Skip to content
← All news
4 min read

Nine AI chatbots tested: most web apps send chat data to ad trackers

IMDEA Networks researchers tested ChatGPT, Claude, Grok, Gemini and five more. Six web clients and three Android apps handed conversation URLs, titles, prompts or screenshots to third parties, often next to a persistent user ID.

Reject every non-essential cookie on nine AI chatbots and 80.8% of their third-party trackers keep running.

Researchers at IMDEA Networks tested nine AI chatbots and found that six web clients and three Android apps sent conversation URLs, titles, prompts or screenshots to third-party services, "often alongside persistent user identifiers", according to their paper. They counted 124 third-party domains from 44 organizations, 34 of them advertising and tracking services.

One medical prompt, nine services, May 2026

The nine are ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Microsoft Copilot, Mistral's Le Chat and Meta AI. The team tested every web client and the Android apps of the eight that offer one, in Spain during May 2026. A researcher asked each service about a medical condition, with cookies accepted, rejected and ignored, on guest, free and paid accounts. The study covers Android only, so iOS was not tested, and the team could not extract traces for Gemini's mobile app.

A chat title is a summary of the chat

All nine contacted at least one advertising or tracking service. The new part is what those services received. Many chatbots auto-title each conversation: in the paper's Table 7, Claude turns "What are the symptoms of early-stage Parkinson's disease?" into "Early-stage Parkinson's disease symptoms".

Three web clients leaked titles to nine third parties, including Meta, TikTok and DoubleClick, eight of those nine flows only after cookies were accepted. Gemini's web client sent titles to Google Analytics. Five web clients disclosed conversation URLs or IDs to nine trackers, three by default. They saw no conversation URLs leave an Android app.

Grok sent one conversation to seven trackers

The authors trace a single Grok conversation to seven advertising and analytics trackers. Meta Pixel alone received the conversation ID, title, full URL, share ID and share URL, tied to the user's Meta identity by the _fbp cookie. A server-side Google Tag Manager container relayed the URL and title to Meta Conversions API and TikTok Events API, a path the paper calls unblockable by ad blockers.

On shared Grok chats, TikTok collected a screenshot, and Meta and TikTok received the latest prompt. Grok permalinks on free and premium tiers are public by default, with an opt-out. Canary links placed in Grok chats fired 70 times from 70 IP addresses in 14 countries.

Perplexity always makes guest conversations public. The paper says it stopped sharing those URLs with trackers like Meta on April 3, 2026, "possibly in response to a USA class action". It also sends hashed emails to Singular.

What Claude and ChatGPT sent

Disclosure: we build with Anthropic's Claude Code. ChatGPT's and Claude's web clients both sent the conversation ID to Datadog, which the authors say lets someone rebuild the conversation URL. Claude's Android app forwards conversation IDs to Datadog with account-linked IDs, and sends geolocation coordinates and the Android ID to Sift Science. The paper notes Meta AI sends the Android ID to Meta's own servers, and that such attributes are often collected for analytics, security or fraud prevention.

After a user accepts cookies on claude.ai, Segment Analytics, proxied through an Anthropic domain, forwards events server-to-server to eleven trackers, including Facebook, LinkedIn, TikTok and Reddit. On claude.ai, rejecting cookies stopped Meta Pixel, the Datadog telemetry and that forwarding. With cookies rejected, Claude, ChatGPT, Perplexity, DeepSeek, Gemini and Copilot still contacted Google Ads.

On August 15, 2026, OpenAI updated ChatGPT's privacy policy to name third-party trackers. The authors cannot confirm their work caused it.

Rejecting cookies left 80.8% of trackers running

"Even when non-essential cookies are rejected, 80.8% of third-party trackers remain active," the authors write. Free and premium accounts talked to nearly the same third parties. On Android there is no cookie banner.

The team notified data protection authorities in the EU and UK on April 13 and reported Grok's permalinks to xAI on April 17. As of September 10, the paper says, Grok still used public permalinks and xAI had not replied. Spain's AEPD cited the work on May 27 when it asked for the matter to go to a plenary EDPB meeting. Early findings went up on LeakyLM in May. The paper calls its results a point-in-time lower bound.

Why a build studio cares

The authors expect the same leaks in custom support chatbots and AI wrappers, because the cause is ordinary trackers dropped into a chat interface. That is the kind of product we build. A pixel reads the page URL and title because that is its job. In a chat product the title is an AI-written summary of the user's question, so a tag that is harmless on a pricing page can send the gist of a health question to an ad network. A cookie-banner review will not catch it: 80.8% of trackers survived rejection here. A data-flow map listing every third-party endpoint and the fields it receives will, and that map is where a DPDPA readiness check starts.

Next step: read the full paper. If your product puts a chat window and a tag manager on the same page, write to us at hello@gattyworks.com.

PrivacyAI ResearchEuropeChatGPTGrokClaudeMetaPixelIMDEANetworksAIPrivacyGDPRThirdPartyTrackersDataPrivacyAdTech

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call