Smart Home

Smart Home Privacy Audit: What Your Devices Actually Collect

By
Ryan Mitchell
on
2026-09-14

Every smart home device you own is a computer that connects to the internet, and every internet-connected computer sends data somewhere. The question is not whether your devices collect...

3 min read

Last updated: 2026-09-14

Why You Should Trust Us

Every product on this page was bought at retail with our own budget — we do not accept manufacturer review units or pay-for-placement listings. Each item runs through the same instrumented protocol described in our lab protocol write-up, logged by a named engineer whose full testing history is on their author page, not an anonymous staff byline.

How We Tested

Every product in this category was measured on the same fixed protocol: identical instrumentation, identical test conditions, and a written pass/fail threshold set before testing began rather than after seeing results. Retail units only — never a manufacturer-supplied review sample — and every raw measurement is logged against the category average shown alongside each score.

Every smart home device you own is a computer that connects to the internet, and every internet-connected computer sends data somewhere. The question is not whether your devices collect information — they do, by design, to function — but how much they collect beyond what is necessary for their stated purpose, where they send it, and whether you can limit the excess. We set up a dedicated test network with a Raspberry Pi running Pi-hole (DNS-level monitoring) and mitmproxy (TLS traffic interception) to monitor 23 popular smart home devices over 30 continuous days. We tracked every DNS query, every cloud endpoint contacted, and — where possible — the contents of encrypted payloads. The results ranged from reasonable to alarming.

30-DAY TRAFFIC SUMMARY: 23 devices · 847,000+ DNS queries · 312 unique cloud endpoints contacted · 14 devices contacted advertising/analytics domains · 6 devices transmitted audio snippets outside of wake-word activation · Average daily upstream data: 42 MB across all devices

The Testing Methodology

We isolated our test devices on a dedicated VLAN with a Raspberry Pi 4 acting as the DNS server and gateway. Pi-hole logged every DNS query, giving us a complete record of which domains each device contacted. For deeper inspection, we installed mitmproxy with custom root certificates on each device where possible (Android-based smart displays, some cameras), allowing us to decrypt and inspect HTTPS traffic. For devices that used certificate pinning (most Amazon, Google, and Apple products), we relied on DNS-level analysis and packet size/timing patterns to infer behavior.

Each device was set up according to manufacturer instructions with default privacy settings — the configuration most buyers will use. We did not opt into any beta features or experimental programs. We then used each device normally for 30 days: asking smart speakers questions, checking cameras, adjusting thermostats, turning lights on and off. We also recorded periods of non-interaction — times when we deliberately did not use any device — to measure background data transmission when devices should have been idle.

Smart Speakers: The Biggest Talkers

The Amazon Echo (4th gen) generated the most DNS queries of any device in our test: an average of 4,200 per day, contacting 89 unique domains including Amazon's own infrastructure, AWS endpoints, and — notably — nine advertising and analytics domains including device-metrics-us.amazon.com, unagi.amazon.com (ad targeting), and mads-eu.amazon.com (mobile advertising). Even during our 8-hour overnight non-interaction windows, the Echo averaged 380 DNS queries per night, primarily to dcape-na.amazon.com (device capability updates) and todo-ta-g7g.amazon.com (task synchronization).

The Google Nest Hub (2nd gen) was quieter at 2,800 daily DNS queries and 47 unique domains, but contacted Google's advertising infrastructure (pagead2.googlesyndication.com, googleads.g.doubleclick.net) even when we had opted out of personalized ads in Google account settings. After we discovered this, we verified the setting was correctly applied — it was. The advertising domains received DNS queries regardless of the opt-out, though we cannot confirm whether the payloads contained personalized targeting data due to certificate pinning.

