I am bored with the topic of whether AI can be or not our killer asteroid.
But I have evidence that it is today, already, our nosy confessor.
When you chat with ChatGPT or Claude and company, you think you are in a safe room talking privately with “your” AI.
In reality, you are in an interrogation room with a two-way mirror, like those in the movies: and on the other side of the mirror there is not Wonderland: there are the same data vampires that monitor you on the internet.
The nine most famous AI assistants filter your data to Google, Meta, and several of the main data brokers.
It makes little difference if you do not accept cookies.
It does not matter whether you pay or not.
It does not matter if you use Brave and adblockers. TikTok receives screenshots of your chats in Grok.
The experts at IMDEA Networks have demonstrated this in a study on ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Copilot, Le Chat de Mistral and Meta AI with a browser and a very special phone that allows them to study and document the information that leaves your browser and your Android mobile apps, and where it goes.
The resulting paper is “Prompt like a Butterfly, Sting like a Tracker”, led by Narseo Vallina-Rodríguez and his team, in which I participated as a lawyer, has been accepted in PoPETs 2027, the academic forum of reference in privacy technologies, with peer review.
Link to an infographic summary of the paper (Substack does not allow this kind of stuff).
You are reading ZERO PARTY DATA. The newsletter on current affairs and technology law by Jorge García Herrero and Darío López Rincón.
In the free time that this newsletter leaves us, we solve complicated issues related to personal data protection regulations and artificial intelligence. If you have any of these, make a sign with your hand. Or contact us by email at jgh(arroba)jorgegarciaherrero.com
Bottomline: It is much worse than what we anticipated in May.
In May, we published a preview, limited to just four services and their web versions.
The final version of the paper examines nine assistants (ChatGPT, Claude, Gemini, Copilot, Grok, Perplexity, Mistral, DeepSeek and Meta AI) on the web and on Android, in free and paid versions, accepting and rejecting cookies.
Notably, we now know something that in May we could only imagine: that text, screenshots and documents from your chats are transmitted to and read by third parties.
I know, I know: it’s another stripe on the tiger, and it rains on wet ground and all that
We are all saturated with headlines about abuses by big tech companies over our data, self-esteem, mental health and democracies and the natural response is to shrug: “another stripe on the tiger”.
Allow me three reasons to question the “one more”:
First.- Cookies “only” filtered metadata to third parties …
Classic tracking knew where you were, with whom, which pages you visited, how long, from what device.
You had just had coffee with your friend who was returning from Iceland and told you about the vacation.
And from those metadata, they inferred a possibility of sale and shot you an ad for vacations in Iceland.
And you thought that “Instagram had heard your conversation”.
… AI filters directly the “content”
Today, your AI assistant filters directly the summary and/or the link to your chat: your symptoms, your salary, your fling, your divorce, your company’s cash flow.
The AI itself summarizes the chat automatically in a “title” that several of the services analyzed send to Meta, TikTok, Google or X along with the URL of the chat and other persistent identifiers.
In the study, this question was formulated: “I earn $85,000, what mortgage can I afford in New York?”
The AI summarizes it in the title “Salary 85k NYC: Mortgage of 280-350k”.
This title, in the hands of an advertiser with your synchronized cookie, is a credit score, ready-to-use credit profile.
· The web versions of 3 of the 9 assistants studied filter the title of your chats to third parties, including Meta, TikTok and DoubleClick (Google).
· Grok presents public conversation URLs by default, so whoever receives the URL (the link to the chat) can read the entire conversation.
· TikTok receives screenshots of the Grok chat when someone shares it.
Second: here usually come the “useful tips to protect yourself”. But I’m sorry: you can barely do anything. That’s the tweet.
I don’t have a section “five tips to be smarter than them”. Sorry:
· Rejecting cookies leaves 80.8% of the trackers observed active.
· On mobile, they do not even ask you (you accept terms and conditions when installing the app).
· Paying for the premium service barely reduces the number of third parties that access your information.
· They send your information from server to server so that neither the Brave browser nor any adblocker can prevent that sending: Claude forwards events to eleven advertising platforms, Grok talks from its servers with Meta and TikTok.
Of course, all this is illegal: they do not have either the knowledge or the consent (or other legal basis) of the users. And do not tell me that the transmitted data are anonymous.
The analysis is also in the paper (and in the summary).
Who can do something? The providers… or the authorities.
This has been the timeline:
· We notified the first findings to the European data protection authorities in April.
· The AEPD brought the matter to the plenary of the European Data Protection Board in June.
· OpenAI changed its privacy policy in August to expressly mention the trackers.
· The links to Grok chats are still public today.
Otherwise… Have you heard anything else about it?
I only heard… cri-cri cri-cri cri-cri [sound of crickets at night].
So far is what has been proven and documented. Now I warn that I am entering speculative territory.
Third: The obvious risk: The infrastructure is ready for another qualitative leap.
The optimistic reading of this study is that AI has simply inherited the vices and sins of unconsented tracking that are the daily bread of the web.
But you do not have to be Spielberg to see the risk of a linear evolution.
AI has devoured all this infrastructure and is in a position to close, for the first time, the traditional circle in real time:
1.- Capture of signal directly from what the user writes,
2.- Transmission to advertising intermediaries with identifiers that allow attributing the signal to the user,
3.- Auction among companies interested in presenting their product/service precisely to that user at exactly that moment
4.- Sponsored recommendation embedded in the assistant’s response, with the naturalness of a disinterested advice.
Whoever trusts that this mechanism will be informed to the user, let them ask if they have been informed about the data filtering mechanism described in this paper...
This summer we were told that the “watermark” that identifies text generated by AI is the text itself (not a mark, label or separate signal that betrays it).
It does not seem impossible that advertising becomes intertwined in the responses of the AI, undetectable to the human eye.
Have a great week. And be careful what you tell your AI assistant.
Jorge García Herrero
Lawyer and Data Protection Officer


