It is infuriating. Read the terms and conditions/privacy policy for the apps!
For a soundbar, that sits in my living room to produce sound from a television, maybe stream music to it via Bluetooth or listen to online radio why does it need to send analytical data home! I run my own local DNS server with blocklists with one domain being metrics.bose.com. No way am I buying the newer models with built-in microphones.
Likewise, I have the soundtouch on it's own IoT of crap VLAN which has very restrictive firewall rules. I had to jump through several hoops to get this to work so I can control it from my phone which is on a trusted VLAN. This should be straight forward enough using avahi mDNS reflector and igmpproxy however Bose says the Soundtouch does not support cross VLAN https://community.bose.com/t5/SoundTouch-Archive/SoundTouch-.... That's not completely true, by default it does support it as it is just standard networking with unroutable requests being past to the default gateway however Bose have gone out of there way and done extra work to explicitly block traffic from a different subnet the soundbar is on, probably as a cheap way of securing the device for people who leave their internet routers wide open. The proper solution would have been for Bose to provide some authentication mechanism between the app and soundbar. Luckily it's easy to work around with NAT / IP masquerading.
Even with this, I've had the app switch the soundbar from it's IoT wifi SSID to the trusted wifi SSID on one occasion. I'm not sure how or why but I'll be monitoring it.
I'm going to actively avoid IoT devices now on, the general implementation seems to be substandard, end-of-life will generally be the end of app updates instead of the device physically breaking. Sonos have already done this by essentially changing the terms and conditions for users with existing devices and users not agreeing have their devices essentially become bricks https://www.zdnet.com/article/sonos-accept-new-privacy-polic....