Pangram verdict · v3.3
We believe this text is mainly human-written, with some AI and AI-assisted content.
AI likelihood · overall
HumanArticle text · 901 words · 6 segments analyzed
Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents Guilherme Oliveira IMDEA Networks Miguel Sanchez IMDEA Networks Juan Manuel De Santa Olalla Gómez IMDEA Networks Roi S. Serna IMDEA Networks/UC3M Tautvydas Jackevicius IMDEA Networks Jorge Garcia-Herrero Independent Aniketh Girish IMDEA Networks Guillermo Suarez-Tangil IMDEA Networks Narseo Vallina-Rodriguez IMDEA Networks Abstract As prominent conversational AI providers like OpenAI adopt ad- vertising-based business models, traditional web and mobile track- ing practices are expanding into conversational AI services [15]. However, despite their growing adoption, the tracking, data-sharing, and monetization practices of conversational AI services remain largely opaque and have received comparatively limited scrutiny from researchers, regulators, and the public. In this paper, we present a systematic privacy analysis of the web and mobile deployments of nine prominent conversational AI services. Using a combination of static and dynamic analysis, we study the presence of third-party Advertising and Tracking Services (ATSes), characterize their data flows, and evaluate how consent choices, subscription tiers, and access-control mechanisms influ- ence conversation exposure to third parties. We uncover privacy risks unique to conversational AI platforms: multiple providers disclose sensitive conversation-derived artifacts—including titles, prompts, and screenshots—to third parties, often alongside persis- tent user identifiers that enable user attribution. We also find that some providers publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation. Our findings reveal how traditional tracking technologies are increasingly intertwined with AI-mediated interactions, creating new pathways through which sensitive user and conversational information can be collected, inferred, and disseminated. To assess the broader implications of these practices, we analyze them in the context of the GDPR and ePrivacy Directive. We conducted a respon- sible disclosure process involving affected providers and competent European Data Protection Authorities. Our results demonstrate that conversational AI services introduce a novel privacy attack sur- face in which provider-generated conversational artifacts become subject to tracking and public exposure, highlighting the need for stronger safeguards governing AI-mediated interactions. Keywords Conversational AI, LLMs, Privacy, Mobile, Web, Trackers This work is licensed under the Creative Commons Attribu- tion 4.0 International License. To view a copy of this license visit https://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA. Proceedings on Privacy Enhancing Technologies YYYY(X), 1–18 © YYYY Copyright held by the owner/author(s). https://doi.org/XXXXXXX.XXXXXXX 1 Introduction Recent advances in Large Language Models (LLMs) have enabled the emergence of conversational AI services such as ChatGPT, Gemini, and Claude, capable of supporting persistent interactions, multi- modal processing, and autonomous task execution. As adoption of these services grows for personal and professional activities [43], service providers are exploring new business models to monetize their growing user bases. Advertising is emerging as one such model, potentially extending into conversational AI the tracking and attribution infrastructures traditionally associated with web and mobile platforms. For exam- ple, Reuters reported that OpenAI partnered with Criteo to conduct an advertising pilot for ChatGPT free-tier users in the United States in early 2026 [52].
However, the integration of these tracking technologies raises distinct privacy concerns. Unlike traditional web and mobile applica- tions, conversational AI services routinely process highly sensitive prompts, contextual information, behavioral patterns, uploaded documents, and persistent interaction histories that may reveal intimate aspects of users’ lives and professional activities. The dis- closure of such information to third-party tracking services, partic- ularly without meaningful transparency or consent, may therefore expose users and organizations to significant privacy risks.
Prior work by Jazlan et al. has examined the integration of third- party tracking in web-based conversational AI services [32], pri- marily focusing on identifying trackers and characterizing their data collection practices.
However, the unique interaction models of conversational AI services introduce new privacy risks across their web and mobile clients: these services generate conversation- derived artifacts—including conversation identifiers, URLs, titles, previews, prompts, responses, and interaction metadata—that may be disclosed to third parties or exposed through publicly accessible resources.
Moreover, how these exposures are shaped by by con- sent choices, privacy settings, subscription tiers, and access-control mechanisms remains largely unexplored. To address this gap, we investigate three research questions: • RQ1: To what extent do conversational AI services integrate third-party tracking, analytics, advertising, and attribution in- frastructures across their web and mobile clients? • RQ2: What conversation-derived artifacts and user information are exposed by conversational AI services, either to third-party entities or through publicly accessible resources, and what pri- vacy risks emerge from their disclosure? 1 Proceedings on Privacy Enhancing Technologies YYYY(X) Oliveira et al. • RQ3: How do cookie consent choices, subscription tiers, privacy settings, and access-control mechanisms shape the disclosure and accessibility of information in conversational AI services? To answer these questions, we conduct a systematic privacy analysis of nine prominent conversational AI services, covering the web clients of all nine providers and the Android clients of the eight that offer an Android mobile app. We combine static and dynamic analysis to evaluate their privacy practices across consent choices, subscription tiers, and access-control configurations. Specifically, we make the following contributions: (1) Across the evaluated services, we identify 44 third-party organi- zations and observe that every evaluated AI service integrates at least one third-party advertising or tracking service.
We fur- ther uncover substantial differences between web and Android clients and identify third-party services that are activated only after users explicitly accept non-essential cookies, demonstrat- ing that consent decisions directly influence the tracking surface of conversational AI platforms (§5).