| dc.identifier.citation | [1] Gunes Acar, Christian Eubank, Steven Englehardt, Marc Juarez, Arvind Narayanan, and Claudia Diaz. 2014. The web never forgets: Persistent tracking mechanisms in the wild. In Conference on Computer and Communications Security (CCS). [2] AdExchanger. 2026. Daily News Roundup: OpenAI, Advertising, and AI Com- merce. https://www.adexchanger.com/daily-news-roundup/tuesday-03032026/ Accessed: 2026-05-31. [3] AEPD. 2026. La Agencia promueve ante las autoridades europeas de protección de datos que se estudie si algunos sistemas de IA permiten a terceros acceder a las conversaciones. https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/ la-agencia-promueve-ante-las-autoridades-europeas-proteccion-estudie-ia. Ac- cessed: 2026-09-7. [4] Google Developers Blog. 2025. Under the Hood: Universal Commerce Pro- tocol (UCP). https://developers.googleblog.com/under-the-hood-universal- commerce-protocol-ucp/ Accessed: 2026-05-31. [5] Canary 2026. Canarytokens. https://canarytokens.org/. Accessed: 2026-05-27. [6] Juan-Carlos Carrillo, Jose Luis Martin-Navarro, Rongjun Ma, and Jose Such. 2026. Personal Data Flows and Privacy Policy Traceability in Third-party LLM Apps in the GPT Ecosystem. In Proceedings on Privacy Enhancing Technologies (PoPETs). [7] Certificate Transparency. 2026. crt.sh: Certificate Transparency Search. https: //crt.sh/. Accessed: 2026-05-29. [8] Jeffrey Yang Fan Chiang, Seungjae Lee, Jia-Bin Huang, Furong Huang, and Yizheng Chen. 2025. Why are web ai agents more vulnerable than standalone llms? a security analysis. arXiv preprint arXiv:2502.20383 (2025). [9] Cliqz GmbH and Ghostery GmbH. 2026. WhoTracks.Me. https://whotracks.me Accessed: 2026-05-24. [10] Aldo Cortesi, Maximilian Hils, Thomas Kriechbaumer, and contributors. 2010–. mitmproxy: A free and open source interactive HTTPS proxy. https://mitmproxy. org/ [11] Court of Justice of the European Union. 2019. Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV. https://eur-lex.europa.eu/legal-content/EN/TXT/ ?uri=CELEX:62017CJ0040 Case C-40/17, ECLI:EU:C:2019:629. [12] Court of Justice of the European Union. 2024. Gesamtverband Autoteile-Handel e.V. v Scania CV AB. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri= CELEX:62022CJ0319 Case C-319/22, ECLI:EU:C:2024:845. [13] Court of Justice of the European Union. 2024. Meta Platforms Ireland Ltd v Bundesverband der Verbraucherzentralen und Verbraucherverbände – Ver- braucherzentrale Bundesverband e.V. https://eur-lex.europa.eu/legal-content/ EN/TXT/?uri=CELEX:62022CJ0757 Case C-757/22, ECLI:EU:C:2024:598. [14] Court of Justice of the European Union. 2025. European Data Protec- tion Supervisor (EDPS) v Single Resolution Board (SRB). https://eur-lex. europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413 Case C-413/23 P, ECLI:EU:C:2025:645. [15] Criteo. 2025. Agentic Commerce Is Emerging, Just Not the Way Most People Expect. https://www.criteo.com/blog/agentic-commerce-is-emerging-just-not- the-way-most-people-expect/ Accessed: 2026-05-31. [16] Anthony Desnos, Geoffroy Gueguen, and Sebastian Bachmann. 2015. Androguard: Reverse engineering, malware and goodware analysis of android applications... and more (ninja!). https://androguard.github.io/androguard/. Accessed: 2026-05- 25. [17] Yana Dimova, Gunes Acar, Lukasz Olejnik, Wouter Joosen, and Tom Van Goethem. 2021. The cname of the game: Large-scale analysis of dns-based tracking evasion. In Proceedings on Privacy Enhancing Technologies (PoPETs). [18] Android Official Documentation. 2025. Settings.Secure. https://developer.android. com/reference/android/provider/Settings.Secure#ANDROID_ID Accessed: 2026- 05-31. [19] Peter Eckersley. 