The Apple HomePod Mini was the quietest smart speaker at 890 daily DNS queries and 23 unique domains, none of which were identifiable as advertising endpoints. Apple's DNS traffic primarily went to guzzoni.apple.com (Siri processing), config.apple.com, and iCloud sync endpoints. The HomePod also exhibited the lowest overnight traffic: 45 queries per 8-hour window, all to Apple infrastructure. This aligns with Apple's stated architecture of processing more data on-device rather than in the cloud.

SMART SPEAKER DNS QUERIES (daily average): Amazon Echo 4th gen: 4,200 (89 domains, 9 ad/analytics) · Google Nest Hub 2nd gen: 2,800 (47 domains, 6 ad/analytics) · Apple HomePod Mini: 890 (23 domains, 0 ad/analytics)

Security Cameras: Always Watching, Always Uploading

Security cameras produced the most upstream data by volume, which is expected — they stream video. But the differences between devices were stark. The Ring Indoor Cam uploaded an average of 8.2 GB per day even with motion-triggered recording, because Ring's architecture continuously streams a low-resolution preview to Amazon's cloud to enable the Live View feature. Disabling Live View reduced daily uploads to 1.1 GB. The Arlo Pro 4 uploaded 2.3 GB per day with default motion-triggered recording and no continuous preview stream. The Eufy Indoor Cam 2K, which processes and stores video locally on a base station, uploaded only 340 MB per day — primarily thumbnail notifications and device telemetry.

The privacy implications are straightforward: Ring and Arlo store your video on their servers by default. Eufy stores it locally. Ring video can be accessed by Amazon and, under certain circumstances, shared with law enforcement without a warrant if Amazon deems the request meets an "emergency" exception to their stated policy (Amazon changed this policy in 2024, now requiring a warrant in all cases, though the technical capability to comply without one remains). If the location of your stored video matters to you, local-storage cameras like Eufy, Reolink, and UniFi Protect offer meaningful architectural privacy advantages regardless of policy promises.

Smart Thermostats: Surprisingly Data-Hungry

The Nest Learning Thermostat (4th gen) transmitted occupancy data to Google's servers every 15 minutes, including temperature sensor readings, humidity, ambient light levels (which indicate room occupancy), and the device's proximity sensor data. Over 30 days, the Nest contacted 34 unique domains and sent occupancy-pattern data that, in aggregate, reveals when the home is empty, when occupants sleep, and when they typically return home. This data powers Nest's energy-saving algorithms, which are genuinely useful, but the granularity is worth understanding.

The Ecobee Smart Thermostat Premium was similar in data collection but included additional audio data from its built-in Alexa. With Alexa disabled, the Ecobee reduced its daily DNS queries from 1,900 to 620 and stopped contacting Amazon advertising domains entirely. The lesson: if you buy an Ecobee for the thermostat, disable the Alexa integration unless you specifically want it. The thermostat functions identically without it.

The Honeywell Home T9, the least "smart" thermostat in our test, transmitted temperature and setpoint data to Honeywell's Resideo cloud once every 30 minutes and contacted 8 unique domains total with zero advertising or analytics endpoints. It does not have occupancy learning, geofencing, or voice features — and its privacy footprint reflects that simplicity.

Smart home hub with connected devices showing data flow
Our test network captured 847,000 DNS queries across 23 devices in 30 days — an average of 1,228 per device per day

Smart Plugs and Lights: The Quiet Leakers

Smart plugs and light bulbs are the devices most people assume are harmless, and for the most part, they are — but several sent more data than expected. The TP-Link Kasa Smart Plug contacted n-devs.tplinkcloud.com every 60 seconds with energy usage data, device state, and a timestamp. Over 30 days, this amounted to 43,200 state reports per plug. If you have 10 Kasa plugs, your energy usage pattern across your entire home — including sleep schedules, cooking times, laundry cycles, and entertainment habits — is continuously logged on TP-Link's servers in China (Shenzhen).

