DictaFlow
DictaFlow Blog

AI Prompts and Ad Tracking: A Privacy Check for 2026

A research-backed checklist for keeping sensitive work out of the wrong AI prompt.

September 29, 2026

Professional using a microphone at a desk while abstract data trails leave a screen
A prompt can carry the work itself, not just a record of where you clicked.

AI prompts are not ordinary search queries. People paste contract clauses, customer problems, private notes, medical questions, code, and half-finished ideas into chat boxes. That makes a new privacy analysis of conversational AI worth reading even if you never touch an ad-supported AI plan. The practical point is simple: treat every prompt, shared link, and cookie choice as part of the work product.

What the new research found

A research team at IMDEA Networks examined the web versions of nine conversational AI services and the Android apps of eight of them. Their paper looked for third-party advertising and tracking services, then tested how consent choices, subscription tiers, privacy settings, and shared links changed the exposure of conversation data.

The headline result deserves a careful reading. The researchers found at least one third-party advertising or tracking service in every AI service they tested, and identified 44 third-party organizations across the sample. They also reported that six of nine web clients and three of eight Android clients disclosed conversation-derived material such as URLs, titles, prompts, or screenshots to third parties. Those are study findings from a defined set of tests, not a claim that every prompt on every AI product is public. Still, the distinction between a page visit and a prompt matters. A prompt can contain the actual work.

Why a prompt is a different kind of data

Web tracking has always been uncomfortable. A retailer can infer a lot from which pages you visit. A chat assistant can receive the reason you are visiting, the draft you are struggling with, and the details you did not put in an email because they felt too sensitive.

The paper's most useful idea is that AI products create conversation artifacts around the message itself. Titles, previews, share links, screenshots, and persistent identifiers can turn a supposedly private exchange into a much wider trail. That does not mean every tracker receives full prompt text. It means privacy reviews should ask what is sent, when it is sent, and what a shared URL actually exposes.

The share-link test takes two minutes

Start with the feature people forget: sharing. If an AI tool creates a public link for a conversation, open that link in a private browser window where you are not signed in. Check what a recipient can read. Then revoke the link and repeat the test. Do not assume deleting a chat title removes a preview, an old shared URL, or a screenshot already created by the product.

The research team reported that some providers exposed full conversations through publicly accessible permalinks without access controls. That is a sharp reminder to use a shared link like an attachment, not like an internal bookmark. If it contains a client name, a patient detail, a personnel issue, source material under embargo, or a secret, do not send it until you have checked the exact access behavior.

Cookie banners are not cosmetic

Many people click through cookie choices because the task is waiting. The study found that consent choices changed which third-party services became active in some of the tested products. A paid plan or a privacy toggle may change the picture too, but neither is a substitute for reading the current product controls.

For work accounts, the useful rule is boring and effective: decline non-essential tracking when the service offers that choice, avoid putting sensitive material in a consumer chat by default, and review the vendor's current privacy and sharing controls before rolling it out to a team. A policy written last year is not proof of what the app sends today.

Voice input needs the same boundary

Voice makes it easier to give an assistant real context. You can explain the exception, the decision, and the tone you need faster than you can type it. That is useful. It also makes it easier to say something sensitive before you have decided whether the destination deserves it.

A safer habit is to capture the thought in an editable text field first, then decide what actually belongs in the AI request. Hold-to-talk dictation is good for this because recording starts and stops on purpose. You can dictate a rough brief, remove names and account details, and only then paste a smaller, cleaner request into the tool you chose. DictaFlow is built around that editable hold-to-talk step, and its privacy policy is where its own data practices should be evaluated.

Use a smaller prompt when the stakes are high

This is not an argument for never using AI at work. It is an argument for separating the task from the identifying details. Ask for an outline structure instead of pasting the whole contract. Replace a customer's name with a role. Use a made-up example to test a workflow. Keep protected records out of a general-purpose consumer tool unless your organization has approved that exact processing path.

The best test is simple: if this exact prompt appeared in a browser history, a shared URL, a screenshot, or a third-party event log, would it cause a real problem? If yes, change the prompt, change the tool, or keep the work outside that system.

Do the privacy check before the next urgent request

The paper drew attention on Hacker News because it gave a concrete shape to a vague worry. The discussion was not just about ads. It was about the awkward fact that chat tools now sit close to drafts, decisions, source files, and private questions.

Do one quick audit this week. Open your most-used AI tool, review its sharing controls, inspect its cookie choices, and look for whether it offers a work-approved option for sensitive material. Then keep your voice workflow honest: speak freely into your own editable draft, but treat the final AI prompt as something you are deliberately choosing to disclose.

Sources

[1] Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents

[2] Hacker News discussion: AI companies leak data to advertisers