Fast Facts
- A security researcher found that OpenAI runs a ChatGPT tracking cookie, called __obi, that follows users from ChatGPT onto ordinary websites like Chewy, Wayfair, and HelloFresh, then reports what they did there back to their ChatGPT account.
- The mechanism only works on Chrome for Android — Safari and Chrome on iOS block it outright — and it fires in roughly one of every five ChatGPT sessions.
- OpenAI’s own cookie policy lists the tracker under “Analytics,” not “Marketing,” so users who opt out of marketing tracking may still get it as long as analytics consent is on.
- OpenAI acknowledged the researcher’s findings on September 14 but hasn’t answered whether the classification is accurate or whether declining marketing consent actually stops it.
A security researcher published a technical teardown this week of a ChatGPT tracking cookie that does something OpenAI’s own policy doesn’t fully disclose: it follows users off ChatGPT and onto the websites of companies that advertise on the platform, then reports what they did there back to OpenAI. The finding, published by researcher Buchodi on September 20, climbed toward the top of Hacker News within hours, and reopened a familiar data privacy question — how far cross-site tracking and third-party cookies have quietly spread from ordinary ad tech into AI chat products.
How the ChatGPT Tracking Cookie Actually Works
The mechanism runs in three steps. ChatGPT generates a random 16-byte identifier and gets it signed into a short-lived token tied to the user’s account. That token is exchanged, cross-site, for a cookie called __obi, set with the exact configuration — SameSite=None, Secure, valid for a year — that browsers require before a cookie can travel to other domains. From there, any company that has installed OpenAI’s advertising pixel, the same way retailers already run Meta or Google tracking code, sends __obi back to OpenAI whenever a user loads that company’s page.
What Actually Gets Collected
Buchodi tested the mechanism across a dozen commercial sites, including Chewy, Wayfair, ThriftBooks, Eventbrite, HelloFresh, Coursera, and SeatGeek, and confirmed the identifier reaching OpenAI’s servers from all of them. The pixel doesn’t just relay what a merchant chooses to share — it scrapes form fields and page text directly, and in the traffic Buchodi observed, scraped data outnumbered merchant-supplied data by more than two to one. Email, phone numbers, and names get hashed before transmission; location data — country, region, city, and postal code — does not, and postal code was the single most frequently harvested field.
📊 The Numbers That Matter
- __obi — the cookie name, valid for 1 year, the only OpenAI identifier configured to travel cross-site
- ~1 in 5 — ChatGPT sessions that actually generate a tracking sync token
- 12+ — commercial sites confirmed sending the cookie back to OpenAI in testing
- 685 to 255 — ratio of scraped identity data to merchant-supplied data in observed traffic
- Sept 14, 2026 — date OpenAI was notified about the ChatGPT tracking cookie; still unanswered as of publication
“What has no precedent is running it on an AI chat product.”— Buchodi, independent security researcher
Who’s Actually Exposed
The mechanism behind the ChatGPT tracking cookie has real limits. It has only been observed on Chrome for Android — Safari’s tracking protections block it outright, and Chrome on iOS runs on Apple’s WebKit engine, so it’s blocked there too; desktop Chrome hasn’t been tested. It doesn’t fire on every visit either: roughly one in five ChatGPT sessions generates a sync token, and the mobile web version of ChatGPT doesn’t trigger it at all. It also works while logged out — an anonymous version of the identifier persists on a device for at least 27 days, tied to the browser rather than an account.
What OpenAI Has (and Hasn’t) Said
Buchodi sent the findings to OpenAI’s press and privacy teams on September 14, asking why the cookie is classified as analytics rather than marketing, and whether opting out of marketing tracking actually stops it. OpenAI Support acknowledged the message and said it would be reviewed internally; as of publication, neither question has been answered. That silence matters more than it would for a typical ad-tech disclosure — see our analysis where we explain how OpenAI’s rogue AI hack already raised procurement risk questions the company hasn’t fully closed, making the ChatGPT tracking cookie the second unresolved trust gap in as many months.
