pbasista

Tangential:

I have recently noticed that e.g. ChatGPT, when used from a web browser, periodically sends unfinished prompts to their servers, namely to the `conversation/prepare` endpoint, without waiting for the user to actually send it.

This partial prompt data might potentially be used to "pre-warm" some kind of cache.

But it may also be used to track the user's writing cadence, error correction style and evolution of their stub ideas as they are being formulated into a prompt. I would assume that such data could also be sold to the advertisers.

show comments
kdaniel_03

It's the same lesson as the Navier-Stokes credit fight earlier this month. Buckmaster and Alpoge had their unpublished drafts in private Codex sessions and OpenAI says nobody saw them but admits de-identified product data may have improved its models. There it's training data, here it's ad trackers. Either way, prompts and results that should stay private don't. Thats why even though open models aren't perfect it has to win. You can skip the app and run the model yourself.

postalcoder

My least favorite trend I’ve noticed with so many AI chat services is they seem to equate a UUID in the url with privacy.

Perplexity does this. Visiting a past perplexity search url exposes your full conversation.

show comments
delis-thumbs-7e

In an old Simpsons episode Lisa gets to visit the Teachers room, where all the staff are making fun of the children. Groundskeeper Willie is pantomiming Milhouse “Oh I am Milhouse, I tell all my secrets to Willie since I have no friends!” and the teachers laugh. Later something embarrassing happens to Milhouse and he immediately runs away crying “I have to tell this to Willie!”.

We have all become Milhouse now.

show comments
j4k0bfr

This is a bit surprising to me, considering how much AI companies love to hoard data. Especially since some of these ad companies are direct competitors!

My best guess is that these ad mechanisms are a bit rushed and/or that investor demands for profitability are fighting against company self-interest.

Edit: I guess some data will always need to be leaked for AI chat ads to be most effective. But I imagine AI companies would rather deliver the targeted ads themselves rather than letting competitors do it for them. It would be scary to see AI companies become ad companies too (instead of just hosting them).

show comments
20k

A lot of people seem to be very in denial about the fact that OpenAI and co do not give a crap about you. They don't care about the agreements you've signed. You're just a pile of cash to them

show comments
segmondy

Prior to this new AI age, your data was calculated and what was inferred about you was "shallow", but as of today. The sort of profile and things that can be known about you is scary especially if you are constantly engaged with cloud AI. IMO, the number one risk of using cloud AI is loss of privacy and loss of freedom. With AI and capabilities, more controls can be placed on people and the more you put yourself out there, the more you are going to lose.

For example, we now have self driving cars, we have cameras everywhere. Based on your chat with a cloud AI, you can automatically trigger an automatic monitoring event that follows and tracks you in the real world with the fleet of cameras, cars, GPU, cell signal. Your tracking due to AI has moved into the real world and eventually, a self driving car will take you in to be "processed" against your will, not even for what you posted in a public forum, but for your private ribbing and chatting with some cloud AI.

So definitely put local AI into the mix and keep personal stuff and thoughts local only.

vivekpolavarapu

Ad-tech spent 20 years trying to infer intent from clickstreams. Chat apps now hand over an AI-written one-line summary of intent, labeled and keyed to a cookie. Are we sure the ads business model in AI is about ads in the chat, and not the chat as the targeting signal?

troyvit

This paper focuses on the use of the providers' web and phone tools, and the data sharing arrangements they built through ad networks and tracking services like Data Dog. It doesn't talk about how they handle data from API calls. For one thing that can be pretty opaque.

I have a friend/client who understandably doesn't trust the existing privacy policies of the major providers. They have the same problem many of us do: We want the most powerful models, we're willing to pay for them, but we see over and over how much of a frontier the frontier actually is. Frontiers are ugly if you don't have guns.

So for now maybe platform tools like Open WebUI and TypingMind are a good workaround since the big boys don't (apparently) train on API data (for now) or (probably) send that data to advertisers. It would be interesting to confirm that.

yoaviram

Not surprising. When privacy is a selling point on the enterprise plan regular users, even paying ones, are the product. OpenAI had this from day one, the writing was on the wall. We all knew it so let's not act surprised now.

