Project ideas from Hacker News discussions.

A Privacy Analysis of Web and Mobile Conversational AI Agents [pdf]

📝 Discussion Summary (Click to expand)

1. Poor access controls let anyone see private chats
- “Entire conversations via exposed permalinks. For Grok: trackers receiving the conversation URL could access the full chat because the link lacked access controls.” — damaru2
- “Multiple providers disclose sensitive conversation‑derived artifacts — including titles, prompts, and screenshots — to third parties… some providers publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation.” — Coeur
- “My least favorite trend … is they seem to equate a UUID in the url with privacy.” — postalcoder

2. Data sharing with advertisers is often intentional, a business model rather than a leak
- “No, they don't ‘leak data’, data is sold. Leaking data requires a mistake. This is intentional.” — drywater2
- “It's not a ‘leak’. It's in the T&Cs you agreed to. This is the business plan.” — kjs3
- “The word is ‘sell’ not ‘leak’.” — DrMandalay

3. rushed, low‑quality “vibe‑coding” and a move‑fast culture cause these failures
- “what do you want it's the era of vibecoding.” — ex1fm3ta
- “Incompetence and carelessness is rampant in our industry and with vibe coding it has only gotten worse.” — jeltz
- “the amount of vibecoded platforms and documentation is staggering.” — amarcheschi


🚀 Project Ideas

ShieldLink – Private, Expirable AI Chat Share Links

Summary

  • Provides token‑protected, time‑limited share links for AI chat conversations, eliminating reliance on insecure UUIDs.
  • Core value proposition: enforce real access control so only intended recipients can view a chat, even if the link is leaked or appears in browser history.

Details

Key Value
Target Audience Privacy‑conscious users of AI chat services (developers, professionals, teams)
Core Feature Wraps any chat URL with an auth gateway that requires a secret token, enforces expiration, and limits number of views
Tech Stack Node.js/Express backend, Redis for token storage, optional Cloudflare Workers for edge; lightweight React browser extension to auto‑wrap share links
Difficulty Medium
Monetization Revenue-ready: freemium (free limited links/month; paid tier for unlimited links, custom domains, analytics)

Notes

  • HN commenters warned that UUID‑based links are guessable and end up in browser histories; ShieldLink adds real authentication and expiry to mitigate this.
  • Practical utility: can be dropped in front of existing services (ChatGPT, Perplexity, Grok) without requiring them to change their sharing flow.

LocalLens – On‑device AI Chat Desktop App with Encrypted Export

Summary

  • Runs open‑source LLMs locally so no conversation data ever leaves the user's machine; offers encrypted export/share of chats.
  • Core value proposition: full data sovereignty and the ability to share conversations securely without trusting third‑party servers.

Details

Key Value
Target Audience Developers, privacy advocates, enterprises handling sensitive information
Core Feature Local inference via llama.cpp/Ollama, chat UI, export to password‑protected .enc file (AES‑256 via libsodium) decryptable only with the shared passphrase
Tech Stack Tauri (Rust backend + Svelte frontend), llama.cpp/Wasm for model inference, libsodium for encryption
Difficulty High (due to model performance, UI polishing, and secure packaging)
Monetization Hobby (open source) – optional donationware or premium model packs for revenue

Notes

  • HN users lamented that AI providers sell or leak chat data; LocalLens gives users complete control, addressing the “data is the business model” concern.
  • Practical utility: works offline, prevents accidental leaks via screenshots or history, and can be used in regulated environments.

TrackerBlock – Browser Extension to Strip AI Chat Tracking & Prevent Screenshot Leakage

Summary

  • Blocks requests to known ad/tracker domains from AI chat sites, strips tracking UUIDs from URLs, and adds warnings/overlays to deter accidental screenshots.
  • Core value proposition: reduces unintended data exposure while preserving the core chat experience.

Details

Key Value
Target Audience General users of AI chat services worried about privacy leaks and tracking
Core Feature Declarative network rules to filter out tracker requests, URL cleanup (remove UUIDs, session tokens), and optional page‑level CSS overlay that obscures content when a screenshot shortcut is detected
Tech Stack Manifest V3 extension (JavaScript/HTML/CSS), using declarativeNetRule API, regex‑based URL filters
Difficulty Low
Monetization Hobby (open source) – optional premium tier for advanced rule sets, reporting dashboard, and priority support (subscription)

Notes

  • Commenters noted that browser histories and accidental pasting expose UUIDs; TrackerBlock mitigates by cleaning links and blocking trackers before they harvest data.
  • Potential for discussion: could be showcased on HN as a lightweight privacy shield that works with ChatGPT, Perplexity, Grok, etc., and invites community rule contributions.

Read Later