ChatGPT already knows your other browsing.
ChatGPT's ad collector integration joins cross-site tracking data with your prompts under one identity. The exposure, the mechanism, and what stays unconfirmed.
ChatGPT now knows what a user does on other websites. The stated access path is an integration with an ad collector. Cross-site activity data, collected outside the conversation, is now reachable inside the system where users enter prompts. This exposes user tracking data and creates new privacy risk. That is the position. Treat it as a change in what the platform holds, not a change in what it produces in a reply.
The relevant fact is data reach. One system now spans two data sets that were held apart: the prompts a user enters into ChatGPT, and the record of that user’s behaviour across other sites supplied through the ad collector. The identifier tied to a ChatGPT account now sits alongside the identifier tied to that user’s browsing. When two data sets are joined under one system, the exposure of the combined set is larger than the exposure of either set alone. That is a logically necessary result of the join, not a prediction.
Several conditions are not confirmed, and their absence is part of the briefing. The specific ad collector is not confirmed. The exact fields exposed are not confirmed beyond user tracking data. Whether this applies to all accounts or a subset is not confirmed. The duration, sequence, and persistence of the access are not confirmed. Absence of that data does not narrow the exposure. It means the exposure cannot yet be scoped, and unscoped exposure is treated as a live condition, not a resolved one.
The observable behaviour is direct. User tracking data describing activity on other websites is now present within ChatGPT through the ad collector integration. Data that was generated for advertising collection is reachable by a conversational AI system tied to a user account. The line between an advertising data source and the AI system is not present in this configuration. That is what is externally visible: the data crossed from one domain into the other.
What is not visible is the enforcement. Whether a control existed to prevent tracking data from reaching ChatGPT is not confirmed. If such a control was in place, its presence is not stated, so it is not confirmed. What can be stated is the outcome. The data movement occurred, and no control that blocked it is confirmed. If a system permits a data path, that path is available for use. Here the path from cross-site tracking to the conversational system is available, because the data arrived.
Stated at the boundary level, the thing that did not hold is the separation between an advertising data source and the AI. The failure is not a stored setting described as wrong. It is a data flow that ended inside a system it was not required to reach. The observable fact is the crossing itself. Everything downstream of that crossing, including how the data is retained or used, is not confirmed and is not asserted here.
The mechanism is the integration. ChatGPT was connected to an ad collector. An ad collector accumulates cross-site activity. Connecting the two creates a path from that accumulation into ChatGPT. Given the stated integration, the presence of tracking data inside the system is the necessary consequence of the connection, not a separate event that has to be explained on its own.
No additional cause is required, and none is confirmed. No attacker technique is stated, so none is confirmed. The data reached ChatGPT as a function of the connection between the two systems, not as the product of an intrusion. This is a trust decision. ChatGPT now consumes data from the ad collector, which means the source is treated as an accepted input. Once a source is accepted, its data flows by default, without a further action from the user for each transfer.
Automation carries this at the scale of the integration. Every account within the connection inherits the same data path on the same terms. Whether that reach covers all accounts is not confirmed, but within its reach the behaviour is not selective and does not depend on individual intent. Identity is the boundary, and the boundary tied to a ChatGPT account now includes cross-site behaviour attributed to that identity. That is the condition to plan against.
The mechanism is a trust decision converted into a standing data path. ChatGPT accepts the ad collector as an input. Acceptance is not a single transfer. It is a state. Once a source is accepted, the records it holds are reachable on the same terms, without a separate action from the user for each one. The failure is not that data moved on one occasion. It is that the path exists as a function of the connection. Whether that path can be closed at the account level or the field level is not confirmed.
The boundary that did not hold is identity scoped. The identifier tied to a ChatGPT account and the identifier tied to cross-site browsing are now resolvable to the same subject inside one system. That resolution is the mechanism. Two identifiers held under one system describe one identity. The join is what produces the exposure, and the join is a property of the integration. Whether the correlation occurs at ingestion or at query time is not confirmed. In either case the correlation is available, because both data sets are present in the same system.
