You bought a smart speaker because it was convenient. A doorbell camera because it felt safe. A few smart bulbs because they were on sale. Now they’re sitting in your kitchen, your bedroom, your living room — and they’re never really off.
Here’s what I want you to know before you read another sentence: this isn’t a scare-piece about smart devices. Plenty of them genuinely improve daily life. But the trade you didn’t read in the quick-start guide is that these devices collect real data, ship that data to corporate servers, and increasingly have been caught mishandling it — by their own employees, by hackers, and by regulators.
This guide is the practical follow-up to the Smart Home Security Checklist 2026. Where that checklist focused on locking down access to your devices, this one focuses on locking down your data — what leaves your home, where it goes, and how to make that decision deliberately. I’m going to walk you through what your devices actually know, what the FTC and state attorneys general have caught vendors doing with that data, and the concrete moves you can make this weekend — no CS degree required.
What Smart Devices Actually Know About You
The phrase “smart device” usually means “microphone, camera, or sensor plus internet connection.” That connection is where your data starts to travel. Here’s the realistic inventory:
- Voice assistants (Alexa, Google Assistant, Siri): audio recordings of every command, every conversation within earshot of the wake-word detection, timestamps, your contact list (if you linked one), and the device IDs you’ve authorized.
- Security cameras and doorbells: continuous video, motion events, who walks up to your door, when your kids get home from school, license plates, faces. Cloud retention varies — many vendors store clips 30 to 90 days by default.
- Smart thermostats, plugs, and appliances: when you’re home, when you’re away, sleep patterns inferred from temperature adjustments, energy-usage fingerprints.
- Robot vacuums: a map of your home — room layouts, furniture placement.
- Smart TVs and streaming devices: what you watch, when, how long, and — on older models — content from other inputs on the same HDMI port.
This isn’t speculation. In May 2023, the U.S. Federal Trade Commission announced a $5.8 million settlement with Amazon’s Ring after investigators confirmed that Ring employees and contractors had unrestricted access to customers’ private video feeds, and that hackers had taken control of users’ cameras. The FTC’s complaint is the closest thing we have to a federal audit of what cloud-stored smart-home video actually looks like from the inside — and it’s worse than most consumers assumed.
The Electronic Frontier Foundation has been tracking this category for years. Their 2023 holiday-season guidance was blunt: smart-home gifts can become indoor surveillance devices the moment they’re connected.
Real Incidents, Real Consequences
If privacy in the abstract doesn’t move you, here’s what documented, regulator-adjudicated incidents look like.
The Eufy settlement (January 2025). The New York Attorney General’s office secured a $450,000 settlement with three companies distributing Eufy home-security cameras. The investigation found that video streams lacked end-to-end encryption in some configurations and could be accessed without authentication via specific URLs. The order required penetration testing and stronger encryption. Read that again: a name-brand camera you can buy at Best Buy was accessible without authentication. The case closed because the vendors agreed to fix it; it didn’t require user action to begin with.
The NVD-tracked CVEs of 2024. The U.S. National Vulnerability Database lists new flaws in shipped smart-home firmware every month. CVE-2024-44097 and CVE-2024-51346 are two of them — both affecting named-brand cameras, both disclosed after the products had been in consumers’ homes for months. These aren’t zero-days; they’re known flaws that require firmware updates the vendor may or may not push automatically.
The Ring employee-access finding. The same FTC settlement mentioned above documented that Ring gave virtually every employee and contractor working on its “tagging” feature — designed to label objects in videos — full access to live customer feeds. Employees could (and did) watch people they knew personally. That’s not a hacking scenario; that’s an internal-controls failure at a company with millions of devices deployed.
The pattern across all three: documented harm, settled by regulators, addressed in vendor press releases, and largely missed by consumers who bought the device when it was on sale.
Architecture Matters: Local Processing vs. Cloud Surveillance
Once you understand the data-flow picture, the architectural distinction that matters most is whether your device thinks locally or hands raw data to a vendor cloud.
