Tuesday Sep 22

ChatGPT's Ad Cookie Follows You Off-Site

22SEP
936 PIXELSOPENAIYOU

A researcher pulled apart ChatGPT's ads and found a one-year tracking cookie. It rides along when you visit Chewy, Wayfair, or HelloFresh. Refusing marketing consent does not stop it.

ChatGPT mints an ID, signs it, and posts it to an OpenAI server that sets the __obi cookie. Advertiser sites load an OpenAI pixel, and the cookie comes with it.

The pixel reads hashed email, phone, and name from site data layers. City and postal code go in plaintext. Page paths include medical and legal intake forms.

OpenAI labels the cookie analytics, so consent banners never block it. Safari blocks it by default. Android Chrome does not. OpenAI acknowledged the report and said nothing else.

full brief & sources

⚡ Why this matters

  • OpenAI spent two years saying it was not an ad company. This is the exact plumbing Meta and Google built. The neutrality pitch is over.
  • Classifying a cross-site ad identifier as analytics is the move regulators in the EU have punished before.
  • Everyone building on ChatGPT ads inherits this consent risk on their own sites.

🔍 What happened

  • Independent researcher Buchodi published the teardown on September 20. It hit the top of Hacker News with over 300 comments. Cybersecurity News and Tbreak confirmed the mechanics on September 21.
  • ChatGPT creates a 16-byte ID, binds it to the account in a signed JWT, and posts it to bzr.openai.com. That server sets __obi on .openai.com with SameSite=None and a one-year expiry.
  • The cookie is sent whenever a site loads OpenAI's ad pixel. The researcher found the pixel on 12 commercial sites including Chewy, Wayfair, HelloFresh, and Coursera, across 936 pixels and 1,029 hostnames.
  • The pixel scrapes dataLayer, Adobe, and GTM variables: hashed email, phone, and name, plus city and postal code in plaintext, plus full page paths.
  • It works logged out. The ID stayed stable for 27 days. All 932 decoded tokens carried analytics_allowed, so users who refused marketing consent still got it.
  • Disclosed to OpenAI on September 14. OpenAI acknowledged the inquiry and has not given a detailed response.

💬 Smart takes

  • Buchodi, the researcher: the cookie behaves as an ad identifier wearing an analytics label, and the consent flag is the part that should worry lawyers.
  • Hacker News consensus: nothing here is technically new. The Meta Pixel does the same. The news is that OpenAI joined the club quietly.
  • Skeptic: OpenAI may argue the pixel is for conversion measurement, which many EU regulators still treat as marketing. That argument has lost before.

🧭 Where this goes

  1. LikelyOpenAI reclassifies __obi as marketing and ships a consent toggle within weeks.
  2. Likelyat least one EU data protection authority opens an inquiry before year end.
  3. PossibleApple adds ChatGPT's pixel to the Safari tracker blocklist by name, and Google follows in Chrome.
  4. Wild Carda publisher lawsuit argues ChatGPT ads now use publisher first-party data without a contract.

🥄 The Spoon Take

OpenAI didn't invent this. It copied it. That is the story. The company that said ads would ruin the product now runs the same pixel-and-cookie machine as Meta, plus a consent label that dodges the banner. If you run ChatGPT ads, your privacy policy just changed and nobody told you.

🤔 Pushback

Every ad platform does this, and the researcher found no evidence the data is used beyond conversion tracking yet.