Study finds conversational AI services hand chat titles, prompts, and screenshots to ad trackers
- A static and dynamic privacy analysis of the web and mobile clients of nine conversational AI services found multiple providers disclosing conversation-derived artifacts (chat titles, prompts, and screenshots) to third-party advertising and tracking services, often alongside persistent identifiers that let those parties attribute the data to a specific user.
- Grok was the worst case: conversation permalinks had no access controls, so any tracker that received the URL could read the entire chat, and TikTok received screenshots of Grok conversations during sharing, exposing the visible chat content itself.
- Auto-generated chat titles leak sensitive facts on their own. The paper cites a title reading "Salary 85k NYC: mortgage 280-350k" as an example of what reaches third parties.
- The authors tested how consent choices, subscription tiers, privacy settings, and access controls change exposure, analyzed the results against the GDPR and ePrivacy Directive, and ran a responsible disclosure process with the affected providers and European data protection authorities.
- The work lands as advertising business models spread into chat AI: Reuters reported that OpenAI ran a ChatGPT free-tier advertising pilot with Criteo in the United States in early 2026.
Hacker News opinions
A full conversation readable from just the URL is staggering incompetence. Grok permalinks had no access controls at all, so a tracker that got the link had the whole chat.
The screenshots part bothers me more. People leave so much sensitive stuff visible on screen, and that image just ships straight to an ad network.
Is it even a leak when the leak is the entire point of the deal? Someone should investigate, but I guess it all counts as legal.
Legal in the US maybe. In the EU this looks like a plain GDPR violation to me.
Call it sold, not leaked. Using the word leak takes all the agency away from companies selling private data to advertisers.
Nobody seems to be asking when the app actually sends the conversion artifact. The paper doesn't pin down the timing, and that's the part I want answered.
Perplexity has the same habit of treating a UUID in the URL as privacy. Open an old search URL and your entire conversation is sitting there.
If you never share the URL, who is going to guess it? Except that's security by obscurity, an anti-pattern older than the web. Share links get prefetched, indexed, shortened, and scraped. Claude artifacts got indexed en masse by Google not long ago.
Isn't that basically a password? Knowing my password exposes all my data too, we just accept that tradeoff.
I'd be surprised if OpenAI did this on purpose. A bunch of their execs came from Meta and learned the hard way: you keep the targeting data in house and sell the ad placement yourself, that unique data is the whole competitive advantage.
The lesson they took from Meta is that when the profit beats the reputational hit, it's full steam ahead. They didn't learn the lesson, they learned the wrong one.
They're hemorrhaging money with no path to profitability and enormous data center commitments, so they need revenue now. Hoarding data is more profitable long term, but long term may not be on the table.
The vibecoding angle here is real. I'm in onboarding at an AI company that serves much bigger AI companies, and the amount of broken platforms and never-tested pipelines is staggering.
Hanlon's razor. These tools are almost certainly vibecoded at this point, and carelessness in this industry was already rampant before vibecoding made it worse.
My read of the abstract is that this is accidental, a rushed implementation chasing profitability. I also wouldn't be shocked if some of it were deliberate, but that's a different story.
At least the Chinese models are upfront about collecting your data.