ChatGPT, Gemini, and Claude are leaking your conversations to advertisers

AI companies leak data to advertisers [pdf]

A systematic privacy analysis of nine conversational AI services—including ChatGPT, Gemini, and Claude—reveals that every one integrates third-party advertising or tracking services. Six of nine web clients and three of eight Android clients disclose conversation URLs, titles, prompts, and even screenshots to third parties, often alongside persistent user identifiers. Some providers expose entire conversations through public permalinks without access controls, creating a novel privacy attack surface that challenges the perception of AI chats as confidential.

Our results challenge the perception of conversational AI services as confidential exchanges between users and AI providers. Instead, they are increasingly integrated into the broader online tracking ecosystem.
  1. delis-thumbs-7e

    In an old Simpsons episode Lisa gets to visit the Teachers room, where all the staff are making fun of the children. Groundskeeper Willie is pantomiming Milhouse “Oh I am Milhouse, I tell all my secrets to Willie since I have no friends!” and the teachers laugh. Later something embarrassing happens to Milhouse and he immediately runs away crying “I have to tell this to Willie!”.

    We have all become Milhouse now.

  2. Coeur

    "multiple providers disclose sensitive conversation-derived artifacts — including titles, prompts, and screenshots — to third parties, often alongside persistent user identifiers that enable user attribution. We also find that some providers publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation."

    Not good at all.

  3. drywater2

    No, they don't "leak data", data is sold. Leaking data requires a mistake. This is intentional.

  4. pbasista

    Tangential:

    I have recently noticed that e.g. ChatGPT, when used from a web browser, periodically sends unfinished prompts to their servers, namely to the `conversation/prepare` endpoint, without waiting for the user to actually send it.

    This partial prompt data might potentially be used to "pre-warm" some kind of cache.

    But it may also be used to track the user's writing cadence, error correction style and evolution of their stub ideas as they are being formulated into a prompt. I would assume that such data could also be sold to the advertisers.

  5. kdaniel_03

    It's the same lesson as the Navier-Stokes credit fight earlier this month. Buckmaster and Alpoge had their unpublished drafts in private Codex sessions and OpenAI says nobody saw them but admits de-identified product data may have improved its models. There it's training data, here it's ad trackers. Either way, prompts and results that should stay private don't.

    Thats why even though open models aren't perfect it has to win. You can skip the app and run the model yourself.

  6. segmondy

    Prior to this new AI age, your data was calculated and what was inferred about you was "shallow", but as of today. The sort of profile and things that can be known about you is scary especially if you are constantly engaged with cloud AI. IMO, the number one risk of using cloud AI is loss of privacy and loss of freedom. With AI and capabilities, more controls can be placed on people and the more you put yourself out there, the more you are going to lose.

    For example, we now have self driving cars, we have cameras everywhere. Based on your chat with a cloud AI, you can automatically trigger an automatic monitoring event that follows and tracks you in the real world with the fleet of cameras, cars, GPU, cell signal. Your tracking due to AI has moved into the real world and eventually, a self driving car will take you in to be "processed" against your will, not even for what you posted in a public forum, but for your private ribbing and chatting with some cloud AI.

    So definitely put local AI into the mix and keep personal stuff and thoughts local only.

  7. j4k0bfr

    This is a bit surprising to me, considering how much AI companies love to hoard data. Especially since some of these ad companies are direct competitors!

    My best guess is that these ad mechanisms are a bit rushed and/or that investor demands for profitability are fighting against company self-interest.

    Edit: I guess some data will always need to be leaked for AI chat ads to be most effective. But I imagine AI companies would rather deliver the targeted ads themselves rather than letting competitors do it for them. It would be scary to see AI companies become ad companies too (instead of just hosting them).

  8. skybrian

    In case anyone finds it helpful, I asked ChatGPT to break down what they found by app:

    https://chatgpt.com/s/t_6abbbee386bc8191a26717b4f1442657

More from this day

2026-09-29