Every smart lock now promises privacy. Can any of them keep it?

Three of the biggest home-security brands spent the autumn arguing about whose door is safest. We read the fine print so you do not have to.
The pitch arrived in near-identical slides at three launch events this autumn: your front door is the most personal device you own, and this company — unlike its rivals — will never treat it as a data source.
It is a good pitch. It is also, on close reading, a set of promises with very different shapes, and the differences matter more than the slogans.
What "on-device" actually covers
Every lock we looked at now advertises on-device processing for its fingerprint reader. That part is true and genuinely good: a print template that never leaves the deadbolt cannot leak from a cloud bucket.
But the logs are another matter. Two of the three still upload an event history — who unlocked, when, with which credential — to a server, where it is kept for between 30 days and "as long as your account is active."
A lock that remembers every time your teenager came home late is not a privacy product. It is a diary with a deadbolt.

The guest-code problem
Temporary codes are where the promises get slippery. Sending a code to a dog-walker means the walker's phone number, name and schedule enter the vendor's system. None of the three privacy pages mentions guests at all.
Brand A deletes guest data when the code expires.
Brand B keeps it with your account history.
Brand C would not say, and declined to answer follow-up questions.
What to buy, if you buy one
If the log matters to you, pick the model that lets you switch it off entirely, and check that the setting survives a firmware update. We tested that last part. One of them did not.
The honest answer is that the safest smart lock is still the one with the fewest features turned on. That is not a slide anyone will put in a keynote.