The chat box is not the boundary.
A 2026 study by researchers from IMDEA Networks and collaborators examined nine consumer conversational AI services on the web and eight Android clients. The researchers report that every tested service contacted at least one third-party service they classified as advertising or tracking infrastructure.[1]
The paper reports conversation-derived artifacts leaving some clients. It found such disclosure in six of nine web clients and three of eight Android clients. The observed artifacts included conversation URLs, generated titles, prompts, screenshots, and conversation identifiers. Some traveled with persistent user or device identifiers.[1]
A blank chat window can sit on top of a crowded network trace.
A title can carry the secret.
Conversation titles are small, but they summarize intent. The study uses examples about Parkinson's symptoms and mortgage affordability to show how a generated title can encode health or financial context. The researchers report that three of nine web clients disclosed titles to third parties in their tests.[1]
This does not mean every third-party request is an advertising sale. Analytics, fraud prevention, support, crash reporting, and attribution can share infrastructure. The paper states that its black-box method cannot determine every processing purpose. It also describes the measurements as a point-in-time lower bound from May 2026.[1]
Rejecting cookies is useful, not complete.
The researchers tested ignored, rejected, and accepted cookie states where the service offered those choices. They report that rejecting non-essential cookies reduced some disclosures. They also found third-party connections under rejected settings, and they saw little difference between free and paid tiers in the set of third parties contacted.[1]
Anthropic's current consumer data-retention page covers a different route. It explains chat deletion, model-improvement settings, Incognito chats, feedback, and retention after trust and safety flags. Those controls matter, but they do not replace a client-side network inspection. A retention policy answers how the first party stores data. A network trace asks where the client sends it.[2]
Sharing changes the access model.
The study opened conversation permalinks in a separate private session without authentication. It reports that some services exposed ordinary conversation links by default or used an opt-out model. It also reports that every tested sharing feature created a public link when the user chose to share.[1]
The Spanish Data Protection Agency responded to the preliminary work in May. It asked European authorities to consider three issues: permanent links exposed to trackers, interaction data linked to user identity, and privacy controls that may not match the measured data flows.[3]
Run a witness test before the sensitive prompt.
Use a fresh profile and harmless canary text that belongs to you. Record the client type, account tier, privacy settings, and cookie choice. Capture network requests during an ordinary chat and during sharing. Search the capture for the canary, generated title, conversation identifier, account identifier, and full URL.
Then test access separately. Open the ordinary conversation URL and any explicit share URL in a signed-out private session. Do not test another person's link. Record the result and the exact time. Repeat after a major client update because this route can change without a model release.