What Smart Home Devices Actually Send
A smart speaker is not listening to everything you say and sending it to a server. That claim is wrong, it has been wrong for years, and repeating it does more harm than good. While everyone argues over the microphone, the actual privacy problem in a connected home sits in plain sight and gets almost no attention.
The real issue lives in the metadata. A house full of connected devices produces a continuous, timestamped record of when you’re home, when you sleep, when you leave, and what you do in between. None of that requires a microphone at all.
I run network infrastructure for a living, so I think about what traffic reveals rather than what a device claims to do. That turns out to be the useful lens here.
What a voice assistant actually does
It’s worth settling this properly, because the rest of the argument depends on it.
The device listens locally for a wake word. That processing happens on the device itself, and it has to, because streaming continuous audio from every speaker in every home to a server would cost the manufacturer an enormous amount of bandwidth for no return.
When it thinks it heard the wake word, it starts recording and sends that clip onward. So the audio that leaves your house is the clips, not a live feed.
The genuine problem is false triggers. Wake word detection is deliberately loose, because a device that misses you is more annoying than one that occasionally wakes up on its own. So it fires on similar sounding phrases, on television dialogue, on conversation that happens to rhyme with the wake word. Those clips leave the house too.
That’s the accurate version. Not surveillance, and not nothing either. An intermittent recording that starts without you meaning it to.
For years, those clips were reviewed by humans as part of improving the systems, something several manufacturers didn’t make clear until it was reported. The settings to opt out generally exist now, and they’re usually not on by default. So go look at yours, and while you’re there, delete the history. Both take a few taps, and almost nobody has done either.
The thing that actually leaks
Now the part that matters and gets no attention.
Every connected device in a house reports to a server. A light switch, a plug, a doorbell, a thermostat, a television. Each one sends small, regular messages, and each message is timestamped.
Nobody needs to know the contents. The pattern is the information, and the pattern arrives whether or not anybody is interested in it, simply as a consequence of the device staying connected.
The hall light goes on at six forty every weekday and at nine on Saturdays. The thermostat drops to away mode at eight fifteen. The door sensor fires twice, ten hours apart. The television starts at seven thirty and stops around eleven.
That’s a diary of your household, produced automatically, held by several companies, and none of it required anybody to listen to a word you said.
The television is the worst one
If you have to pick one device to be concerned about, this is it.
A modern television identifies what’s on the screen by taking periodic samples and matching them against a library. That includes broadcast, streaming, and in many cases anything connected to it through a cable.
That data is the actual business. Televisions are sold near cost, and the money is made afterward, from knowing what households watch and selling that knowledge to advertisers.
The setting to turn this off exists, and it’s usually buried under a name chosen so that nobody browsing the menu would guess what it controls. Worth finding anyway.
The second thing about a television is that it’s the device most likely to still be running the software it shipped with, because manufacturers stop updating them long before people stop using them. A seven year old set on the same network as everything else is the least maintained computer in your house.
The doorbell problem is different
Worth separating out, because it’s the one that involves other people.
A camera facing a corridor or a street records neighbours, visitors, delivery workers, and passers by, none of whom agreed to anything. This is the one device where your privacy decision is also somebody else’s.
That footage goes to a company, is retained under their policy rather than yours, and has in various countries been handed to authorities on request, sometimes without the owner being told.
If you want one, point it at your own door rather than at the shared space, keep the retention period short, and be aware that you’ve become a custodian of other people’s movements. That’s a real obligation even when nobody frames it as one.
The account is the thing
Here’s the structural point underneath all of it.
These devices are terminals for an account rather than independent products, and the account is where the value sits.
A company with your speaker, your doorbell, your thermostat, and your television has all four streams keyed to one identity, and the combination is worth far more than the sum. The speaker knows when you ask about the weather. The thermostat knows when the house empties. Together they know your routine.
Which means the practical decision is about how many separate accounts your house reports to, and whether you’re comfortable with one company holding the complete picture. Brand barely enters into it.
Spreading devices across manufacturers is genuinely protective for this reason, and it’s the opposite of what every ecosystem is designed to encourage.
