Popular AI chatbots are passing details of users' private conversations to advertising and tracking firms, often alongside identifiers that link them to real people.
The study, by nine researchers led by IMDEA Networks Institute in Madrid, tested the web and Android versions of ChatGPT, Claude, Gemini, Grok, Copilot, Perplexity, DeepSeek, Meta AI and Mistral's Le Chat.
Senior authors Narseo Vallina-Rodriguez and Guillermo Suarez-Tangil have spent more than a decade studying how apps and websites track users, including work on children's privacy and hidden data collection in Android apps.
What is leaking
Six of the nine websites and three of the eight Android apps sent conversation data to third parties.
That includes chat web addresses, prompts, screenshots and the short titles chatbots generate to summarise each conversation.
Those titles can be revealing: a question about Parkinson's symptoms becomes "Early-stage Parkinson's disease symptoms".
Grok was the worst offender, sending a single conversation's address and title to seven trackers, including Meta, TikTok, X's ad pixel and Google Ads.
When a Grok chat is shared, TikTok also receives the user's latest prompt and a screenshot of the conversation.
How it happens
The chatbots carry the same tracking tools used across the web, such as Meta's pixel, a snippet of code that reports page activity back to the social network.
Because a chatbot's page title and web address describe the conversation, those tools pick up its content automatically.
Some services go further: Claude and Grok forward data server to server, a route ad blockers cannot see.
Rejecting cookies offers limited protection, with 80.8% of trackers staying active after users said no.
Public by default
Grok conversations can be read by anyone with the link unless users opt out.
Links planted in Grok chats were opened 70 times from 14 countries, sometimes days later.
The researchers told xAI in April and say they have had no reply, with the problem unfixed as of 10 September.
Why it matters
The researchers link the trend to chatbot makers' search for revenue, noting OpenAI's move to bring adverts to free ChatGPT users.
Unlike ordinary browsing, chatbot conversations often cover health, money and personal problems, which carry extra protection under European data law.
Spain's data protection agency, the AEPD, cited the work in May when it asked European regulators to examine whether AI systems let third parties reach users' chats.
The paper, prepared for the journal Proceedings on Privacy Enhancing Technologies, is based on tests carried out in Spain in May, and practices may since have changed.