No enforcement point between the accepted source and the conversational system is confirmed. Absence of a confirmed control means the default condition is flow. Automation sets the terms. Within the reach of the integration the behaviour is uniform, and individual intent does not gate a transfer. Whether that reach covers all accounts is not confirmed. The mechanism does not require an attacker, an error, or a misuse. It requires only the connection, which is stated. Given the connection, tracking data inside ChatGPT is the necessary result of the mechanism, not a separate outcome that has to occur.
The pattern is that accepted inputs become standing data paths. A system that treats an external source as trusted acquires what that source holds, on the source’s terms, for as long as the connection stands. Exposure is set at the point of acceptance, not at the point of use. The generalisation extends only to sources that accumulate, because accumulation is the property present in the stated mechanism. An accumulating source connected to a system delivers its accumulation into that system. That is the same mechanism, not a similar one.
The second element is the identity join. When a system holds two identifiers that resolve to the same subject, the subject’s exposure is the union of both data sets. This is not addition of two separate risks. Prompts describe content and intent. Cross-site activity describes behaviour and presence. Held apart, each set is bounded by its own domain. Held together, each set can be read against the other. The mechanism is the join, and a join under one system is not reversible by policy applied after the data sets are already present together. Presence is the condition. Statements about later handling of the joined set are not confirmed.
The third element is that scope you cannot see is scope you cannot bound. The specific collector is not confirmed. The exact fields are not confirmed beyond user tracking data. Account coverage is not confirmed. Persistence is not confirmed. Under the mechanism, unconfirmed scope does not reduce exposure. It removes the ability to measure it. A data path of unknown extent is treated as maximal until its limits are stated. Any integration that ingests an accumulating source, with no stated field level and account level boundary, holds whatever that source holds. That is the same data reach through an accepted input, applied to the general case.
State what must now be true. The separation between an advertising data source and the conversational system was not enforced, so it does not function as a control. If a control is claimed, its presence must be stated at the field level and the account level. Until it is stated, it is not confirmed, and the path is open. Identity is the boundary. The boundary tied to a ChatGPT account now includes cross-site behaviour attributed to that identity. That is the condition of the system, not a concern about it.
Name the trust decision as what it is. ChatGPT consuming ad collector data is an accepted input, and accepted inputs flow by default. A position that treats the data movement as incidental misreads the mechanism. If the system permits the path, the path is in use. The data arrived. Arrival is the evidence that the path is enforced open, and no control that enforced it closed is confirmed.
What must be established is specific. The collector. The exact fields. The account coverage. The persistence. The enforcement point, if one exists. Each is currently not confirmed, and each must be confirmed before the exposure can be scoped as anything less than maximal. Accuracy overrides completeness. The confirmed fact is single and it is enough to act on its own terms: data generated for advertising collection now sits inside the system where prompts are entered, resolvable to one identity, with no control that blocked it confirmed. Define the remainder before treating any part of it as resolved.
Keep Reading
privacyYour privacy settings are decoration.
Privacy is no longer a default state. A former black hat defines what failed, why it failed, and what operators must now assume.
privacyYour Git history is already in the cloud
ZCode transmits local Git history to the cloud with no consent prompt and no notification. A post-incident breakdown of the boundary that was never enforced.
iOS 27 securityEvery new feature makes iOS 27 less safe
iOS 27, iPadOS 27, and macOS 27 concentrate risk at one point: whether a capability re-checks identity at execution, not at the moment consent was captured.
Latest on the Wire
Full wire →- A six-step loop for building product — and why being wrong is the pointHacker News
- Apple Ships a Kill Switch for Apple Intelligence on macOS 27Hacker News
- Bryan Cantrill: Sun's fatal flaw wasn't strategy — it was boredom with the businessHacker News
- EPA Repeals Biden-Era Carbon Limits on Coal and Gas Power PlantsHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.