A research team in Spain opened nine popular AI chat apps and recorded everything their browsers and phones sent out. All nine were talking to at least one advertising or tracking company. On several of them, the link to your chat, the title of your chat, and sometimes the last thing you typed went along for the ride.
People will argue about whether that's a mistake or the plan. My answer is that it started as one and stayed as the other, and the rest of this piece explains why, what it means for what you type into these things, and what I'd do about it.
What the researchers found
The team is from IMDEA Networks, and their paper has the full method if you want it. They tested ChatGPT, Claude, Gemini, Grok, DeepSeek, Perplexity, Copilot, Mistral and Meta AI, on the web and on Android, from Spain in May 2026. Here's the part that matters for this piece.
| App | What left the page | Who got it |
|---|---|---|
| Grok | Chat link, chat title, and a scrambled ID tied to the account | Seven ad and analytics companies, including Meta, TikTok, X and Google Ads |
| Gemini | Chat title | Google Analytics |
| Mistral | Chat title | A customer support tool |
| ChatGPT, Claude, Perplexity | Chat ID and account IDs (plus the full link on ChatGPT and Perplexity) | A monitoring service |
| Shared chats on Grok | A screenshot of the conversation and the latest message | TikTok, and Meta for the message |
Across the nine apps they counted 44 outside companies, 34 of them advertising or tracking. Six of the nine websites and three of the eight phone apps sent chat details (links, titles, messages or screenshots) to outsiders.
Nobody proved an ad was targeted off a chat. The researchers measured what got sent, not what the receiving companies did with it. They also tested consumer accounts only, so work and enterprise plans are an open question.
Why a chat window is different
In a search box you type a few words. In a chatbot you write paragraphs, with names, numbers, symptoms and fears in them. People ask these things about their health, their debt, their marriage and their legal trouble. It feels private because the whole product is built to feel that way: it answers in a voice, it remembers you, it apologizes when it's wrong.
Advertising technology was built for browsing. Its tools assume the page is public and the visitor is a stranger to be measured. Put those tools on a chat page and you get an ad tracker sitting next to the most personal writing most people do online, which is something nobody set out to design.
The title is the part that gets me. Every chat app writes a short title for each conversation so you can find it later, and the AI writes it. Ask "What are the symptoms of early-stage Parkinson's disease?" and you get a title like "Early-stage Parkinson's Symptoms". Ask a mortgage question with your salary in it, and Grok's title comes out as "$85k NYC Salary: $280k-$350k Mortgage". Those are the researchers' own examples. Ad and analytics tags routinely read the page title, so the chatbot has done the advertiser's homework: your whole conversation squeezed into one clean line.
The argument for calling it a flaw
Give the companies their best defense first, because part of it is probably true. Nobody sat in a meeting and decided to send somebody's Parkinson's question to TikTok. What almost certainly happened is more boring. A growth or marketing team put the same tracking tags on the chat site that every website uses, because that's how you measure signups and ad campaigns. The chat page was just another page, and the page title happened to hold a user's private question. Nobody went back and asked what those tags could now see. That's a design flaw in the plainest sense, a product built without anyone thinking about the case that mattered most.
The links are worse, and I can't think of a defense for that part. On Grok, a chat's link opens for anyone who has it, with no login, unless you find the setting that turns it off. Perplexity does the same for guest chats. So when a tracker receives the link, it can receive the ability to read the whole chat along with it. A link that works as a key shouldn't be handed to advertising companies, and I'd bet nobody who designed it meant it to be.
Why I call it a feature anyway
A flaw is something you fix when somebody points it out, so look at how that went.
The researchers told xAI about Grok's public chat links on April 17. On September 10 the links were still public and xAI hadn't replied. After five months I'd call that a decision.
Where things did change, a lawyer or a regulator was close by. Perplexity stopped sending chat links to trackers on April 3, days after a class action lawsuit was filed against it, though the researchers say they can't tell if that's why. OpenAI updated its privacy policy in August to mention third-party trackers. Spain's data protection agency asked European regulators to take up the research in late May. Things get fixed when leaving them alone gets expensive.
