A paper on nine conversational AIs: chat fragments reach advertising and analytics vendors
Researchers tested nine conversational AIs on web and Android in May 2026. All embedded ad and analytics vendors, and some sent conversation URLs and titles to third parties.
TL;DR
- A research team including IMDEA Networks examined the web and Android apps of nine conversational AIs (ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Copilot, Mistral and Meta AI) in May 2026
- All services embedded one or more advertising and analytics vendors, and six services on the web and three on Android sent conversation URLs, titles, prompts or screenshots to third parties
- Even after rejecting cookies, four of nine services kept sending data to third parties. Grok also makes conversation URLs open to anyone by default, even before sharing
- The paper also states a limit, that the mere presence of a third party doesn't mean an advertising purpose. Spain's data protection authority (AEPD) shared the findings with authorities across Europe
- Users should consider rejecting cookies, managing shared links and not entering sensitive content
Contents
It’s easy to assume that only the AI provider sees what you type into ChatGPT or Claude. A research team including IMDEA Networks tested that assumption by measurement in a paper, “Prompt like a Butterfly, Sting like a Tracker”, which they have published. They examined the web and Android apps of nine conversational AIs, and found that every service had advertising and analytics vendors built in. Some services passed information that reveals what a conversation is about, such as its URL and title, to third parties.
What they examined
The nine services were ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Copilot, Mistral (Le Chat) and Meta AI. All nine were tested on the web, and the eight that have an Android app were tested there. Measurements were taken in Spain in May 2026. The team recorded web traffic with Chrome DevTools, and recorded app traffic on Android on a device modified for measurement.
For the conversations they used health-related content, written as if by a user asking about an illness. They then compared traffic while varying conditions such as the cookie consent choice (reject, accept, ignore), account type (guest, free, paid) and incognito mode.

What they found
The paper’s main results are as follows.
Every service uses third-party advertising and analytics
All nine services used one or more advertising and analytics vendors (the paper calls them ATS). They connected to 124 domains and 44 organizations, and Google’s products were the most widely used. Note that the paper also counts advertising and analytics mechanisms owned by the provider itself, as with Google and Meta, as ATS for comparison.
Rejecting cookies doesn’t stop the traffic. Perplexity, DeepSeek, Gemini, Copilot, ChatGPT and Claude still connected to Google Ads with cookies rejected. Four of nine services (44.4%) kept sending to third parties. On the other hand, with Claude, rejecting cookies is reported to have stopped Meta Pixel and similar tools from starting, and the server-side forwarding to 11 advertising platforms disappeared. In other words, rejecting can work in some cases.
Conversation URLs and titles are passed on
Six services on the web and three on Android sent conversation URLs, titles, prompts or screenshots to third parties.
- Conversation URL: five web services sent it to nine vendors. It wasn’t observed on Android
- Conversation title: three web services sent it to nine vendors, including Meta, TikTok and DoubleClick. It is a summary the AI generates automatically, so topics such as health or money can be read from it
- Identifiers that identify the user: Claude and Mistral passed email addresses and user IDs to Intercom together with the conversation URL
Eight of nine instances of sending the conversation title happened only after cookies were accepted. When it is sent together with an identifier, the topic gets tied to a specific user. The paper explains: “A single Meta Pixel call that carries the conversation URL and the _fbp cookie can tie a chat to a Meta profile.”
There were big differences between services, and Grok had the most. On the web, Grok sent the conversation URL and title to seven vendors. All seven happened only when cookies were accepted.
Shared links open to anyone
Every service has a feature to share a conversation, and shared conversations open without authentication. If third-party analytics run on that shared page, the whole conversation may be exposed. In the paper, nine third parties were present on shared pages. On Grok’s shared page, TikTok is reported to have captured a screenshot of the conversation, and Meta and TikTok to have captured the latest prompt.
Services also differ in how they treat the conversation URL before sharing. On Grok, free or paid, the conversation URL is public by default, and you opt out to make it private. Perplexity always made guest conversations public. However, it says that since April 3, 2026, it no longer sends that URL to third parties such as Meta.
For Grok, a trap URL embedded in a conversation (a canary token) was accessed 70 times after some time had passed. The visits came hours to days later, from 70 IP addresses in 14 countries. DeepSeek, Copilot, Mistral and Claude saw only about one visit right after sending. Perplexity fetched the URL repeatedly even when told not to access it. The paper treats only Grok as a problem that an outside third party could abuse, and notified xAI on April 17, 2026. As of September 10, 2026, it says there had been no official reply and the public URL behavior hadn’t changed.
Caveats when reading
The paper itself notes these limits.
- The presence of a third party doesn’t always mean an advertising purpose. There are also operational functions such as payments and fraud detection
- Tracking by the provider’s own domains can’t be distinguished from functional traffic
- Enterprise and government plans were out of scope
- It is a lower bound at that point in time, from a single vantage point and a single assumed user
The paper’s PDF has parts where the venue’s year and the DOI are blank. IMDEA Networks’ public repository gives the paper’s date as July 19, 2027. EUobserver reports that the paper is due to be presented at an academic conference in Delft next year. In other words, what you can read now is a draft-stage version of a paper that has been accepted. It is safer to read the figures as the paper’s own statements and check each company’s current implementation separately.
Reactions, and what users can do
Spain’s data protection authority (AEPD) announced on May 27, 2026 that it had sent a summary of this research to the European Data Protection Board (EDPB) and asked for it to be shared with authorities across Europe. It also says it pushed for it to be taken up at the June plenary. According to the paper, OpenAI updated its privacy policy on August 15, 2026 to mention third-party trackers. The paper’s authors say, however, that they can’t confirm whether the change was influenced by the research.
What the researchers and groups say
EUobserver’s article (October 1, 2026) carries an explanation from Narseo Vallina-Rodriguez, who led the research. He says the aim was to examine the link between existing tracking technology and AI advertising. According to the article, the paper points to “tension” between current practice and the obligations under the GDPR (the EU’s General Data Protection Regulation) and the ePrivacy Directive. The view is that there are broad failings in consent, access control and transparency mechanisms. The paper also writes that “vague language” in the terms of service makes the role of tracking hard to see.
A policy officer at the digital rights group EDRi says that because users confide in AI about their health, state of mind and money, this goes deeper than earlier tracking. The article also reports that Mistral didn’t offer an option to reject non-essential cookies.
Vallina-Rodriguez adds that the tracking industry is moving toward cookie-less methods and methods based on identity, and is circumventing tracking-prevention mechanisms. If so, rejecting on the cookie consent screen may become even less effective in the future.
EUobserver also notes that a preliminary version of the research was published in May 2026, which led to the AEPD’s push to share it with authorities in Europe. The final paper covers nine services, as in the text above.
What follows is my own view. For an ordinary user, or someone who lets staff use conversational AI at work, these seem realistic.
- On the cookie consent screen, reject everything non-essential. The effect is partial, but there are cases like Claude where it stops tools from starting
- Create a shared link only when needed, and revoke it when done. Treat it as visible to anyone who knows the URL
- Don’t enter content that can identify individuals or customers, or ask about health or money, in free web versions. Enterprise plans were out of scope, so check data handling in the contract separately
- If you use it in an organization, decide on installing ad blockers and a policy for the sharing feature
Changelog
- Added where the paper will appear, confirmed through IMDEA's public repository and EUobserver's coverage. Added the views of the lead researcher and EDRi, how this relates to the preliminary version, and the researcher's view that tracking is shifting to cookie-less methods
Spotted an error or something out of date? Let me know on X.