
Smart home privacy discussions tend to focus on the dramatic case: someone watching a camera feed. It is the easiest risk to picture, and it is not the one that applies to most households.
The data that actually leaves a typical smart home is far more boring, and considerably more revealing. It is a list of times and state changes.
Why boring data is the revealing kind
A motion sensor does not transmit a description of you. It transmits motion detected and a timestamp. That looks harmless in isolation.
Now collect a few weeks of it across a house.
You know when the household wakes and when it sleeps. You know which days someone works from home. You know when the house is empty, and for how long, and how predictably. You can see a routine change — someone sleeping in the spare room, someone getting up at 3am repeatedly, a household that suddenly has an extra person in it. You know when they went on holiday and roughly when they will be back.
None of that required a camera, a microphone, or your name. It is derivable from door sensors, motion sensors, and light switches — the cheapest, least alarming devices in the house.
This is why "we only collect anonymous telemetry" is a weaker assurance than it sounds. Occupancy patterns are not anonymous in any meaningful sense. There is one household producing them, and the pattern is the identity.
What actually gets transmitted
Four categories, roughly in order of how often people underestimate them.
State and events. Every on, off, open, closed, and detected, with a timestamp. The bulk of the traffic and the most revealing in aggregate.
Telemetry and diagnostics. Firmware versions, connection quality, battery levels, error reports. Genuinely useful to a manufacturer. Also a reliable presence signal, because a device that reports in is a device with power and a person nearby.
Account and identity data. Email, household name, device names, sometimes location for weather or sunset timing. "Master Bedroom Camera" tells someone a lot before it transmits a single frame.
Voice and video. The category everyone thinks of, and the one most tightly governed by published policies. Real, but usually not the main leak.
Metadata leaks through encryption
This is the part that surprises people, and it is worth understanding because it changes how you evaluate promises.
Your smart home traffic is almost certainly encrypted, so nobody on the path reads the contents. But encryption hides the payload, not the fact of the transmission. An observer on the network can still see which device talked, to which server, when, and how much data it sent.
That is often enough. A burst from the doorbell at 07:14 followed by activity from indoor sensors is a person leaving for work, whether or not anyone can read a single byte. Traffic patterns alone can reconstruct a household's rhythm.
The practical consequence: "end-to-end encrypted" is a real and worthwhile guarantee about contents. It is not a guarantee that your routine is private. The only thing that fully addresses the metadata problem is not sending the traffic at all — which is the actual argument for local processing, independent of any privacy policy.
Curious whether Nexop fits your home?
Book a live demo — one of the founders runs it, not a salesperson — or join the waitlist and hear from us the day it ships.
How to check for yourself
Read the retention section, not the intro. Every privacy policy opens by saying privacy is important. Skip to how long data is kept, whether it is shared with affiliates or partners, and what happens on account deletion. Vagueness there is the signal.
Look for "affiliates" and "business transaction". Both are standard clauses that permit data to move to companies you have not evaluated, including if the vendor is acquired.
Do the disconnect test. Cut the internet, leave the local network up, and see what still works. Whatever stops was reaching outside for something. This tells you more than any document.
Watch your own DNS. Your router or a Pi-hole will show which servers your devices contact and how often. Nothing to decrypt — the pattern of who-talks-to-whom is the useful part, and it is often surprising.
Check whether deletion is real. Can you delete history, and does it delete or just hide? Is there an export? Absence of both usually means data is being retained for reasons other than serving you.
Being fair about the other side
Cloud processing is not automatically bad faith, and treating it that way makes for poor decisions.
Some genuinely valuable things need offsite data: video stored away from a camera a burglar could take, cross-device features, models that are too large to run at home. Vendors also have legitimate needs — diagnostics genuinely improve products, and a company with no telemetry ships worse software.
The reasonable position is not zero transmission. It is proportionality: does the data leaving match the value coming back, and did anyone ask you? A thermostat sending diagnostics is proportionate. A light switch requiring a cloud account to toggle is not.
Where Nexop stands
Nexop is built so household data stays on the local device by default — routine learning, device state, occupancy, and automation history. Not as a promise about how we behave with your data, but as an architecture where the question mostly does not arise. A pattern that never leaves the building does not need a retention policy.
Two honest qualifications. Nexop is pre-launch, so this is a description of how it is designed, not a track record. And a local-first product still has ordinary internet touchpoints — updates, optional remote access, and this website, which does use analytics. What we collect there and why is in our privacy policy, written to be read rather than to be defensible.
If you want to interrogate any of this properly, book a demo and ask the awkward version — those are the questions we would rather answer before you buy than after.