AI Chatbot Data Privacy: Trackers Persist After Cookie Rejection
euobserver.com

AI Chatbot Data Privacy: Trackers Persist After Cookie Rejection

Tech News
3 min read

Published by AINave Editorial

TL;DRAn EUobserver report on IMDEA-led research found at least one advertising or tracking service in each of nine popular chatbots. In six services, connections to Google Ads persisted after users rejected non-essential cookies.

AI chatbot data privacy is not just a question of what a service does with a conversation after it is sent. An IMDEA-led study, reported by EUobserver, found that all nine popular chatbots examined integrated at least one third-party advertising or tracking service. Six still connected to Google Ads after users rejected non-essential cookies, a finding that complicates the assumption that a cookie choice necessarily blocks tracking.

A connection is not proof of ad targeting

The six services named were Perplexity, DeepSeek, Gemini, Copilot, ChatGPT and Claude. The report establishes connections to Google Ads after cookie rejection; it does not establish that every conversation was disclosed, or that those connections led to a person receiving a targeted advertisement.

That distinction matters. A tracker connection is evidence of a data flow between a chatbot and a third-party service, not by itself a complete account of what data moved or how it was used. Still, the researchers say tech companies may have been able to connect conversation summaries with personal identifiers, creating a potential route from a private prompt to an identifiable user.

People may ask chatbots about health, psychological wellbeing, finances and relationships. The study found that chat titles could summarize sensitive questions and be shared with third parties, turning a short label into a revealing piece of context even if it is not the full conversation. The report describes potential linkage to personal identifiers, not a measured rate of such matches.

Grok presented a more direct exposure in the reported findings: public conversation links were exposed by default, allowing trackers to access whole conversations. EUobserver also reports that TikTok processed screenshots of Grok conversations. These examples show why privacy review needs to account for outputs and sharing features, not only the prompt box or cookie banner.

The researchers identified tensions between the reported practices and obligations under the GDPR and ePrivacy Directive. The report says GDPR requires clear explanations of data harvesting and ePrivacy requires consent for cookies unless they are strictly necessary; researchers questioned whether vague tracker disclosures in terms and conditions provide adequate transparency. These findings are concerns about compliance, not a legal ruling that a named provider broke the law.

The report also says Mistral did not offer users a choice to reject non-essential cookies. More broadly, researcher Narseo Vallina-Rodriguez warned that cookie-less and identity-based tracking can work around some anti-tracking measures. That makes a cookie rejection button a limited signal of user choice, not proof that all tracking has stopped. For product teams, the practical distinction is between presenting consent controls and ensuring the underlying data flows respect them.

FAQs

The reported study found third-party advertising or tracking services in all nine chatbots examined, and says sensitive details could appear in chat titles shared with third parties. It does not establish that every conversation was shared or used for ad targeting. The report describes these findings.

Sources

Latest Tech News