Apple’s HomeKit Secure Video is the clearest example of the local-first pattern. According to Apple’s security documentation, IP cameras stream video directly over your local network to the home hub, with encryption keys exchanged over a secure HomeKit session. When motion is detected, the clip is decrypted and analyzed on the home hub, then re-encrypted with AES-256-GCM using per-clip random keys before upload to iCloud. Face recognition runs against the encrypted metadata using iCloud end-to-end encryption — meaning Apple itself can’t read which faces you tagged. When you view a clip remotely, your device decrypts it locally. The vendor sees ciphertext. That’s a meaningful privacy floor.
The opposite pattern is the default for most consumer smart cameras: video is uploaded to the vendor’s cloud in (hopefully) encrypted form but with the vendor holding the keys. That gives the vendor’s engineers, their contractors, law-enforcement subpoena recipients, and any hacker who breaches the vendor — access to your video. The architecture choice is what makes the difference.
A common assumption: “Matter is private because it works locally.” This is half-true. Matter is a local-first interoperability standard — devices on a Matter fabric communicate over IPv6 without going through vendor clouds for the basic commands. But Matter does not prohibit manufacturers from implementing cloud-dependent features, requiring accounts, or collecting telemetry. As Matter Alpha’s Bertel King has written, you still need network-level controls to enforce privacy.
For a deep dive on choosing hubs that lean local, see the Matter Setup 2026 guide. And if your Wi-Fi is the bottleneck behind these decisions, start with the Smart Home Wi-Fi troubleshooting guide.
Two-Factor Authentication — The Single Highest-Lever Move
Most smart-home compromises don’t start with a device hack. They start with an account takeover: someone gets your email and password, logs into the smart-home vendor’s portal, and watches your cameras from their couch. The fix is one setting change, and the FTC’s consumer guidance on two-factor authentication is the canonical playbook.
Three options, ranked by security:
- Hardware security key (YubiKey, Google Titan Key). Highest protection against phishing and interception. Requires carrying the key.
- Authenticator app (Google Authenticator, Microsoft Authenticator, Authy). Time-based codes generated on your phone. Strong and convenient.
- SMS codes. Better than nothing but vulnerable to SIM-swapping, where an attacker convinces your carrier to port your number to their SIM.
The setup is the same on every smart-home app: open the app, go to Settings → Account → Security → Two-Step Verification, and follow the prompts. Do this for Amazon, Google, Apple, Ring, Nest, Eufy, Wyze, Arlo, TP-Link/Kasa, and any other account that controls a camera, lock, or speaker in your home. Budget an hour. It’s the highest-leverage thing you can do.
Enable number-matching push notifications if your app supports it — the small extra step that defeats MFA-fatigue attacks where someone spams your phone hoping you’ll tap “approve” by reflex.

Network Segmentation — The Architectural Lockdown
If a smart bulb is compromised, do you want it to be able to talk to your laptop, your phone, your NAS? Most home routers ship with every device on the same flat network — meaning anything infected can probe everything else. Network segmentation breaks that into separate sub-networks, so an IoT compromise can’t pivot to your laptop.
There are three practical patterns, in order of how much they assume about your router.
Guest network. Every modern router supports a guest SSID that’s isolated from your main network. Put your smart-home devices on the guest network. They’ll still have internet access for cloud features, but they can’t reach your laptop. This is the 10-minute fix. The EFF’s surveillance-gifts guidance recommends it explicitly.
VLAN-based segmentation. More advanced routers (consumer-grade: eero Pro, Asus RT-AX86U, TP-Link Archer AX90; prosumer: Ubiquiti UniFi, MikroTik) let you create multiple VLANs and define firewall rules between them. The recipe from Bitdefender’s network-segmentation guide is straightforward: IoT VLAN → can reach the internet but not your trusted VLAN; trusted VLAN → can reach IoT only as needed for control apps. For remote access, use a VPN rather than port forwarding.
