Mrs. Technology

| Women’s Tech Education

Your Smart Home Devices Know More About You Than Y

Your Smart Home Devices Know More About You Than You Think. Here Is How to Stop Them.

&#middot;

&#middot;

If you’ve stood in your living room and wondered whether the speaker on the counter is listening to a conversation you’re having across the room — even when you haven’t said its name — you are not paranoid. You are paying attention. In 2026, the average US household with smart devices has between 17 and 25 connected endpoints (smart speakers, doorbells, thermostats, vacuums, light bulbs, TVs, displays), and almost none of them ship with privacy turned on by default. The defaults favor data collection. The FTC has now settled with three of the largest smart-home camera companies for exactly that pattern.

This guide walks through what each category of device is actually collecting, what stays on the device versus what goes to a vendor’s cloud, and the concrete steps you can take this weekend to lock it down — without throwing your smart home in the trash. I’m not going to tell you smart devices are evil. I’m going to show you which knobs actually do something, which vendor claims to look past, and which settings will quietly undo themselves in a firmware update.

I’ve organized the article by device category (speakers → cameras → locks → thermostats/TVs) and closed with a 7-step lockdown checklist you can save as a PDF and run through once a month. Every factual claim is linked to a primary source — the FTC settlement press release, the EFF’s actual published guidance, Mozilla’s Privacy Not Included reviews, or the vendor’s own privacy policy page. If a vendor makes a claim in their marketing that doesn’t match what’s in their policy, I’ll say so.

What Your Devices Actually Collect (and Why)

The first thing to internalize is that “smart” in 2026 means “internet-connected sensor with a microphone, camera, or both, plus a cloud backend.” Every category of smart device ships with at least one of the following collection streams:

  • Audio. Smart speakers, displays, doorbells, and some thermostats have always-on microphones that listen for a wake word locally. Once the wake word fires, the audio is uploaded to a cloud server. Per the EFF’s 2022 smart-home privacy guide, even after wake-word rejection the device may transmit short audio snippets for “false-acceptance” tuning.
  • Video. Doorbells, indoor cameras, outdoor cameras, robot vacuums (yes, really — most 2025+ models have obstacle-avoidance cameras mapped to your floor plan), and some smart displays have continuous or motion-triggered video. Without end-to-end encryption, this video is stored on a vendor-controlled cloud server.
  • Motion and presence. Motion sensors, smart locks, and presence-detecting lights log who is home and when, with timestamps. Some smart locks log every open/close event including partial opens.
  • Voice biometrics. Alexa, Google Assistant, and Siri all build a voice ID over time — a fingerprint of your voice used to identify who’s speaking in a household. You can disable it, but it’s on by default.
  • Ad identifiers. Most vendor apps register your device with an advertising ID that ties your usage patterns to a profile. Even if you opt out of “ad personalization,” the ID may still be collected.
  • Behavioral telemetry. “Product improvement” toggles, which are typically ON by default, send usage data — which features you tap, how often, what fails — back to the vendor for analytics.

The Electronic Frontier Foundation’s Surveillance Self-Defense “Your Security Plan” framework is the cleanest way to think about which of these streams are problems for you. The framework asks three questions: what do you want to keep private, who do you want to keep it private from, and what happens if you fail? If your answer is “I’m fine with Amazon knowing when I turn my lights on, but not with Amazon knowing when I’m home and when I’m not,” that’s a different threat model than “I don’t want any vendor to know anything.” Both are valid. The settings are different.

Why Local-First Matters in 2026

The single biggest shift in the smart-home industry between 2024 and 2026 has been the move toward local-first architecture — processing data on the device itself, or on a hub in your home, before any cloud upload. This isn’t a marketing trend; it’s a technical response to two converging pressures: privacy regulation in the EU and California, and latency demands from AI features that work better when there’s no round-trip to a remote server.

Matter 1.4 (finalized September 2024) and Matter 1.6 (released 2026) made the local-first case explicit in the spec — devices that pass Matter certification are required to support local control even when internet is down. My 2026 Thread hubs guide covers which hubs actually implement this cleanly. The short version: if you want a smart home where the vendor doesn’t see what’s happening inside it, Matter + Thread + a hub that processes locally (Apple HomePod, Home Assistant Yellow, Hubitat Elevation) is the closest thing we have to that in 2026.

Apple’s HomeKit Communication Security architecture is the clearest implementation of local-first in any major ecosystem. With HomeKit Secure Video, your camera’s video stream is processed on a HomePod, Apple TV, or iPad in your home — face recognition, package detection, motion zones — and only encrypted, anonymized clips are uploaded to iCloud. Apple explicitly states that they cannot read the contents of these clips even with a subpoena, because the encryption keys live on your local Apple devices. This is not marketing; it’s documented in the security guide linked above.

