In 2025, Transsion Holdings (the Shenzhen-based company behind the Tecno, Infinix, and Itel brands) accounted for roughly 48% of smartphone shipments across Africa which equates to more than 40 million of the 84.4 million handsets shipped on the continent, according to Omdia data. That dominance means nearly one in two new smartphones sold in Africa carries a built-in data collection system that researchers have now fully decrypted.
What the phones are actually sending
An independent researcher (publishing as Buchodi), working with the mobile security firm NowSecure, reverse-engineered the firmware of a Tecno Spark 40. They recovered the encryption keys embedded in the phone’s own software and decrypted the traffic.
The system called Athena for event collection and oneID for cross-app tracking, reports to Transsion-controlled domains (shalltry.com and related servers).
Key findings include:
- Precise GPS location (latitude/longitude and geohash), plus nearby cell towers and signal strength.
- Which app is in the foreground at any moment.
- Which app has just activated the camera (though not the content of what is filmed).
- Per-app data usage across dozens of apps in a single day, including mobile-money services such as M-Pesa, messaging apps, betting apps, and loan apps.
- A stack of roughly 14 permanent, non-resettable device identifiers that link every event back to the same handset for its entire lifespan.
This is not ordinary app-level analytics. On Transsion devices the collection framework runs as a privileged system component (system-signed and embedded in Settings, the system UI, the camera service, and a hub package labeled “TPMS” / com.hoffnung). Users cannot uninstall it; attempts to remove the package have been known to brick devices or cause boot loops. The data travels over the user’s own mobile connection, consuming prepaid airtime without consent or notification.
NowSecure’s reporting frames the traffic as exfiltration “to China.” The observed endpoints in the research sit on Alibaba Cloud infrastructure in Frankfurt (Europe) behind a CDN. Transsion is a Chinese company, the data pipeline references ByteDance analytics components, and Chinese companies are subject to national security laws that can compel data access. The direct observed hop is not always inside China, but ownership and potential onward flow create the geopolitical concern.
Transsion succeeded in Africa by designing phones for local realities: dual SIM, long battery life, cameras tuned for darker skin tones, and aggressive pricing that put smartphones within reach of lower-income users. That success also concentrated a large share of the continent’s mobile fleet under one manufacturer’s software stack.
The collection is device-wide and continuous. Because it is baked into the OS, standard Android sandbox protections do not apply. The same SDK also appears (in sandboxed form) inside popular third-party apps such as Boomplay (Transsion-owned music streaming), StarTimes, and Orange’s self-service app, extending the reach beyond pure Transsion hardware.
Privacy policies exist, but they lag the actual behavior. Location is described as consent-based and controllable; the research found the Settings app itself emitting location telemetry. Camera activity is not clearly disclosed. Few users read multi-thousand-word manufacturer policies, and nothing on the device itself asks permission or offers an opt-out.
This sits against a broader backdrop of Chinese technological presence in African digital infrastructure from network equipment to smart-city surveillance systems. The Transsion case is not classical spyware that records calls or camera video; it is persistent, granular behavioral and location telemetry that cannot be turned off by the owner.
What users can do (and the limits)
Because the component is system-level, the practical defense is network-level blocking: wildcard blocks of `.shalltry.com` and related Transsion domains via Pi-hole, NextDNS, or an on-device DNS filter. Single-server blocks are ineffective because the system rotates addresses. Standard mobile security advice (keep the OS updated, avoid untrusted apps) does little against firmware-level collection.
Experts note that heavy telemetry is not unique to Transsion alone as Google and Apple also collect substantial data but the lack of user control and the permanence of the identifiers set this apart. As one security professional put it, the real issue is the absence of meaningful user agency over whether the data is sent and how it is tied to a lifelong device identity.
Transsion has not yet issued a detailed public response at the time the research circulated in mid-July 2026. The technical findings are reproducible from firmware and live traffic, and they align with earlier user reports of persistent connections from Infinix and Tecno devices.
Africa’s rapid smartphone adoption has been a genuine development success story. The dominance of one manufacturer’s unremovable telemetry stack means a large fraction of that success now carries an opaque data pipeline whose full downstream use remains outside the control and often the knowledge of the people carrying the phones.





