Let's focus on the big players right now: Windows Mixed Reality (WMR), HTC Vive, Oculus Rift, PlayStation VR, Google Daydream, and Samsung Gear VR. All of them have privacy policies available to users on their websites, and not surprisingly, all have pretty similar clauses. The language may change a little from one brand to the next, but they essentially say the same thing.
Here's what the privacy policies for these brands have in common
Cookies are small files that store things like login information and ads you've already been exposed to on various sites. Beacons are a means for your device to communicate with a server and they're embedded in online content. That's not unique to VR; your laptop, desktop, phone, and tablet do it, too.
All will collect location-based information.
This includes things like your timezone and the country you live in; these have to do with apps and content availability, ensuring that user experiences are relevant for your part of the world with proper language availability and time-sensitive software upgrades. Those are necessities, so you can't mind them knowing where in the world you are.
All will share aggregate data with third-party companies.
This generally doesn't include your specific or personal data; it's more like the statistics of when people are actively playing and the numbers of regional users. That's not terrible, and most non-VR games and apps do that anyway.
With Google, you can opt in and allow your personal data to be shared with "companies, organizations or individuals outside of Google," otherwise it's the usual sharing with affiliates or for legal reasons.
All will take data about your IP address, the browser you're using, and your device.
Each will also ask for details like your name, an email address, and your date of birth. Depending on how much you want to honestly volunteer, you can falsify a handful of those "facts". Plenty of people do, but plenty of people provide their real information, and the choice is yours.
All will the use information they collect about you to guide their marketing strategies.
Sony does give you a choice, but it's whether you want your information shared with Sony Interactive Entertainment America (SIEA) or SIEA's third-party partners; either way, you're receiving direct marketing.
Part of the reason for this is, as always, unforeseen security breaches, but there is something else you need to be aware of. Your data may be transferred to servers throughout the US and around the world at each company's discretion since they're all international companies. Once your data is "over there", it's subject to the laws of that land, and those laws may be far less stable or enforceable. That's a little scary, but VR isn't the only industry doing it.
All communication via the social features of your VR is stored.
Your messages are generally saved in a temporary cache if they're between users, but more permanently if they're forum posts, like in the Oculus support community. However, there will always be a record that some form of communication happened between you and a friend or another user. Again, that kind of permanent digital trail of breadcrumbs isn't unique to VR, but it's good to be reminded that it's there.
No matter which VR you're using, your data will be shared with network affiliates and subsidiaries.
These large companies have many affiliates and subsidiaries, which aren't always easily tracked down. Some information can be found here.
So how are the privacy policies different?
The basic differences are pretty simple:
Let's add to that the fact that Facebook bought Oculus Rift in 2014. This means that whatever Oculus knows, Facebook knows, and that's unnerving for lots of people, especially in the wake of some recent bad press. Yes, Facebook has been collecting everyone's data, and it's not exactly being kept safe. To be fair, Facebook never said it'd keep your data safe, but that's a whole other can of worms.
The point here isn't to tear up one company for oversharing, but instead to raise awareness about how data is being handled when you're in VR. Oculus isn't exactly doing anything legally wrong ― what it's collecting is all laid out in writing ― though where that data goes is kind of alarming; Facebook is no stranger to highly publicized privacy concerns.
Remember, none of this is new. Some people call it spying, others call in necessary, and the companies that are producing top-notch VR call it business. Data makes companies a lot of money, and ignoring that stream when there is no legal reason to doesn't make sense.
What is your opinion on privacy in VR? What about the eroding privacy in our everyday lives? Let us know in the comments section!
Updated April 19, 2018: I've added information about Windows Mixed Reality, as well as some information about current Facebook privacy issues to ensure you're up to date on how the most popular VR companies are treating your privacy.
Get the Windows Central Newsletter
All the latest news, reviews, and guides for Windows and Xbox diehards.
Cale Hunt is formerly a Senior Editor at Windows Central. He focuses mainly on laptop reviews, news, and accessory coverage. He's been reviewing laptops and accessories full-time since 2016, with hundreds of reviews published for Windows Central. He is an avid PC gamer and multi-platform user, and spends most of his time either tinkering with or writing about tech.