Study Finds Conversational AI Services Leak Conversation Artifacts to Third-Party Trackers
Key point
A privacy analysis of nine major AI assistants reveals that 6 web and 3 mobile clients leak conversation artifacts like URLs and IDs to third-party trackers, with specific services exposing titles and prompts.
Details
A new study published in the Proceedings on Privacy Enhancing Technologies analyzes the privacy practices of nine major conversational AI services, including ChatGPT, Gemini, Claude, Grok, DeepSeek, Perplexity, Copilot, Le Chat, and Meta AI. The research identifies that these services integrate traditional web and mobile advertising trackers, exposing user interactions to third-party data brokers.
Third-Party Tracking Infrastructure
The study found that every evaluated service integrates at least one third-party advertising or tracking service (ATS). In total, 44 distinct organizations were identified as receiving data from these platforms. Key findings include:
- Web Clients: 6 out of 9 services transmit conversation artifacts to third parties. Specifically, 5 web clients leak conversation URLs, 3 leak conversation titles, and 1 leaks user prompts.
- Mobile Clients: 3 out of 8 Android apps exhibit similar leakage, primarily involving conversation IDs.
- Persistent Identifiers: Data is often sent alongside persistent user identifiers (such as hashed emails, AAIDs, or tracking cookies), enabling cross-platform user profiling.
- Server-Side Tracking: Services like Claude use Segment Analytics to forward events to 11 trackers (including Facebook and LinkedIn), bypassing ad blockers. Grok uses server-side Google Tag Manager to send conversation URLs and titles to Meta and TikTok APIs.
Conversation Artifact Exposure
Unlike traditional browsing, conversational AI generates artifacts that directly encode user intent and sensitive information. The study highlights specific leakage vectors:
- Conversation Titles & Prompts: Sent to trackers like Meta, TikTok, and DoubleClick. For example, Grok’s Meta Pixel collects conversation IDs, chat titles, and full URLs, linking them to Meta identities via synced cookies.
- Permalinks: Several services generate public conversation links by default or with weak access controls. Grok and Perplexity were found to have permalinks accessible to third-party crawlers. Canary URL tests revealed that Grok conversations were accessed by automated agents from 14 countries, with 65.7% of accesses originating from US infrastructure despite EU-based interactions.
- Screenshots: Grok’s sharing feature sends screenshots of the latest conversation portion to TikTok and Meta.
Consent and Legal Implications
The research indicates that current consent mechanisms offer limited protection. Even when users explicitly reject non-essential cookies, 80.8% of third-party trackers remain active across the ecosystem, though rejecting cookies did prevent specific leaks in services like Claude. Subscription tiers (Free vs. Premium) showed minimal difference in tracking infrastructure. Roughly 95% of ChatGPT users remain on free tiers, where OpenAI has announced plans for advertising.
From a regulatory perspective, the study argues these practices may conflict with the GDPR and ePrivacy Directive. The transmission of chat data to third parties for advertising purposes lacks clear legal basis, and transparency notices often use vague terms. The study notes that these findings raise important technical and regulatory challenges for AI-mediated services.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.