Economy

The Silent Third Party in the AI Chat: Grok Is Particularly Brazen

ChatGPT did not transmit prompts in the test — Musk’s Grok was far less restrained

11 Min.

07.10.2026

An AI chat feels different from an ordinary website. People talk about illnesses, finances, problems at work or private decisions and receive an immediate, personal response. That conversational setting creates the impression of a protected space. Technically, however, what happens behind the interface can look much more conventional: AI services also use external analytics, telemetry and advertising systems. Researchers have now examined what data actually flows to third parties. The findings matter — but they require careful interpretation.

Nine AI Services Under Scrutiny

Researchers at the Madrid-based IMDEA Networks Institute examined ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Microsoft Copilot, Mistral’s Le Chat and Meta AI.

They tested all nine web versions as well as eight Android apps. Gemini could not be fully included in the dynamic Android analysis.

The measurements were carried out in Spain in May 2026. The researchers used different account types, either accepted or rejected non-essential cookies, and recorded which data browsers and apps transmitted to external servers.

They deliberately used sensitive conversation topics. Among other scenarios, they simulated users asking an AI system about medical problems.

The study has been accepted for the Proceedings on Privacy Enhancing Technologies 2027. The team had already published initial findings in May.

The basic result is clear: every one of the nine services communicated with at least one system classified by the researchers as an advertising or tracking service.

In total, they identified 124 third-party domains belonging to 44 organisations. Thirty-four of those organisations were classified as advertising and tracking services.

But that is where the more interesting question begins.

A Tracker Does Not Automatically Mean Someone Is Reading the Chat

The category covers very different types of services.

It includes conventional advertising networks, but also providers used for error diagnostics, technical monitoring, customer support and usage analytics.

Datadog, for example, helps companies monitor applications and identify performance problems or errors. Intercom provides customer support and communications software, among other services.

The researchers count these services as third parties alongside systems such as Google Analytics, Meta Pixel or TikTok Analytics whenever data is processed outside the AI provider itself.

Google, Microsoft and Meta create another methodological complication: the study also counts advertising or analytics systems operated by the same corporate group as separate tracking services.

So the statement that “all nine AI services use trackers” does not mean that all nine send complete conversations to advertising companies.

The differences between providers are substantial.

ChatGPT Did Not Send the Prompt to Datadog

For ChatGPT, the researchers observed data transfers to Datadog in both the browser and Android app.

The information included a unique conversation identifier as well as user, device or session identifiers. In the web version, the study also observed the chat URL being transmitted.

What the researchers did not find in ordinary ChatGPT conversations was transmission of the actual prompt, an automatically generated chat title or a screenshot to Datadog.

That distinction matters.

Ordinary ChatGPT conversations were also access-restricted during the tests. Someone who knew only the URL of a conversation could not open it without being logged into the account.

From a privacy perspective, transmitting a conversation identifier can still be problematic, particularly when it is linked to a persistent user identifier.

But that is not the same thing as handing over the contents of the conversation.

The study therefore does not support the claim that ChatGPT simply sends ordinary chats to external advertising companies.

Even an Automatically Generated Title Can Reveal a Lot

With other services, a much smaller piece of data may already contain sensitive information.

Many AI assistants automatically generate a title for a conversation. A question about the first signs of Parkinson’s disease, for example, might produce a title such as “Early Parkinson’s Symptoms”.

A few words can therefore reveal a significant part of the context of a conversation.

With Gemini, the researchers observed such chat titles being transmitted to Google Analytics.

Mistral’s Le Chat forwarded titles to Intercom during the tests. With Grok, titles were sent to several analytics and advertising systems.

In conversations about health, finances or relationships, even a short title can reveal more than its small data size suggests.

A third party does not need the full conversation to learn what the user is concerned about.

Grok Clearly Stands Out

The strongest third-party involvement was observed with Grok.

In the browser, the researchers identified seven systems that simultaneously received conversation-related information and user or tracking identifiers.

These included Google Ads and DoubleClick, Google Search, Google Tag Manager, Meta, TikTok and Twitter Analytics.

During ordinary conversations, depending on the service involved, data transmitted included the chat URL, a unique conversation identifier and the automatically generated title.

Some of these transmissions only occurred after users had accepted non-essential cookies.

The more serious finding appeared when a Grok conversation was deliberately shared.

The researchers observed that Meta received the user’s most recent prompt. TikTok received the chat title, the latest prompt and a screenshot of the conversation.

At that point, the issue is no longer limited to metadata.

Parts of the actual conversation content are being transmitted.

The Link Could Open the Entire Chat

Grok presented a second problem.

In the free and paid accounts tested, ordinary conversation URLs were configured so that anyone who knew the address could open the corresponding conversation.

Users could disable that public accessibility, but access was not fundamentally restricted to the account holder.

That clearly distinguished Grok from ChatGPT and Claude.

The researchers also inserted so-called canary links into conversations — special URLs designed to register when somebody accesses them.

