Commenters warned that many AI chat services are exposing conversation-derived artifacts to third parties and ad networks. Examples offered include browsers sending unfinished prompts to a prepare endpoint (pbasista), services exposing full conversations via UUID-based URLs (postalcoder, postalcoder), permalinks without access controls and screenshots being shared with apps like TikTok (damaru2, Coeur). Several argued this effectively hands advertisers a labeled, cookie-keyed intent signal (vivekpolavarapu, vivekpolavarapu), and that conversation titles, prompts and generated summaries tied to persistent identifiers can reveal sensitive facts (Coeur). Others pointed to lax link-sharing designs, preloads and URL handling as routes for broad indexing and leakage (albert_e, charcircuit).
Opinion splits on cause and remedy. Some said this is deliberate business-as-usual - data sold, not leaked - and that ad tech’s incentives drove it (DrMandalay, drywater2, 20k), while others think much of it is accidental poor engineering and rushed implementations (mrweasel, Traster, amarcheschi). Proposed responses include running local or open-weight models and self-hosted interfaces to preserve privacy (kdaniel_03, lukehandcool, 0xcrypto), poisoning histories or defensive tooling (zug_zug), and legal or regulatory pushback against ad-based surveillance (Razengan, maybewhenthesun). Deep concerns about real-world tracking and loss of freedom from cloud AI use were also voiced (segmondy).
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.