But if it's a LAN API, how exactly will the manufacturer harvest your usage information to sell to third parties? How will they get that sweet, sweet, post-sale monetization?
Local API for control, then submit telemetry via the cloud-version of the API they use for the app.
The obvious answer why not is: it enables people like me to just block the telemetry uploads.
But they can't have it both ways then, they can't make inefficient cloud-based control mechanisms, and then complain when people (ab)use them, because the truth is that that will not stop no matter how many cease and desists they send.
Security by obscurity is another phrase for it.