Nine Chatbots, One Ad Network, and One Button

The Hacker News submission that surfaced this paper on 29 September was titled “AI companies leak data to advertisers [pdf].” Both halves of that title need a second look, starting with the PDF. It looks like a one-author self-publication, and it isn’t. The paper is “Prompt like a Butterfly, Sting like a Tracker”, nine authors, eight of them at IMDEA Networks in Madrid, and it is licensed CC BY 4.0. It is hosted on the personal site of one co-author, Jorge Garcia-Herrero, who is listed as independent, which is what makes it look self-published. It is not on arXiv. The title page still carries the PoPETs template’s “YYYY(X)” placeholder, and the claim that it has been accepted to PoPETs 2027 comes from Garcia-Herrero’s own posts, not from the venue, whose 2027 page did not exist when I looked. I would call it a serious preprint that has not been through review, and read it as one.

The headline is about something a bit different from what the team measured. The team captured the web clients of nine services (ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Copilot, Mistral, Meta AI) and the Android apps of eight, in Spain in May 2026. One researcher drove each session by hand with a health-related persona. Each configuration, meaning consent choice, subscription tier and incognito mode, was captured once, on the reasoning that behaviour in pilots was “highly deterministic.” One co-author labelled the third-party domains by hand.

what reached whom

The paper’s introduction says 6 of 9 web clients and 3 of 8 Android clients disclose conversation URLs, titles, prompts or screenshots to third parties. Those counts come from the paper’s introduction and §6.1, and they hold up against Table 4, the table of flows. What that sentence does not say is who the third parties are. I went through Table 4 row by row, and sorted the recipients into three kinds.

A dense table, one row per chatbot, platform and tracker, with columns for the permalink and content artifacts sent, the user identifiers sent with them, and icons showing whether guest, free and premium tiers were affected.
Table 4 of the paper: each row is one service, one recipient and one kind of interaction. The Grok rows fill the middle of the table, and the icons in the last three columns say whether a flow needed the user to accept cookies. Image: Oliveira et al., "Prompt like a Butterfly, Sting like a Tracker," Table 4, source PDF, CC BY 4.0. Cropped from page 8.
Who receives a web chatbot's conversation artifacts, by service and consent state A dot matrix of six web chatbot clients against three kinds of recipient. Each dot is one recipient. Filled dots receive the artifact even when cookies are rejected; outlined dots only after the user accepts. ChatGPT: one monitoring vendor, filled. Claude: two, Intercom filled and Datadog outlined. Gemini: one provider-owned analytics endpoint, filled. Grok: seven ad and pixel endpoints, all outlined. Mistral: one support vendor, outlined. Perplexity: one monitoring vendor, filled. RECIPIENTS OF URL, ID, TITLE OR PROMPT · WEB · OLIVEIRA ET AL., TABLE 4; CATEGORIES ARE MINE Monitoring and support Datadog, Intercom Provider’s own analytics Google Analytics Ad networks and pixels seven endpoints ChatGPT Datadog — ChatGPT: sent even when cookies are rejected Claude Intercom — Claude: sent even when cookies are rejected Datadog — Claude: sent only after the user accepts Gemini Google Analytics — Gemini: sent even when cookies are rejected Grok DoubleClick — Grok: sent only after the user accepts Google Ads — Grok: sent only after the user accepts Google Search — Grok: sent only after the user accepts Google Tag Manager — Grok: sent only after the user accepts Meta — Grok: sent only after the user accepts TikTok — Grok: sent only after the user accepts X Analytics — Grok: sent only after the user accepts Mistral Intercom — Mistral: sent only after the user accepts Perplexity Datadog — Perplexity: sent even when cookies are rejected sent even when the banner is rejected sent only after the user accepts Grok’s seven: DoubleClick, Google Ads, Google Search, Tag Manager, Meta, TikTok, X Analytics. Claude’s Datadog flow is accept-only per the paper’s §6.1; its Intercom flow is not. Mistral requires accepting its terms, so “accepts” there is not an optional button.
One dot per recipient. The six services differ less in how much they send than in who gets it, and Grok is the only row where that is an advertising endpoint.

