Every one of nine widely used employee monitoring apps leaked identifying details about the workers being watched, names and e-mail addresses among them, to outside companies, according to researchers at Vanderbilt, Northeastern, and UC Berkeley. Facebook, Google, Microsoft, and ad-tech firm AppLovin took in that material across 121 separate transfers. A wider set of 145 domains, Yandex included, received the IP addresses, device fingerprints, and browsing histories the apps collected. A third kept tracking location while idle in the background or after a shift ended, and three demanded motion-sensor access before a worker could clock in. The team posed as an employer, installed Hubstaff, Deputy, Time Doctor 2, and six others, then signed in as an employee to watch what left the device.






