You have probably seen the headlines in the last week. Social media platforms being held liable for how they handle user data. New rulings about consent, about what companies can collect, about who is responsible when that data gets misused. It is the same conversation we have been having for years, just louder now.
But here is the thing about the data privacy conversation. It is almost always framed around fear. Someone took your data. Someone sold it. Someone used it to manipulate you. The language is adversarial. The solutions are regulatory. And the feeling it leaves you with is a kind of low-grade dread that sits in the background of every click.
Thanks for reading AI with breakfast! Subscribe for free to receive new posts and support my work.
This morning, before breakfast, I wanted to approach it from the opposite direction.
Check it out https://onceart.leemallon.com
The Data You Are Already Giving Away
Right now, your browser is leaking information about you. Not through cookies or login sessions or anything you opted into. Through the machine itself.
Your screen resolution. Your timezone. Your battery level. The number of CPU cores in your device. The GPU model. The fonts installed on your hard drive. Your colour depth. Your connection speed. The exact millisecond you arrived on a page.
This is not hypothetical. This is how browser fingerprinting works. Ad networks use these signals - over fifty of them - to identify and track you without ever needing a cookie. It is one of the reasons “clearing your cookies” does not actually stop you from being tracked. Your machine has a shape, and that shape is as unique as a thumbprint.
Most people do not know this is happening. And the people who do know tend to respond with either resignation or outrage. Both are understandable. Neither changes anything.
So I asked a different question. What if you took exactly the same data - every signal, every fingerprint - and instead of using it to track someone, you used it to make something beautiful?
once art
once art is a website. You visit it, and it creates a unique artwork using only the data your device is already leaking. Nothing is sent to a server. Nothing is stored. No cookies. No analytics. No tracking pixels. The entire thing runs in the browser with zero server calls.
Why Show The Art For Just Thirty Seconds?
The time limit is not a gimmick. It is the point.
In a world where everything digital is copied, screenshotted, cached, and archived, once art creates something that genuinely cannot be reproduced. The combination of signals that generated your piece - down to the millisecond timing of performance.now() - will never occur again. Right-click is disabled. Drag-to-save is blocked. The piece requests fullscreen.
These are not security measures. Anyone technical enough could work around them. They are design decisions that reinforce the message: this is yours, and it is temporary. Like every moment.
Think about that for a second. We live in an era of infinite reproduction. Every photo, every post, every piece of content is designed to persist, to be shared, to accumulate engagement. once art does the opposite. It creates something that exists only in the moment of its creation, shaped entirely by the circumstances of your visit, and then it lets it go.
It is an analogy for how we should think about data. Something experienced, not extracted. Something present, not permanent.
The Art Is Not Random
This is the part that matters technically. Every visual decision in the artwork is driven by real signals from the viewer’s machine.
Someone on a fast connection with a high-res screen and a fully charged battery will see a fundamentally different piece than someone on mobile with 12 percent battery over 3G. Your time of day shifts the colour temperature. Your installed fonts affect the texture density. Even your mouse movements during the experience get hashed into the generative seed.
The piece harvests over fifty signals - hardware specs, network conditions, browser configuration, temporal data, device state - and normalises them into a vector that seeds a deterministic random number generator. Same inputs, same art. But the inputs will never be the same twice.
The whole project is vanilla JavaScript. No frameworks. No dependencies. No build tools. A single file you open in a browser. This was a deliberate choice. The thing that is making a point about data minimalism should itself be minimal.
So why write about a generative art experiment?
Because the pattern behind it points toward something much bigger that is about to happen.
Two years ago I wrote a book about hyper-personalisation called DKR (Dynamic Knowledge Rendering). At the time, most people treated the idea as niche. But 2027 personalisation goes mainstream. By the end of 2027, hyper-personalisation will not be a buzzword. It will be the default expectation. Every feed, every interface, every experience shaped precisely around you.
And now, with the rise of AI agents acting on our behalf - browsing, booking, filtering, deciding - the stakes around personalisation have changed completely. These agents will need to know us intimately to be useful. Which raises an uncomfortable question: does hyper-personalisation have to mean hyper-surveillance?
What if it did not? What if personalisation in this new AI-driven world could be privacy-first by design? What if the data that makes an experience uniquely yours never had to leave your device, never had to be stored, never had to be sold? What if it stayed entirely in your control?
That is the question once art accidentally answers. It creates a deeply personal experience - unique to your device, your moment, your exact configuration - without collecting a single thing. No server calls. No profiles. No data leaving the browser. Hyper-personalisation with zero extraction.
This is not a policy proposal. It is a provocation. A thirty-second one. But it demonstrates a pattern that matters far beyond art. As AI agents become the primary way we interact with the internet, we are going to need new models for personalisation that do not require surrendering everything about ourselves to a platform. The old bargain - your data in exchange for relevance - does not have to be the only deal on the table.
Provocations are how the edges of conversations move. The privacy debate is stuck in a loop of fear, regulation, and compliance. We need more people approaching it from unexpected angles - through design, through art, through experiences that make people feel the weight of their own data rather than just reading about it in a terms-of-service update.
I built this before breakfast.
Not because the world needs another art project, but because the convergence of hyper-personalisation and AI agents is about to reshape how we live online, and we are sleepwalking into it with the same extractive model we have had for twenty years.
As AI agents get more capable and more personal, the question will not be whether they know us. It will be who controls that knowledge. The platform, or the person.
Every person’s machine already carries a unique fingerprint. That fingerprint is currently being used, billions of times a day, to serve ads and build profiles. once art uses the same fingerprint to create something that exists for thirty seconds and then disappears forever. No server. No storage. No extraction. Just a moment of personalisation that belongs entirely to you.
That is the model I want to see more of. Not just in art. In agents. In interfaces. In the infrastructure we are building right now that will define how personalisation works for the next decade.
We get to choose. And we should choose before someone else chooses for us.
Check it out https://onceart.leemallon.com
Thanks for reading AI with breakfast! Subscribe for free to receive new posts and support my work.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.