Google and Amazon both support local processing in specific cases (Google’s local presence sensing, Alexa’s “Local Voice Control”), but the default for most actions still involves a cloud round-trip. If local-first is your priority, plan your hub choice accordingly. The trade-off is a smaller device catalog and more upfront setup time. For most readers, that’s a worthwhile trade.

Smart Speakers: The Always-On Question

The honest answer is: technically, no, your smart speaker is not “always listening” in the sense most people worry about. The wake-word detection runs locally on the device, and audio that doesn’t match the wake word is discarded in milliseconds. That’s verifiable by reading the firmware source for any major vendor, and it’s consistent with what Mozilla’s smart-speaker privacy comparison documents.

The honest caveat is: the wake word fires more often than you think. Coughs, TV audio, similar-sounding words, accidental activations from a podcast or a YouTube video saying “Alexa” — all of these can trigger an upload. And once the upload happens, the audio is on a vendor server, retained for some period, and potentially reviewed by humans for quality purposes (Amazon, Apple, and Google all confirm human review of a small percentage of recordings for “improving speech recognition” unless you opt out).

The 2026 Voice Assistant Showdown guide walks through which platform gives you the most control. The short answer for speakers:

  • Amazon Alexa: Default retention is “until I delete them.” You can change this to “delete after 3 months” or “delete after 18 months” in the Alexa Privacy Hub. You can also disable “Help Improve Alexa” (which sends recordings to human reviewers) and “Use messages to improve transcriptions.”
  • Google Assistant / Gemini: Default retention is “until I delete them,” but Google now lets you set auto-delete at 3, 18, or 36 months. Per the Google Home & Nest Privacy Hub, you can also disable Voice & Audio Activity entirely, which prevents Google from storing any audio at all (at the cost of losing “Hey Google” personalization).
  • Apple HomePod / Siri: Default is “do not retain audio recordings” when you opt in during setup. Siri requests are associated with a random device identifier rather than your Apple ID, and audio is deleted after processing. The trade-off is that Siri is meaningfully less capable than Alexa or Gemini in 2026.

None of these platforms are “perfect.” All three have updated their defaults within the last 18 months in response to EU Digital Markets Act pressure and consumer complaints. But all three give you genuine, verifiable controls — the key is that you have to actively engage with them. The default settings are not the privacy-preserving ones.

Smart Cameras: The Ring, Eufy, and Verkada Reality

Smart cameras are where privacy enforcement has actually caught up with the industry. Three of the largest camera vendors have settled FTC or state attorney general actions in the last three years. These settlements are the receipts for why “but the marketing says end-to-end encrypted” is not a substitute for reading the actual security history.

Ring. In May 2023, the FTC charged Ring with illegally surveilling customers — Ring employees had unrestricted access to customer video feeds, and at least one case involved an employee accessing a customer’s camera while they were in the bathroom. The 2023 settlement required Ring to pay $5.8 million in refunds (which started flowing in April 2024 per the FTC’s refund announcement) and to delete any videos it shouldn’t have retained. Ring is still on the market, still works, and has implemented additional access controls since the settlement.

Verkada. In August 2024, the FTC settled with Verkada for $2.95 million over a 2021 incident in which a hacking collective gained access to 150,000 customer cameras — including cameras inside hospitals, prisons, and (notoriously) a Tesla factory. The settlement required Verkada to implement a comprehensive information security program and to delete all data it shouldn’t have retained. Verkada continues to sell enterprise-grade cameras; if you use them at work, your employer’s IT team should have documentation of the post-settlement security posture.

Eufy. In 2025, New York Attorney General Letitia James secured $450,000 from two companies selling Eufy-branded cameras over allegations that the cameras uploaded unencrypted user data and used facial recognition without consent. The settlement is a state-level action, not federal, but it signals that consumer-protection enforcement is not limited to the FTC.

What does this mean for you, the person buying a camera today? Three things:

  • “End-to-end encrypted” is not the same as “private.” E2EE protects the data in transit and at rest on the vendor’s server, but the vendor still holds the encryption keys. If the vendor gets hacked (Verkada) or an employee abuses access (Ring), E2EE doesn’t help. The strongest privacy posture is local processing + E2EE — Apple HomeKit Secure Video is the only major example that does both.
  • Default settings matter. If your camera ships with cloud recording enabled by default and you don’t actively turn it off, the vendor is recording. The fix is in the app, not the hardware.
  • Two-factor authentication on the vendor account is non-negotiable. Most of the Verkada-class breaches started with stolen employee credentials. The same applies to your personal account — if you reuse your email password and a credential-stuffing attack succeeds, the attacker doesn’t need to break E2EE.

