You open ChatGPT, have a conversation, then close the tab and move on.
But a recent investigation found that something from ChatGPT may not stay behind when you leave.
An independent researcher found an OpenAI cookie called __obi being sent from websites that use OpenAI’s advertising technology back to OpenAI. The cookie can persist for up to a year and the requests can include information about the pages you’re visiting.
That doesn’t mean OpenAI has been proven to see everything you do online or connect every visit directly to your ChatGPT account. The researcher could observe the identifier being sent back to OpenAI, but not the final server-side step that would confirm that account-level connection.
Still, the discovery raises a question.
What happens when an AI assistant that people use for deeply personal questions also becomes part of an advertising system that can observe activity beyond the chat?
Table of Contents
The Cookie That Shows Up Outside ChatGPT
The investigation started with a small piece of code, a cookie called __obi.
Independent cybersecurity researcher Buchodi found the identifier being used across websites that had OpenAI’s advertising technology installed. When someone visits one of those sites, information about that visit can be sent back to OpenAI.
The researcher found the mechanism across hundreds of advertiser pixels and more than a thousand hostnames, showing that this wasn’t limited to a single website or an isolated test.
OpenAI’s own cookie policy lists __obi as an analytics cookie with a one-year lifespan.
The important part is what this means in practice.
A cookie like this can give an advertising system a way to recognize activity across websites. It doesn’t automatically tell OpenAI who you are or prove that every visit is connected to your ChatGPT account.
But it creates the technical infrastructure for activity outside ChatGPT to become part of OpenAI’s analytics and advertising ecosystem.
So What Does It Actually Track?
When a site uses OpenAI’s advertising technology, the __obi identifier can be sent along with information about activity on that site. That can include the page being visited and other signals used for analytics or advertising.
What the public research does not establish is that OpenAI can automatically connect all of that activity to a specific person’s ChatGPT account.
That difference matters.
A tracking identifier can exist across websites without proving that the company operating it has built a complete record of an individual user’s browsing history.
What researchers found is the mechanism that makes that kind of data collection possible.
The unanswered part is how OpenAI ultimately uses the information it receives and whether activity from those sites is actually joined with individual ChatGPT users.
The Part That Makes This Different
Web tracking isn’t new.
Google, Meta and countless other advertising systems already collect signals about what people do across the web.
What makes ChatGPT different is the kind of relationship people have with it.
People don’t just visit ChatGPT to read something. They tell it what they’re researching, what they’re buying, what they’re working on and sometimes things they wouldn’t share publicly anywhere else.
That makes the idea of advertising around an AI assistant more complicated.
The same product that has access to what you voluntarily tell it is now connected to technology that can also collect signals from activity outside the chat.
And that creates a boundary that wasn’t really there with a normal website.
When does the ChatGPT experience actually end?
Closing the chat might end the conversation. But if OpenAI’s advertising technology is also present elsewhere on the web, the relationship between the user and the product doesn’t necessarily stop at the edge of that chat window.
What Can You Actually Do About It?
You can’t control every website you visit or every cookie it asks your browser to accept.
But you can control how much information you leave behind.
The easiest place to start is your browser. Use its privacy controls to limit cookies and tracking where possible, clear stored data regularly and consider a browser that gives you stronger protection against cross-site tracking. Just remember that blocking everything can also break parts of some websites.
Beyond that, the simplest rule is to share less.
Don’t put personal information online that you wouldn’t be comfortable becoming public. Treat your passwords and other credentials as if they are irreplaceable. Use strong, unique passwords and a password manager rather than reusing the same credentials everywhere.
You can also separate your online identity. Your primary email doesn’t need to be the address you use for every website you try. Keep it for services you genuinely trust and use separate addresses for newsletters, shopping, forums and sites you don’t expect to use regularly.
None of this makes you invisible online.
That’s not really possible anymore.
But privacy doesn’t have to be all or nothing. Every piece of information you choose not to share, every account you don’t connect and every tracker you prevent from following you is one less piece of your digital footprint sitting somewhere on the internet.
And in a web where more services are trying to understand what we do, leaving a smaller footprint is one of the few parts of privacy we can still control.




