Pimp My IDE / garage dispatch
Back to garage
September 29, 2026 | conversational AI / privacy

Your prompt has an exhaust system.

The chat box looks private because it has one input and one answer. The client can still send titles, links, identifiers, and interaction data through other pipes.

Treat every conversational client as a data route. Inspect the content, destination, identity link, and access control before you put sensitive work in the seat.

The chat box is not the boundary.

A 2026 study by researchers from IMDEA Networks and collaborators examined nine consumer conversational AI services on the web and eight Android clients. The researchers report that every tested service contacted at least one third-party service they classified as advertising or tracking infrastructure.[1]

The paper reports conversation-derived artifacts leaving some clients. It found such disclosure in six of nine web clients and three of eight Android clients. The observed artifacts included conversation URLs, generated titles, prompts, screenshots, and conversation identifiers. Some traveled with persistent user or device identifiers.[1]

A blank chat window can sit on top of a crowded network trace.

A title can carry the secret.

Conversation titles are small, but they summarize intent. The study uses examples about Parkinson's symptoms and mortgage affordability to show how a generated title can encode health or financial context. The researchers report that three of nine web clients disclosed titles to third parties in their tests.[1]

This does not mean every third-party request is an advertising sale. Analytics, fraud prevention, support, crash reporting, and attribution can share infrastructure. The paper states that its black-box method cannot determine every processing purpose. It also describes the measurements as a point-in-time lower bound from May 2026.[1]

Rejecting cookies is useful, not complete.

The researchers tested ignored, rejected, and accepted cookie states where the service offered those choices. They report that rejecting non-essential cookies reduced some disclosures. They also found third-party connections under rejected settings, and they saw little difference between free and paid tiers in the set of third parties contacted.[1]

Anthropic's current consumer data-retention page covers a different route. It explains chat deletion, model-improvement settings, Incognito chats, feedback, and retention after trust and safety flags. Those controls matter, but they do not replace a client-side network inspection. A retention policy answers how the first party stores data. A network trace asks where the client sends it.[2]

Sharing changes the access model.

The study opened conversation permalinks in a separate private session without authentication. It reports that some services exposed ordinary conversation links by default or used an opt-out model. It also reports that every tested sharing feature created a public link when the user chose to share.[1]

The Spanish Data Protection Agency responded to the preliminary work in May. It asked European authorities to consider three issues: permanent links exposed to trackers, interaction data linked to user identity, and privacy controls that may not match the measured data flows.[3]

Run a witness test before the sensitive prompt.

Use a fresh profile and harmless canary text that belongs to you. Record the client type, account tier, privacy settings, and cookie choice. Capture network requests during an ordinary chat and during sharing. Search the capture for the canary, generated title, conversation identifier, account identifier, and full URL.

Then test access separately. Open the ordinary conversation URL and any explicit share URL in a signed-out private session. Do not test another person's link. Record the result and the exact time. Repeat after a major client update because this route can change without a model release.

Interactive makeover / privacy witness bench

Trace the prompt exhaust

Traditional purpose replaced: a generic privacy checklist. Better version: choose the client surface, connect four evidence lines to one witness bus, and copy a test card with explicit blanks. This bench plans an audit. It does not capture traffic.

Load a client surface

Pick the surface you will inspect. Then select only the evidence your test will collect.

Client surface
Evidence lines
Audit card draft1 of 4 evidence lines selected
Witness manifold

Web app inspection

Surface: web appWitness bus incomplete

One evidence line is selected.

The audit card will request a content witness. Destination, identity, and access evidence remain open. No capture has run.

What this component proves. It creates a structured audit request and shows which evidence lines were selected. It does not inspect a client, identify a tracker, establish a legal purpose, or prove that a service is private.

Sources and limits

Open the source log
  1. Oliveira et al., "Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents", read September 29, 2026. The manuscript reports black-box tests run in Spain in May 2026 across nine web services and eight Android clients. Its repository labels the work for PoPETs 2027, while the PDF still contains placeholder publication fields. Treat it as a current manuscript, not a finished journal record.
  2. Anthropic Privacy Center, "How long do you store my data?", updated July 1, 2026 and read September 29, 2026. This first-party page describes consumer chat deletion, model-improvement settings, Incognito chats, feedback retention, and retention after policy flags.
  3. Spanish Data Protection Agency, "La Agencia promueve...", May 27, 2026. The regulator says it sent the preliminary study to the European Data Protection Board and summarizes the three issues it wanted authorities to assess.
  4. Research artifact repository for the paper, read September 29, 2026. The repository contains scripts, expected outputs, labeled-domain data, and sample captures. It states that the full captures used for the paper are not public because they contain sensitive data.
  5. Hacker News discussion for the paper, item 49890226, resolved through the Hacker News API on September 29, 2026.

Evidence boundary. The measured results belong to the tested versions, regions, accounts, and conditions. The paper excludes enterprise and government tiers, could not extract Gemini mobile traces, and cannot assign a legal or commercial purpose to every observed third-party request. A new client release can change the route.