For a fuller audit framework, the 2026 Smart Home Security Checklist walks through the camera-specific lockdown steps in more detail.

Smart Locks, Doorbells, and the Tenant Privacy Problem

Smart locks are the device category with the most documented legal-landscape risk in 2026. The technical capabilities are real and useful — temporary guest access codes, automatic lock-when-you-leave, alerts when the door opens — but the data they generate (who entered, when, with which code) is exactly the kind of data that surfaces in custody disputes, landlord-tenant conflicts, and (more rarely) criminal investigations.

The EFF published a 2023 piece arguing that smart locks endanger tenants’ privacy and should be regulated. The core concern: when a landlord installs a smart lock on a rental property, the landlord gets a log of every entry and exit — and may have the ability to unlock the door remotely without the tenant’s consent or knowledge. In some US states, this is a gray area legally. The EFF’s argument is that tenants should not have to choose between renting the unit and giving up a log of their comings and goings.

If you rent, three things to check before you sign a new lease or move into a property with a smart lock:

  • Does the landlord have remote unlock access? Some locks have a feature called “remote admin” that allows the account holder (often the landlord or property manager) to unlock the door from anywhere. If yes, ask for that access to be removed from your tenancy account before you move in.
  • Can the landlord see the activity log? Most consumer-grade smart locks log every open and close event. Ask whether this log is shared with anyone outside the unit.
  • What happens to the data after you leave? Some locks retain historical data indefinitely on the vendor’s cloud. Ask whether your data will be deleted when your tenancy ends.

If you own your home and you’re choosing a smart lock for yourself, the privacy calculus is different — you control the account, you control the data. Most major smart locks (Schlage Encode, Level Lock+, Yale Assure) have reasonable defaults in 2026 and offer local-only modes that don’t require a cloud account. The trade-off is that you lose remote-unlock from outside the home.

Thermostats, TVs, and the Quiet Trackers

The most under-discussed privacy leaks in a smart home are the devices people forget they own. Three categories stand out in 2026.

Smart thermostats. A learning thermostat logs when you’re home, when you’re away, when you go to bed, when you wake up. Combined with geofencing (your phone’s location triggering the “away” mode), this generates a precise daily-routine fingerprint. Nest, ecobee, and Honeywell all offer local-control options that don’t require a cloud account, but the cloud-dependent features (learning, scheduling, energy reports) require sharing this data. The trade-off is real: the thermostat becomes meaningfully less useful if you turn off the data sharing.

Smart TVs and streaming devices. Modern TVs use Automatic Content Recognition (ACR) to identify what’s playing on screen — including content from cable boxes, gaming consoles, and DVDs. This data is sold to advertisers and data brokers. Samsung, LG, Sony, and Vizio all have ACR enabled by default; you can disable it in the settings, but the menu is usually nested under “Terms & Privacy” or “Viewing Information Services.” Roku and Fire TV devices have similar tracking under different names. The April 2026 Google Home update added more granular control for Google TV devices specifically, including a per-app ACR toggle.

Smart displays and voice ID. Echo Show, Nest Hub, and Google Assistant on Android all support Voice ID

Smart TV with Samsung privacy settings and a Google Home Mini speaker on a wooden shelf with a plant and a book
A real smart-home setup: TV with vendor privacy settings on screen, voice assistant on the shelf, plant nearby. Default settings are usually the data-collecting ones.
— they learn to recognize who’s speaking in a household and personalize responses accordingly. Voice ID is convenient (you get your own calendar, not your partner’s), but it requires the vendor to maintain a voiceprint of every household member on its cloud servers. Google’s privacy hub documents how to delete a voiceprint; the setting is under “Voice & Assistant → Voice Match → Delete Voice Match.” If you have children in the household, this is also where you can manage Voice Match for kids.

Across all three categories, the recurring pattern is the same: the default behavior maximizes data collection, the privacy-preserving setting is one or two menu layers deep, and the vendor’s marketing language downplays how much is being collected. The 7-step lockdown in the next section is the practical counter to this.

Lit pendant lamp on a teal accent wall — warm smart lighting example
Smart lighting is one of the easier categories to keep local-first: the bulb does its work without needing to call home.

The 7-Step Privacy Lockdown

This is the actionable checklist. Print it, save it, run through it once a month. Each step is concrete; none of them require technical expertise beyond navigating a phone app and a router admin page.