Datadog and Intercom, which receive the conversation URL or ID from ChatGPT, Claude, Mistral and Perplexity, sell monitoring and customer-support tooling. Google Analytics, which gets Gemini’s chat titles under every consent setting, belongs to Gemini’s own provider. The seven endpoints that get Grok’s titles and URLs are the ones the word “advertisers” fits, with Google Search the loosest fit among DoubleClick, Google Ads, Tag Manager, Meta, TikTok and X Analytics. The paper’s discussion says as much about its own category: the presence of a third party “does not by itself imply” that data is sent “only for advertising or tracking purposes.” Its conclusion then speaks of “third parties with advertising-based business models.” In normal use, Table 4 supports that sentence for one service.

The consent column narrows it again. Every Grok row is marked as occurring only after the user accepts non-essential cookies, and the paper says that ignoring the banner produces no connections beyond those seen when rejecting it.

Nine web chatbot clients narrow to one ad-network recipient, and none without consent A four-row bar chart out of nine web chatbot clients. Nine contact at least one third-party tracker or analytics service. Six send one a conversation URL, identifier, title or prompt. One, Grok, sends it to ad networks or social pixels. None does so while the cookie banner is ignored or rejected. WEB CLIENTS, OUT OF NINE · NORMAL-CONVERSATION FLOWS · SPAIN, MAY 2026 · MY TALLY OF OLIVEIRA ET AL. Contacts at least one third-party tracker or analytics service 9 of 9 — every web client; Oliveira et al. 2026 9 of 9 Sends one a conversation URL, ID, title or prompt 6 of 9 — ChatGPT, Claude, Gemini, Grok, Mistral, Perplexity; Oliveira et al. 2026 6 of 9 ChatGPT, Claude, Gemini, Grok, Mistral, Perplexity Sends it to an ad network or social pixel 1 of 9 — Grok; Oliveira et al. 2026 1 of 9 Grok Does so while the cookie banner is ignored or rejected 0 of 9 — every Grok ad-endpoint row is accept-only; Oliveira et al. 2026 0 of 9 every Grok ad-endpoint row is accept-only Ad network or social pixel: Google Ads, DoubleClick, Google Search, Tag Manager, Meta, TikTok, X Analytics. Gemini’s titles reach Google Analytics under every setting; Google is Gemini’s own provider, so I counted it in row 2 only. One capture per configuration.
From “leak data to advertisers” to what Table 4 records. The gap between rows 2 and 3 is monitoring and support vendors plus Gemini’s own analytics; the gap between rows 3 and 4 is one button.

The Datadog and Intercom flows still matter. Table 4 shows Claude’s web client sending Intercom a user ID, an email address, an organization ID and a hash alongside the chat URL, and Perplexity’s web client sending Datadog an email address with the chat URL. Those are processors receiving identifiable conversation metadata, and the paper argues under the GDPR that users are owed a clear account of it. It is a different problem from ad targeting, and the paper is careful to say it is not offering “a definitive legal assessment.”

the sharpest case, and the ordinary one

Grok is where the paper’s most concrete finding lives. Its web client sent the conversation ID, the auto-generated title and the chat URL to seven endpoints, with Meta’s _fbp and TikTok’s _ttp cookies riding along. The paper says the Meta and TikTok events also travel server to server through a Google Tag Manager relay, where an ad blocker cannot see them. On a shared-conversation page, the paper reports TikTok receiving a screenshot of the most recent part of the conversation, and Meta and TikTok both receiving the latest prompt. All of it, again, sits behind the Accept button.

Claude appears in the paper for a similar mechanism. After the user accepts non-essential cookies, the paper reports Segment analytics loaded through a first-party domain (a-cdn.anthropic.com), forwarding events from Anthropic’s servers to eleven trackers, among them Facebook, LinkedIn, TikTok and Reddit. Rejecting cookies prevented that, and the passage does not say a conversation URL or title is in those events; it says two shared IDs travel with each one. The Anthropic help page I read lists Facebook, Reddit, TikTok and Twitter cookies among its marketing cookies, and neither it nor the cookie policy mentions server-side forwarding, as far as I could find. A missing mention on two pages is thin evidence either way. It tells you where a reader would have to look.

