AI Conversations Leaked to Advertisers? Results of a Comprehensive Analysis of 9 Services

Have you ever confided company secrets or personal worries to an AI assistant today? If so, those conversations might be being secretly sold to advertising companies. This study conducted a comprehensive investigation of 9 prominent conversational AI web clients and 8 Android apps. The results revealed traces of links to advertising or tracking services in all the services examined. Notably, it was confirmed that some clients transmit the prompts and titles entered during conversations directly to external parties. This issue occurs without voluntary consent and poses a significant risk to user privacy. In this article, we will detail the specific data leakage paths, legal controversies, and the response strategies we should adopt.



AI Conversations Leaked to Advertisers? Results of a Comprehensive Analysis of 9 Services

AI Conversations Leaked to Advertisers? Results of a Comprehensive Analysis of 9 Services

1. The Shocking Convergence of Ad Tracking Platforms and AI

1. The Shocking Convergence of Ad Tracking Platforms and AI
1. The Shocking Convergence of Ad Tracking Platforms and AI

This study was conducted through a comprehensive analysis covering both web-based services and mobile apps. Static code analysis and dynamic analysis, which involves real-time monitoring of network communications occurring during actual service usage, were performed simultaneously. This allowed us to uncover the issue of third-party advertising and tracking service infrastructure being deeply embedded within AI services. Significant differences existed between web and Android clients in terms of the types of tracking services and data transmission methods. Some third-party services were structured to activate only after users explicitly consented to non-essential cookies. This means that if consent is not thoroughly checked, information is effectively exposed in a defenseless state.

This tracking infrastructure aims for deeper access to personal information beyond simply collecting website visit logs. While traditional web trackers mainly identified which pages were visited frequently, AI trackers know the actual content of the conversations. The researchers accurately identified the relevant organizations across the entire scope of the investigation and confirmed that all AI services embedded at least one advertising or tracking code. This is a prime example showing that the AI industry is rapidly joining the existing internet advertising ecosystem in search of revenue models. Users’ simple act of typing words is immediately leading to complex data collection.

💡 Key Point
The comprehensive investigation revealed that all AI services embed ad tracking codes, and there are differences in data transmission methods between web and apps.

2. Leakage of Conversation-Derived Information Containing Your Secrets

2. Leakage of Conversation-Derived Information Containing Your Secrets
2. Leakage of Conversation-Derived Information Containing Your Secrets

The most shocking finding is that sensitive information derived from conversations is directly transmitted to third parties. This phenomenon was confirmed in 6 out of the 9 web clients and 3 out of the 8 Android clients investigated. Specifically, this includes unique conversation addresses, session titles, user-entered prompts, and even screenshots. Since new data is generated every time there is a gap in the conversation, it is possible to grasp the user’s current interests and thought processes in real time. A particularly dangerous aspect is that this data is transmitted bundled with persistent user identifiers.

In other words, advertising tracking data that appears “anonymous” is linked to specific individuals. What if you showed a colleague a draft report written by a work AI, and that AI was connected to tracking code? Advertisers would be able to integrate everything from your work habits to your professional focus areas. This data has maximized utility because it directly captures user interactions, going beyond the browsing activities primarily observed by existing tracking systems. The level of risk associated with this information exposure is critically influenced by consent choices and sharing features.

💡 Key Point
Sensitive information such as conversation URLs, titles, and prompts is sent to advertisers along with user IDs, increasing personal information risks.

3. Public Conversation Links and Invisible Risks

3. Public Conversation Links and Invisible Risks
3. Public Conversation Links and Invisible Risks

The researchers pointed out the issue of several providers offering public unique conversation links without access control. This is akin to leaving a door wide open without a lock or password. Tracking companies or external actors could read the entire conversation content through these links. People often think that links disappear once a conversation ends, but in reality, they are often permanent or valid for long periods. If such links exist regardless of cookie consent, the defense of refusing consent is rendered ineffective.


It is noteworthy that it is not yet clear whether these public links are intentionally designed or due to sloppy security settings. However, as a result, user privacy is left defenseless in the face of these technical vulnerabilities. This risk is amplified when asking AI about sensitive legal consultations, medical inquiries, or financial planning. If a link is accidentally shared or discovered by a malicious developer, it could expand into an incident where multiple sessions are leaked on a large scale.