Step 1: Threat-model yourself (15 minutes)

Before you change a single setting, write down three things:

  1. What do I most want to keep private? (Common answers: my daily routine, my kids’ voices, who comes to my front door, my medical-device data.)
  2. Who do I most want to keep it private from? (Common answers: the device vendor, advertisers, my internet service provider, a specific person who has access to my home.)
  3. What is the worst realistic outcome if I fail? (Common answers: targeted phishing, identity theft, a break-in informed by knowledge of when I’m home, an abusive ex-partner knowing my routine.)

You don’t need a fancy framework. The EFF’s Surveillance Self-Defense “Your Security Plan” has a more thorough version if you want one. The point is to anchor your decisions in what’s actually at stake for you — not in a generic “more privacy is better” rule.

Step 2: Create a separate email for smart-home accounts (5 minutes)

Set up a dedicated email address (Gmail, ProtonMail, or whatever you already use) that you only use for smart-home device accounts. This isolates breach notifications from your personal email, makes it easier to delete the whole ecosystem if you ever want to, and lets you set up stronger filtering on smart-home-related messages. Don’t reuse a password from any other account.

Step 3: Strong unique passwords + 2FA on every vendor account (30 minutes)

Every smart-home vendor account (Amazon, Google, Apple, Ring, Eufy, Arlo, SimpliSafe, whatever you have) needs:

  • A unique password that you don’t use anywhere else. Use a password manager — Bitwarden (free), 1Password, or Apple/Google built-in. Don’t reuse passwords.
  • Two-factor authentication enabled, ideally an authenticator app (Authy, Google Authenticator, or your password manager’s built-in TOTP) rather than SMS. SMS 2FA is better than nothing.

This is the single highest-leverage step. Most of the camera-class breaches of the last three years started with credential reuse or stolen passwords. Per the FTC’s enforcement actions, vendors have improved their security postures since 2023, but the customer-side credential hygiene is still the largest unprotected surface.

Step 4: Audit microphone, camera, and location permissions (20 minutes)

Open each smart-home vendor app on your phone. Look for:

  • Microphone access for the vendor app — most vendor apps request this. Disable unless you use the app to talk to the device.
  • Location access — “always” is rarely needed; “while using” is usually sufficient.
  • Background app refresh — turn off for any vendor app that doesn’t need to run in the background.
  • Contacts / calendar / photos access — most vendor apps don’t need any of these.

Also check your phone’s OS-level app permissions (Android Settings → Privacy → Permission Manager; iOS Settings → Privacy & Security). The OS-level view is the authoritative one — vendor apps can request permissions, but the OS is what enforces them.

Step 5: Disable ad personalization, voice recording storage, and product-improvement telemetry (30 minutes)

This is the biggest per-vendor effort. For each platform you use:

  • Amazon Alexa: Alexa Privacy Hub → “Manage Your Alexa Data” → turn off “Help Improve Alexa,” “Use messages to improve transcriptions,” set voice recording retention to 3 months or “don’t save recordings.”
  • Google Home / Nest: Data Security and Privacy on Assistant Devices — turn off Voice & Audio Activity (full disable) or set auto-delete to 3 months; turn off “Use voice and audio to improve Google’s products.”
  • Apple Home: Settings → Privacy & Security → Analytics & Improvements → turn off all three toggles. HomeKit Secure Video settings already default to local-only.
  • Ring: Control Center → toggle off “Video Cloud Storage” if you have a local storage alternative; toggle off “Receive Neighbors app alerts.”
  • Google Home + Nest cameras: Toggle off “Video and audio recordings” or set retention to the minimum; turn off “Help improve Nest products.”
  • Smart TV (any brand): Settings → Terms & Privacy (or “Viewing Information Services”) → disable ACR and interest-based ads.

Document each setting you change. Vendors update their apps frequently and sometimes reset “default” settings in firmware updates. The 7-step lockdown only works if you re-run it monthly.

Step 6: Update firmware on every device (20 minutes)

Most smart-home devices update their firmware automatically when connected to Wi-Fi, but some don’t — particularly older devices, niche-brand devices, and devices that have been disconnected from their vendor cloud for a while. Check each vendor app for “Device Updates” or “Firmware” sections, and force-update anything that’s behind by more than 3 months. The 2026 beginner mistakes guide covers firmware-update-forgetfulness as one of the most common pitfalls.

Step 7: Review monthly (15 minutes, recurring)

Put a recurring monthly reminder on your calendar. During the review:

  • Check each vendor app for newly-added “improvement” or “analytics” toggles.
  • Review your router’s connected-device list for anything you don’t recognize.
  • Verify 2FA is still enabled on all accounts.
  • Delete any voice recordings, video clips, or activity history you don’t want retained.
  • If a vendor has had a public breach or settlement since your last review, take the documented remediation steps.

