ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI information
Nine AI chat apps caught sending conversation titles and prompts to third parties, IMDEA paper finds

Nine AI chat apps caught sending conversation titles and prompts to third parties, IMDEA paper finds

AI information • Admin • • 8 views

On September 29, 2026, researchers at Spain's IMDEA Networks published a systematic privacy analysis, "Prompt like a Butterfly, Sting like a Tracker," applying static and dynamic testing to the web and mobile clients of nine mainstream conversational AI services: ChatGPT, Claude, Grok, DeepSeek, Gemini, Perplexity, Copilot, Mistral, and Meta AI. The conclusion is blunt: several providers hand conversation-derived titles, prompts, and even screenshots to third-party advertising and tracking services, along with persistent identifiers like advertising IDs, hashed email addresses, and tracking cookies.

Four findings worth reading one by one

First, the reach is wider than you'd expect. The study observed 124 third-party domains belonging to 44 organizations, 34 of them advertising and tracking services; nearly every tested service contacts at least one third-party tracker. Second, it's not just metadata being leaked: "conversation derivatives" like titles, prompts, and screenshots go to third parties, often alongside persistent identifiers that can tie conversations to long-term user profiles. Third, cookie consent popups and paid subscriptions offer limited protection — the leaks continue whether you clicked through the consent dialog or paid for membership. Fourth, some providers' conversation share links are public by default with no access controls; using "canary tokens," the researchers confirmed that shared conversations were subsequently accessed from distributed third-party infrastructure.

Why this research is appearing now

The backdrop is that major model vendors are turning advertising into a new business model. The paper cites Reuters reporting that OpenAI partnered with ad-tech company Criteo in early 2026 to pilot advertising for ChatGPT free-tier users in the United States. Once the chat box starts serving ads, the traditional internet's tracking infrastructure follows it into the conversation. The researchers also evaluated these practices under the GDPR and the ePrivacy Directive, and carried out responsible disclosure with the affected providers and European data protection authorities.

What it means for ordinary users

The default assumption has to change: chat history isn't "known only to you and the AI" — on some services, titles and prompts flow into the ad ecosystem, so be extra careful with sensitive conversations about medical issues, salary talks, or business plans. Second, treat share links with care: a public conversation permalink can be read in full by trackers, so check link permissions before sharing. Third, paying doesn't buy privacy exemption — the paper explicitly finds that subscription tiers offer limited protection. Similar disputes over chat-record privacy have surfaced before: once conversation data becomes an asset, it isn't only model vendors competing for it.

Recommended Tools

More