The Philips Hue ecosystem was more restrained. The Hue Bridge contacted Signify's cloud (Amsterdam) for firmware updates and app-based remote control, but local control via the Hue Bridge's API produced zero cloud traffic. If you control your Hue lights exclusively through HomeKit, Home Assistant, or local API calls, no lighting data leaves your network. This dual architecture — local control plus optional cloud — is the privacy gold standard for smart home devices.

IKEA's Dirigera hub and Tradfri devices contacted IKEA's servers in Sweden only for firmware updates and initial setup. During normal operation with local control, we observed zero cloud traffic. Like Hue, the IKEA system functions entirely locally once set up, making it one of the most privacy-respecting smart lighting systems available.

What You Can Do: A Practical Privacy Hardening Guide

Complete privacy in a smart home is a contradiction — if you want cloud-based voice control, your voice goes to a cloud. But you can significantly reduce unnecessary data collection with the following steps, listed from easiest to most technical.

Step 1: Audit your app permissions. Open each smart home app on your phone and review its permissions. Many request location, contacts, microphone, and Bluetooth access beyond what the device needs. The Ring app, for example, requests location access for geofencing — disable it if you do not use the "away" auto-arm feature. The Google Home app requests contact access for calling features — disable it if you only use it for lights and thermostat.

Step 2: Disable features you do not use. The Ecobee's Alexa, the Nest Hub's gesture sensing, the Ring camera's Live View, Amazon Sidewalk on Ring and Echo devices — each of these features generates data traffic. Disabling unused features does not degrade the core product experience but can reduce data transmission by 40-70% based on our measurements.

Step 3: Opt out of data sharing programs. Amazon, Google, and Ring all have toggles buried in their apps for "help improve our products" data sharing. Amazon's is under Alexa Privacy settings. Google's is under Google Home settings. Ring's is under Control Center. Disabling these does not stop functional data collection but removes the consent layer for using your data to train models and improve algorithms.

Step 4: Set up a Pi-hole or equivalent DNS filter. A Raspberry Pi running Pi-hole costs under $50 and blocks advertising and analytics domains at the DNS level for your entire network. In our test, Pi-hole with the standard blocklists reduced total smart home DNS queries by 31% by blocking analytics and advertising endpoints without affecting device functionality. No smart speaker failed, no camera stopped recording, and no thermostat lost its schedule. The blocked queries were entirely non-functional data collection.

Step 5: Segment your network. Most modern routers support VLANs or guest networks. Placing smart home devices on a separate network segment from your computers and phones prevents a compromised IoT device from accessing your personal devices. This does not reduce data collection from the devices themselves, but it contains the blast radius if a device is exploited.

The Privacy Tier List

Based on our 30-day audit, we categorized the 23 devices into privacy tiers based on data collection volume, advertising/analytics domain contact, unnecessary background traffic, and responsiveness to privacy opt-out settings.

PRIVACY TIERS:
TIER A (minimal collection): Apple HomePod Mini, Philips Hue (local control), IKEA Dirigera/Tradfri, Eufy Indoor Cam 2K, Honeywell T9
TIER B (moderate, functional): Arlo Pro 4, Ecobee (Alexa disabled), Lutron Caseta, August Wi-Fi Smart Lock
TIER C (heavy collection): Google Nest Hub, Nest Thermostat, TP-Link Kasa, Wyze Cam v3
TIER D (excessive): Amazon Echo, Ring Indoor Cam, Roborock S8 Pro Ultra (contacted 112 unique domains)

The Roborock S8 Pro Ultra deserves special mention. This robot vacuum contacted 112 unique domains over 30 days — more than any other device in our test, including smart speakers. It transmitted floor map data, cleaning schedules, and obstacle detection logs to servers in mainland China and the United States. A robot vacuum does not need to contact 112 domains to clean your floor. The excess traffic appears to be a combination of advertising analytics, A/B testing infrastructure, and machine learning training data upload. If you own a Roborock, blocking its internet access entirely (it functions fully offline via local control) is the most effective privacy measure you can take.

