"Your AV" you don't know what AV I'm using, and you're wrong. I have setup a local update server which regularly downloads updates from the vendor and then updates endpoints on the LAN with no traffic going from LAN->Cloud for that.
"so do many security products. Its a common feature"
That also is why I don't use those products, and many others would agree.
"where are the privacy guides for that?"
I don't know, but are you trying to pretend there are none? If you are asking did you even do a couple of searches? I doubt it.
"Oh right, there's a double standard for MS."
Nope, same standard for all things. I don't like it if you send any of my or my computers info to servers without my knowledge of the content or purpose and I explicitly approve.
"Also, the author didn't disable Defender because he is using a different AV. He left it on and just disabled the cloud definitions feature, meaning he's not going to be up-to-date on definitions."
Once again... wrong. The cloud feature is for sending info about what is on your computer to MS so they can use it to update the definitions, it does not provide the definitions itself.
"Cloud defs are a bit different than what you get via WU. Its a dynamic list of suspicious hashes" if this is true, then I would be wrong on the previous section, but I have seen no documentation that specifies this. Care to provide a source for this info?