DNS-layer filtering. Services like NextDNS, Pi-hole, or your router’s built-in safe-search filter can block known tracking domains at the DNS level. This won’t stop a determined attacker but it cuts down the chatter from devices phoning home to analytics services you didn’t sign up for.
Don’t forget to disable UPnP on your router — it’s a protocol that lets devices open incoming ports automatically, which is convenient but punches holes in your firewall you can’t see.
For the Wi-Fi layer that underlies all of this, the Smart Home Wi-Fi troubleshooting guide covers the most common pitfalls.
Before You Buy: Check the Privacy Score First
Every time you add a smart device, you’re making a privacy decision. The Mozilla Foundation runs a project called *Privacy Not Included that rates consumer smart-home products against minimum security standards — encryption in transit, automatic security updates, transparent data collection, and known-incident history. It’s the closest thing the consumer market has to a Consumer Reports for IoT privacy.
Before you click “buy,” spend 90 seconds on the Mozilla page. Three questions it helps you answer:
- Does the device require a cloud account, or can it run local-only?
- Has the vendor had a documented security incident, and how did they respond?
- What data does the device collect, and is there an opt-out?
If the device scores poorly and there’s no local-only alternative, the right answer might be to buy the dumb version of the product — a regular bulb, a regular doorbell, a regular thermostat. “Smart” is not always worth what it costs in data.
If you’re deciding between ecosystems, the Alexa vs Siri vs Google Assistant comparison walks through the privacy postures of each platform. They are not equivalent.
Why ‘Set and Forget’ Is the Most Dangerous Setting
Smart devices don’t ship with a “this device is now secure” sticker. They ship with today’s firmware, today’s threat model, today’s vendor security posture. All three of those change — and the device that was safe in 2024 may not be safe in 2026.
Two patterns drive most of the risk:
Unpatched firmware. The NVD-disclosed CVE-2024-44097 and CVE-2024-51346 are both smart-camera flaws from 2024 that required vendor patches to fix. If your camera doesn’t auto-update — and many don’t — you have a known-vulnerable device in your home until you manually flash the firmware.
Default credentials. The most common IoT attack vector isn’t a sophisticated exploit; it’s logging into a camera with the factory-default username and password. The 2024 IoT landscape surveys consistently find 15-20% of deployed devices still running default credentials within their first year. Change the default admin password on every device the day you set it up.
Build the habit: every three months, walk through the house and check the vendor app for each device. Is the firmware current? Are there users on the account you don’t recognize? Is the device connected to the right Wi-Fi network? It’s the same kind of seasonal check you’d do on a smoke detector — boring, but the cost of skipping it is paid in someone else’s data.
One last thing: the Smart Home Setup Mistakes guide covers nine other common pitfalls, including the “smart bulbs disconnecting” loop and the “Matter over Thread still flaky” reality — both of which lead people to default-share credentials when troubleshooting.
Your Rights: Data Access, Deletion, and ‘Do Not Sell’
If you’re in California (and increasingly, if you’re anywhere in the U.S. because vendors honor CCPA requests nationally), the California Consumer Privacy Act gives you three concrete rights:
- Right to Know: ask a vendor what personal data they hold on you.
- Right to Delete: ask them to delete it. Vendors must acknowledge within 10 days and complete the request within 45 days.
- Right to Opt Out of Sale/Sharing: tell them not to sell or share your data with third parties.
If you’re in the EU, the UK, or another jurisdiction with GDPR-equivalent laws, the rights are even stronger. The right-to-erasure and data-portability provisions apply to smart-home vendors as they do to any data processor.
The exercise takes about 20 minutes per vendor. Amazon, Google, Apple, and Meta all have self-service dashboards; smaller vendors require a privacy-request email. You can do this once a year as part of your privacy hygiene, the same way you do a credit-report check.
