Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

ChatGPT now tracks what you do on other websites through ad-collector cookie

OpenAI's ChatGPT tracks users via an ad-collector cookie called __obi, harvesting email, hashed names, and locations across websites.

By mitch·4 min read
A web browser window with a magnifying glass and tracking cookie symbol glowing with data streams.

OpenAI’s ChatGPT now tracks what you do on other websites through an ad-collector cookie called __obi, a new discovery that has drawn fresh attention to how the company gathers data on its users. The cookie links a visitor’s browsing history to their ChatGPT account, and it carries sensitive details including email addresses, hashed names, and locations.

The cookie’s name tells part of the story: __obi.

When set, it is scoped to .openai.com and tied to a user’s ChatGPT account. A company that buys ads on ChatGPT installs OpenAI code on its own site. That code sends the cookie to OpenAI along with browsing data as users move from page to page.

Advertisement

How the Cookie Travels

The cookie value is tied to a user’s ChatGPT account, and it travels to OpenAI with every visit to a site that runs it. Data sent includes products searched, articles read, and purchase behaviors. Verified with two independent capture methods across 936 advertiser pixels, 1,029 hostnames, the cookie’s reach is broad.

JWT is signed with RS256, issuer is “chatgpt-wadi”, audience is “bzr.openai.com”. JWT expires 60 seconds after issuance. POST /backend-api/bazaar/obi/sync-token or /backend-anon/ generates token. POST to bzr.openai.com/v1/obi/sync sets the cookie.

The cookie itself is HttpOnly, Max-Age=31536000, SameSite=none, Secure. That combination means it can be read by the server but not by the browser’s code, and it follows requests across sites. The data inside it is not encrypted end to end.

Set-Cookie: __obi=«redacted»; Domain=.openai.com; HttpOnly; Max-Age=31536000; Path=/; SameSite=none; Secure

Data from web pages is harvested through script loads, including Google Tag Manager and Facebook’s own services. Email, phone, names are hashed with SHA-256. Country, region, city are sent in clear text. Postal code is harvested most, 100 events across 28 sites.

The source material shows a system designed to follow a user’s movements across the web. The cookie is placed on a visitor’s browser before any OpenAI code runs, meaning tracking begins before the user can stop it.

What the Data Reveals

The capture methods tracked 936 advertiser pixels across 1,029 hostnames, a large sample that gives the findings real weight. The JWT signature, issuer, and audience details confirm the cookie’s source.

Capture method Data gathered
Independent capture 936 advertiser pixels
1,029 hostnames verified 1,029 hostnames
JWT signature RS256, issuer “chatgpt-wadi”, audience “bzr.openai.com”
JWT expiration 60 seconds
POST endpoints /backend-api/bazaar/obi/sync-token, /backend-anon/
Cookie settings HttpOnly, SameSite=none, Secure

12 of 30 distinct __obi values appeared under multiple advertisers. That means the cookie is not unique to a single site; it follows a user across many. The source material shows a system designed to follow a user’s movements across the web.

What OpenAI Says

OpenAI cookie policy lists __obi under Analytics cookies on chatgpt.com and openai.com. The policy describes analytics cookies as helping understand service performance and use.

OpenAI runs analytics and marketing as separate consent choices: oai_consent_analytics and oai_consent_marketing. Every decoded token carried consent_decision: analytics_allowed. That means a user who grants analytics consent is tracked, even if they refuse marketing.

The disclosure of identifiers via script loads means the cookie is sent before any OpenAI code runs, meaning the tracking happens before the user can stop it.

The paper’s own view is clear: the cookie is a privacy problem that OpenAI has not yet answered.

A question was sent to press@openai.com and privacy@openai.com on 14 September. The reply came from OpenAI Support, acknowledged the inquiry, and said observations would be shared for review. That is an acknowledgment, not an answer.

Where the paper stands

The paper backs the citizens and local groups pushing back against mass tracking, and is against camera networks, data dragnets and the vendors lobbying to keep them. OpenAI’s __obi cookie is far beyond those limits. It follows a user’s movements across the web, gathers hashed names and clear text locations, and travels to OpenAI with every visit to a site that runs it.

The cookie is placed on a visitor’s browser before any OpenAI code runs, meaning tracking begins before the user can stop it. The company’s cookie policy treats this as analytics, but the data gathered goes far beyond service performance.

OpenAI has acknowledged the inquiry but offered no answer. The paper wants OpenAI to say plainly what data the cookie gathers, where it goes, and how long it stays. The company should also explain how a user who grants analytics consent can refuse it later, and how the cookie is removed when consent is withdrawn.

Source material: “ChatGPT now knows what you do on other websites via ad collector,” buchodi.com.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.