Skip to content
IdeaScout.
← Back to archive

Watchdog that monitors AI providers' privacy/training consent settings

AI-discovered

Problem

Users opt out of AI training on ChatGPT/Claude etc., but the setting silently flips back to 'allowed' after updates, new TOS acceptances or resubscriptions - and past conversations may already be added to training sets before you notice. There is no way to detect this, and screenshots can't prove anything.

Opportunity

A third-party watchdog service that periodically audits your consent/privacy toggles across AI providers, alerts you the moment a setting changes, and keeps a timestamped, verifiable audit log that could serve as evidence.

Market analysis

No consumer-facing tool was found that watches personal AI-provider consent toggles and alerts on silent changes; existing consent-monitoring products (Privado, TrustArc) are enterprise B2B for websites and apps. The gap is real and freshly documented, but the technical path is fragile: providers offer no API for reading privacy settings, so the watchdog depends on unofficial scraping that can break or violate terms.

Market · Privacy-conscious AI power users (ChatGPT/Claude/Gemini subscribers); demand signal is active HN discussion and repeated TOS-change outrage cycles, e.g. Anthropic's Sept 2025 opt-in training shift.

Pricing · Comparable consumer privacy subscriptions run a few dollars per month; enterprise consent-monitoring platforms are far pricier, leaving room for a $3-5/mo personal tier.

score 6/10 by glm-5.1

Pros

  • + Verified gap: existing consent monitors target companies, not individual AI users.
  • + Timely: every provider TOS change renews demand and press coverage.
  • + Timestamped audit log is a defensible, hard-to-copy evidence feature.
  • + Natural expansion path to team/enterprise compliance budgets later.

Cons

  • − No official APIs to read consent settings; browser-automation or scraping is brittle and may breach provider terms.
  • − Login delegation to a third party is a hard trust sell in exactly the privacy-sensitive audience it targets.
  • − Niche willingness to pay: most users never touch these settings at all.
  • − Providers could legitimize or expose settings via API, erasing the gap overnight.

Source

Hacker News (Tell HN)

Open original thread ↗

The hard part is not the alerting, it is the credential problem: to audit settings the service must act as the user, and the very people who want this tool are the least willing to hand an AI account session to a startup. A browser-extension model, where audits run locally on the user’s machine and only signed change-events sync to the log, sidesteps both the trust issue and most ToS exposure, and makes the timestamped evidence chain genuinely verifiable. That positioning, a local witness with a tamper-evident remote log, is the version of this that could survive contact with providers’ legal teams.