If you’re building your smart-home kit from scratch — moving into a new place, replacing an aging hub — the Smart Home Energy Savings guide covers how the choices you make in the first week affect the next decade. The privacy decisions are equally long-lived.
Your Weekend Privacy Checklist
You don’t need to overhaul your smart home this weekend. You need seven deliberate actions, each one under an hour:
- Enable two-factor authentication on every smart-home account you own. Authenticator app over SMS. Hardware key over app, if you have one.
- Update firmware on every device. Check the vendor app, not just the device.
- Create a guest network on your router and move IoT devices to it.
- Disable voice-history sharing on Alexa, Google Assistant, and Siri. Delete existing recordings while you’re there.
- Audit cameras and mics: which devices have them, what rooms they cover, who can see the feeds.
- Submit a CCPA data-deletion request to your top three vendors. Twenty minutes per vendor.
- Check Mozilla *Privacy Not Included before your next smart-home purchase.
Smart devices are not going away. The convenience is real. The question isn’t whether to use them — it’s whether to use them on your terms or on the vendor’s. You can change the answer to that question this weekend.
Frequently Asked Questions
Are smart speakers always listening even when I haven’t said the wake word?
Yes — they have to in order to detect the wake word. The audio buffer that listens for the wake word is processed locally, but recordings after the wake word ARE retained on the vendor’s servers unless you opt out of voice-history storage and human review. Apple’s Siri uses on-device processing for many requests (post-iOS 17) but still routes some queries to Apple servers.
Is Matter a privacy guarantee?
No. Matter is an interoperability standard for local IPv6 communication, but it does NOT prevent manufacturers from sending data to their own clouds, requiring accounts, or collecting telemetry. You still need network-level controls.
Does turning off the microphone on my smart speaker actually stop recording?
Hardware-mute switches on devices like Echo Show, Nest Hub, and HomePod do disable the microphone electrically. But if the device has a camera, that camera continues to operate independently. Read each device’s privacy documentation — mute behavior is not uniform across vendors.
Can I delete all my voice/video history from Alexa, Google, and Siri?
Yes. Amazon Alexa → Settings → Alexa Privacy → Review Voice History. Google Assistant → My Activity → Delete activity by. Siri → Apple ID → Siri & Dictation History → Delete Siri & Dictation History. You can also set auto-delete windows (e.g., 3 months or 18 months).
What’s the single most important privacy move I can make today?
Enable two-factor authentication (preferably an authenticator app, not SMS) on every smart-home account you own. The FTC, EFF, and every recent regulator settlement point to account takeover as the #1 attack vector — not device hacking.
{ “@context”: “https://schema.org”, “@type”: “Article”, “headline”: “Your Smart Home Is Watching You u2014 The Privacy Guide to Protecting Your Data”, “description”: “Smart devices collect data by default. Here’s what they know, what they share, and how to lock down every device to protect your privacy u2014 in 7 weekend steps.”, “datePublished”: “2026-08-25”, “dateModified”: “2026-08-25”, “author”: { “@type”: “Organization”, “name”: “Mrs. Technology”, “url”: “https://mrs.technology/” }, “publisher”: { “@type”: “Organization”, “name”: “Mrs. Technology”, “logo”: { “@type”: “ImageObject”, “url”: “https://mrs.technology/wp-content/uploads/2026/05/cropped-mrs_technology-logo.jpg” } }, “mainEntityOfPage”: { “@type”: “WebPage”, “@id”: “https://mrs.technology/your-smart-home-is-watching-you-the-privacy-guide-to-protecting-your-data/” }, “image”: [ “https://mrs.technology/wp-content/uploads/2026/08/smart-home-privacy-hero.jpg” ], “keywords”: “smart home privacy, IoT privacy, smart home data, smart device privacy, smart home security” } { “@context”: “https://schema.org”, “@type”: “FAQPage”, “mainEntity”: [ { “@type”: “Question”, “name”: “Are smart speakers always listening even when I haven’t said the wake word?