What the study is
The paper is titled "Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents." It is a systematic privacy analysis of the web and mobile deployments of nine conversational AI services. It uses static and dynamic analysis to study third-party advertising and tracking services, and to test how consent choices, subscription tiers and access controls affect exposure.
The IMDEA Networks repository lists it as an open-access conference paper for the Privacy Enhancing Technologies Symposium in Delft, July 2027, with status "in press". Treat it as peer-reviewed research that has not yet been presented. The paper carries no release date, so coverage dates vary. PPC Land says researcher Wolfie Christl flagged it on October 5, but German and Hacker News-linked coverage shows it circulating from late September.
The tested services were ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Microsoft Copilot, Mistral's Le Chat and Meta AI. According to PPC Land's account, all experiments ran in Spain in May 2026. They used Chrome 148 on the web and an instrumented Pixel 3a running Android 12, plus static analysis of the apps. The prompts were health-related, so the results show what happens with sensitive questions. They are not a census of all use.
Where Copilot sits
Copilot is the Microsoft-relevant case, so here is what the reporting says about it, and what it doesn't.
- Web: A German-language analysis of the paper says Copilot, DeepSeek and Meta AI did not send conversation data to third-party services on the web. That is a favourable result compared with six of nine peers.
- Google Ads contact: PPC Land reports that most traffic from Copilot, Mistral and Meta AI comes from native code, not WebViews. Separately, it says Copilot still connected to Google Ads in the reject-all cookie scenario, alongside five other services. Contact with an ad domain is not the same as conversation content being sent. The paper notes that third-party presence alone doesn't prove data is used for advertising.
- Android advertising ID: The paper reports that Copilot's Android app sent the mobile advertising ID to the attribution firm Adjust. That is a device identifier, not a conversation artifact. Attribution SDKs often support install measurement, which the authors acknowledge.
- Canary URLs: The researchers planted unique URLs in prompts. For DeepSeek, Copilot, Mistral and Claude, some were fetched once, at submission, from cloud providers such as AWS and Google Cloud. That points to one-time fetching, not repeated access like Grok's.
The study doesn't show Microsoft using any of this for ad targeting. It also doesn't cover enterprise tiers, so Microsoft 365 Copilot in a managed tenant is outside the findings. The authors also counted Google, Microsoft and Meta analytics endpoints as third-party services even where the AI product belongs to the same company. "Third party" here does not always mean an unrelated company.
The core finding: titles and links reveal things
The authors argue that chat apps create a new kind of leak. Even when the full prompt isn't sent, the auto-generated title and the URL can describe the conversation. PPC Land lists the researchers' examples: a question about early-stage Parkinson's became a title naming the condition, and a salary-and-mortgage prompt became a Grok title containing the figures.
Several other findings stood out:
- Five web clients disclosed conversation URLs, or the IDs behind them, to third parties. Three web clients, per PPC Land, leaked generated titles: Gemini, Grok and Mistral.
- 77.3% of observed web identifier transmissions occurred only after users accepted non-essential cookies.
- Grok's server-side tag setup reportedly sent the conversation URL and topic to Meta and TikTok, with cookies attached. The authors say such flows evade ad blockers.
- Some providers publicly expose conversation permalinks without access controls, which lets trackers read the entire conversation. Grok is the main example, and the authors say xAI had not responded as of September 10.
Consent banners and paid tiers did little
The reported results are blunt:
- Rejecting non-essential cookies cut some tracking, but not all. Ignoring the banner gave the same contacts as rejecting.
- Free and paid accounts showed nearly identical third-party sets, with one Claude mobile exception.
- Android apps have no cookie-banner equivalent.
Two numbers describe what survives rejection, and PPC Land says the paper doesn't reconcile them. One is 44.4% of free-tier services (four of nine) and the other is 80.8% of third-party services. The denominators differ, so don't merge them into one claim.
Caveats
- The authors call the results a point-in-time lower bound. They also say the study excludes enterprise and government tiers and persistent-memory risks.
- Gemini's mobile traces could not be extracted. That is why the Android denominator is eight. PPC Land notes the paper's tables are inconsistent on this point.
- Detecting fingerprinting APIs shows capability, not proof of fingerprinting.
- The authors say their goal is not a legal compliance ruling. They point to the ePrivacy Directive and GDPR as relevant frameworks.
- Spain's data protection authority, the AEPD, asked for EU-level review. The paper doesn't report the outcome.
- One independent hobbyist test found far fewer ad-related destinations for a logged-out ChatGPT than for Grok. That is anecdotal, but it fits the paper's point that behaviour differs a lot by vendor.
Practical steps for Windows and IT users
This is analysis based on the findings, not advice from the paper:
- Assume titles are visible. Avoid putting health, financial or legal details into consumer chatbots, even if you never share the chat.
- Don't rely on cookie rejection alone. Consider DNS-level or network-level blocking of ad domains on managed devices. Server-side flows can bypass browser blockers.
- Check sharing settings. Shared conversation links worked without a login in every service tested. Treat any shared link as public.
- Review mobile apps. Android advertising IDs can be reset or opted out in system settings, and corporate mobile policies can restrict them.
- Use managed tiers for work. Enterprise offerings were not tested, so ask vendors for their own tracking documentation instead of assuming it's cleaner.
Bottom line
For Microsoft shops, the study doesn't show Copilot leaking chat content to advertisers. It does show consumer Copilot contacting Google Ads even after cookie rejection, and its Android app sending an advertising ID to an attribution vendor. Those are narrower findings than what the study reports for Grok. The wider lesson is that AI chat apps now carry the same ad-tech plumbing as the rest of the web.
References
- 6 of 9 AI chatbots pass chat titles or links to trackers, IMDEA finds - PPC Land PPC Land · 2026-10-05T16:54:23+00:00
- Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents dspace.networks.imdea.org
- Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents dspace.networks.imdea.org