Remember that the S in IoT stands for Security.
I have deployed open MQTT to the world for quick prototypes on non personal (and healthcare) data. Once my cloud provider told me to stop because they didn’t like it, that could be used for relay DDOS attacks.
I would not trust the sleep mask company even if they somehow manage to have some authentication and authorisation on their MQTT.
And the P in IoT stands Privacy, and the Q for quality.
The K, of course, stands for Ka-ching!
I don't think there is an S in IoT?..