three numbers about rejecting

The paper’s central claim about controls is that they help little, and it gives three numbers for it. It states that “80.8% of third-party trackers remain active” after a reject, that in 4 of 9 services third-party trackers still collect data when the user rejects, and, separately, that six services (Perplexity, DeepSeek, Gemini, Copilot, ChatGPT, Claude) still connect to Google Ads under reject. The denominators differ (trackers, services, connections), and I could not reconcile them from the text. A connection to Google Ads after a reject is not a conversation artifact reaching Google Ads; Table 4 is where the artifacts are, and it has no Google Ads row for those six. Google’s consent-mode pings are one thing that could make a connection appear without carrying content, though the paper does not say that is what happens.

sent is not read

The paper’s evidence on reading is the canary test, and it is the part that travels worst. The authors planted unique URLs inside prompts and uploaded files and watched for anyone fetching them. Grok’s is the only one the paper counts as external access: 70 activations, from 70 IP addresses in 48 networks across 14 countries, over hours to days. For DeepSeek, Copilot, Mistral and Claude, some canary URLs were fetched once, from cloud addresses at submission, and Perplexity’s crawler kept fetching even when the prompt told it not to. But the URLs were pasted in by the authors. They were not permalinks handed to a tracker, so the test shows that a link a user puts into Grok is fetched from many addresses. It does not show that a tracker holding a permalink read the conversation behind it, and the paper’s conclusion (“we confirmed that shared conversations are subsequently accessed”) is stronger than the test. The paper, to its credit, adds that the “absence of observed accesses should not be interpreted as evidence that no access occurs.” The project website in May was more careful than some later commentary: “we do not yet have evidence that conversations are read by trackers,” it said, while the capability exists. Garcia-Herrero’s posts of 21 September and 22 September go further and say that third parties read chat text, screenshots and documents. The paper does not measure that.

Grok’s permalinks are a separate matter, and the one place the paper reads as a security finding. The authors emailed xAI’s vulnerability-disclosure address on 17 April. On 10 September, by the paper’s account, Grok permalinks were still publicly accessible and no official response had been received.

Disclosure timeline for the Grok permalink finding, 23 March to 10 September 2026 A timeline. 23 March 2026: authors first notice tracker activity. 13 April: data-protection authorities notified. 17 April: xAI notified by its vulnerability-disclosure email. 4 May: partial findings published on the project website. 27 May: the Spanish data-protection agency writes to the European Data Protection Board. 10 September: the paper says Grok still uses publicly accessible permalinks and no official response has been received. A bracket marks 146 days from the xAI notice to that statement. GROK PERMALINK DISCLOSURE · 2026 · AS STATED IN THE PAPER, EXCEPT 27 MAY (AEPD) 23 Mar 2026 13 Apr 2026 17 Apr 2026 4 May 2026 27 May 2026 10 Sep 2026 23 Mar: first tracker activity seen 17 Apr: xAI notified by email 13 Apr: data-protection authorities notified 4 May: partial findings public 27 May: AEPD writes to the EDPB 10 Sep: Grok permalinks still public, no reply 146 days 146 days is my arithmetic from the paper’s two dates. The paper’s own timeline also lists 15 Aug (an OpenAI policy update), which I could not confirm.
The security-relevant finding in the paper is one service’s public permalinks, disclosed by the standard route, and the paper records no reply.

the other paper

A concurrent preprint from Jazlan, Wang, Vekaria and Shafiq, posted on 30 April and revised on 13 May, covers 20 web chatbots with one prompt each and no consent or sharing tests. It found 17 of 20 sharing information with at least one third party and 15 of 20 sending a conversation URL or chat ID to one. Its harder result is about content: three chatbots not in the IMDEA set (Genspark, SeaArt and ChatOn) sent plaintext conversation text to Microsoft Clarity’s session replay. It also reports “no identity or content exposure to any third party in any private chat session,” which sits awkwardly with the IMDEA table, where several flows are marked as also occurring in incognito mode. Both papers agree on the recurring identifiers, Meta cookies and Perplexity’s hashed emails going to Singular. The Federal Trade Commission wrote in July 2024 that hashes “aren’t ‘anonymous’ and can still be used to identify users.” On reading, the stronger evidence of conversation text in third-party hands is in the paper the headline did not go to.

