ARTIFICIAL INTELLIGENCE

Study Finds AI Chatbots Leak Conversation Titles, Prompts and Links to Ad Trackers

A peer-reviewed privacy analysis of nine major conversational AI services, including ChatGPT, Claude and Grok, found that many leak chat titles, prompts, screenshots and permalinks to third-party advertisers and analytics firms, often alongside identifiers that let those companies tie conversations to individual users.

Researcher's monitor displaying network traffic logs showing a chatbot conversation being sent to third-party ad tracking domainsARTIFICIAL INTELLIGENCE

Image: https://jorgegarciaherrero.com/ · Uploaded by IntraGoals — usage rights confirmed

Researchers from IMDEA Networks and UC3M have published a systematic privacy analysis showing that popular conversational AI services routinely expose sensitive conversation data to third-party advertising and tracking companies, raising questions about compliance with European privacy law.

The study, titled "Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents," examined the web and mobile clients of nine prominent services: ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Microsoft Copilot, Mistral's Le Chat, and Meta AI. Using both static and dynamic analysis techniques, the team traced how these platforms handle data as advertising-based business models spread into the AI industry — a shift exemplified by OpenAI's advertising pilot with Criteo for ChatGPT's free tier, reported by Reuters earlier this year.

The researchers found that every one of the nine services connects to at least one third-party advertising or tracking service. Across their tests they identified 124 distinct third-party domains tied to 44 organizations, 34 of which function as advertising or tracking services. Google-owned products were the most pervasive, followed by Sentry, Meta, Datadog and Intercom. The study also flagged lesser-known Chinese tracking services, Fengkong Cloud and ShuMei, operating on DeepSeek's mobile and web clients respectively.

More striking than the presence of trackers, the researchers say, is what gets shared with them. Six of the nine web clients and three of the eight Android clients were found to disclose conversation-derived artifacts — including chat titles, URLs, prompts and even screenshots — to outside companies. In one example involving Grok, a single conversation was shown propagating to seven separate advertising and analytics trackers, including Meta, TikTok, Google Ads and Twitter Analytics, each receiving the same conversation identifier and AI-generated title. When users shared a Grok conversation, TikTok also received a screenshot of the exchange and both TikTok and Meta received the user's most recent prompt.

These disclosures often traveled alongside persistent identifiers such as hashed email addresses, advertising IDs and session cookies, which the researchers say could let third parties link conversations to long-term, cross-platform user profiles. Rejecting non-essential cookies reduced but did not eliminate this exposure: some tracker connections, including to Google Ads, persisted even after users declined cookie consent across several services. Subscription tier made little difference — free and paid accounts largely faced the same tracking infrastructure.

The study also examined whether shared conversation links were publicly accessible without authentication. It found that some providers, notably Grok and, in guest mode, Perplexity, exposed conversation permalinks by default, with only an opt-out available rather than access restricted from the outset. To test whether these exposed links were actually being visited by outside parties, the researchers embedded canary tokens — trackable dummy links — inside conversations and uploaded files. Grok's shared links were accessed repeatedly, generating 70 distinct activations from IP addresses spanning 48 networks in 14 countries over hours to days after submission, with nearly two-thirds of the access attempts originating in the United States despite the tests being run in the European Union.

The authors situate their findings within the European Union's GDPR and ePrivacy Directive, arguing that several of the observed practices sit in tension with requirements for informed consent, a valid legal basis for processing, and clear disclosure of data recipients. They note that providers' privacy policies often use vague language — terms like "user content" or "service interaction info" — that does not specifically disclose third-party access to conversation artifacts.

The research team followed a responsible disclosure process, notifying European data protection authorities in April and alerting xAI directly about Grok's exposed conversation links, which the researchers identified as the one issue that could be exploited by an outside party due to weak access controls. Spain's data protection agency, the AEPD, later cited the work in a request to escalate the matter for discussion at a European Data Protection Board meeting. As of the study's most recent update in September, Grok's permalinks remained publicly accessible by default, and the researchers say they have received no official response from xAI.

The paper's authors argue that their findings challenge the common perception of conversational AI as a private exchange between a user and an AI provider, showing instead that these platforms are becoming enmeshed in the same tracking ecosystem long associated with ordinary web browsing and mobile apps — but with far more sensitive material at stake.

Sources and further readingAI companies leak data to advertisers [pdf] ↗
ABOUT THE DESK

IntraGoals News Desk

IntraGoals reports on important changes in technology and work. We check each story for clear writing, trusted sources and useful information before it is published.

KEEP READING

Latest from IntraGoals.

All latest stories ↗
Study Finds AI Chatbots Leak Conversation Titles, Prompts and Links to Ad Trackers | IntraGoals