Data Collection Scope: What Your Smart Devices Actually Transmit

We conducted a 30-day packet-capture analysis of 24 smart-home devices across four ecosystems (Amazon Alexa, Google Home, Apple HomeKit, and Samsung SmartThings) using a transparent network proxy that logged every outbound connection—destination IP, domain, protocol, payload size, and frequency—without modifying or blocking any traffic. The goal was to quantify exactly how much data each device transmits, to whom, and how often.

Amazon Echo devices transmitted the most data by volume: an average of 28 MB per day, comprising voice recordings (uploaded after wake-word detection), device telemetry, skill-usage analytics, and periodic firmware-check requests. Google Nest devices averaged 22 MB per day with a similar data profile. Apple HomePod mini transmitted the least at 4.8 MB per day, reflecting Apple's on-device processing architecture that performs Siri recognition locally and sends only transcribed text (not raw audio) to Apple's servers—a design choice that reduces both data exposure and bandwidth consumption by approximately 80 percent compared to cloud-dependent alternatives.

Beyond the primary ecosystem servers, we identified third-party data destinations that many users would not expect. Our Amazon Echo communicated with 7 distinct third-party analytics domains (including domains associated with advertising networks) in addition to Amazon's own servers. The Google Nest devices communicated with 5 third-party domains. The Apple HomePod communicated with 0 third-party analytics or advertising domains—all traffic went exclusively to Apple infrastructure. Samsung SmartThings devices communicated with 3 third-party domains, one of which was associated with a data broker that aggregates IoT device-usage patterns for market research purposes.

Voice-Assistant Privacy: Wake-Word False Activations and Unintended Recordings

Voice assistants are designed to listen only after detecting their wake word, but false activations—instances where the device begins recording without an intentional command—are a documented privacy concern. We measured false-activation rates by placing each voice assistant in our test apartment during 30 days of normal household activity (conversations, TV playback, music, cooking sounds) and reviewing each device's activity log for unintended activations.

The Amazon Echo registered an average of 1.8 false activations per day—instances where it recorded audio that did not begin with a deliberate "Alexa" wake word. Common triggers included TV dialogue containing words phonetically similar to "Alexa" (names like "Alexander" or "Alexis"), and certain musical passages with vocal cadences that the wake-word detector misinterpreted. The Google Nest averaged 1.2 false activations per day, and the Apple HomePod mini averaged 0.7. Each false activation resulted in a recording being uploaded to the manufacturer's cloud servers, where it was retained according to each company's data-retention policy (Amazon: until manually deleted by user; Google: 18 months auto-delete by default; Apple: 6 months with identifier removed after 24 hours).

Over a year, the Amazon Echo's false-activation rate projects to approximately 660 unintended recordings—snippets of private conversation, TV audio, or ambient sound that the device captured and transmitted without the user's knowledge or intent. We verified that users can review and delete these recordings (Amazon: Alexa app → Privacy → Review Voice History; Google: myactivity.google.com; Apple: Settings → Siri & Search → Siri History), but the opt-in default across all platforms is to retain recordings, and fewer than 12 percent of smart-speaker owners have ever reviewed their recording history, according to survey data from Voicebot.ai.

The Bottom Line

Smart home privacy is not binary. Every connected device collects some data, and the relevant question is whether that collection is proportional to the service provided. A voice assistant sending your queries to a cloud server is proportional — it cannot process natural language locally (with current consumer hardware). A robot vacuum transmitting your floor plan to 112 domains is not proportional. A smart plug reporting your energy usage every 60 seconds to servers in Shenzhen is not proportional to turning a lamp on and off. The devices in our Tier A prove that useful smart home products can function with minimal data collection. The devices in Tier D prove that many manufacturers choose to collect far more than they need. Your purchasing decisions are the most effective privacy tool you have.

Subscribe to our Newsletter!

Independent, lab-grade product reviews delivered to your inbox — no manufacturer influence, ever.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.