the record moved under it

The May version of the project website covered four services, and it described Perplexity’s Meta pixel as discontinued on 3 April. The paper says Perplexity stopped sharing conversation URLs with trackers such as Meta that day, possibly in response to a US class action. The website also says ChatGPT sent page titles and URLs to Google Analytics for free logged-in users regardless of consent; I do not find that flow in the final paper’s Table 4, whose ChatGPT row is Datadog alone. The two may differ by date or by capture, and the repository’s domain-label file has no ChatGPT row for Google Analytics either. I cannot tell which is right. The paper also says OpenAI updated its privacy policy on 15 August to mention third-party trackers. The US policy now reads “Updated: September 10, 2026” and the EU policy 24 August, and the cookie policy speaks of “third-party cookies” and pixels. I could not find the 15 August version. And the paper puts the European data-protection board’s plenary at 6 June, where the Spanish agency’s 27 May note says 8 and 9 June. That note is a coordination request, worded in the conditional (“que permitirían”). It lists Google, Meta and TikTok as example recipients and names no chatbot.

None of these slips changes what Table 4 records. They change how much weight a single capture in May can carry in late September, and the paper calls its own results “a point-in-time lower bound.”

where the habit comes from

The mechanism underneath is older than chatbots. A page that loads a third party’s pixel tells that party where the visitor is, and the web has worked that way for a long time. RFC 1945, the May 1996 specification for HTTP/1.0, defines the Referer header, which carries the address of the page a request came from, and adds a note that “it is strongly recommended that the user be able to select whether or not the Referer field is sent.” The recommendation was a note. A chat URL is a page address, and the appendix shows Grok’s pixel calls carrying it as the dl parameter, next to a title the model wrote about you. What is new is that the address is a description of what you asked.

I wrote a few days ago about a privacy promise whose paper trail was about another product. This one is the reverse: a careful paper trail with a headline running ahead of it. The version I would defend has three parts. In May 2026 one of nine web chatbots sent conversation titles and URLs to ad networks once a user clicked Accept. Several others sent conversation identifiers and account details to monitoring and support vendors. And by the paper’s 10 September statement Grok still had conversation permalinks readable by anyone holding the link, 146 days after the authors told xAI. What I would want next is a repeat capture of the same nine, with the tracker classes separated.


References

  1. Oliveira, G., Sanchez, M., De Santa Olalla Gómez, J. M., Serna, R. S., Jackevicius, T., Garcia-Herrero, J., Girish, A., Suarez-Tangil, G., Vallina-Rodriguez, N. (2026). Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents. Preprint, file dated 16 September 2026; fieldwork May 2026. Artifacts: github.com/guinucool/pbst2027.
  2. Jazlan, M., Wang, E., Vekaria, Y., Shafiq, Z. (2026). Tracking Conversations: Measuring Content and Identity Exposure on AI Chatbots. arXiv:2604.27438, v1 30 April 2026, v2 13 May 2026.
  3. Agencia Española de Protección de Datos (2026). Press note on the IMDEA Networks study and the EDPB. 27 May 2026.
  4. LeakyLM project site (2026). leakylm.github.io. Four-service preview, released 4 May 2026 per the paper.
  5. Hacker News (2026). AI companies leak data to advertisers [pdf]. Submission of 29 September 2026.
  6. Garcia-Herrero, J. (2026). ChatGPT, Claude y estas otras IAs comparten datos de tus chats con terceros. Author’s post, 21 September 2026; and I do not know if AI will kill us, Zero Party Data, 22 September 2026.
  7. OpenAI (2026). Privacy policy (US, updated 10 September 2026), EU privacy policy (updated 24 August 2026) and cookie policy (10 September 2026). Read 29 September 2026.
  8. Anthropic. Cookie policy (effective 19 March 2024) and What cookies does Anthropic use?, help-center article, undated. Read 29 September 2026.
  9. Federal Trade Commission, Office of Technology (2024). No, hashing still doesn’t make your data anonymous. 24 July 2024.
  10. Berners-Lee, T., Fielding, R., Frystyk, H. (1996). Hypertext Transfer Protocol – HTTP/1.0. RFC 1945, May 1996, section 10.13.