ChatGPT Ad Tracking Cookie Exposes User Activity Across Third-Party Sites
Key Takeaways OpenAI’s advertising measurement system utilizes a cross-site tracking cookie, named __obi. This cookie links user activity on third-party advertiser websites to their ChatGPT...
Key Takeaways
- OpenAI’s advertising measurement system utilizes a cross-site tracking cookie, named
__obi. - This cookie links user activity on third-party advertiser websites to their ChatGPT accounts or device identifiers.
- The tracking mechanism was confirmed across 936 advertiser pixels and 1,029 hostnames, collecting data like page paths, and potentially sensitive personal information.
- The
__obicookie is configured for cross-site requests and has a one-year lifespan, differentiating it from other OpenAI cookies. - Safari’s Intelligent Tracking Prevention is expected to block this tracking method on WebKit-based browsers.
OpenAI’s advertising measurement framework reportedly employs a cross-site cookie that enables the correlation of user activities on advertiser websites with their respective ChatGPT accounts or persistent device identifiers.
Table Of Content
This cookie, identified as __obi, is generated when a user accesses ChatGPT. Subsequently, it can transmit data back to OpenAI when the user visits websites that have integrated OpenAI’s advertising pixel.
Independent verification of this mechanism was conducted on a mobile device, revealing its presence across 936 distinct advertiser pixels spanning 1,029 hostnames. While mirroring the conversion tracking employed by prominent advertising platforms, its direct link to a leading artificial intelligence service introduces novel privacy concerns.
Upon a user initiating a session with ChatGPT, the client system creates a unique random identifier and requests a temporary, signed token from OpenAI’s backend infrastructure. This token encapsulates an account-specific subject value, the __obi identifier, and a consent status indicating “analytics_allowed.”
ChatGPT Ad Tracking Cookie Tracks Users
Mechanism of the __obi Cookie
ChatGPT then dispatches this token to bzr.openai.com, an OpenAI advertising data collector internally referred to as “Bazaar.” In response, the collector sets the __obi cookie for the entire .openai.com domain.
The cookie is configured with SameSite=None and Secure attributes, permitting web browsers to include it in cross-site requests. Furthermore, it is assigned a maximum validity period of one year.
This particular configuration distinguishes __obi from other OpenAI cookies, which have reportedly been blocked during third-party requests due to domain restrictions or more restrictive SameSite=Lax settings.
Advertisers who purchase ad placements within ChatGPT’s ecosystem can embed OpenAI’s measurement pixel onto their websites. This pixel loads necessary code from OpenAI’s infrastructure and transmits conversion event data to bzr.openai.com.
When a user already possesses the __obi cookie, their browser may automatically append this identifier to these requests. This functionality enables OpenAI to receive granular information about pages a user navigates on third-party advertiser sites, encompassing product pages, article URLs, purchase pathways, and conversion actions.
Although query strings were observed to be stripped from recorded URLs, the page paths themselves remained visible. These paths reportedly included content related to sensitive topics such as medical conditions, debt relief solutions, and legal consultation services.
Beyond explicit conversion data, OpenAI’s advertising software also harvests information directly from advertiser web pages. It can receive data intentionally provided by advertisers and is also capable of scraping information from web forms, rendered page content, and tag management systems.
According to Buchodi, observed data included hashed email addresses, phone numbers, names, and location-specific fields. Geolocation data, such as country, region, city, and postal code, could be transmitted in plain text.
OpenAI’s pixel reportedly monitors various data layers, including window.dataLayer, Adobe’s data layer, and custom-named Google Tag Manager layers. In the analyzed traffic, automatically scraped identity information appeared more frequently than data explicitly supplied by advertisers.
This tracking mechanism can operate even when a user is not logged into their ChatGPT account. Anonymous users are assigned a device-linked subject identifier that remained stable for a minimum of 27 days. However, testing was primarily conducted on Chrome for Android.
It is important to note that Safari’s Intelligent Tracking Prevention (ITP) blocks third-party cookies, suggesting that this particular tracking method should not function in Safari or other iOS browsers built upon WebKit.
OpenAI’s public cookie policy categorizes __obi as an analytics cookie, not a marketing cookie. The observed sync tokens were issued when analytics consent was granted, even in instances where marketing consent had reportedly been declined.
OpenAI acknowledged an inquiry regarding this privacy concern but had not provided a detailed response concerning the cookie’s classification or its consent behavior at the time of this report.
What You Should Do
- Review your OpenAI and ChatGPT privacy settings and consent preferences, particularly regarding analytics and advertising.
- Consider using browsers with strong built-in tracking prevention, such as Safari or Brave, which may mitigate the effectiveness of such cross-site cookies.
- Regularly clear your browser cookies, especially third-party cookies, to reduce persistent tracking.
- Employ browser extensions designed to block trackers and advertisements for an additional layer of privacy protection.
- Exercise caution when interacting with websites that request personal information, particularly if they are linked to third-party advertising pixels.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.