You only need an external server if you want to make it so the end user can access their device remotely. Otherwise, an app can very easily just scan the network for the device. Heck, the app itself could be the thing that sets up the device on the network in the first place.
Remote access should also be do-able without having a manufacturer-run server. We over-complicate things with NAT and with ISPs sabotaging inbound connections to our networks. At least with IPv6 every device on my network is addressable by the outside world, and I can (and should be allowed to) make the decision about whether they are accessible. The device manufacturer should not have to insert themselves into this conversation.
users sometimes end up with some combination of the above:
1) multiple wifi networks 2) ‘guest mode’ wifi networks (you can’t communicate to other devices on the same network) 3) various airplane mode type scenarios where they have cellular but not wifi connections semi-randomly, even on the same property/area.
these all happen with out of the box ISP setups pretty regularly, btw.
and they’ll just blame you for the flakiness.
also, for most of them, they love remote access anyway and don’t want to consider the security implications.