Jorge Garcia Herrero's 'Prompt like a butterfly, sting like a tracker' paper claims AI companies leak users' conversation data to advertisers; a named-vendor acknowledgment, fix, or credible refutation decides whether prompt-derived advertising leakage becomes an established privacy failure of deployed chatbots.
state: watchingheat: mediumuncertainty: highconvergesscott: highai-privacy prompt-leakage agentic-securityJorge Garcia Herrero
Surfaced 2026-09-30T13:43:48Z — Original public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in — The front-page burst has decayed into a single-thread long tail of speculative and tangential commentary (ChatGPT keystreaming, Perplexity UUID URLs) — no vendor acknowledgment, fix, refutation, or independent replication has landed, so the claim remains single-sourced pending the vendor-response window. Cooled despite the magnitude-valve reading because the loud signal reflects the expired HN burst (now 0/h, 8th percentile) and the periphery stopped expanding at two objects; a vendor response would re-fire sensors on its own. Provenance upgrade from last cycle (accepted IMDEA manuscript, named co-authors) is what justifies seed → watching rather than any new fact this look.
What is this?
Per the case, Jorge Garcia Herrero's self-published paper 'Prompt like a butterfly, sting like a tracker' — surfaced on HN as 'AI companies leak data to advertisers' — claims that deployed chatbot vendors expose users' conversation data to advertising infrastructure, with the open question being whether a named vendor acknowledges, fixes, or credibly refutes it. Caution: none of the supplied snippets actually surface the paper, its author, or its evidence; they establish only the surrounding territory — chatbots converging with advertising (research demos of embedded personalized ads, OpenAI reportedly rolling ads into ChatGPT while denying that ad placement alters replies), prompt/system-prompt leakage codified as OWASP LLM01/LLM07, and expert 'signal leakage' warnings about prompt data. The claim's specific mechanism, affected vendors, and evidence quality therefore cannot be confirmed from this material — which is exactly what the vendor-response window this case is watching should resolve.
Why it matters to Scott
If the claim survives verification, this documents the advertiser as the chatbot's actual secondary principal — dated receipts for his shadow-principal/fiduciary-agent argument and the strongest real-world instance yet of the prompt-to-advertiser exfiltration class his containment and privacy-tokenization architectures exist to stop. The grounding could not surface the paper's evidence or named vendors, so treat the vendor-response window as the decision point rather than the claim as established.
ip:concept.shadow-principalip:concept.fiduciary-agentip:concept.architectural-containmentdev:concept.privacy-tokenized-agent-boundaryradar:concept.ai-privacyradar:concept.ai-monetizationradar:openai-chatgpt-ads-global-rolloutradar:chatgpt-free-go-adsradar:anthropic-claude-tracker-privacy
queries asked of Scott's wikis
- chatbot advertising monetization incentives user profiling
- third-party tracker telemetry in LLM client apps data exfiltration
- local inference privacy advantage over hosted chatbots
- agent memory conversation retention privacy design
- prompt injection exfiltration defenses harness
- chatbot vendor data handling defaults retention opt-out
Measured heat
now 0 pts/hpeak 106 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 3866h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
| 05-03 14:00 | ⭐ origin echo-reconstructed | Original public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in LeakyLM research team, IMDEA Networks (Oliveira, Sanchez, De Santa Olalla Gómez, Serna, Jackevicius, Garcia-Herrero, Girish, Suarez-Tangil, Vallina-Rodriguez) on other (echo) · attributed from hn.story.49890226 | — |
| 09-29 09:03 | first on hacker news · published · +3571.1h | AI companies leak data to advertisers [pdf] damaru2 | — |
| 10-07 07:25 | first on r/ClaudeAI · published · +3761.4h | I trust Anthropic with my data. I didn't agree to share it with Meta, TikTok and Google. (IMDEA study) ZoeyPanthera | — |
| 09-29 09:03 | amplified on hacker news 👑 | hn.story.49890226 damaru2 | peak 426 · 140 comments · 83% of case engagement |
| 10-07 07:25 | amplified on r/ClaudeAI | reddit.post.1wzq8z2 ZoeyPanthera | peak 176 · 31 comments · 17% of case engagement |
| 09-29 10:20 | our radar first saw it · +3572.3h | discovery anchor: hn.story.49890226 | — |
| 09-30 13:43 | reached heat=high · +3599.7h · via ledger | — | — |
Evidence (3) — ⭐ canonical anchor
| source | object | author | score | comments |
| 🟧 hn | AI companies leak data to advertisers [pdf] | damaru2 | 426 | 140 |
| 🟧 echo.other ⭐ | Original public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in | LeakyLM research team, IMDEA Networks (Oliveira, Sanchez, De Santa Olalla Gómez, Serna, Jackevicius, Garcia-Herrero, Girish, Suarez-Tangil, Vallina-Rodriguez) | — | — |
| 🟠 reddit | I trust Anthropic with my data. I didn't agree to share it with Meta, TikTok and Google. (IMDEA study) ClaudeAI | ZoeyPanthera | 173 | 31 |
Interpretation history
2026-10-11T04:41:45Z
Velocity spikes on the Reddit discussion (37x and 13.7x baseline) reflect renewed comment activity on the existing thread, not new evidence; measured_heat shows current rate at 0 pts/h, peer percentile 12.5, momentum steady. No vendor acknowledgment, fix, refutation, or independent replication has arrived. The counter-reading (subprocessors/telemetry vs. ad trackers) is already in the record. Case remains single-sourced pending the vendor-response window.
