AI companies leak data to advertisers [pdf]

(jorgegarciaherrero.com)

76 points | by damaru2 1 hour ago

10 comments

  • j4k0bfr 1 minute ago
    This is a bit surprising to me, considering how much AI companies love to hoard data. Especially since some of these ad companies are direct competitors!

    My best guess is that these ad mechanisms are a bit rushed and/or that investor demands for profitability are fighting against company self-interest.

  • Coeur 41 minutes ago
    "multiple providers disclose sensitive conversation-derived artifacts — including titles, prompts, and screenshots — to third parties, often alongside persistent user identifiers that enable user attribution. We also find that some providers publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation."

    Not good at all.

    • postalcoder 8 minutes ago
      My least favorite trend I’ve noticed with so many AI chat services is they seem to equate a UUID in the url with privacy.

      Perplexity does this. Visiting a past perplexity search url exposes your full conversation.

  • gagan2020 12 minutes ago
    All sells but I saw Chinese models are upfront about that most of the time.
  • reedf1 10 minutes ago
    my first guess is always Gboard.
  • DrMandalay 18 minutes ago
    The word is "sell" not "leak". This title takes away all agency from the thieves selling private data to advertisers.
  • charcircuit 32 minutes ago
    The paper doesn't say when the app sends the conversion artifact.
  • classified 35 minutes ago
    Is it still called a leak if it was the whole point and purpose of the deal?

    Someone should have to investigate, but I suppose it's all "legal"?

    • lava_pidgeon 6 minutes ago
      In the US.

      In EU law it is very likely against GDPR.

  • folkrav 35 minutes ago
    Insert surprised pikachu meme
  • damaru2 1 hour ago
    Entire conversations via exposed permalinks. For Grok: trackers receiving the conversation URL could access the full chat because the link lacked access controls.

    Screenshots of conversations. TikTok received screenshots of Grok chats during sharing, exposing the actual visible conversation content.

    Conversation-derived content tied to persistent identifiers, including prompts and automatically generated chat titles revealing sensitive facts. "Salary 85k NYC: mortgage 280–350k".

  • irregularbowels 1 hour ago
    [dead]