Example of ZTE blatantly violating an NDA it signed. http://thepatentinvestor.com/federal-judge-says-vringo-has-c...
The way that Xiomi blatantly copies Apple, including the "one more thing", I wouldn't expect them to have any qualms turning any and all info to their govt. for any small benefit.
Also, a couple of months ago, Xiaomi phones uploaded adsressbook information to their servers without user permission. After the backlash, they issued software updates to ask for consent.
On a general note, one wonders how many instances of arbitrary data uploading they - by which I mean pretty much every 'cloud' integration provider - get away with.
Gather any data, upload it to an IP otherwise publicly known for benign purposes, over an encrypted connection with a closed-source sync daemon, and cover your ass with some vague and easily glossed-over clause in the privacy policy that no one reads. I hope otherwise but I am almost certain something like this exists in every commerical mobile OS today. :-/
I assume the consideration here is that the Chinese government (via Xiomai's cloud) is to be feared more than the US (via Google's Android backup) - which of course is a topic worthy of debate itself