Haha that’s exactly what I do. 99% is local, the 1% is either “off site” in such a way it can’t be moved local, or I’m moving it to a local solution when possible.
I'm not particularly knowledgeable about IT but I avoid IoT like the plague. Everything should run locally and if I want to control it from away I'll use a VPN to home.