Then there's the money. OpenAI began testing ads with logged-in adult users on the Free and Go tiers in the US in February 2026, and the paper cites an estimate that about 95 percent of ChatGPT users don't pay. Chatbots cost a lot to run. If the free version is where nearly everyone lives, somebody other than the user is paying for it, and that somebody is an advertiser. Paying doesn't get you out of tracking either. The researchers found free and paid accounts contacting nearly the same outside companies.
So the leak may have started by accident, but it now fits neatly with how these companies plan to make money, and that's a strong reason not to hurry the cleanup. My verdict is that it's a flaw in how it got there and a feature in why it's staying.
The cookie banner won't save you
Most of these sites show a cookie banner, so you'd expect clicking reject to settle it. It helps, and it isn't enough. On Grok, the ad trackers only ran after the researchers clicked accept. On Claude's site, clicking reject stopped the Meta tracker and a setup that forwards events to eleven ad platforms (the researchers saw user IDs and events on that path, not chat text). But with reject selected, six of the nine services, including ChatGPT, Claude and Gemini, still connected to Google's ad servers. The paper says connection, not chat content, so I won't claim more than that.
The bigger problem is that a banner is a promise about what your browser will do. Once your data reaches the company's servers, where it goes next, including to Meta or TikTok, can't be seen from your side at all. Several of these sites forward tracking data server to server, so no browser tool or ad blocker can check it for you. You're trusting the banner because nothing else is available.
Treat the share button like publishing
A share link turns your chat into a public web page. The researchers found outside trackers watching those pages on several services, nine companies in total. On Grok's share page, TikTok received a screenshot of the conversation and both Meta and TikTok received the latest message. I'd assume anything you share is public for good and read by machines.
They also hid unique tripwire links inside their chats. On Grok, something fetched those links 70 times, over hours and days, from 70 different addresses in 14 countries, and more than 65 percent of the fetches came from machines in the US even though the tests ran in Europe. The researchers don't know who or what was doing it. Perplexity's crawler fetched their tripwire links even when the message told it not to. Telling a chatbot "don't open links" is a request, and it doesn't lock anything.
If you want real privacy, local models are an option
Everything above happens in the middle. Your words travel to a company's website or app, and outside code sits on the page that shows them. If you'd rather not have a middle, you can run a model on your own computer. Nothing you type leaves the machine, so there are no ad tags, no share links and no account tied to your chats.
A few years ago that meant a hobby project and mostly bad answers. Local models have gotten much better, and fast. Models that run on a 16GB machine today, like OpenAI's gpt-oss-20b (about a 14GB download), were out of reach not long ago, and newer designs from Qwen and Gemma only use a slice of the model for each word, so bigger ones now run on modest hardware. The best hosted models are still ahead on the hardest tasks, but for a lot of everyday questions the gap matters less than it used to.
If that sounds interesting, a Mac mini (new ones start at $899 at the time of writing), a spare desktop or a homelab box will do it. Free apps like Ollama and LM Studio get you chatting with a downloaded model in a few minutes, and a private VPN like Tailscale lets you reach it from your phone. One thing to check, though: local doesn't automatically mean private. The leaks in the paper came from software wrapped around the AI, so keep an eye on what any app you install connects to.
It's not for everyone, and nobody has to. If you'd rather stay on a hosted chatbot, reject non-essential cookies, skip the share button, and leave names and specifics out of what you type. That much is in your control.
How sure I am
| Claim | Confidence | Why |
|---|---|---|
| Several chat apps send chat links, titles or messages to ad and analytics companies | High | The researchers captured the network traffic directly. |
| Grok's chat links are public by default and were still public in September | High | Tested logged out, and re-checked by the researchers on September 10. |
| Nobody planned the leak at the start | Moderate | It fits the evidence, but I can't see inside these companies. |
| It's staying because it pays | Moderate | Fixes arrived after lawsuits and regulators. Motive is my inference. |
| Advertisers use your chats to target ads | Unknown | Nobody tested it. |
| Work and enterprise plans behave the same way | Unknown | Not tested. |
| All of this is still true today | Moderate | The tests ran in May from Spain, and two companies have changed things since. |
Until there's a law with teeth, I'd treat any hosted chatbot like a page with an advertiser standing behind you, because on several of them that's what the network traffic showed. If something is too personal for that audience, a local model is one way out.