October 7, 2026, 2:36 pm | Read time: 4 minutes
AI chats are perceived by many users as private spaces: type a question, get an answer, done. But what happens with the entered information in the background is hardly visible. A new study now shows that conversation data from several well-known AI services can reach external companies.
Researchers scrutinize well-known AI services
For the study by the IMDEA Networks Institute, researchers examined nine prominent AI offerings: ChatGPT, Claude, Gemini, Grok, DeepSeek, Perplexity, Le Chat, Meta AI, and Microsoft Copilot. They analyzed the web versions as well as the Android apps available from eight providers.
The researchers found at least one external advertising or tracking service in all the AI services examined. In total, they identified 44 third-party providers in this area. However, this does not automatically mean that these companies receive content from the conversations. What is crucial is which information is actually transmitted to them.
Conversation data can end up with external companies
According to the study, six of the nine web services examined and three of the eight apps examined transmitted conversation URLs, titles, inputs, or screenshots to external companies. In some cases, even permanent user identifiers were included, which could potentially link conversations to a specific user.
In some cases, not just individual pieces of information from the conversations were sent out. According to the study, some services also transmitted automatically generated summaries of conversations to third parties. This could give external companies an idea of what a user discussed with the chatbot without necessarily receiving the entire chat.
When conversation links become a data protection issue
Particularly sensitive can be links to individual conversations. If such references are not adequately protected, as was the case with several of the services examined according to the researchers, external services could potentially access the entire chat history.
The researchers specifically mention Grok and Perplexity. Both services reportedly transmitted conversation URLs with weak access control to external trackers like Meta Pixel. This allows website operators, for example, to track whether users perform certain actions after an advertisement.
In Grok, the researchers also found literal message content in Open Graph metadata captured by TikTok. This metadata, among other things, determines how a link appears as a preview when shared. The issue here was that parts of the actual conversation were apparently included.
Millions of Chrome Users Secretly Spied On
“Reject All” Ineffective? Many Websites Use Cookies Despite Rejection
Rejecting cookies is not always enough
Rejecting non-essential cookies can partially limit tracking, but according to the researchers, it cannot always be completely prevented. Although the number and type of integrated services changed depending on consent, certain information could still be transmitted.
Also of interest: “Reject all” ineffective? Many websites set cookies despite rejection
This becomes particularly relevant when this data can be linked to a user. The researchers found, among other things, cookies, hashed email addresses, and other identifiers. In combination, such information could be used to recognize users and link activities together.
What follows from the study
The results do not mean that every AI provider examined sends complete chats to advertising companies. There are significant differences between the individual services. And just because an AI service integrates a tracker does not mean that it can read the entire chat. However, the study shows that information from conversations can leave the platform in several offerings.
The results were also analyzed in terms of the General Data Protection Regulation (GDPR) and the ePrivacy Directive. According to the researchers, the affected providers and relevant European data protection authorities have already been informed of the identified issues.
For users, this means one thing above all: Conversations with an AI should not automatically be considered confidential exchanges. Particularly sensitive personal, health, or professional information should therefore only be shared with caution in a chatbot.