- Listening, sending and keeping are three different things. A device can detect a wake word without sending or storing everything. The useful question is what leaves the room and what happens next.
- Three questions cover most smart devices. What does it measure, where are the records stored and who can access them?
- A short settings check goes a long way. Voice history, retention, shared users, MFA, updates and app permissions can all be reviewed in a sitting.
In part two of our Cybersecurity Awareness blog series, we discussed how to shrink your digital profile for a safer, more private online life. In part three, we will discuss how smart devices at home collect your data and the simple settings that put you back in control.
Alexa can set a timer, but you still get to set the boundaries
A smart speaker can play music, set timers and settle arguments about who starred in that film. It also puts a microphone attached to a computer in your kitchen. Both facts deserve a place in the purchase decision.
Should you worry? Enough to check the controls and understand the trade. Not enough to assume your dinner conversation is being live-streamed to a sinister room full of headphones. A microphone’s existence and continuous transmission are different claims.
Listening, sending and keeping are different things
A wake word is the phrase, such as “Alexa,” that starts an interaction. Amazon describes typical Echo (its line of smart speakers) wake-word detection as happening on the device. After activation, audio can be sent to the cloud (servers operated by the provider) for processing. False activations can occur, meaning the device mistakes another sound for its wake word, and conversation modes can change how long an interaction continues. Check the particular product you own.
Detecting a trigger locally, sending audio and keeping a recording or transcript (a written copy of what was said) are separate steps. A device can do one without doing all three continuously. Equally, deleting an audio clip does not necessarily delete every related record. The interesting question is not merely “Is it listening?” It is “What leaves the room, and what happens after that?”
There is a real example behind the advice to check deletion settings. In 2023, the FTC (the Federal Trade Commission, the US government’s consumer-protection agency) and the Department of Justice alleged that Amazon kept children’s Alexa recordings and undermined deletion requests. The case required changes to its practices. It is a good reason to look at retention (how long a company keeps your data) and deletion settings. It does not show that every current speaker records everything.
The microphone is only one member of the household
Cameras can capture visitors and private spaces. A thermostat’s schedule may suggest when someone is home; a connected lock’s activity can reveal arrivals and departures. These are examples of what such records could reveal, not claims that every manufacturer sells them. For each product, three questions cover most of it: what does it measure, where are the records stored and who can access them?
Smart TVs deserve attention too. A historical FTC case against VIZIO, a TV maker, concerned viewing histories collected without consumers’ consent. Review your TV’s viewing-recognition settings (features that identify what is on your screen) and its advertising settings rather than assuming today’s devices all behave the same way. You bought a television to watch things. That does not automatically mean you wanted the television to take notes.
Apps add another route. A permission is a setting that decides what an app may access, such as your location, contacts or camera. A location permission granted for a useful feature may reveal routines, and advertising or measurement software inside an app can involve other companies. A navigation app has a reason to know where you are. Another app demanding your entire contact list should make a persuasive case, preferably one stronger than “because we asked.”
A smart home check that does not require a bunker
Picture Priya with a mug of tea and a new smart speaker. She opens the companion app, finds the voice history, picks a retention period that suits her and removes two skills she never used. A few minutes later the speaker still plays her playlists, and she knows exactly what it keeps.
Start with the device’s account and privacy menu. Review voice history for unexpected activations, choose a retention period that suits your needs, and look at the controls for letting the company use your interactions to improve its services. Remove unused skills (third-party voice add-ons, a bit like apps for your speaker) and old account connections. Options vary by product and region. Deletion reduces retained information; it cannot promise every earlier disclosure has been reversed.
For a confidential work call at home, mute a nearby speaker’s microphone using its device control. If you need certainty it is not operating, unplug it. Follow employer policy and keep cameras out of sensitive views. Tell guests and household members what is recording. “It is my house” is a property statement, not a privacy explanation.
For cameras, review shared users and who can view recordings. Remove former household members or other access that is no longer needed. Enable multifactor authentication, or MFA, which asks for a second proof that it is you, such as a code from an app, in addition to your password. Position cameras to avoid bedrooms, bathrooms and unnecessary views of neighbors. Physical security and personal privacy can conflict; choose the view deliberately.
Update devices and their apps, replace default passwords (the factory-set ones) and disable remote access (controlling a device from outside your home network) if you do not use it. Check the promised update support, meaning how long the maker will keep sending security fixes, before buying. A separate guest or smart-device network, which many home routers can create, keeps your gadgets in a different lane from your laptop and phone. That can help contain certain security risks if it is configured appropriately; it does not stop a gadget sending data to its provider. Network separation is useful plumbing, not a gag order.
Review phone permissions too. On iPhone, start at Settings > Privacy & Security. On Android, search for “Permission manager” or “Privacy dashboard.” Prefer location only while using an app, approximate location when sufficient and selected photo access where supported. If a feature stops working, restore the specific permission it needs instead of granting everything out of frustration.
Creepy ads are not a microphone test
An ad arriving after a conversation feels like evidence. But the timing alone does not establish the cause. EFF (the Electronic Frontier Foundation, a nonprofit digital rights organization) explains that browsing, data broker profiles and household activity can produce unexpectedly relevant ads without covert microphone recording. Spyware, meaning software that secretly monitors a device, and microphone misuse are possible; an advertisement is not enough to demonstrate either.
Use three questions: What evidence do I have? Is the explanation plausible? Will this precaution help? An unfamiliar login or unexpected recording deserves investigation. Treating every coincidence as proof of the same theory is where skepticism stops doing its job. You do not need to ridicule the concern; you need to test the explanation.
Apple’s App Privacy Report and Android’s Privacy Dashboard are built-in tools that show which apps recently used permissions such as the microphone, camera or location. Apple’s also shows which web addresses (domains) apps contacted. These are useful clues, not a complete account of where data goes next. If you see specific warning signs, such as an unfamiliar login or a device behaving oddly, involve IT or qualified support. If you see only a suspiciously good ad, start with the ordinary tracking controls.
Try this today
Check one speaker’s recording history, one camera’s shared users and one app’s permissions. If a connected feature gives you no benefit, turn it off. Your light bulb does not need a rich inner life. One check is a fine start. Three is a pleasant Saturday morning.
Sources and answers to common questions
Selected bibliography and practical reading. Sources reviewed October 5 2026. Follow official instructions for your device and region; settings and policies can change.
What does Alexa record and retain?
Amazon. Alexa and Alexa Device FAQs
Manufacturer guidance on activations, recording history, deletion and privacy controls; available features vary.
How do I mute the microphone?
Amazon. Turn Your Echo Device’s Microphones On or Off
Official device-control instructions. Muting prevents normal voice responses until re-enabled.
Why double-check deletion promises?
FTC and DOJ. May 2023. Amazon Alexa children’s privacy and deletion case
Primary regulator account of the allegations and required changes.
How do I secure connected devices?
UK National Cyber Security Centre. Smart devices: using them safely in your home
Updates, passwords and remote-access guidance. Security does not itself prevent a provider’s data collection.
What about smart TV viewing data?
FTC. 2017. VIZIO viewing history settlement
Historical evidence of unexpected collection; not a description of every current TV.
Is my phone secretly listening for ads?
EFF Digital Rights Bytes. Is My Phone Listening to Me
Explains alternative sources of ad targeting and recommends practical controls.
How can I inspect app activity?
Apple Support. About App Privacy Report
How to inspect supported permission use and contacted domains on iPhone or iPad.
Where are Android permission controls?
Google Android Help. Manage permissions from the privacy dashboard
Official instructions; menus depend on Android version and manufacturer.
Stay tuned for part four of our Cybersecurity Awareness blog series.