[1](https://chatgpt.com/pricing/?type=team)

show comments
zug_zug

time for somebody to make a quick script to poison your chat history by starting 1000 fake conversations with contradictory identifying details "I worry as a lesbian woman, my tween daughter doesn't blah blah Shabbat blah blah move home to Australia"

show comments
dhanushnehru

It’s not a leak if it’s the business model.

skybrian

In case anyone finds it helpful, I asked ChatGPT to break down what they found by app:

https://chatgpt.com/s/t_6abbbee386bc8191a26717b4f1442657

Traster

I'd be kind of surprised if OpenAI were really doing this deliberately because a whole bunch of their execs come from Meta, and all those guys learned the hard way.

First: You don't want to leak information about your users to advertising networks because it's going to leak, get back to your customers, they're going to figure out you're doing it and get really angry.

But second and more importantly - it's a much better business model to collect that data for yourself, keep it in house and then you control how you use that data to target ads which gives you a massive competitive advantage in selling ads because you have unique targeting data.

The way meta does this now is the model, they don't give the advertiser a list of the people you're going to show the advert to, the advertiser gives you a list of characteristics they want to hit and meta decides who those people are.

show comments
lukehandcool

You should really assume that any information you give to a private model is going directly into a database. These companies don't care about your privacy. Local, open weight models are the only way to truly protect your data.

show comments
Coeur

"multiple providers disclose sensitive conversation-derived artifacts — including titles, prompts, and screenshots — to third parties, often alongside persistent user identifiers that enable user attribution. We also find that some providers publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation."

Not good at all.

show comments
DrMandalay

The word is "sell" not "leak". This title takes away all agency from the thieves selling private data to advertisers.

show comments
0xcrypto

This is why I built my own chat interface. https://ai.ivx.run/

Access through: https://ai.ivx.run/chat/

pluc

You thought... they didn't?

gagan2020

All sells but I saw Chinese models are upfront about that most of the time.

classified

Is it still called a leak if it was the whole point and purpose of the deal?

Someone should have to investigate, but I suppose it's all "legal"?

show comments
r0b05

Why do you think they are fighting so hard to dethrone Google?

Google is an ad company.

ChrisArchitect

Title is: Prompt like a Butterfly, sting like a tracker

or A Privacy Analysis of Web and Mobile Conversational AI Agents

Site link with context: https://jorgegarciaherrero.com/en/prompt-like-a-butterfly-st...

maybewhenthesun

Yea no shit sherlock!

My stance used to be that the invention of the filter bubble combined with targeted advertising is the most dangerous invention for human society of the last 100 years.

AI turns that up to 11

okokwhatever

I never thought this could happen (XD)

reedf1

my first guess is always Gboard.

nwhnwh

I am very surprised.

charcircuit

The paper doesn't say when the app sends the conversion artifact.

titzer

Not surprised. Just wait until they bake the goddamn advertising right into the model.

bix6

Hard to read on mobile. Is there a tldr of how bad each provider is?

robertclaus

Hanlon's Razor given that these tools are almost certainly vibe coded at this point?

show comments
Grimeton

Oh no, what, what happened?

What happened? Oh no!

How terrible! That’s just, that’s just awful!

How terrible! Oh no!

999ziyadej

data is sold i think

folkrav

Insert surprised pikachu meme

Razengan

The ads ~~industry~~ racket is a cancer upon civilization.

This shit needs to be stamped down by law.

People take up pitchforks and torches against AI data centers,

well how much time, money, and resources have been wasted on advertisements over the centuries?

How many people, including children, have been deceived by ads?

How much privacy has been violated in the name of "sErViNg YoU rElEvAnT aDs"?

Have you ever tried browsing YouTube from a poor connection, and noticed how long it takes to serve ads? How much bandwidth has been wasted on ads so far?

Who[m] does it all benefit?

micromacrofoot

these companies are complete dumpster fires and we just keep giving them more to burn

damaru2

Entire conversations via exposed permalinks. For Grok: trackers receiving the conversation URL could access the full chat because the link lacked access controls.

Screenshots of conversations. TikTok received screenshots of Grok chats during sharing, exposing the actual visible conversation content.

Conversation-derived content tied to persistent identifiers, including prompts and automatically generated chat titles revealing sensitive facts. "Salary 85k NYC: mortgage 280–350k".

show comments
sick_of_slop

Of course they do. As soon as ads entered the equation this was always going to happen. Nobody should be suprised.

drywater2

No, they don't "leak data", data is sold. Leaking data requires a mistake. This is intentional.

show comments