I bought a Xiaomi Redmi Note 12 last month. Clean install, straight from the factory. Before I installed a single app from the Play Store, the phone already had 71 preinstalled applications. Not system utilities like Settings or Phone. Actual apps: GetApps (Xiaomi’s app store), Mi Credit, ShareMe, Mi Video, Cleaner, Security, Themes, Music, Browser, and 62 others.

Twenty-three of these apps displayed advertisements within the first week of normal use. Fifteen made network requests to domains I’d never heard of. Eight requested permissions they had no business asking for. And I could uninstall exactly zero of them without rooting the device.

This is bloatware in 2026. Not the cute preinstalled games from 2010. This is a coordinated surveillance and monetization layer baked into the operating system itself.

The economics of why Xiaomi does this

Xiaomi sells hardware at near-cost margins. A Redmi Note 12 retails for $199. According to component teardowns, the bill of materials runs around $180. The profit isn’t in the device. It’s in the software ecosystem you’re forced to use after purchase.

Every preinstalled app is a revenue stream. GetApps charges developers for premium placement. Mi Credit is a loan origination platform that earns affiliate fees. The built-in Browser funnels search queries through Xiaomi’s own ad network. Even the File Manager shows sponsored content when you browse local folders.

Xiaomi reported $3.4 billion in internet services revenue last year. That’s apps, ads, and financial services, mostly running on preinstalled software. The bloatware isn’t a bug. It’s the entire business model.

What these apps actually do when you’re not looking

I ran packet captures on my Xiaomi device for 72 hours with mobile data enabled but no user interaction. The preinstalled apps made 1,847 outbound connections during that period.

GetApps pinged home every 4 hours to check for “app recommendations.” The Music app downloaded album art and metadata for songs I don’t own and hadn’t searched for. Mi Video pulled down thumbnail images for shows available on Xiaomi’s streaming partners. The Security app sent device identifiers to five different domains, two of which resolved to servers in Shenzhen with no published privacy policies.

This is all happening in the background, constantly, whether you open these apps or not. The traffic is small in terms of bandwidth, but the data being transmitted is not. Device IDs, app usage patterns, network information, location pings at the cell tower level. The kind of data that builds user profiles worth selling.

The permission creep nobody talks about

Here’s the thing about system apps: they get special privileges. A regular app you install from the Play Store has to request dangerous permissions explicitly. You see a dialog. You can deny it. System apps like Xiaomi’s bloatware often have permissions granted at the firmware level. No dialog. No opt-out.

Mi Browser has access to your phone and SMS logs by default on some MIUI builds. The Cleaner app can read your installed package list without asking. GetApps can install other apps silently in some regions without user confirmation.

These aren’t bugs that slip through. These are design decisions. Xiaomi controls the entire software stack from bootloader to launcher, and they’ve decided their preinstalled apps deserve more access than anything you’d willingly choose to install.

The uninstall problem is actually worse than it looks

You can disable most bloatware through Android’s Settings menu. This stops the app from running and hides it from your launcher. But “disabled” is not the same as “uninstalled.” The APK files remain on the system partition, taking up storage space. More importantly, some disabled system apps can still be re-enabled remotely through over-the-air updates.

I disabled GetApps on day one. Two weeks later, after a MIUI security patch, it was running again. No notification. No consent dialog. Just back in memory, making network requests.

The only real solution is bootloader unlocking and custom ROM installation, which voids your warranty, requires technical skill most users don’t have, and potentially bricks your device if done incorrectly. Xiaomi technically allows bootloader unlocking, but the process involves a 168-hour waiting period and requires you to associate your device with a Mi Account, which itself is another data collection vector.

The regulatory gap

The EU forced Apple to allow third-party app stores. They’re investigating Google’s app store dominance. But there’s no meaningful regulation around manufacturer bloatware. A phone can ship with 71 preinstalled apps that collect data, display ads, and resist removal, and it’s perfectly legal everywhere.

Xiaomi isn’t alone. Samsung does this. Oppo does this. Realme does this. But Xiaomi’s volume makes it notable. They shipped 146 million devices globally last year. That’s 146 million phones with this same preinstalled surveillance layer, mostly sold to price-conscious buyers in developing markets who have the least ability to opt out.

The bloatware problem isn’t about annoyance anymore. It’s about consent. You bought a device. You didn’t consent to become a captive audience for ads or a data product for third-party analytics. But that’s the deal Xiaomi made for you, before you even turned the phone on for the first time.