Security & AI news

AI assistant privacy · By FireAI Security & Research Team · Published

IMDEA Networks paper finds six of nine AI chatbot web clients pass conversation titles or links to third-party trackers

IMDEA Networks researchers report that nine AI assistants contact ad or analytics firms, and that six web clients pass chat titles, links or prompts to them.

A chat bubble and the AISir mascot, next to the words “Chat titles sent to trackers.”

Researchers at IMDEA Networks in Madrid report that six of the nine most popular AI chatbots exposed user input to third parties through advertising and analytics trackers, EUobserver reported on 1 October 2026. The final paper, “Prompt like a Butterfly, Sting like a Tracker”, has been accepted for publication at an academic forum in Delft in 2027 [1]. The findings concern what people type into assistants about health, money and other private matters.

Background

A tracker is a piece of code from an advertising or analytics company that a website or app loads to measure and target its users. The researchers’ starting point, in IMDEA Networks’ own words, is that while a chatbot’s interface “resembles a conversation, underneath it operates on technical infrastructures similar to those of the traditional web ecosystem” [3]. A conversational product also produces records about each exchange, such as an automatically generated chat title and a permanent link to the conversation, which other web pages do not.

Part of the work was published in May 2026 on a project site called LeakyLM, which covered Perplexity, Claude, ChatGPT and Grok [4]. According to EUobserver, that preview led Spain’s data protection authority, the AEPD, to ask for the preliminary findings to be shared with its European counterparts [1]. The paper now extends the analysis to nine services.

What the paper describes

The nine services are ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Microsoft Copilot, Mistral’s Le Chat and Meta AI. All experiments ran in Spain in May 2026, with health-related prompts modelled on a user asking about a medical condition. Six of the nine web clients and three of the eight Android apps handed conversation URLs, auto-generated conversation names, prompts or screenshots to outside firms, often next to persistent user identifiers, PPC Land reported from the paper on 5 October [2].

The researchers’ examples show why titles matter. A prompt about the symptoms of early-stage Parkinson’s disease became the title “Early-stage Parkinson's Symptoms” in ChatGPT. One Grok conversation reached seven advertising and analytics services, and the Meta Pixel alone collected the conversation ID, the generated name, the full URL, the share ID and the share URL [2]. Perplexity, according to the paper, transmits users’ hashed email addresses to the analytics company Singular [2].

Claude’s web client, the paper says, loads a configuration that forwards user events from server to server to eleven services, among them Facebook, LinkedIn, TikTok, Reddit and Google; that forwarding occurred only after cookies were accepted, and the authors describe such flows as invisible to browsers and unblockable by ad blockers [2]. Rejecting non-essential cookies did not end third-party contact: Perplexity, DeepSeek, Gemini, Copilot, ChatGPT and Claude still connected to Google Ads in that scenario [1] [2].

On access controls, Narseo Vallina Rodríguez of IMDEA Networks said in May that “in some cases weak or non-existent access controls mean that simply having a link to a conversation can grant access to its content” [3]. The authors write that most findings “reflect intentional product-level practices rather than exploitable security vulnerabilities”, and that their objective is not a definitive legal assessment [2].

Implications for Mac users

The measurements were taken in Chrome on the web and on Android phones; the reports do not describe the macOS desktop apps, so the results cannot be assumed to apply to them in the same way. A Mac user who reaches these assistants in a browser is in the situation the paper measured. The practical consequence the researchers draw is that a chat title written by the service can summarise a private question, and that this title can travel with an identifier such as a cookie or a hashed email address. Aniketh Girish, a co-author, said that “most users have no way of knowing this is happening” and that declining non-essential cookies “is not always enough” [3].

Recommendations

  1. Reject non-essential cookies in each assistant used on the web; the researchers report it reduces, but does not end, third-party contact [2].
  2. Check whether shared conversation links are public, and revoke links that are no longer needed, as the LeakyLM site advises for Grok [4].
  3. Set Perplexity conversations to private where that option exists [4].
  4. Avoid writing names, diagnoses or account numbers into a cloud assistant when an answer does not depend on them.
  5. Prefer an assistant whose model runs on the Mac for notes and questions that should stay private.

Relevance to AISir and FireAI

AISir runs Gemma, Whisper and its voice on the Mac. Conversation audio stays in memory and is never saved, and AISir has no account and no telemetry. Web lookups are optional and off by default. AISir does not change what any cloud assistant does with the conversations a user gives it, and its small on-device model is less capable than the large cloud models in the study.

FireAI, the HisnLabs firewall for macOS, shows which apps connect and to which companies and domains, and per-app rules can block one domain for one app, for example an analytics domain. FireAI cannot see forwarding that a provider does from its own servers, it cannot read the content of encrypted connections, and in a browser it sees the browser’s connections rather than one tab’s.

Limitations

This item relies on press coverage of the paper and on IMDEA Networks’ own pages; the full paper was not reviewed here. PPC Land notes that the paper’s copy carries a placeholder publication year and that two figures on cookie rejection are not reconciled in it [2]. The experiments ran in May 2026 in Spain, and providers may have changed their clients since; PPC Land reports that OpenAI updated ChatGPT’s privacy policy on 15 August 2026 to mention third-party tracking, without the authors being able to confirm a link [2]. The LeakyLM site records that xAI was notified on 17 April 2026 and lists no response [4].

To keep tasks and voice notes on the Mac, download AISir and try every feature free for 17 days. AISir is made by HisnLabs.

Sources

  1. EUobserver, 1 October 2026: AI chatbots turn users’ most intimate data into a potential goldmine for advertisers, researchers warn
  2. PPC Land, 5 October 2026: 6 of 9 AI chatbots pass chat titles or links to trackers, IMDEA finds
  3. IMDEA Networks, 6 May 2026: Your conversations with AI may not be as private as you think
  4. LeakyLM project site (IMDEA Networks researchers): AI Assistants Are Leaking Your Conversations