The Procurement Read
None of this requires a new regulation to matter today. Any team embedding ChatGPT, GPT-based copilots, or third-party agents built on OpenAI’s models into a customer-facing product should be asking the same two questions Buchodi asked and got no answer to. See our analysis where we explain how the EU AI Act’s €7 fine already made silence like this expensive for AI agent vendors operating in Europe, and how agentic AI governance is failing to keep pace with a 140-to-1 identity problem that a cross-site tracking cookie only adds to.
This wouldn’t be the first time a widely deployed AI product leaked more than its vendor disclosed — see our analysis of the AI notetaker breach that exposed 181,874 meetings for six silent months before anyone noticed. Vendor risk assessments written before generative AI companies started running ad businesses need a line item for exactly this — see our analysis of the five costly AI agent security blind spots no one is fixing in 2026, where consent boundaries kept failing in places procurement teams weren’t looking.
How the ChatGPT Tracking Cookie Fits the Bigger Ad-Tech Picture
Cross-site tracking and third-party cookies aren’t new — Meta and Google have run similar ad tracking pixel mechanisms for conversion tracking for years, and both have faced GDPR and CCPA scrutiny over exactly this kind of data privacy practice. What makes the ChatGPT tracking cookie different is the platform it’s attached to: an AI chatbot people use for medical questions, financial planning, and personal advice, not a search engine or social feed.
Regulators evaluating AI vendor risk and enterprise AI privacy compliance in 2026 are increasingly applying the same cross-site tracking standards to chatbot cookies that already govern Meta’s pixel or Google’s conversion tracking — which means OpenAI’s cookie policy is about to get read a lot more closely than it has been.
Quick Questions
What is the __obi cookie?
The technical name for the ChatGPT tracking cookie — an identifier OpenAI sets on ChatGPT that’s configured to travel to other websites, letting OpenAI connect a user’s activity on those sites back to their ChatGPT account.
Does the ChatGPT tracking cookie affect iPhone users?
No — it has only been observed on Chrome for Android. Safari’s tracking protections and Chrome on iOS, which runs on Apple’s WebKit engine, block the mechanism outright.
Can I opt out of it?
OpenAI classifies it under analytics consent rather than marketing consent, so declining marketing tracking alone may not stop it — the company hasn’t confirmed either way.
Is the ChatGPT tracking cookie legal under GDPR or CCPA?
It likely falls under existing cross-site tracking and third-party cookie rules in both frameworks, but no regulator has issued a specific ruling on the ChatGPT tracking cookie yet — exactly the kind of enforcement gap AI vendor risk teams should be watching.
💡 CreedTec Analyst’s Note by Daniel Ikechukwu
Strategic Impact: The ChatGPT tracking cookie is a reminder that generative AI vendors are increasingly also ad businesses, and their advertising infrastructure inherits the same trust and data-handling expectations as their core product — expectations most enterprise buyers haven’t updated their vendor questionnaires to cover.
Stop
- Assuming a generative AI vendor’s ad or analytics infrastructure carries the same privacy guarantees as its core chat product.
Start
- Adding a specific question to vendor risk assessments about cross-site tracking cookies for any AI product with an advertising or pixel-based business line.
Watch
- Whether OpenAI answers Buchodi’s two questions, or reclassifies the cookie, before regulators in the EU or California do it for them.
ROI Outlook: There’s no direct cost to this today for most readers, but the exposure is real for any company running ChatGPT-based tools on a customer-facing surface — the ChatGPT tracking cookie is exactly the kind of undisclosed cross-site tracker that turns into a compliance audit later.
— Daniel Ikechukwu
Sources
- Buchodi’s Threat Intel — ChatGPT Now Knows What You Do on Other Websites via Ad Collector
- OpenAI — Cookie Policy
- 36Kr — Developers Confirm OpenAI Ads Collect Cross-Site User Behavioral Data
- KuCoin News — OpenAI ChatGPT Tracks User Activity Across Websites via Cookie
- 36Kr — OpenAI Exposed: ChatGPT Can Track Your Purchases on Other Websites


