Skip to content

Build1 publisher2 min readPublished

IMDEA Networks audit traces AI chatbot conversation titles and prompts to ad trackers

IMDEA Networks researchers found six of nine AI chatbot web clients passing conversation titles, links, prompts or screenshots to third parties. With 80.8 percent of trackers still running after a reject-all click, containment depends on what staff type and share.

The Engineer · Build desk

Illustration accompanying IMDEA Networks audit traces AI chatbot conversation titles and prompts to ad trackers

What happened

  • The audit covered ChatGPT, Claude, Grok, DeepSeek, Gemini, Perplexity, Microsoft Copilot, Mistral's Le Chat and Meta AI on web and Android.
  • Every one of the nine services contacted at least one third-party advertising or tracking service during testing.
  • Three web clients sent AI-generated conversation titles to nine third parties, among them Meta, TikTok and DoubleClick.
  • In one session, Grok's web client sent the conversation URL and title to seven trackers, and Google Ads also received a hashed user email.
  • Free and paid accounts produced nearly identical tracking behaviour across the services.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure A hashed email travelling with the title and URL means a sensitive conversation can be matched to a known account on the advertising side.
  • decision Grok's prompt and screenshot captures happened on shared conversations. Permission to create share links needs its own rule, separate from permission to use the chatbot.
  • cost Paying for plans bought no reduction in tracking in these measurements. A team cannot justify paid consumer seats on privacy grounds for these services.
  • constraint Web clients leaked at about 67 percent against 37.5 percent for Android apps. In this sample, steering staff to the browser version puts them on the leakier surface.

The trackers in the study are ordinary ones. Google products appeared in some form on all nine services, with Sentry, Meta, Datadog and Intercom next [10]. A dev.to write-up of the paper calls them the same pixels and SDKs that ship with any commercial web app [10]. Of the 44 third-party organisations observed across 124 domains, 34 were advertising or tracking services, about 77 percent [6][1].

On a chatbot, each conversation gets a title the model generates, and the write-up describes those titles as compressed summaries of the user's intent [19]. A question about early Parkinson's symptoms became "Early-stage Parkinson's Symptoms". A mortgage question became "$85k NYC Salary: $280k-$350k Mortgage" [13]. Five web clients also disclosed conversation permalinks, or the identifiers needed to rebuild them, to nine tracking organisations [11].

I think the likeliest path is the dull one: a tag installed for analytics or ad attribution reports on the page where it fires, and on a chatbot the URL and title now describe the conversation. If that is right, each vendor's build decides the leak. The Grok evidence fits. On Grok's sharing pages, the user's latest prompt reached Meta Pixel verbatim through its page-description field [14].

The study design is good work. The team crossed guest, free and paid accounts with three consent states: ignore the banner, reject all, accept all [3]. It captured full network traffic from Chrome and ran the Android apps on an instrumented phone that logged every outbound connection, permission access and identifier read [3]. The paper, "Prompt like a Butterfly, Sting like a Tracker", was accepted into the Proceedings on Privacy Enhancing Technologies [1].

The prompts were deliberately sensitive, covering health conditions and salary questions [4]. For the percentages to describe a particular team's exposure today, the vendors would have to be shipping the same tag setup the researchers captured. Grok is the service named in the prompt, screenshot and seven-tracker cases [14][15][16]. The write-up's author wrote that the piece is "built on a research paper I have not replicated myself" [17]. The research artifacts are on GitHub, so the capture can be rerun against current builds [1].

In my context, a team whose staff ask chatbots about health or payroll, I would write the policy around what goes into a consumer chatbot and whether it gets shared. The study does not identify a user-side setting that stops the leaks. On consent, the same author wrote: "Reject-all is not the protection people assume it is." [18]

What to watch

  • A rerun of the published GitHub artifacts against current builds of the nine clients, showing whether the captured tag setups still ship.
  • Whether the full paper names which web clients beyond Grok leaked titles, permalinks or prompts.
  • Any change by Grok's operator, or by Meta and TikTok, to the pixels on shared-conversation pages that captured prompts and a screenshot.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories