AI NewsInfrastructureReported
IMDEA Networks researchers find trackers in all nine chat AI services they tested, including Grok sending a screenshot to TikTok on shared chats
Nine researchers at IMDEA Networks and UC3M looked at the web and Android clients of ChatGPT, Claude, Grok, Gemini, Copilot, DeepSeek, Perplexity, Mistral and Meta AI, and in a paper dated 16 September 2026 they report that every one of them contacts a third-party tracker during a normal chat.

Why it mattersA team letting an employee paste a customer document into a chat UI now needs to know which services forward the conversation title, the share link or a screenshot to third parties, because the picked service is also a disclosure decision.
Any team that pastes customer notes into a chat UI is making a data-handling choice, and the names of the companies on the receiving end are not in the vendor's privacy page. A paper from IMDEA Networks and UC3M, posted to Hacker News on 29 September with 422 points, is the first systematic look at which third parties get what from each of nine chat AI services, picked from Tranco's top-14,000 list and from Play Store install counts.
The authors (Guilherme Oliveira, Miguel Sanchez, Roi S. Serna, Juan Manuel De Santa Olalla Gomez and five colleagues) tested the web clients of ChatGPT, Claude, Grok, Gemini, Microsoft Copilot, DeepSeek, Perplexity, Mistral and Meta AI, plus the Android app for the eight that offer one. In every service, at least one third-party advertising or tracking service received something during a normal conversation. Across the nine, the paper counts 124 third-party domains and attributes them to 44 organisations, of which 34 are tracking services.
What leaks and to whom
The paper reports that six of nine web clients and three of eight Android clients send conversation-derived artifacts (titles, share URLs, screenshots or the prompts themselves) to trackers. Google-owned services (Firebase, Analytics, Ads, Tag Manager, DoubleClick, Accounts) appear in eight of nine services. Sentry is in four of nine, Datadog in three. Perplexity transmits a hashed email address to the marketing analytics company Singular. Claude's web client proxies Segment Analytics through a first-party subdomain, a-cdn.anthropic.com, and the Conversion API behind it forwards user events server-to-server to eleven trackers including Facebook, LinkedIn, TikTok, Reddit and Google Enhanced Conversions.
The most direct finding sits in the shared-conversation flow. Five web clients expose the full conversation at a stable public URL (a permalink) with no access control, so any third party receiving the URL can read the whole chat. On Grok, when a user opens a shared conversation, the client sends a screenshot of the most recent part of the chat to TikTok along with the auto-generated title and the last user prompt. The paper reproduces one such screenshot (a user asking about a biopsy result) in Figure 12.
Rejecting cookies does less than teams assume
The researchers ran the same tests three ways: ignore the consent banner, accept all, and reject non-essential. Rejecting still leaves trackers active in 44.4 percent of services (4 of 9). Perplexity, DeepSeek, Gemini, Copilot, ChatGPT and Claude all still contact Google Ads after a reject-all. Mistral's banner has no reject option: a user must accept the Terms of Service and Privacy Policy to use the product at all. Guest, free and premium account tiers made almost no difference to the tracker list.
Mobile apps leak less than web clients, because the user-visible chat titles do not propagate the same way, but tracker traffic is still present. ChatGPT and Claude Android apps still send a convId and a userId to Datadog on every interaction. The authors conducted responsible disclosure with the providers and the competent European Data Protection Authorities before publishing.
The authors recommend treating conversation URLs as sensitive by default, and treating any field a tracker can read inside the chat UI as leaked by default. For a team integrating one of these services into a product the practical consequence is simpler, which is to check what the provider you picked sends to whom, and to assume the answer is more than its privacy page implies.
Source
- Primary: "Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents" (PDF), IMDEA Networks, 16 September 2026
- Discussion: Hacker News thread
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.