2010. How Unique Is Your Web Browser?. In Proceedings on Privacy Enhancing Technologies (PoPETs). [20] European Data Protection Board. 2022. Binding Decision 3/2022 on the dis- pute submitted by the Irish Supervisory Authority on Meta Platforms Ireland Limited and its Facebook service (Art. 65 GDPR). Technical Report. European Data Protection Board. https://www.edpb.europa.eu/system/files/2023-01/edpb_ bindingdecision_202203_ie_sa_meta_facebookservice_redacted_en.pdf Adopted pursuant to Article 65 GDPR. [21] European Data Protection Board. 2024. Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive. Technical Report. European Data Protec- tion Board. https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_ 202302_technical_scope_art_53_eprivacydirective_v2_en_0.pdf [22] European Parliament and Council of the European Union. 2002. Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive). Official Journal of the European Union, L 201, 31 July 2002, pp. 37–47. https://eur- lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02002L0058-20091219 Article 5(3), as amended by Directive 2009/136/EC. [23] European Parliament and Council of the European Union. 2016. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Official Journal of the European Union, L 119, pp. 1–88. https://eur-lex.europa.eu/eli/reg/2016/679/oj [24] Álvaro Feal, Julien Gamba, Juan Tapiador, Primal Wijesekera, Joel Reardon, Serge Egelman, and Narseo Vallina-Rodriguez. 2021. Don’t accept candy from strangers: An analysis of third-party mobile sdks. Data Protection and Privacy: Data Protection and Artificial Intelligence 13 (2021), 1. [25] Federal Trade Commission. 2024. No, hashing still doesn’t make your data anonymous. https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/07/ no-hashing-still-doesnt-make-your-data-anonymous. Accessed: 2026-05-31. [26] Imane Fouad, Cristiana Santos, and Pierre Laperdrix. 2024. The Devil is in the Details: Detection, Measurement and Lawfulness of Server-Side Tracking on the Web. In Proceedings on Privacy Enhancing Technologies (PoPETs). [27] Julien Gamba, Álvaro Feal, Eduardo Blazquez, Vinuri Bandara, Abbas Razagh- panah, Juan Tapiador, and Narseo Vallina-Rodriguez. 2023. Mules and permission laundering in android: Dissecting custom permissions in the wild. IEEE Transac- tions on Dependable and Secure Computing 21, 4 (2023), 1801–1816. [28] Aniketh Girish, Joel Reardon, Juan Tapiador, Srdjan Matic, and Narseo Vallina- Rodriguez. 2025. Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android. In Proceedings on Privacy Enhancing Tech- nologies (PoPETs). [29] Alejandro Gómez-Boix, Pierre Laperdrix, and Benoit Baudry. 2018. Hiding in the crowd: an analysis of the effectiveness of browser fingerprinting at large scale. In Proceedings of the ACM Web Conference (WWW). [30] Umar Iqbal, Steven Englehardt, and Zubair Shafiq. 2021. Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting Behaviors. In IEEE Symposium on Security and Privacy (S&P). [31] Umar Iqbal, Tadayoshi Kohno, and Franziska Roesner. 2024. LLM platform security: Applying a systematic evaluation framework to OpenAI’s ChatGPT plugins. In Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society. [32] Muhammad Jazlan, Ethan Wang, Yash Vekaria, and Zubair Shafiq. 2026. Tracking Conversations: Measuring Content and Identity Exposure on AI Chatbots. arXiv preprint arXiv:2604.27438 (2026). [33] John Doe. 2026. Complaint for Damages and Demand for Jury Trial: Doe v. Perplexity AI, Inc. Complaint filed in the Superior Court of Califor- nia. https://cdn.arstechnica.net/wp-content/uploads/2026/04/Doe-v-Perplexity- Complaint-3-31-26.pdf Filed March 31, 2026. Available online. [34] Pierre Laperdrix, Gildas Avoine, Benoit Baudry, and Nick Nikiforakis. 