Homekit products (and namely their apps) have access to anything you grant them permission to access. Generally this is just 'home data'. Even then this data is very limited but its safe to assume those products could access all the information in there.
You would need to intentionally grant more permissions to allow access to more data (photos, contacts, microphone, etc etc).
Outside of what you are allowed to grant will remain inaccessible. This is Apples double edge sword referred to as sandboxing.
For example you smart plug and its associated app on your phone it can not access a 3rd party password app you may also have installed.