💡 Key Point
Public conversation links without access restrictions create the possibility that external entities can illegally access the entirety of user conversations.

4. Issues of Regulatory Violations and Opaque Monetization Models

4. Issues of Regulatory Violations and Opaque Monetization Models
4. Issues of Regulatory Violations and Opaque Monetization Models

The researchers meticulously analyzed the observed practices against the globally strict GDPR and specific privacy directives. Current regulations provide very specific criteria regarding consent procedures and setting the scope of data sharing. However, the pace of the current AI market is far ahead of legal review and regulatory verification. While providers are considering monetization models, user consent mechanisms still rely on simplified cookie selection windows.

This opacity distorts the essential information provision required for consumer protection. True “consent” cannot exist if it is unclear what data goes where and who can view that data. The researchers officially notified the relevant providers and the competent European data protection authorities of the confirmed issues through responsible disclosure procedures. This is significant not only as technical advice but also because it opens a channel for legal legitimacy, laying the physical foundation for users to seek remedies for their rights.

💡 Key Point
Consent procedures and data sharing practices that fall short of GDPR and ePrivacy Directive standards have emerged as legal issues and entered the stage of notifying regulatory authorities.

5. The Social Value of Sensitive Data and Attack Surface

5. The Social Value of Sensitive Data and Attack Surface
5. The Social Value of Sensitive Data and Attack Surface

Conversational AI supports autonomous task execution and multimodal processing beyond powerful search functions. Consequently, the nature of the data processed is fundamentally different. It encompasses not just click streaming, but also uploaded documents, continuous interaction logs, and behavioral patterns included in the context. This information reveals the most intimate aspects of privacy and the core of business activities. Exposing this data to third parties for ad monetization directly leads to significant security damage for both individuals and organizations.

Compared to traditional internet advertising, AI-based data has much higher predictive accuracy. Knowing what a user searched for is different in dimension from knowing what additional documents a user requested to solve a specific problem. This high-dimensional data has the potential to be misused for insurance premium calculation, credit evaluation, and even political orientation analysis. Therefore, information collection via AI should be viewed not just as a marketing issue, but as a matter directly related to the diversity and safety of society as a whole.

💡 Key Point
The advanced sensitive data handled by AI is distinct from existing advertising data and can cause more serious privacy infringements for individuals and organizations.

6. Future Outlook and Protection Strategies Individuals Should Adopt

6. Future Outlook and Protection Strategies Individuals Should Adopt
6. Future Outlook and Protection Strategies Individuals Should Adopt

In the future AI service market, the conflict between data ownership and revenue models is expected to intensify. As regulatory scrutiny strengthens, companies will face pressure to redesign their data processing methods. However, while laws are being refined, users can be their own best shield. Before entering sensitive information, one must carefully check the service’s privacy policy.


If possible, it is recommended to separate work and personal accounts and block all possible external sharing options in security settings. Additionally, it is important to develop the habit of setting “reject” as the default for cookie consent rather than accepting by default, allowing only exceptions. These practices are a realistic alternative to filling the gaps where legal protection does not reach. Technological advancement will not stop, but our privacy awareness must grow accordingly. Small habits starting now will protect you in future digital data disputes.

💡 Key Point
Even amidst strengthening regulations, user-driven security settings and restraint in entering sensitive information are the most certain response strategies to prevent AI data leaks.

Frequently Asked Questions

Can anyone actually see AI conversation content?
Yes, the investigation confirmed pathways where operators of advertising and tracking services receive information derived from conversations.
What is the difference between free and paid AI services?
Research results indicate that the scope of tracking and the degree of information exposure vary depending on consent choices or subscription tiers.
Does rejecting cookies block all tracking?
No, some services expose the entire conversation in the form of public links, so simply rejecting cookies does not provide complete defense.
Where can I report or file a complaint about this issue?
You can contact local data protection authorities or make a direct request to the company by referring to the responsible disclosure procedures carried out by the researchers.

=