Pebble account option not linked to big tech!

New Pebble user that just received a Time 2 here. I only purchased a pebble because of the new companies commitment to open source. While I’m grateful that almost all the functionality appears to be available without an account, the settings app requires an account to view battery usage data. I would also like to try paid apps, and develop apps myself.

I have refused to use “sign in with” ever since I had to waste many hours decoupling a dozen accounts from Facebook a decade ago. My opinion is that big tech and surveillance capitalism are both incompatible with freedom and democracy, and the only account creation options currently available utilise such companies (Apple, Google, and Microsoft).

  1. Please implement alternative Pebble account options that do not require big tech accounts, such as email (even magic links) &/or passkeys. This will soon become a requirement for much of the global user base, as Americas democracy continues to collapse under the weight of its own political corruption.
  2. Also, please provide clarification about what pebble device data is shared with Pebble or alternate stores. While I expect my Pebble Core app usage and store interactions to be logged, I do not expect the devices health data, or other user app data (notifications, notes, reminders, speech-to-text transcripts, etc), to ever leave my devices.
23 Likes

Hi, also just ordered a PT2 and I am also not happy with the current options. Would be happy to see an alternative soon.

6 Likes

Some kind of explicit (and easily readable) privacy policy would be wonderful.

For what it’s worth, the stores themselves don’t get any data besides what apps you “like” and what apps you install. Health data isn’t sent anywhere except for if you sync it to Apple or Google. Audio for transcribing is sent off to Cactus if you use remote dictation. Notifications and other logs can get sent to Core Devices if you submit a bug report, though I believe the privary obfuscation option is enabled by default. Reminders are completely local, Core Devices literally doesn’t have a timeline server so they cannot send or recieve reminder/calendar timeline pins.

3 Likes

Not sure how it is on Android, but on the App Store, the privacy policy is a required part of any app listing and is linked to directly on the store page.

2 Likes

I ran into the same (no login options that I like). Then I wanted to report this (and one other, more “real” problem) as a bug - but reporting a bug requires signing in!

4 Likes

Gadget bridge is great! I think they might have also recently added App Store support. I’m not quite sure about that though. There’s also Micropebble, which is the app that I use. That one definitely has App Store support, both Core and Rebble App Store

3 Likes

Yeah I’ve seen it thanks @particles => Privacy Policy - Core Devices

It’s good enough regarding the store and phone-app specific data, but doesn’t explicitly state what Pebble device sensor data or user-specific content (if any) is shared with Core Devices LLC or third party app stores (beyond the standard location/IP, device identifiers, etc).

It’s important to hold corporations accountable and expect them to be explicit. If they’re allowed to be vague, they’re more likely to gradually (silently) add more data points to grow revenue streams, and before you know it they’re just another surveillance capitalism company where you are the product being sold; assimilated by the borg.

2 Likes

Awesome! Looks like all Pebble products are “highly supported” Pebble - Gadgetbridge

… but I’m on iOS due to past me’s decisions ~20 years ago, and distrust that Google won’t kill the AOSP, like they inevitably seem to be trying. Another app added to the list to try if I bite the bullet on GrapheneOS.

1 Like

Quoting the privacy policy:

the Pebble operating system and mobile applications

is a covered entity, and “What Information Do We Collect?” and “How Do We Use Your Information?” clearly enumerate all possible data transmission events.

In addition, the Pebble operating system and related features are entirely open source.

With all due respect, these documents are written by lawyers and have a certain amount of prerequisite knowledge and understanding required to parse them correctly.

I don’t know how to spell this out more. I don’t particularly have fondness for Eric, or the Pebble team, or anything else – but I have given them money. I think you are placing a lot of assumptions down that have no substantiation with respect to this hardware and software. The software is literally 100% open source, and Core Devices is the reprisal of Pebble, which was already bought by Google and assimilated into the borg. You can look at the exact history of the Pebble acquisition and subsequent liberation from Google as evidence of what has happened and could happen. But I’m like pretty sure that Eric is not down for that this time, and it’s clear that the reborn Pebble products are designed with protection against this in mind.

If you don’t like the software’s promises, you can compile it yourself. With agentic coding you could probably ask Claude to audit the codebase, remove anything that sends any data to Core Devices, and recompile the firmware with zero programming experience. I’m not exaggerating.

It is worth giving companies like Core Devices the benefit of the doubt. You have no idea who I am, but I have read hundreds of privacy policies, and this privacy policy is explicitly lacking any kind of broad “send data vaguely to third-parties to do whatever” you would expect to see if they were doing something shady. I do not believe they are. The terms of service are also quite explicit in what precisely they do with what data: Terms of Service - Core Devices.

I doubt you will find any product or service more open than Core Devices right now. And I say this out of no special love or anything for Core Devices. I’m still wearing my device, but like, I’m not in love. I generally speaking believe them to be honest and respectful. You can always express your GDPR protected and California protected privacy rights to ask them for a copy of data they have on you and explore it yourself, if you believe the privacy policy, the source code, and everyone else to be hiding something.

5 Likes

Upvote. I created an account to find a solution to this, disappointed that there is no option to simply create an account with an email.

I’ve never encountered any device or service that restricts access to these, except Apple for Apple devices, Google for Google devices.

I don’t “Sign in with Google” or others as a rule. Why using these services’ credentials is the only option is beyond me. I don’t see any upside in this restriction, only downside.

I’d like to hear arguments for this design decision, maybe I’m missing something in the wonders of signing in with a third party account. If it’s passkeys, those don’t appear ready for mainstream due to the fragmented ecosystem and poor handling by various providers.

