\n\n\n\n Your Chatbot Has a Side Hustle and It's Tracking You - AgntHQ \n

Your Chatbot Has a Side Hustle and It’s Tracking You

📖 4 min read•782 words•Updated Sep 29, 2026

Remember when Moltbook was supposed to be the moment AI agents proved they could organize themselves? MIT Technology Review’s W. D. Heaven called it “peak AI theater” back in February. The agents on that agent-only social network reportedly invented their own religion, Crustafarianism, which Koetsier documented in January. Funny stuff. Great screenshots. Everybody had a take.

Meanwhile, a group of researchers was quietly measuring what conversational AI agents actually do when nobody’s watching the timeline. The answer is less charming than crustacean theology.

Localhost, the Back Door Nobody Checks

The paper is titled “Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost,” from Tim Vlummens, Aniketh Girish, Nipuna Weerasekara, Frederik Zuiderveen Borgesius, Gunes Acar, and Narseo Vallina-Rodriguez. That subtitle is doing a lot of work, so let me sit with it for a second.

Silent. Web-to-app. Via localhost.

Localhost is your own device talking to itself. It’s the loopback address, the thing you use when you’re testing a server on your laptop. It is not supposed to be a tracking channel. When a browser tab can whisper to an installed app through that channel, you get identity linking that doesn’t touch a cookie, doesn’t trip a consent banner, and doesn’t show up in any of the privacy dashboards users have been trained to trust. The researchers describe fingerprinting techniques alongside it. Fingerprinting is the trick where you don’t need to store an identifier on someone’s device because the device itself is the identifier.

I review AI tools for a living. I click through a lot of onboarding flows. Not one of them has ever mentioned this category of behavior. Not because the vendors are hiding it in the fine print, but because the fine print was written for a world where tracking meant cookies and pixels.

Nobody Has a Yardstick

The gap this exposes is measurement. You cannot review what you cannot test, and until recently there was no agreed method for testing whether an AI agent respects the boundaries it claims to respect.

The CLTC at UC Berkeley published a white paper in June introducing a method for evaluating the privacy and security of AI agents. That’s the boring, essential work. Not a demo, not a benchmark leaderboard, a method. Somebody had to build the yardstick before anyone could argue about the numbers.

Western University’s Centre for Teaching and Learning framed it more bluntly, calling conversational AI “a privacy trap that’s easy to ignore.” Easy to ignore is the operative phrase. The interface is a text box. It feels like a conversation. Conversations don’t feel like data collection, which is precisely why they’re such effective data collection.

The Market Already Knows

Here’s what I find genuinely interesting about the business side. Market forecasts for conversational AI through 2026 to 2033 project substantial growth, driven by AI-powered customer support and human-AI partnerships. Those same forecasts name data privacy and security concerns, along with weak contextual understanding, as the major factors holding growth back.

Read that as an admission. The analysts selling optimism about this category are also telling you, in the same document, that privacy is the ceiling. Not a footnote. A named constraint on revenue.

And the failure modes aren’t hypothetical. The sources describe incidents of unauthorized data exposure and outright catastrophic failures from deployed agents. An agent that leaks is worse than a database that leaks, because an agent has been handed permissions, context, and the ability to act. It doesn’t just hold your data, it goes places with it.

What This Changes About How I Review

I’m adjusting my own process, and I’d suggest anyone evaluating these tools do the same.

  • Stop treating the privacy policy as evidence. It describes intent, not behavior. The Vlummens paper exists because behavior and documentation diverged.
  • Ask about localhost specifically. If a vendor can’t tell you whether their mobile app and web properties communicate through loopback, that’s an answer.
  • Ask what evaluation method they used. The CLTC paper gives them something concrete to point at. “We take privacy seriously” is not a method.
  • Treat agent permissions as a cost. Every integration you approve widens the blast radius of a failure.

Implementing these systems requires high-quality customer data and deep integration with business systems for real-time operation. That is the architecture. The tracking capability isn’t a bug bolted onto the side, it’s a natural consequence of building something that needs to know everything to be useful.

Which means the fix won’t come from a settings toggle. It comes from measurement, disclosure, and buyers who ask harder questions than I was asking a year ago. The agents inventing religions made better headlines. The ones quietly linking your browser to your phone deserve more of your attention.

🕒 Published:

📊
Written by Jake Chen

AI technology analyst covering agent platforms since 2021. Tested 40+ agent frameworks. Regular contributor to AI industry publications.

Learn more →
Browse Topics: Advanced AI Agents | Advanced Techniques | AI Agent Basics | AI Agent Tools | AI Agent Tutorials
Scroll to Top