ChatGPT’s __obi Cookie May Be Tracking You Beyond Its Site

OpenAI’s __obi Cookie Raises New Privacy Questions Around ChatGPT Ads

OpenAI’s advertising system is drawing fresh attention after researchers found that a browser cookie tied to ChatGPT can be sent back to OpenAI when users visit certain third-party websites. The cookie, named __obi, can remain in a browser for up to one year and appears to be connected to a user’s ChatGPT account.

The issue centers on how the cookie behaves outside OpenAI’s own websites. When a person visits a site that uses OpenAI’s ad measurement tools, the browser may send the __obi identifier back to OpenAI along with information related to the page being viewed. That could include details about shopping activity, forms, or the type of content someone is reading.

A security researcher published findings on Sept. 20 after testing the mechanism, including on a mobile device. The discovery adds to growing concerns about ChatGPT ads, online tracking, and how much information can move between websites through advertising pixels.

Why the __obi cookie matters

OpenAI identifies __obi in its cookie policy as an analytics cookie with a one-year lifespan. What makes it stand out is that it is reportedly the only OpenAI cookie in that category configured with SameSite=None.

That setting is important because it allows a browser to include the cookie in requests made from other websites. In simple terms, it makes it possible for the cookie to travel beyond OpenAI’s own domain when a third-party site loads OpenAI’s advertising or measurement technology.

During testing, other OpenAI cookies were blocked in this cross-site context, while __obi was still sent. That makes the cookie especially significant for anyone concerned about third-party tracking and ChatGPT-related advertising.

How OpenAI’s ad measurement pixel works

Advertisers can place a small script on their websites known as a measurement pixel. OpenAI documents this tool as part of its advertising measurement system. When loaded on a participating website, the pixel reports activity back to OpenAI’s servers.

In one reported example, the pixel was found active on a major retail website on Sept. 21. When the browser developer console was used, OpenAI’s tracking function appeared to be present on the page.

OpenAI ads have already expanded into Europe, including Germany and dozens of other markets. They are shown to users on Free and Go accounts, while paid subscriptions remove ads.

The privacy concern is not simply that ads exist. The concern is that a persistent identifier linked to ChatGPT may be sent back to OpenAI when users browse external websites that use the company’s measurement tools.

What data may be collected

According to the analysis, OpenAI’s pixel can detect customer information from pages where it is installed. OpenAI describes this as automatic advanced matching, meaning the tool can identify supported customer data without the advertiser manually sending each field.

Some types of data, such as email addresses, phone numbers, and names, are hashed in the browser before being transmitted. Hashing is intended to obscure the original value, although it does not always eliminate privacy concerns entirely.

Other location-related fields, such as country, region, city, and postal code, were listed as being sent without hashing. In the reported testing, postal codes appeared frequently, with 100 events observed across 28 websites.

The research also found that data automatically detected by the pixel appeared more often than data deliberately passed by advertisers. The reported numbers were 685 automatically scraped events compared with 255 intentionally provided events.

Some URLs also revealed sensitive context through page paths. While query strings after a question mark were not included, the remaining paths still sometimes contained meaningful details, including references to medical conditions, debt-relief pages, and legal intake forms.

OpenAI does maintain a denylist designed to block certain sensitive fields, including passwords, one-time codes, card numbers, birth dates, diagnoses, and court records. However, the findings suggest that the protection may not prevent all sensitive context from being transmitted, especially when meaningful information appears in page paths or location fields.

What OpenAI has said

OpenAI has stated that it keeps conversations private from advertisers and does not sell customer data. Those statements are not directly contradicted by this tracking behavior because the data flow described in the research works in the opposite direction.

Advertisers cannot read the __obi cookie themselves because it belongs to OpenAI’s domain. The cookie is not directly available to third-party website scripts. Instead, the browser sends the identifier back to OpenAI when the measurement pixel is loaded.

That distinction matters. The concern is not that advertisers can access private ChatGPT identifiers, but that OpenAI may receive browsing-related events from advertiser websites and associate them with a persistent identifier.

The researcher reportedly asked OpenAI why an advertising-related identifier was categorized under analytics and how the company handles the data. The response from support did not answer those questions directly.

Important limits to the findings

The testing was conducted using Chrome on Android, so the results may not apply equally to every browser or device.

On iPhone and iPad, all browsers are required to use WebKit, which includes tracking protection that blocks many third-party cookies. As a result, this specific mechanism may not work the same way on Apple mobile devices.

The analysis also found that only about one in five ChatGPT sessions produced the identifier. That means the behavior may not affect every user in the same way.

Another important point is that the research did not directly observe OpenAI linking incoming events to a specific user account on its servers. However, the cookie’s design and account connection raise reasonable questions about whether such matching is technically possible.

How users can reduce tracking

The most effective protection is to block third-party cookies in the browser. If third-party cookies are blocked, the __obi cookie cannot travel in the same way to other websites using OpenAI’s measurement pixel.

Users can also review OpenAI’s cookie settings through the Manage cookies button found on OpenAI pages. The __obi cookie appears under analytics. However, refusing marketing cookies alone may not be enough, because the identifier was reportedly tied to analytics consent rather than marketing consent.

Clearing cookies for openai.com can reset the identifier, but a new one may be created on the next visit. Signing out of ChatGPT may not fully solve the issue either, since some identifiers were found in anonymous sessions and remained stable for at least 27 days.

For users who want stronger privacy, the best steps are:

Block third-party cookies in the browser.

Regularly clear cookies for OpenAI sites.

Use browser privacy protections that limit cross-site tracking.

Review cookie consent settings carefully.

Consider using a paid ChatGPT plan if avoiding ads inside ChatGPT is important.

The bigger privacy question

The discovery of the __obi cookie highlights a larger issue in modern advertising: the line between analytics, ad measurement, and user tracking is increasingly difficult to see.

OpenAI’s move into ads creates new privacy questions because ChatGPT is not just another website. Many people use it for personal, professional, educational, and sensitive conversations. Even if chat conversations are not shared with advertisers, users may still be uncomfortable with a ChatGPT-linked identifier appearing in the broader advertising ecosystem.

As AI platforms become more deeply connected with online advertising, transparency will be essential. Users need clear explanations of what is collected, how long identifiers last, whether browsing events are connected to accounts, and how to opt out effectively.

For now, anyone concerned about OpenAI tracking, ChatGPT ads, or third-party cookies should check their browser settings. Blocking third-party cookies remains the simplest and strongest way to stop this particular cookie from following activity across participating websites.