TL;DR: Don't buy Mesh WiFi, especially if offered at a low price/subscription by your ISP. Use old-fashioned routers and access points.
If you already have or really need Mesh WiFi, consider installing a VPN client on every single device that supports it. A VPN config on your router will not protect your data from the spying WiFi Mesh Pods.
I get why ISP provided routers and some brands of mesh router would collect and sell data but what is it about "mesh" that is particularly bad here? I have a cheap TP Link router that is apparently mesh compatible but it seems like a traditional router in all the other way. Should I be concerned?
Thanks for this: so sick of seeing “mesh” WiFi everywhere, what a load of trash. Just set up access points with roaming capability, actually use the correct broadcast power (instead of trying to blast it off to space), etc. I’ll never understand why people want their backhaul going over WiFi; yikes.
First, a VPN won't solve much because this garbage will still be able to log connection periods (when you are home), signal strengths changing over time, (where are you in your home), and traffic bursts (when are you doing something on your phone or other devices). A VPN will just help a very little bit, by the devices having less visibility into what sites you visit. But this "solution" is like if people would have forced cameras into your house, and from that on you would only be going around while holding a towel in their line of sight to "disguise" you.
Second, this is not about mesh WiFi, as I understand. Install OpenWRT, and the mesh function of that won't do any of this.
The problem is with new (but probably preexisting too) router brands who's sole purpose is making all the unknowing customers into a product, but stealing their private life and giving it away for money (or anything else).
The problem is basically that a facebook-like company has got deep insight into your network, which you can't avoid using, especially if your ISP forced you to use these garbage.
Just buy old Ruckus units and run the mesh on their Unleashed firmware. Still worse than wired backhaul, but better than running a VPN entirely internal to your own network.