2026-10-11 16:38 UTC

Jorge Garcia Herrero's 'Prompt like a butterfly, sting like a tracker' paper claims AI companies leak users' conversation data to advertisers; a named-vendor acknowledgment, fix, or credible refutation decides whether prompt-derived advertising leakage becomes an established privacy failure of deployed chatbots.

state: watchingheat: mediumuncertainty: highconvergesscott: highai-privacy prompt-leakage agentic-securityJorge Garcia Herrero
Surfaced 2026-09-30T13:43:48Z — Original public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in — The front-page burst has decayed into a single-thread long tail of speculative and tangential commentary (ChatGPT keystreaming, Perplexity UUID URLs) — no vendor acknowledgment, fix, refutation, or independent replication has landed, so the claim remains single-sourced pending the vendor-response window. Cooled despite the magnitude-valve reading because the loud signal reflects the expired HN burst (now 0/h, 8th percentile) and the periphery stopped expanding at two objects; a vendor response would re-fire sensors on its own. Provenance upgrade from last cycle (accepted IMDEA manuscript, named co-authors) is what justifies seed → watching rather than any new fact this look.

What is this?

Per the case, Jorge Garcia Herrero's self-published paper 'Prompt like a butterfly, sting like a tracker' — surfaced on HN as 'AI companies leak data to advertisers' — claims that deployed chatbot vendors expose users' conversation data to advertising infrastructure, with the open question being whether a named vendor acknowledges, fixes, or credibly refutes it. Caution: none of the supplied snippets actually surface the paper, its author, or its evidence; they establish only the surrounding territory — chatbots converging with advertising (research demos of embedded personalized ads, OpenAI reportedly rolling ads into ChatGPT while denying that ad placement alters replies), prompt/system-prompt leakage codified as OWASP LLM01/LLM07, and expert 'signal leakage' warnings about prompt data. The claim's specific mechanism, affected vendors, and evidence quality therefore cannot be confirmed from this material — which is exactly what the vendor-response window this case is watching should resolve.

Why it matters to Scott

If the claim survives verification, this documents the advertiser as the chatbot's actual secondary principal — dated receipts for his shadow-principal/fiduciary-agent argument and the strongest real-world instance yet of the prompt-to-advertiser exfiltration class his containment and privacy-tokenization architectures exist to stop. The grounding could not surface the paper's evidence or named vendors, so treat the vendor-response window as the decision point rather than the claim as established.
ip:concept.shadow-principalip:concept.fiduciary-agentip:concept.architectural-containmentdev:concept.privacy-tokenized-agent-boundaryradar:concept.ai-privacyradar:concept.ai-monetizationradar:openai-chatgpt-ads-global-rolloutradar:chatgpt-free-go-adsradar:anthropic-claude-tracker-privacy
queries asked of Scott's wikis
  • chatbot advertising monetization incentives user profiling
  • third-party tracker telemetry in LLM client apps data exfiltration
  • local inference privacy advantage over hosted chatbots
  • agent memory conversation retention privacy design
  • prompt injection exfiltration defenses harness
  • chatbot vendor data handling defaults retention opt-out

Measured heat

now 0 pts/hpeak 106 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 3866h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

05-03 14:00⭐ origin echo-reconstructedOriginal public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in
LeakyLM research team, IMDEA Networks (Oliveira, Sanchez, De Santa Olalla Gómez, Serna, Jackevicius, Garcia-Herrero, Girish, Suarez-Tangil, Vallina-Rodriguez) on other (echo) · attributed from hn.story.49890226
—
09-29 09:03first on hacker news · published · +3571.1hAI companies leak data to advertisers [pdf]
damaru2
—
10-07 07:25first on r/ClaudeAI · published · +3761.4hI trust Anthropic with my data. I didn't agree to share it with Meta, TikTok and Google. (IMDEA study)
ZoeyPanthera
—
09-29 09:03amplified on hacker news 👑hn.story.49890226
damaru2
peak 426 · 140 comments · 83% of case engagement
10-07 07:25amplified on r/ClaudeAIreddit.post.1wzq8z2
ZoeyPanthera
peak 176 · 31 comments · 17% of case engagement
09-29 10:20our radar first saw it · +3572.3hdiscovery anchor: hn.story.49890226—
09-30 13:43reached heat=high · +3599.7h · via ledger——

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnAI companies leak data to advertisers [pdf]damaru2426140
🟧 echo.other ⭐Original public disclosure of the study, titled "Your AI Assistant Is Leaking Your Conversations": "We disclose structural privacy risks in LeakyLM research team, IMDEA Networks (Oliveira, Sanchez, De Santa Olalla Gómez, Serna, Jackevicius, Garcia-Herrero, Girish, Suarez-Tangil, Vallina-Rodriguez)——
🟠 redditI trust Anthropic with my data. I didn't agree to share it with Meta, TikTok and Google. (IMDEA study)
ClaudeAI
ZoeyPanthera17331

Interpretation history

Decision trace