Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents
Date
2027-07-19Abstract
As prominent conversational AI providers like OpenAI adopt advertising-based business models, traditional web and mobile tracking practices are expanding into conversational AI services [15]. However, despite their growing adoption, the tracking, data-sharing, and monetization practices of conversational AI services remain largely opaque and have received comparatively limited scrutiny from researchers, regulators, and the public.
In this paper, we present a systematic privacy analysis of the web and mobile deployments of nine prominent conversational AI services. Using a combination of static and dynamic analysis, we study the presence of third-party Advertising and Tracking Services (ATSes), characterize their data flows, and evaluate how consent choices, subscription tiers, and access-control mechanisms influence conversation exposure to third parties. We uncover privacy risks unique to conversational AI platforms: multiple providers disclose sensitive conversation-derived artifacts—including titles, prompts, and screenshots—to third parties, often alongside persistent user identifiers that enable user attribution. We also find that some providers publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation.
Our findings reveal how traditional tracking technologies are increasingly intertwined with AI-mediated interactions, creating new pathways through which sensitive user and conversational information can be collected, inferred, and disseminated. To assess the broader implications of these practices, we analyze them in the context of the GDPR and ePrivacy Directive. We conducted a responsible disclosure process involving affected providers and competent European Data Protection Authorities. Our results demonstrate that conversational AI services introduce a novel privacy attack surface in which provider-generated conversational artifacts become subject to tracking and public exposure, highlighting the need for stronger safeguards governing AI-mediated interactions.


