Originally shared on LinkedIn, May 11, 2026
Turns out your favorite chatbot is maybe forwarding your conversation content to third parties. In some cases, the literal plaintext of what you typed and what the model said back.
A new preprint on arXiv by Muhammad Jazlan, Ethan Wang, Yash Vekaria, and Zubair Shafiq (all of University of California, Davis) ran the first systematic measurement of web tracking across 20 popular AI chatbot platforms. They submitted a controlled sensitive prompt (“pregnancy test near me”) and captured all network traffic.
![]()
17 of 20 chatbots shared data with at least one third party during a single session. Advertising services appeared on 12 of 20. SeaArt alone contacted 13 distinct advertisers in one session, including Facebook, Google, TikTok, and Amazon. Claude and Mistral’s support widgets transmitted user name, email, account ID, and user hash on page load… before anyone even typed anything.
Three chatbots (Genspark, SeaArt, ChatOn) sent readable conversation snippets to Microsoft Clarity’s session replay tool. On Genspark, Clarity received the response “Here are a few pregnancy test options near you.” On ChatOn, it received “Most pharmacies like CVS, Walgreens, or Rite Aid carry home pregnancy tests.”
Private/temporary chat modes did substantially reduce third-party exposure where available, so there’s that…
The paper, in 200 words
As AI chatbots replace search engines for sensitive queries — health, finances, relationships — the question of who else sees those conversations has gone largely unexamined. This study offers the first systematic answer. The researchers tested the 20 most popular web-based chatbots under controlled conditions, submitting a deliberately sensitive prompt combining health information with an implicit location request, then capturing every network request the page made. They looked for two kinds of exposure: content (the prompt itself, AI-generated chat titles, chat URLs and identifiers) and identity (names, emails, account IDs, cookies).
The results: 17 of 20 chatbots contacted at least one third party during a single ordinary session. Several exposed identity information to analytics and advertising vendors, and three transmitted readable fragments of the actual conversation — both user prompts and model responses — to a session-replay service. Because chatbot use typically requires login, tracking attaches to account-level identifiers tied to real individuals rather than anonymous browser cookies. The one encouraging finding concerns private modes: where offered, they eliminated all observed content and identity exposure to third parties. The authors also compared network behavior against each provider’s privacy policy, finding notable gaps between disclosure and practice.
Generated with Claude and reviewed by TDL’s editorial team.


















