There's a very good reason my cameras stay internal only and are blocked 100% from the internet. I can access them via the NVR with a Wireguard tunnel when I'm away from home if need be.
Same here; LAN only with a VPN to get into the LAN. There is no reason to send my camera feeds to another party. All that can come from that is trouble.
Thing is, Ubiquiti cameras aren't cloud based. At least not to the same extent. The authentication system is cloud based, but the controller and storage is local.
You can pay for several years of a cloud subscription for the cost of either a NAS or a Ubiquity storage server.
Reolink has always been a good choice. Very good hardware for the price and they support onvif on most devices, which you can then use however you like.
Reolink, Ubiquiti, Dahua, Amcrest, and Wyze. Nice thing about a third-party NVR is you can mix and match whatever is cheapest or best for a given spot. I'm currently using iSpy Agent for the NVR as it's runs nicely in docker. Then I layer Codeproject.AI over top for person detection rather than just generic motion alerts. I'm using a 2090 Ti GPU (which is WAY overkill but I got it for free) to make the AI detection very fast.
If you want cheap and good cameras: Some Annke cameras like the C800 are rebranded Hikvision models. Add a NVR like Frigate and you have a cheap and powerful local surveillance system.
Best place to start if you're taking security seriously; Implementing file encryption for example has to start with "I would rather that I myself potentially lose access to this data than for it to possibly fall into another person's hands."
When I lose things it's almost always because I've put them in a safe place. Safe from me!
But yeah it's really about factoring in likelihood and opportunity. I think it helps to compare physical and digital spaces. If you have a CCTV system, then anyone could watch the monitors and see what's happening - however they'd have to get into the building, find their way to the secure room, log in to the system, etc. When something is online it creates better opportunity for surreptitious access and also greater likelihood in terms of the number of people who could potentially come across it. While in the physical space you might get away with having staff control access during the day and locking the door at night, online you have to have far more robust security measures to achieve the same level of safety.
So it's maybe better to say: the easier it is for you to access data, the easier it is for someone else to.