Business

Nine bossware apps were tested for leaks. All nine leaked — to 145 domains, including Yandex.

Researchers from four universities posed as an employer, deployed nine popular monitoring platforms — Hubstaff, Deputy and Time Doctor among them — then logged in as workers and captured what the apps actually sent out. Every one shared workers’ names and emails with third parties. A Fortune feature today put the May study back in the spotlight.

N Noah · The Sharp Brief · August 23, 2026 · 3 min read

A research team from Northeastern, Columbia, Vanderbilt and UC Berkeley ran the cleanest possible test of employee-monitoring software: they signed up as an employer, deployed nine widely used platforms — a sample that included Hubstaff, Deputy and Time Doctor — then logged in as workers and recorded every byte the apps transmitted. All nine shared identifying worker data — first name, last name, email, employer — with outside companies. The study landed in May with less noise than it deserved. A Fortune feature published today changed that.

The scale is the story. The nine platforms sent workers’ online activity — IP addresses, device details, pages visited, unique identifiers — to 145 distinct third-party domains: Facebook, Google, Microsoft, LinkedIn, Stripe, mobile-ad platform AppLovin and yandex.com, the Russian search company. Each platform contacted between 14 and 54 outside domains. Researchers logged 121 separate instances of identifying data being shared, with worker emails going to as many as six third parties at once, including ZoomInfo and Segment. Only two of the nine vendors named any third-party recipients in their public privacy documents — and even those lists missed companies the researchers caught in testing.

Two details sharpen the picture. Three of the nine apps can track a worker’s precise location at any time — app in the background, worker potentially off the clock — and three require motion-sensor access just to clock in. And surveillance ran uphill: of the 121 data-sharing instances, 76 involved the managers’ own accounts. The boss who installs the watching software gets watched more than anyone in the building.

Our take: if you pay for monitoring software, this is your problem twice. Workers’ data is leaking to ad networks nobody consented to — and the researchers explicitly map that conduct onto UDAAP, FCRA and state privacy law, where the employer who deployed the tool carries exposure alongside the vendor. You cannot outsource compliance to a company that won’t name its own subprocessors. The same logic that applies to over-permissioned AI agents applies here: audit what your stack actually transmits, not what the brochure claims — and if the answer is ugly, run the vendor exit.

What to watch

The monitoring industry sold employers certainty about what their people do all day. What it built, per this study, is a second business selling everyone’s behavior out the back door — a pattern of unaudited tool risk the software world keeps relearning, from 143,000 vulnerabilities in MCP servers on down. The cheapest fix is knowing what you installed.

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 Side-Hustle Playbook lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.