After a host made a suspicious/creepy comment about our stay, I started logging into host routers (creds usually printed on the device) and look at what other devices are connected. The camera may not be on that network, or not networked at all, but it’s a little peace of mind.
There is an app called Fing on iPhones and maybe Android. It will scan the WiFi you are on and give you a bunch of information. There’s also a few more network functions you can do. It recognizes phones, my plex server, and a brother printer at my house to name a few. No router login required just the WiFi password.
This seemed like a really useful tool; I looked it up on the app store and - uh oh - it's free. Screenshots don't seem to show any ads and there's no IAP, so how do they make their money? Taking a look at their privacy policy[1], they collect:
> Information on MAC addresses and Wi-Fi networks you collect through the App or the Box. Please note that this Privacy Policy does not exempt you from any obligations you may incur should you collect other individuals’ personal data.
So basically, Fing will help you find devices on your network, and then store what it finds forever for other uses. And if you accidentally reveal some PII to Fing while scanning someone's network that's your problem.
This is the state of "apps". Collect everything, store everything, disavow any responsibility for anything. One of the first phone apps I used was a G-meter that just read the accelerometer and showed you a graph of your acceleration. It was a neat little toy. Today that app would send all accelerometer data back to some server farm in case there's anything that can be mined from that data.