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes u2014 they have to in order to detect the wake word. The audio buffer that listens for the wake word is processed locally, but recordings after the wake word ARE retained on the vendor’s servers unless you opt out of voice-history storage and human review. Apple’s Siri uses on-device processing for many requests (post-iOS 17) but still routes some queries to Apple servers.” } }, { “@type”: “Question”, “name”: “Is Matter a privacy guarantee?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “No. Matter is an interoperability standard for local IPv6 communication, but it does NOT prevent manufacturers from sending data to their own clouds, requiring accounts, or collecting telemetry. You still need network-level controls.” } }, { “@type”: “Question”, “name”: “Does turning off the microphone on my smart speaker actually stop recording?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Hardware-mute switches on devices like Echo Show, Nest Hub, and HomePod do disable the microphone electrically. But if the device has a camera, that camera continues to operate independently. Read each device’s privacy documentation u2014 mute behavior is not uniform across vendors.” } }, { “@type”: “Question”, “name”: “Can I delete all my voice/video history from Alexa, Google, and Siri?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes. Amazon Alexa u2192 Settings u2192 Alexa Privacy u2192 Review Voice History. Google Assistant u2192 My Activity u2192 Delete activity by. Siri u2192 Apple ID u2192 Siri & Dictation History u2192 Delete Siri & Dictation History. You can also set auto-delete windows (e.g., 3 months or 18 months).” } }, { “@type”: “Question”, “name”: “What’s the single most important privacy move I can make today?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Enable two-factor authentication (preferably an authenticator app, not SMS) on every smart-home account you own. The FTC, EFF, and every recent regulator settlement point to account takeover as the #1 attack vector u2014 not device hacking.” } } ] } { “@context”: “https://schema.org”, “@type”: “HowTo”, “name”: “Your Weekend Smart Home Privacy Checklist”, “description”: “Seven deliberate actions, each under an hour, to lock down your smart-home privacy.”, “totalTime”: “PT7H”, “step”: [ { “@type”: “HowToStep”, “position”: 1, “name”: “Enable two-factor authentication”, “text”: “Enable two-factor authentication on every smart-home account you own. Authenticator app over SMS. Hardware key over app, if you have one.” }, { “@type”: “HowToStep”, “position”: 2, “name”: “Update firmware”, “text”: “Update firmware on every device. Check the vendor app, not just the device.” }, { “@type”: “HowToStep”, “position”: 3, “name”: “Create a guest network”, “text”: “Create a guest network on your router and move IoT devices to it.” }, { “@type”: “HowToStep”, “position”: 4, “name”: “Disable voice-history sharing”, “text”: “Disable voice-history sharing on Alexa, Google Assistant, and Siri. Delete existing recordings while you’re there.” }, { “@type”: “HowToStep”, “position”: 5, “name”: “Audit cameras and mics”, “text”: “Audit cameras and mics: which devices have them, what rooms they cover, who can see the feeds.” }, { “@type”: “HowToStep”, “position”: 6, “name”: “Submit a CCPA data-deletion request”, “text”: “Submit a CCPA data-deletion request to your top three vendors. Twenty minutes per vendor.” }, { “@type”: “HowToStep”, “position”: 7, “name”: “Check Mozilla *Privacy Not Included”, “text”: “Check Mozilla *Privacy Not Included before your next smart-home purchase.” } ] } { “@context”: “https://schema.org”, “@type”: “WebPage”, “name”: “Your Smart Home Is Watching You u2014 The Privacy Guide to Protecting Your Data”, “speakable”: { “@type”: “SpeakableSpecification”, “xpath”: [ “/html/head/title”, “/html/body//article//p[1]”, “/html/body//article//p[2]”, “/html/body//article//h2[contains(text(),’Weekend Privacy Checklist’)]” ] }, “url”: “https://mrs.technology/your-smart-home-is-watching-you-the-privacy-guide-to-protecting-your-data/” }