5 Likes

Why using these services’ credentials is the only option is beyond me. I don’t see any upside in this restriction, only downside.

Cyber security is hard. Outsourcing user authentication to an established major provider is the quickest, simplest, cheapest mechanism to implement. It reduces spam, increases conversion (user just clicks a button and agrees most of the time), and every web auth library has the option built in.

The reasons to have them as an option are overwhelming, and the average user prefers it, but they are ultimately anti-competitive and monopolistic. The average user simply doesn’t understand the long term implications, friction, and risks in growing dependent on them (same as big tech). Source = am software engineer.

5 Likes

I think you are placing a lot of assumptions down that have no substantiation with respect to this hardware and software

My assumptions are based on being a software engineer, and a user of countless products and services which have been progressively destroyed or enshittified in the name of maximising profit over the last two decades; they are neither project or people specific.

I’m well aware of the product and company history. I’ve already given the company the benefit of the doubt by buying their product. I’m actually pretty confident that Eric is an honest, responsible, and ethical person; that Pebble is not shadily harvesting data, nor that it ever intends to. But I’m also completely confident that obscene wealth and power (even the prospect of it), corrupts obscenely, and that most people in tech are ignorant of how powerful mass surveillance + analytics is, or how dangerous and oppressive it will become as ai matures.

Open source doesn’t mean what it used to. When users wised up to “bait and switch” tactics being the standard operating procedure of most startups (illegal in almost every context outside the web), startups then switched tactics to the even greater deception of “foss-washing”; starting out as open source, and espousing the ideals, but later switching to proprietary or other predatory measures once they’d secured enough investment… Also frequently illegal, but it turns out that laws and licenses only matter when the criminals aren’t the ones enforcing them, or running the whole show! The best privacy laws of today are an entirely insufficient joke. Even Meta states “we respect and value your privacy” in their policies.

With all due respect, the USA, its most powerful corporations (in all of human history), and a significant proportion of its population, are consistently displaying a deeply sick level of greed, sociopathy, and psychopathy indicative of widespread, systemic indoctrination and mental illness. As someone who has expected this situation since the early days of the Bush admin, you’ll forgive me for not caring that the majority haven’t got the memo, nor grasped the gravity of the situation. I mean, the president only threatened to nuke and murder tens millions of innocent people last month… How bad could things possibly get, right?

Trust is earned and maintained through actions, constantly. Actions like proactively giving users the option to avoid monopolies, or explicitly commiting to avoid as much data capture as possible. Theis trust is more important in FOSS communities than anywhere else.

3 Likes

Thanks! I also wont use google and want to use this pebble as real open-source-device!

When buying, I did not see / read about needing google or apple for getting an app, so I did not expect having to need it.

I hope that there is an open-source way to use this watch as a developer or in every-day use, without having a company looking over my shoulder.

2 Likes

There’s matejdro/microPebble: An open source Pebble watch companion app
and Gadgetbridge. microPebble should have the majority of the features that the mainline Pebble Core app does. And if it doesn’t, then many features are just a PR away from being implemented.

No dice if you’re on iOS though. At least not yet.

1 Like

Fwiw, the Google account is only used as an OAuth provider, they don’t get any info other than that you have logged in to Core Devices. And presumably whatever Firebase stuff the Core app uses too.

There’s microPebble, it doesn’t require an account. The caveat there is that if you fully uninstall the app and reinstall it, your installed watchapps don’t get saved. This is the app I use day to day.

3 Likes

microPebble doesn’t have most of the new features that the Core app’s been adding. Off the top of my head:

  • No back+up/select quick launch setting
  • No backlight colour selector (this is supported!)
  • No weather API intercepting (though many weather apps have been patcted to use other APIs in the Rebble appstore)
  • No custom vibration pattern selection (this can be set for all notifications, just not individual apps)
  • No battery usage dashboard (can be somewhat replaced by Muninn, though not perfectly)
  • No Index feed
  • No Core Devices bug reporting (if you have any issues with our watrh you’ll need to uninstall microPebble, install the Core app, log in, and submit a bug report. Or create a bug report file (possibly without logging in?) and send it to support via email)

I’m sure there are more things that I’m not aware of too. There’s currently someone being paid by the Rebble Foundation to add iOS support, so hopefully that will happen soon.

3 Likes

Thank you for compiling and sharing this information. Looking forward to more microPebble development!

1 Like

Thanks for this one!
Definitely will give a try to microPebble and see if it is enough for my needs of customization. :hugs:

I guess it will still have more metrics/features than GadgetBridge anyway. :+1:t2:
That way I’ll also figure out if I even need most of the mobile Core-only features to begin with (currently most of them do not speak to me haha)!


That one is rough! wow.
No way to forward a bug on the forum or GH maybe (I’m not gonna join a Discord server for that either tbh)? I get the auth part being more easy with SSO but not having an easier workflow is indeed very meh when it comes down to bug reporting…

I will try to run my PT2 with microPebble and then maybe will also give a try to the mobile app? We’ll see what requires an account and what could be done to avoid an account at all cost.

I mentioned this thread on Github: [Question] about Mobileapp for Android without Google Services · Issue #118 · coredevices/mobileapp · GitHub
Not sure if I am missing some other concerns with the mobile app from Core devices or some other things, let me know if yes. :hugs:

You can send an email to core devices support, but it won’t have the standardized bug report logs that they expect. Last time I submitted a bug report, they had me install the Core Devices Pebble app :sweat_smile:

Also, I was wrong about not being able to pick the backlight color that is a new feature that got added to Micropeble.