All episodes

    Episode 255 · September 21, 2026 · 5:57

    ChatGPT’s new “__obi” cookie can follow you across websites

    Security researchers report that ChatGPT's website sets a one-year, cross-site cookie called "__obi" that can be sent to other websites using OpenAI's advertising pixel. This identifier, starting from within ChatGPT, can potentially link private AI interactions to a user's broader web browsing, raising privacy concerns among users who view ChatGPT as a personal, private tool.

    Listen to this episode

    Episode breakdown

    What happened

    In recent days, security researchers reported that ChatGPT's website is setting a cookie named "__obi." This cookie is designed to be valid for one year and is explicitly configured for cross-site use. When users visit other websites that have installed OpenAI's advertising pixel, their browser automatically sends the "__obi" cookie along with the request.

    This mechanism allows an identifier that originates from ChatGPT to follow users across the internet. The episode explains that an advertising pixel is a small tracker embedded on a website that reports back, indicating that a person with a specific ID visited. This approach mirrors a long-standing playbook used in ad technology, but the notable difference here is that the identifier may originate from interactions within ChatGPT, a platform often used for highly personal inquiries.

    Why it matters

    The introduction of a cross-site tracking cookie originating from ChatGPT shifts the perception of what many users consider a private, conversational tool. People use ChatGPT for sensitive tasks like drafting cover letters, discussing personal issues, or even asking health-related questions. The idea of an ad-style tracker connecting these intimate interactions to broader web activity raises significant privacy concerns, as it moves ChatGPT closer to the data collection practices seen in ad tech.

    While the cookie itself is an identifier and not a name, these identifiers are routinely linked to real individuals through various online activities. This capability allows for the creation of detailed user profiles, potentially revealing personal states like job searching, financial concerns, or health issues. Such deep profiling offers valuable signals for advertisers, who may pay extra for insights into a user's most persuadable, or vulnerable, moments.

    Furthermore, this tracking mechanism can create blurred boundaries in shared computing environments or work settings. If a family computer or an office browser is used by multiple individuals for different purposes, the cookie can mix signals, making it difficult to maintain separation between personal and professional online identities or different users' activities. The episode suggests that while OpenAI may not be intentionally "reading deepest secrets," the existence of such tracking often leads to its use and monetization, reflecting a capitalist incentive rather than malicious intent.

    What to watch next

    • Will OpenAI or other AI providers offer clearer opt-out mechanisms or more granular control over data sharing and tracking?
    • Will privacy-focused AI tools gain market share as users become more aware of tracking practices?
    • How will regulatory bodies respond to cross-site tracking originating from AI conversational tools, especially regarding personal data?
    • Will browser developers introduce new features or strengthen existing ones to automatically isolate or block AI-specific trackers?
    • Will public discourse shift, leading to greater demand for "privacy-by-design" in AI products, particularly those handling personal queries?

    What this means for you

    For business leaders and operators, understanding the implications of cross-site tracking from AI tools is critical for managing data governance, privacy policies, and employee conduct. Review your internal guidelines for AI tool usage, especially concerning sensitive company information or employee data that might be input into conversational AI. Consider whether your company's existing ad pixels or tracking technologies might inadvertently collect or contribute to this type of profiling through integrations with AI services.

    From an individual user perspective, adopting a strategy of "separation for sensitive AI use" is a practical step. This involves creating a dedicated browser profile for ChatGPT and similar AI tools, keeping it distinct from profiles used for shopping or general browsing. Within this dedicated profile, configure settings to block third-party cookies, and consider installing a reputable tracker blocker. Regularly clearing cookies for AI service domains adds another layer of control over persistent identifiers.

    Key takeaways

    • ChatGPT's "__obi" cookie is a one-year, cross-site identifier.
    • This cookie can transmit user IDs from ChatGPT to other sites with OpenAI's ad pixel.
    • The tracking raises privacy concerns because ChatGPT handles personal information.
    • Cross-site identifiers allow for detailed user profiling, including sensitive personal states.
    • Using a dedicated browser profile for AI tools can help separate personal data.

    FAQ

    What is the "__obi" cookie reported to be doing?

    The "__obi" cookie, reported by security researchers, is a cross-site tracking identifier set by ChatGPT's website. It has a one-year validity and can be sent to other websites that have integrated OpenAI's advertising pixel. This process allows an identifier originating from a user's interactions within ChatGPT to follow them across various websites, potentially linking their private AI conversations to their broader online activity.

    Why is cross-site tracking from ChatGPT a concern?

    Cross-site tracking from ChatGPT is a concern because ChatGPT is frequently used for highly personal and sensitive inquiries, such as drafting personal documents, discussing health issues, or exploring career changes. When an identifier from these interactions follows users across the web, it enables the creation of detailed profiles that could reveal vulnerable or private aspects of their lives, which can be valuable to advertisers.

    How does this tracking differ from traditional ad tech?

    While the mechanism of an advertising pixel and cross-site cookies is common in traditional ad tech, the key difference here is the origin point of the identifier. In this reported scenario, the tracking ID may start within ChatGPT, a platform perceived by many as a private, conversational tool, rather than from a general content website or social media feed. This shifts the context of data collection to a more personal and intimate space.

    What can users do to protect their privacy when using ChatGPT?

    Users can protect their privacy by implementing "separation for sensitive AI use." This involves creating a dedicated browser profile (supported by Chrome, Edge, Brave, but not Safari in the same way) specifically for ChatGPT and similar AI tools. Within this profile, users should enable settings to block third-party cookies, consider installing a reputable tracker blocker, and regularly clear cookies for chatGPT.com. Additionally, keeping prompts cleaner by avoiding sensitive personal data can help.

    Why would OpenAI use an ad-style tracking cookie?

    The episode suggests that the use of an ad-style tracking cookie like "__obi" by OpenAI, while raising privacy concerns, may not be driven by malicious intent but rather by data plumbing and capitalist incentives. When data is collected, there's a tendency to utilize and potentially monetize it. Legitimate reasons for such tracking can also include measurement, fraud prevention, rate limiting, abuse detection, and attribution for various services.

    OpenAIPrivacyAI Security

    Share with a friend