All Insights

OpenAI's Ad Tracker Is Following Your Customers. You Might Have Invited It In.

CivSafe Team·September 21, 2026·5 min read

A security researcher published a detailed teardown on September 20 showing that ChatGPT's advertising infrastructure sets a cross-site tracking cookie that follows users to third-party websites — including while they're logged out — and keeps doing so even after users explicitly disable ad tracking in their settings.

The story hit 555 points on Hacker News this morning. Most of the discussion is about OpenAI's privacy practices. The thing your org should actually be thinking about is a bit more specific: if you ran ads on ChatGPT at any point, you may have a pixel installed on your website that's participating in this right now without you knowing.

What the cookie does

The mechanism is named __obi, served from bzr.openai.com. It's configured with SameSite=None; Secure — the specific flag that allows a cookie to follow cross-site requests. When a user visits a website that has OpenAI's ad tracking pixel installed, the cookie fires back to OpenAI with information about the page the user is on: what they're browsing, what they searched for, what they put in a cart.

That data gets linked to the user's ChatGPT account. If you've ever opened ChatGPT in the same browser, OpenAI can associate your browsing history on advertiser sites with your ChatGPT identity.

The part that's generating the most anger: the cookie is classified as "Data Analysis", not "Advertising." That means even if a user goes into their settings and disables ad tracking — which many privacy-conscious users do — this cookie keeps running. OpenAI did not disclose this classification to advertisers or to users, and it took an independent researcher doing network traffic analysis to surface it.

Safari blocks cross-site cookies by default, so Apple users aren't affected. Chrome users are.

Why this matters specifically for small orgs

Two scenarios where this lands on you directly.

Scenario one: you tried ChatGPT ads. OpenAI launched an advertising product earlier this year. A lot of small orgs — including nonprofits running digital fundraising and small businesses testing new acquisition channels — ran campaigns. To do that, you installed a small piece of tracking code on your website. That code is the OpenAI ad pixel. If you installed it, it may still be there.

If you're in Canada, the EU, or anywhere with meaningful privacy law: that pixel, tracking your visitors and linking their behavior to their ChatGPT accounts, may be a compliance problem. PIPEDA requires consent for this kind of cross-site tracking. GDPR is even more explicit. You consented to install the pixel for ad attribution. You did not consent to enabling OpenAI to build behavioral profiles of your visitors — and your visitors certainly didn't.

Scenario two: your employees use ChatGPT. This is almost every org. If your staff uses ChatGPT in their work browser and they also visit advertiser sites in that same browser — supplier portals, news sites, product research — OpenAI can now build a detailed picture of their browsing behavior outside of ChatGPT.

For most orgs this is a privacy issue, not a catastrophic security breach. But for a nonprofit doing sensitive work, a law office, a government team handling procurement — the idea that their staff's research browsing is being silently aggregated by a third party is worth thinking about.

The opt-out problem

The most uncomfortable part of the disclosure isn't the tracking itself — ad pixels have been everywhere for twenty years. It's the opt-out that doesn't work.

OpenAI offers a setting to disable "personalization based on your browsing." But because __obi is classified as Data Analysis rather than Advertising, disabling ad personalization doesn't stop it. You'd have to block the cookie at the network level or use a browser that does it automatically (Safari, Brave, Firefox with the right settings).

This is the kind of thing that tends to surface in regulatory complaints, not press releases. The disclosure went to OpenAI's press and privacy email on September 14. It was published publicly yesterday after no response.

What to actually do

Check your website for the OpenAI pixel. Open your site in a browser with developer tools. Look for requests going to bzr.openai.com in the network tab. Or search your website's code for any script from OpenAI's advertising docs. If you ran a ChatGPT ad campaign, there's a real chance this is still loading.

If you find it and aren't actively running campaigns: remove it. There's no benefit to you in leaving it installed. Any historical conversion tracking it was doing doesn't justify continued cross-site collection on your visitors.

Update your privacy policy if needed. If you installed the pixel and your privacy policy doesn't disclose behavioral tracking by OpenAI, that's a gap. Especially if you have users in Canada or the EU.

For employee browsing on Chrome: The easiest mitigation is running ChatGPT in a separate browser profile from everything else. Browsers keep cookies per-profile. If your ChatGPT work happens in a dedicated profile, __obi can't link it to browsing in your main profile. Takes about five minutes to set up.

The bigger picture

This is what the fast adoption cycle looks like from the other side. Your org tried a new tool, installed the integration code it asked for, and moved on. Six months later you find out that integration has been doing something you didn't intend and possibly didn't disclose to your users.

We're seeing this pattern constantly — not because small orgs are careless, but because the onboarding flows for these tools are designed to get the pixel installed quickly, not to explain what the pixel does.

The fix here is straightforward. The habit worth building is: before any tool asks you to install a pixel or tracking snippet, spend ten minutes understanding what it's actually sending and where.


Auditing what your AI tools are actually doing is part of what we help orgs with during a sprint. If you want a quick look at what's running on your site or in your team's tooling, get in touch.

CivSafe — Strategic Innovation. Community Impact.