Using these links, they were able to demonstrate that conversation resources were subsequently accessed by distributed third-party infrastructure.

According to the researchers, Grok was still using publicly accessible permalinks as recently as September 10.

xAI had already been informed about the issue in April.

Rejecting Cookies Does Not Solve Everything

The obvious response might be to reject all non-essential cookies.

That does help.

With Claude, for example, several additional tracking pathways disappeared. Meta Pixel, Datadog telemetry and redirects to various advertising platforms were not activated under those conditions.

But rejecting cookies did not eliminate all third-party communication.

For four of the nine free web services tested, third parties continued to collect data even after non-essential cookies had been rejected.

ChatGPT, Claude, Gemini, Copilot, DeepSeek and Perplexity established connections to Google Ads infrastructure in the tests even after users had declined optional cookies.

Whether such a connection actually contains personal or conversation-related information has to be assessed separately in each case.

Contact with a domain alone does not prove that a prompt has leaked.

That distinction is essential throughout the study.

Paying for the Service Offers Surprisingly Little Protection

A paid subscription does not automatically mean less tracking either.

The researchers compared free and premium accounts and found very little overall difference in the third-party services involved.

One exception was Claude’s Android app, where certain services appeared only in the free account.

In general, however, the underlying tracking infrastructure remained in place for paying users as well.

A paid business model may create the expectation that user data becomes less economically relevant to the provider.

Technically, the study found no clear divide of that kind.

Android Is Not Automatically More Private

Using an app is not a general solution either.

Mobile applications can access device identifiers, advertising IDs and other information that can make users easier to identify.

Three of the Android apps examined, for example, transmitted the Android Advertising ID to third parties.

With Grok, an email address or hashed email identifier was sent to TikTok and Twitter Analytics. Perplexity transmitted an email address to RevenueCat.

At the same time, the researchers found conversation artefacts in fewer mobile applications than web services: three of eight apps compared with six of nine web clients.

Web and app versions therefore carry different privacy risks.

Neither platform was consistently the safer option.

The Study Does Not Prove That Chat Content Is Being Sold

One limitation of the research is particularly important.

The researchers measure technical data flows.

They can see which information an application sends to which server.

They do not establish that the providers sell this information.

Nor does the study automatically reveal what every recipient subsequently does with the data.

With ChatGPT, for example, the researchers observed identifiers being transmitted to Datadog — not a prompt being sold to an advertising customer.

OpenAI’s European privacy policy explicitly refers to external vendors and service providers for purposes including cloud infrastructure, security and web analytics.

For Free and Go users, where advertising is available, the company may also use data to personalise advertising and measure its performance.

But here again, three different things have to be kept separate: processing by a service provider, advertising-related tracking and the sale of personal data.

Conflating them turns a serious privacy issue into a larger claim than the research actually supports.

The Researchers Still See a Fundamental Problem

Their central concern goes deeper.

People do not treat AI assistants like ordinary websites.

They tell them things.

Someone may enter their salary, ask an AI system to analyse an employment contract, describe medical symptoms or discuss a personal crisis.

That creates a different category of data.

The prompt itself is not the only potentially sensitive information. A chat title, conversation identifier, URL or screenshot can also reveal what a user is dealing with.

These artefacts are now coming into contact with the same tracking infrastructure that has been used for analytics and advertising across the internet for years.

That is the real shift.

Data Protection Authorities Are Already Involved

The research team reported its findings to data protection authorities in the European Union and the United Kingdom in April.

Spain’s data protection authority, AEPD, subsequently took up the issue and indicated that it wanted the matter discussed at European level.

The researchers are examining possible conflicts with the General Data Protection Regulation and the ePrivacy Directive.

Among the questions involved are whether users are sufficiently informed that conversation-related information may reach third parties, what legal basis exists for such processing and whether consent mechanisms genuinely work as intended.

OpenAI updated its privacy information in August and now explicitly refers to third-party tracking or analytics technologies.

The researchers themselves say they cannot determine whether their investigation prompted that change.

AI Chats Are Not Locked Diaries

The study therefore provides neither an all-clear nor evidence for the most alarmist interpretation.

No, major AI services do not all automatically send complete conversations to advertising companies.

But it would be equally wrong to assume that a chat technically takes place only between the user and the AI provider.

Analytics, support and advertising systems have become part of the infrastructure behind many services.

And with some providers, information reaches external systems that goes considerably beyond ordinary usage statistics.

The differences are significant.

With ChatGPT, the researchers found identifiers and a chat URL being sent to a technical service provider during ordinary conversations — but no prompts or chat titles.

With Gemini, even an automatically generated conversation title could leave the service.

And with Grok, the researchers observed the most recent prompt and a screenshot being transmitted to advertising platforms when shared conversations were opened.

The central lesson is therefore simple:

An interface that feels like a private conversation is not necessarily a private one from a technical point of view.

You might also be interested in:

scroll to top