commission, but names no third-party certifications or attestations. No SOC 2, ISO 27001, ISO 42001, or other baseline security/AI framework is mentioned. For a product handling network and security data, the absence of any named security certification is a significant gap.
Model Explainability & Auditability
The policy provides no transparency into model behavior, decision logic, or enterprise auditing capabilities. Despite the product marketing its machine-learning device recognition, there is no explainability or audit provision anywhere in the document.
Security Practices & Breach History
The policy asserts generic administrative, technical, and organizational security measures but names no specific controls such as encryption at rest/in transit, penetration testing, or a bug bounty. No breach history is disclosed and no security page or trust center is referenced in the available text.
Enterprise vs. Consumer Risk Delta
The policy distinguishes an unregistered 'Fing basic' user (no name/email collected, only IP and MAC addresses) from registered account holders and Fingbox users (name, email, location, password collected). This shows a data-minimization tier for anonymous use, but no paid/enterprise agreement was available to assess differing data handling on paid tiers.
Human Review of User Inputs
The policy indicates authorized personnel may access personal data for their professional tasks and that call recordings and forum content may be reviewed and moderated. It does not specifically state whether staff read individual network-scan data, so the scope of human access is only partially defined.
Regulatory & Litigation Exposure
The policy acknowledges it may disclose customer data to competent authorities, legal institutions, and in response to law enforcement requests. No pending litigation or government-request history is disclosed. This is standard language but confirms cooperation with legal requests.
PII & SPI Data Inventory
Fing collects significant PII including name, email, location, IP address, MAC addresses, device identifiers, and detailed usage/clickstream data. It also lists financial/economic data, professional data, and location data as categories processed. This is a substantial PII inventory with adequate disclosure, but the breadth of collected categories (including precise location and network data about third-party devices) warrants caution.
Policy–Product Currency
The only available policy is dated June 21st 2022, version 2.0 — over four years stale relative to the September 2026 analysis date. The product markets itself as AI/machine-learning-powered ('Powered by a decade of machine learning'), yet the policy never addresses AI/ML processing, model training, or third-party model providers. This combination of staleness and lack of AI coverage justifies a RED rating.
Cross-Document Consistency
Only one document (the privacy policy) was retrievable; the referenced DPA and MSA URLs were inaccessible, making a cross-document consistency check impossible. However, the privacy policy contains an internal tension: it states Fing does not sell, distribute, or lease personal data, while elsewhere disclosing sharing of device identifiers and hashed emails with advertising partners. This is an internal inconsistency, not a cross-document one, so no contradiction is recorded per instructions.
You've read all 15 risk ratings for Fing. Create a free account to see the exact policy wording behind each rating.