2019. Morel- lian analysis for browsers: Making web authentication stronger with canvas fingerprinting. In Conference on Detection of Intrusions and Malware, and Vulner- ability Assessment (DIMVA). [35] Victor Le Pochat, Tom Van Goethem, Samaneh Tajalizadehkhoob, Maciej Ko- rczynski, and Wouter Joosen. 2019. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Network and Distributed System Security Symposium (NDSS). [36] Shen Li, Liuyi Yao, Lan Zhang, and Yaliang Li. 2025. Safety Layers in Aligned Large Language Models: The Key to LLM Security. In International Conference on Learning Representations (ICLR). [37] Luoxi Meng, Henry Feng, Ilia Shumailov, and Earlence Fernandes. 2025. cellmate: Sandboxing browser ai agents. arXiv preprint arXiv:2512.12594 (2025). [38] Meta for Developers. 2025. Meta Pixel Reference. https://web.archive.org/web/ 20250531104925/https://developers.facebook.com/docs/meta-pixel/reference/. [39] Maaz Bin Musa and Rishab Nithyanand. 2022. ATOM: Ad-network Tomography. In Proceedings on Privacy Enhancing Technologies (PoPETs). [40] Trung Tin Nguyen, Michael Backes, and Ben Stock. 2022. Freely given consent? studying consent notice of third-party tracking and its violations of gdpr in android apps. In Conference on Computer and Communications Security (CCS). [41] NowSecure. 2025. NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App. https://www.nowsecure.com/blog/2025/02/06/ nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios- mobile-app/. Accessed: 2026-05-28. [42] OpenAI. 2022. Introducing ChatGPT. https://openai.com/blog/chatgpt Accessed: 2026-05-31. [43] OpenAI. 2025. How people are using ChatGPT. https://openai.com/index/how- people-are-using-chatgpt. Accessed: 2026-09-8. [44] Amogh Pradeep, Muhammad Talha Paracha, Protick Bhowmick, Ali Dava- nian, Abbas Razaghpanah, Taejoong Chung, Martina Lindorfer, Narseo Vallina- Rodriguez, Dave Levin, and David Choffnes. 2022. A comparative analysis of certificate pinning in Android & iOS. In Proceedings of the Internet Measurement Conference (IMC). [45] Exodus Privacy. 2024. Homepage. https://exodus-privacy.eu.org/en/. Accessed: 2026-05-31. [46] Ole André Vadla Ravnås and contributors. 2014. Frida: Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. https://frida. re/ [47] Abbas Razaghpanah, Arian Akhavan Niaki, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Johanna Amann, and Phillipa Gill. 2017. Studying TLS usage in An- droid apps. In Conference on emerging Networking EXperiments and Technologies (CoNEXT). [48] Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, Phillipa Gill, et al. 2018. Apps, trackers, privacy, and regulators: A global study of the mobile tracking ecosystem. In Network and Distributed System Security Symposium (NDSS). [49] Joel Reardon, Kenneth A. Bamberger, and Serge Egelman. 2024. Anonymity, Consent, and Other Noble Lies: An Empirical Study of the Data Econ- omy. https://ibl.law.uiowa.edu/anonymity-consent-and-other-noble-lies- empirical-study-data-economy. Accessed: 2026-05-31. [50] Joel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On, Narseo Vallina- Rodriguez, and Serge Egelman. 2019. 50 ways to leak your data: An exploration of apps’ circumvention of the android permissions system. In Proceedings of the USENIX Security Symposium. [51] Reuters. 