A developer teardown published on September 20, 2026, reported that OpenAI's advertising pixel, working with a cookie named __obi, can connect what you do on third-party websites back to your ChatGPT account. The technique itself is not new. It is the same cross-site pixel pattern that Meta and Google have run for years. What makes it worth examining is the identity it resolves to: not an anonymous advertising ID, but a signed-in account tied to an assistant people often talk to in confidence.
The mechanics are worth walking through carefully, because the difference between "standard ad-tech" and "something new" lives entirely in the details.
How the pixel works
When a company buys ads inside ChatGPT, it can install a small piece of OpenAI code on its own website, exactly the way sites install the Meta Pixel or a Google tag. Once that code loads on a page you visit, it reports activity back to OpenAI: the page you are viewing, the product you searched for, and, according to the teardown, recent order details.
How browsing on other sites reaches your ChatGPT identity
Each step is standard ad-tech, with one difference at step three: the identifier resolves to a logged-in assistant account, not just an anonymous ad ID.
The teardown reported that the cookie was categorized under "Data Analysis" and was placed even when a user had turned ad personalization off. OpenAI publishes user controls; the dispute is over how completely they apply.
The __obi cookie is what ties that activity to a person. If you are signed in to ChatGPT, the report can be associated with your account. If you are not, the teardown says the system assigns a stable per-device identifier that persists for at least 27 days, so behavior can still be linked over time even without a login. The report also noted the cookie was categorized under "Data Analysis" and, more pointedly, that it was placed even when a user had turned ad tracking off in settings. OpenAI publishes privacy controls and an ad-settings page; the dispute the teardown raises is about how completely those controls apply in practice.
Why the assistant link changes the calculation
Cross-site tracking is two decades old, and on its own it is not a scandal. The consequential change is what the tracking joins onto.
Same technique, a different identity graph
Cross-site pixels are two decades old. What is new is joining that data to a conversational assistant people talk to in confidence.
The privacy question is not whether tracking is novel. It is whether the value of an assistant depends on users believing what they type stays separate from what they are sold.
A conventional ad pixel resolves to an advertising profile. An assistant-linked pixel can resolve to an account that also holds the content of your conversations. People type things into a chat assistant they would not put into a search box: health worries, financial details, work problems, drafts of things they have not decided to say out loud. The privacy question is not whether pixels are novel. It is whether the usefulness of an assistant depends on users trusting that what they say to it stays separate from what they are later sold.

The regulatory surface
The sharpest claim in the teardown, that the cookie is placed even when a user disables ad tracking, is also the one with the most regulatory weight. Under the EU's ePrivacy rules and GDPR, non-essential tracking generally requires consent, and a control that appears to be off but is not would be a live compliance question. Under California's privacy law, users have a right to opt out of the sale or sharing of personal information, and an identifier that survives an opt-out would sit awkwardly against it. None of this is a finding of wrongdoing. It is a map of where regulators would look, and OpenAI's classification of the cookie as analytics rather than advertising is exactly the kind of distinction that tends to get tested.
The technique is ordinary. The identity it resolves to is not. That gap is the whole privacy story.
Metir analysis
What a careful user, and a careful builder, should take from it
For an individual, the practical steps are the familiar ones: review the ad and data controls in your ChatGPT settings, use browser-level tracking protection, and assume that anything typed into any assistant tied to an ad business may inform a profile. Treating a logged-in assistant as a private notebook is the assumption most likely to be wrong.
For anyone building products on top of AI, there is a structural lesson. When a single company owns the model, the assistant surface, and an advertising business, its commercial incentives sit very close to your users' data. That is not unique to OpenAI, and it is not inherently improper, but it is a reason to keep control of where data flows rather than routing everything through one vendor whose business model may evolve. Designing for portability, so you can move between models and providers and keep your own data boundary, is the version of privacy hygiene that survives a platform quietly adding an ad network. The __obi cookie is a small, early example of why that boundary is worth keeping.
Sources:
- OpenAI ChatGPT tracks user activity across websites via cookie | KuCoin
- ChatGPT Cookies: Complete OpenAI Cookie List, Ads Pixel Tracking and Privacy Guide | Captain Compliance
- ChatGPT now knows what you do on other websites via ad collector | daily.dev
- Privacy policy | OpenAI
Image credits
Pioneer Building, San Francisco, by HaeB, via Wikimedia Commons, licensed under CC BY-SA 4.0.