2026-10-07T08:29:13Z
The Reddit attachment meaningfully upgrades the case's provenance and scope while adding its first counter-reading: it pins the paper to PoPETs 2027 (peer-reviewed venue), widens the study to nine chatbots (adding Gemini, DeepSeek, Le Chat, Meta AI, Copilot), names specific Claude third-party flows (chat IDs, links, user IDs to Meta/TikTok/Google per coverage), and its comments argue those third parties may be disclosed subprocessors/infra (Datadog telemetry, Google Cloud) conflated with ad tracking — sharpening the open question from 'does it leak' to 'does conversation content reach ad infrastructure vs. ordinary subprocessor telemetry'. Heat cools high→medium: the magnitude-valve spread reading rests on the long-expired HN burst plus a thin 21-point echo at ~3.5 pts/h against a ~106 pts/h peak, and the vendor-response decision point hasn't moved in a week; a vendor statement or further periphery expansion would re-fire high.
2026-10-07T08:25:41Z
evidence attached: reddit.post.1wzq8z2 — Detailed community coverage of the same IMDEA 'Prompt like a Butterfly' paper as the open case, with named Claude third-party data-flow findings and real spread (21 points, 12 comments).
2026-09-30T13:43:47Z
magnitude valve eligible (multi-platform, top-decile engagement) and never alerted; deterministic escalation to deliver
2026-09-29T10:49:15Z
origin walked (opencode/cheap-glm, conf 0.82): anchor hn.story.49890226 -> echo.other.42eb2b3126 by LeakyLM research team, IMDEA Networks (Oliveira, Sanchez, De Santa Olalla Gómez, Serna, Jackevicius, Garcia-Herrero, Girish, Suarez-Tangil, Vallina-Rodriguez)
2026-09-29T10:44:29Z
grounded: converges/high — If the claim survives verification, this documents the advertiser as the chatbot's actual secondary principal — dated receipts for his shadow-principal/fiduciar
2026-09-29T10:36:51Z
case created — A front-page HN-linked self-published paper makes a concrete, consequential claim against major vendors, and the vendor-response window makes near-term re-observation worthwhile.
Decision trace
- 10-11 15:41repriceVelocity spikes on the Reddit discussion (37x and 13.7x baseline) reflect renewed comment activity on the existing thread, not new evidence; measured_heat shows current rate at 0 pts/h, peer percentil
- 10-08 19:31sensor_dirtyvelocity_spike
- 10-08 12:21sensor_dirtyvelocity_spike
- 10-08 09:21sensor_dirtycomment_update
- 10-08 03:28sensor_dirtycomment_update
- 10-08 02:21sensor_dirtyvelocity_spike
- 10-08 01:42feedback_briefingScott vote via UI
- 10-08 00:59attention_routeThe editor compared this story and chose to keep watching.
- 10-07 23:21sensor_dirtycomment_update
- 10-07 20:20sensor_dirtyvelocity_spike
- 10-07 19:29repriceThe Reddit attachment meaningfully upgrades the case's provenance and scope while adding its first counter-reading: it pins the paper to PoPETs 2027 (peer-reviewed venue), widens the study to nin
- 10-07 19:25attachDetailed community coverage of the same IMDEA 'Prompt like a Butterfly' paper as the open case, with named Claude third-party data-flow findings and real spread (21 points, 12 comments).
- 10-07 19:25propose_attachDetailed community coverage of the same IMDEA 'Prompt like a Butterfly' paper as the open case, with named Claude third-party data-flow findings and real spread (21 points, 12 comments).
- 09-30 23:43pushOriginal public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in — The front-page burst has decayed into a sin
- 09-30 23:43repriceThe front-page burst has decayed into a single-thread long tail of speculative and tangential commentary (ChatGPT keystreaming, Perplexity UUID URLs) — no vendor acknowledgment, fix, refutation, or in
- 09-30 23:43alert_heldOriginal public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in — The front-page burst has decayed into a sin
- 09-30 23:43alert_routeOriginal public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in — The front-page burst has decayed into a sin
- 09-30 10:22sensor_dirtycomment_update
- 09-30 06:23sensor_dirtycomment_update
- 09-30 01:21sensor_dirtycomment_update
- 09-29 22:20sensor_dirtyvelocity_spike
- 09-29 21:21sensor_dirtycomment_update
- 09-29 20:49promote_anchororigin walk conf 0.82
- 09-29 20:44groundIf the claim survives verification, this documents the advertiser as the chatbot's actual secondary principal — dated receipts for his shadow-principal/fiduciary-agent argument and the strongest
- 09-29 20:36createA front-page HN-linked self-published paper makes a concrete, consequential claim against major vendors, and the vendor-response window makes near-term re-observation worthwhile.