What happens when the company loses interest
This is the risk nobody prices in at the moment of purchase, and it’s the one that has bitten the most people.
A device that depends on a server keeps working for exactly as long as somebody keeps paying for that server. When a product line is discontinued, or the company is bought, or the free tier becomes a subscription, the thing on your wall changes without you touching it.
It has happened repeatedly. Hubs switched off, cameras that stopped recording, thermostats reduced to the functions a dumb one would have had. In the better cases the manufacturer gave notice, which doesn’t help much when the device is screwed to a wall.
Then there’s the other direction, where the company is sold and the new owner rewrites the privacy policy. Your data was collected under one set of promises and is now held under another, and the consent you gave was to a company that no longer exists in the same form.
So the question worth asking before you buy is what this thing does if the company disappears tomorrow. A device that keeps most of its function is a purchase. One that becomes a plastic shell is a subscription you paid for up front.
The second hand problem
Short, and it catches almost everybody.
These devices remember. A used camera, hub, or speaker can carry the previous owner’s account, network credentials, and sometimes recordings, and a factory reset doesn’t always clear as much as the menu implies.
If you sell one, reset it and then remove it from your account on the manufacturer’s side as well, because those are two separate operations and people usually only do the first.
If you buy one second hand, assume it wasn’t reset properly and do it yourself before it touches your network.
The same applies when you move house. The devices you leave behind are still on your account, and the person moving in inherits hardware you can still see. This story comes up more than once, and the previous owner is rarely being malicious. They simply forgot the light switch was a computer.
What actually reduces the exposure
Practical, in order of how much they buy you.
Decide whether the device needs to be connected at all. A great deal of what gets sold as smart is a normal appliance with a radio in it, and the smart part adds a subscription and a data stream in exchange for something you could do with a switch.
Put the connected devices on a separate network. Most home routers support a guest network, and putting everything that isn’t a computer or a phone onto it means a compromised device can’t reach your actual machines. That takes about ten minutes and it’s the highest value thing on this list.
Turn off the features you don’t use: the television’s content recognition, the speaker’s history retention, the assistant’s personalisation.
Check what a device does when the internet is down. One that stops working entirely was routing everything through a server that didn’t need to be involved, and that tells you something about the design.
Prefer devices that work locally. That market is small, but it exists, and it’s the only version of this where the data genuinely stays in the building.
The part I got wrong
For a long time I argued about the microphone question, because it was the interesting one and because people were confidently wrong about it in both directions.
Meanwhile I had a television doing content recognition in my own living room for about two years, with the setting sitting there untouched, because I’d never gone looking. I knew the feature existed. I simply hadn’t connected the general knowledge to the specific device in front of me.
So I was busy arguing about something that wasn’t happening, while the thing that was happening ran continuously in a device I walked past every day. That’s the ordinary shape of this. The dramatic risk gets the attention, and the boring one gets the data.
The one that actually needs the network
Worth naming, because among all of this there’s a category where the connection genuinely earns its place.
Anything that has to reach you when you’re elsewhere: a leak sensor that messages you while you’re at work, a camera you check from another country, a lock you open for somebody standing at the door while you’re in a meeting. Those can’t be done locally, by definition, because the whole point is that you’re not there. The trade is honest and the value is real.
What’s irritating is everything else being sold with the same framing. A kettle doesn’t need to reach you when you’re elsewhere. Neither does a lightbulb in a room you’re standing in, and yet both are sold on the same promise, with the same account, feeding the same timeline.
So the useful test before buying is whether the feature requires you to be absent. If it does, connect it and accept the trade. If it doesn’t, you’re paying with data for a convenience you could have had with a switch.
The honest summary of the trade
These devices are genuinely useful, and I use several of them myself. This isn’t an argument for ripping them out.
What’s worth doing is knowing what you’re trading. You get convenience, and you pay with a continuous record of your household routine, held by companies whose policies can change and whose data can be sold, breached, or subpoenaed.
For a light switch, that’s probably a fine trade. For a camera pointed at a room, it’s a different conversation, and it’s worth having deliberately rather than by default because the device happened to be on offer.
For more explainers like this one, on VPNs, encryption, and the everyday tracking that actually matters, visit The Privacy Wire.