2025. OpenAI Projected at Least 220 Million People Will Pay for ChatGPT by 2030, The Information Reports. Reuters. https://www.reuters.com/technology/openai-projected-least-220-million- people-will-pay-chatgpt-by-2030-information-2025-11-26/ Accessed: 2026-05- 31. [52] Reuters. 2026. OpenAI to introduce ads to all ChatGPT free and Go users in US. https://www.reuters.com/business/media-telecom/openai-expand-ads- chatgpt-all-free-low-cost-users-information-reports-2026-03-21/ [53] Irwin Reyes, Primal Wijesekera, Joel Reardon, Amit Elazari Bar On, Abbas Raza- ghpanah, Narseo Vallina-Rodriguez, Serge Egelman, et al. 2018. “Won’t somebody think of the children?” examining COPPA compliance at scale. In Proceedings on Privacy Enhancing Technologies (PoPETs). [54] Franziska Roesner and David Kohlbrenner. 2026. Agentic Browsers and the Same- Origin Policy. In International Conference on Learning Representations (ICLR). [55] Jaechul Roh, Eugene Bagdasarian, Hamed Haddadi, and Ali Shahin Shamsabadi. 2026. SPILLage: Agentic Oversharing on the Web. arXiv preprint arXiv:2602.13516 (2026). [56] Avishag Shapira, Parth Atulbhai Gandhi, Edan Habler, and Asaf Shabtai. 2025. Mind the web: The security of web use agents. arXiv preprint arXiv:2506.07153 (2025). [57] Singular. [n. d.]. Android SDK: Setting a User ID. Singular Developer Documen- tation. https://support.singular.net/hc/en-us/articles/35636052267803-Android- SDK-Setting-a-User-ID Accessed: 2026-05-31. [58] Thinkst Applied Research. 2026. Dockerized Canarytokens. https://github.com/ thinkst/canarytokens-docker. Accessed: 2026-05-27. [59] uBlock Origin Team. 2026. uBlock Origin. https://ublockorigin.com Accessed: 2026-05-24. [60] Alisha Ukani, Hamed Haddadi, Ali Shahin Shamsabadi, and Peter Snyder. 2025. Privacy Practices of Browser Agents. arXiv preprint arXiv:2512.07725 (2025). [61] Yash Vekaria, Aurelio Loris Canino, Jonathan Levitsky, Alex Ciechonski, Patricia Callejo, Anna Maria Mandalari, and Zubair Shafiq. 2025. Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative {AI} Assistants. In Proceedings of the USENIX Security Symposium. [62] Tim Vlummens, Aniketh Girish, Nipuna Weerasekara, Frederik Zuiderveen Bor- gesius, Gunes Acar, and Narseo Vallina-Rodriguez. 2026. Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost. In Proceedings of the USENIX Security Symposium. [63] Ethan Wang, Zubair Shafiq, and Yash Vekaria. 2026. FP-Agent: Fingerprinting AI Browsing Agents. arXiv preprint arXiv:2605.01247 (2026). [64] Nipuna Weerasekara, José Miguel Moreno, Srdjan Matic, Joel Reardon, Juan Tapi- ador, Narseo Vallina-Rodríguez, et al. 2025. Tracking without borders: Studying the role of webviews in bridging mobile and web tracking. In Proceedings on Privacy Enhancing Technologies (PoPETs). [65] Wired. 2026. OpenAI Enables Cookies by Default for Free ChatGPT Users. https://www.wired.com/story/openai-enables-cookies-by-default-for- free-chatgpt-users/ Accessed: 2026-05-31. [66] Fangzhou Wu, Ning Zhang, Somesh Jha, Patrick McDaniel, and Chaowei Xiao. 2024. A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems. arXiv:2402.18649 [cs.CR] https://arxiv.org/abs/2402.18649 [67] Yuhao Wu, Evin Jaff, Ke Yang, Ning Zhang, and Umar Iqbal. 2025. An in-depth investigation of data collection in llm app ecosystems. In Proceedings of the Internet Measurement Conference (IMC). [68] Yuhao Wu, Ke Yang, Franziska Roesner, Tadayoshi Kohno, Ning Zhang, and Umar Iqbal. 2025. Towards Automating Data Access Permissions in AI Agents. arXiv:2511.17959 [cs.CR] https://arxiv.org/abs/2511.17959 [69] Zhonghao Zhan, Huichi Zhou, Zhenhao Li, Peiyuan Jing, Krinos Li, and Hamed Haddadi. 2026. How Adversarial Environments Mislead Agentic AI? arXiv preprint arXiv:2604.18874 (2026). | es |