What Vendors Don’t Tell You

The privacy policy language you should learn to recognize: “We may share your information with service providers.” This sentence, present in almost every smart-home vendor’s privacy policy, is the catch-all that allows your data to flow to data brokers, advertising partners, and (occasionally) law enforcement without your explicit consent. The EFF’s 2022 smart-home privacy guide walks through how to read a privacy policy for the clauses that matter.

Three things vendors rarely volunteer:

  1. “Don’t sell my info” toggles don’t cover all sharing. Most US state privacy laws (CCPA in California, similar laws in Colorado, Connecticut, Virginia) require a “do not sell” toggle, but the toggle applies only to selling — not to “sharing for advertising,” “sharing with service providers,” or “sharing for product improvement.” Those are separate categories, and they’re often opt-in by default.
  2. Settings can reset themselves. When a vendor pushes a firmware update or a privacy-policy update, settings sometimes revert to defaults. The 7-step lockdown in the previous section is a recurring practice for this reason.
  3. Account deletion doesn’t always delete data. Most vendors retain some data after account closure for “legal and audit purposes” (typically 30-90 days for active processing, sometimes longer for backups). If you truly want a vendor to not have your data, request data deletion in writing per their privacy policy.

For a deeper treatment of the vendor-policy landscape, the earlier Privacy Guide to Protecting Your Data covers the question from the regulatory and consumer-rights angles. This article is the operational follow-through.

Frequently Asked Questions

Is my smart speaker always listening even when I don’t say the wake word?

Technically, no — the wake-word detector runs locally and audio is discarded until the wake word fires. But “triggered” is more frequent than you think (similar-sounding words, coughs, TV audio). Once triggered, the audio is uploaded to the cloud. Disable “Help Improve Alexa/Assistant” and turn on auto-delete for any cloud-stored recordings. Mozilla’s 2026 smart-speaker privacy comparison walks through the per-platform settings in detail.

Should I cover my smart camera when I’m home?

Many privacy advocates do — especially for indoor cameras. Ring and Eufy both sell physical privacy covers. If you want a camera that physically can’t see when you’re home, look for models with a hardware shutter or that are designed for outdoor-only use. The FTC’s 2023 Ring settlement is the most-cited case for why a physical shutter matters — software-only “off” toggles can be bypassed by a firmware update or an employee with admin access.

Does turning off “ad personalization” actually stop data collection?

No — it stops one specific use of the data. The data is still collected and may be used for “product improvement,” analytics, or shared with “service providers” (a broad category that includes data brokers in some vendor policies). The only way to truly stop data collection is to disconnect the device or block its network access at the router. The EFF’s 2022 smart-home guide walks through which settings actually change collection vs. which only change use.

Is HomeKit really more private than Alexa or Google Home?

In 2026, yes — measurably. HomeKit Secure Video and HomeKit accessories process video and motion data on your local Apple devices (HomePod, Apple TV, iPad) before any cloud upload, and Apple’s relay architecture means even Apple can’t see the contents of the encrypted clips. Alexa and Google both default to cloud processing for most device types. The trade-off is ecosystem lock-in and a smaller device catalog. Apple’s Communication Security guide documents the architecture.

What should I do if my smart home device gets hacked?

Three immediate steps: (1) disconnect the device from your network (unplug or block via router); (2) change the password on the device’s associated account and any reused passwords; (3) check the FTC’s identity-theft resources at IdentityTheft.gov and consider a credit freeze if financial data was exposed. For ongoing protection, follow the 7-step lockdown in this guide. The 2023 Ring settlement is the most-documented case of an IoT breach — reviewing it tells you exactly what to do and what not to do.

The Bottom Line

Smart-home devices are not going away. The 2026 model lineup is more capable than any previous generation, and most of them genuinely do make daily life easier — turning lights on automatically when you walk in, letting you check the front door from work, adjusting the thermostat before you get home. The privacy story is not “don’t buy these things.” The privacy story is “buy them with your eyes open.”

The seven steps above will take you about two hours the first time you do them, and fifteen minutes a month after that. Two hours of setup is a small price for the next five years of having a smart home that works for you, not for the vendor’s advertising partners. The defaults are not the privacy-preserving ones — but the defaults are also not the ceiling. Every setting I’ve described in this article is documented, vendor-supported, and reversible if you decide you wanted more convenience than privacy on a particular feature.

Concrete next step: pick a Saturday morning this month. Block out two hours. Run through the seven steps with your phone and a coffee. Then put a monthly reminder on your calendar to re-run the review. You’ll spend more time reading this article than you will doing the lockdown — and that’s a good trade.