ChatGPT's ad collector lets OpenAI see what you do on other websites
ChatGPT now knows what you do on other websites via ad collector
Security researcher Buchodi reverse-engineered OpenAI's ad tracking: ChatGPT sets a cross-site cookie `__obi` scoped to .openai.com with a one-year expiry. When you later visit advertiser sites like Chewy, HelloFresh, or Coursera, that cookie is sent back to OpenAI along with the page path. The SDK also scrapes email, phone, and name from the page, hashes them, and sends them; city and postal code go in the clear. OpenAI labels `__obi` an analytics cookie, but its SameSite=None config is built for cross-site tracking. The mechanism fires even if you allow analytics consent but deny marketing. OpenAI acknowledged the inquiry but did not answer the classification or consent questions. The technical reproduction and packet captures are solid—I'd flag the analytics-consent gap as the sharpest point.
Why it matters: A security researcher reverse-engineered OpenAI's full ad-tracking pipeline with 936 verified advertiser pixels. The privacy-vs-monetization tension is the central conflict in AI product commercialization right now, and this piece delivers the evidence chain. Held back from 90...