Post

Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents

A peer-reviewed study finds that nine conversational-AI services expose conversation-derived data to third-party trackers through their web and mobile apps. Researchers used static and dynamic analysis to trace data flows, consent choices, subscription tiers, and access controls; they report prompts, chat titles, and screenshots disclosed alongside persistent identifiers, and some services leave conversation links publicly readable. The paper is accepted to PoPETs 2027 and is currently in press.

The study concerns tested web and Android app deployments, not every provider interface or API. Its findings describe disclosures to tracking services; they do not by themselves establish that providers sold the data. In the HN discussion, commenters highlighted a separate concern about unfinished prompts reportedly sent to ChatGPT before submission, while others distinguished app/web behavior from API data handling and questioned how opaque provider policies are.