OpenAI’s Hidden Ad-Tracking Cookie Can Follow ChatGPT Users Across the Web
A security researcher found that OpenAI’s advertising system sets a cookie that can link ChatGPT accounts to browsing activity on ordinary websites, raising new privacy questions.
Photo by <a href="https://unsplash.com/@danny144?utm_source=WP+Agent&utm_medium=referral">Dan Nelson</a> on <a href="https://unsplash.com/?utm_source=WP+Agent&utm_medium=referral">Unsplash</a>
OpenAI’s Hidden Ad-Tracking Cookie Can Follow ChatGPT Users Across the Web
A security researcher has found that OpenAI’s advertising system quietly sets a cookie that can link a person’s activity on ordinary websites back to their ChatGPT account. The investigation, published this week by independent researcher Buchodi and independently corroborated by Cyber Security News, documents how the cookie — named __obi — is built specifically to travel across sites in a way OpenAI’s other cookies are not, raising new privacy questions about how ChatGPT’s growing advertising business handles user data.

What Happened
OpenAI began showing ads inside ChatGPT for free and Go-tier accounts earlier this year, and companies that buy those ads can install a small measurement script on their own websites — similar to how retailers already install Meta Pixel or Google Tag on their sites. On September 20, Buchodi published a detailed technical writeup showing that this script quietly reads and sends a cookie called __obi back to OpenAI whenever someone with that cookie visits a participating advertiser’s site.
According to the report, the researcher reproduced the mechanism directly on a phone, verified it using two independent capture methods, and cross-referenced months of observed traffic covering 936 distinct advertiser pixels across 1,029 different websites. On the researcher’s own device, a single __obi value was sent to OpenAI from a dozen real commercial sites, including Chewy, Wayfair, ThriftBooks, Eventbrite, HelloFresh, Coursera, and SeatGeek.
How the Tracking Works
The mechanism happens in three steps. First, when someone opens ChatGPT, the app generates a random identifier and requests a short-lived signed token from OpenAI’s backend, tied to that person’s account. Second, that token is sent to an OpenAI advertising server, which responds by setting the __obi cookie on the person’s browser — configured specifically to be included in requests made to other websites, and set to last a full year. Third, when that person later visits a site that has installed OpenAI’s advertiser measurement code, the cookie is automatically sent back to OpenAI, along with information about what the person is doing on that page.
What makes this notable, according to the research, is that __obi is configured differently from every other cookie OpenAI sets. Its other identifiers were observed being blocked during the same cross-site requests, either because of domain restrictions or stricter same-site settings. __obi was the only one built to survive that trip.
What Data Is Involved
The report says the same advertiser script also collects identifying details directly from the pages people visit — sometimes supplied deliberately by the advertiser, and sometimes scraped automatically from web forms, page text, or a website’s own analytics systems. In the traffic the researcher observed, scraped identity information appeared more often than the information advertisers intentionally shared: 685 scraped events compared with 255 supplied ones.
Email addresses, phone numbers, and names were hashed before being sent, the report says, but location details — country, region, city, and postal code — were transmitted in plain text. Full web addresses were not sent, but the page paths were, and among those paths the researcher says the collector received pages tied to a medical condition, a debt-solutions service, and a legal-intake form.
The tracking also isn’t limited to signed-in users. The report found that people who hadn’t logged into ChatGPT still received a similar identifier, one tied to their device rather than their account, which stayed stable for at least 27 days.
OpenAI’s Response
Buchodi says the findings and two specific questions — why the cookie is classified the way it is, and whether declining marketing consent actually stops it — were sent to OpenAI’s press and privacy contacts on September 14, nearly a week before publication. According to the report, OpenAI Support acknowledged the inquiry and said it would be shared internally for review, but did not directly answer either question by the time the research was published.
OpenAI’s own cookie policy lists __obi as an analytics cookie rather than a marketing one — the only entry in that category. That classification matters because, according to the research, every sync token observed during testing was issued under an “analytics allowed” consent setting, including cases where the same user had declined marketing consent specifically.
What’s Confirmed and What Isn’t
The technical mechanism — how the cookie is created, how it’s configured, and how it’s transmitted to advertiser sites — was independently reproduced and documented with request-level detail, and Cyber Security News’ separate reporting corroborates the same core findings. What hasn’t been independently observed is what OpenAI does with the data once it arrives on its servers; the researcher is clear that resolving the incoming events back to a specific ChatGPT account follows logically from how the system is built, but wasn’t something they could watch happen directly.
The tracking also has real limits. It was documented on Chrome for Android; Safari and other WebKit-based browsers, including every browser on iPhone and iPad, block this kind of cross-site cookie by design and appear unaffected. Only roughly one in five ChatGPT sessions produced a trackable token in the research, and the mobile web version of ChatGPT wasn’t observed triggering the mechanism at all.
Why It Matters
Cross-site ad tracking cookies are not new — the underlying technique closely mirrors systems Meta and Google have run for years. What’s different here is what’s on the other end of the identifier. People increasingly share personal, sensitive context with ChatGPT that they wouldn’t post publicly, and as chat assistants take on more tasks like shopping and browsing on a user’s behalf, tying that account to a person’s activity across the rest of the web raises different stakes than a typical retail pixel. It also lands at a moment of intensifying scrutiny over how AI companies collect and use personal data more broadly — for more on the state of leading AI assistants, see our comparison of ChatGPT, Gemini, and Claude, and for OpenAI’s other recent platform moves, see our coverage of the OpenAI Agents API launch.
What Users Can Do
- Blocking third-party cookies in your browser prevents
__obifrom being sent on other sites, since the cookie depends on that cross-site behavior to function. - On iPhone and iPad, this specific tracking method does not appear to work, since every browser on those devices blocks third-party cookies by default.
- OpenAI’s cookie settings page lists
__obiunder its Analytics category — clearing cookies for openai.com resets the identifier, though a new one is generated the next time the mechanism triggers.
Conclusion
This is an actively developing privacy story rather than a settled one: OpenAI has acknowledged the inquiry but hasn’t yet given a detailed public response, and it’s unclear whether the company will reclassify the cookie or change how it’s deployed. What’s already documented, though, is a working technical mechanism that ties ordinary web browsing to a ChatGPT account — a combination that didn’t exist before ChatGPT started running ads, and one that’s likely to draw attention from privacy regulators given how explicitly it’s built to cross site boundaries.
Sources
- Buchodi’s Threat Intel — “ChatGPT now knows what you do on other websites via ad collector” (September 20, 2026) — buchodi.com
- Cyber Security News — “ChatGPT Ad Tracking Cookie Follows Users Across Third-Party Advertiser Websites” (September 21, 2026) — cybersecuritynews.com

2 thoughts on “OpenAI’s Hidden Ad-Tracking Cookie Can Follow ChatGPT Users Across the Web”