Bearing your soul to AI is "a ticking time bomb for everyone's privacy"
AI chatbots are designed to feel like confidants, and in the US, 200 million free ChatGPT users just had enough of a digital fingerprint handed to ad partners to build a complete personal profile without being asked. On 30 April 2026, OpenAI switched on marketing cookies by default for free-tier users, sharing device IDs and email addresses with ad partners. WIRED confirmed paying subscribers are exempt. Meta already feeds chatbot conversations into ad targeting with no full opt-out. Data aggregation from multiple sources means everyone is in the crosshairs.
The change applies in nearly every global region, with exceptions in the EU, the UK, and South Korea, where strong privacy regulations like the EU’s GDPR remain in place. However, tech companies can bundle helpful settings with broader data access rights which means in-depth personal tracking happen by stealth.
People confess to chatbots what they can't tell a person, debts, diagnoses, marriages falling apart. The LLM's anthropomorphism is not an accident: the warmer the interface, the more encouraging the voice, the more people divulge, making LLMs something closer to a digital Mata Hari. LLMs cost far more than subscriptions cover, so that intimate data probably isn't staying in-house, it could be building highly valuable ad profiles sold off-platform.
If you've watched Facebook and YouTube, there's a pattern: free product, mass adoption, then the data gets monetised. Even if you opt out of online-life, this data is aggregated and you can get lumped in with that data based on other interactions and your offline behaviours like your electric car usage patterns, and visiting shopping centres that can scan your precise presence using your phone's Bluetooth and Wi-Fi signals via multiple BLE sensors placed metres apart around the venue.
The ICO updated The Privacy and Electronic Communications Regulations 2003 (PECR) guidance on 29 April 2026. If this model hits UK users, it lands on consent law.
We'd like your views:
- People confide in chatbots because they feel private. If that data builds ad profiles sold off-platform, should AI providers carry the same duty of confidence as a GP or solicitor?
- Free users get tracked, paying users don't. Is income-based privacy a consumer protection issue?
- AI companies say they need conversation history to deliver a good service. Who decides where "context for quality" ends and "data for advertisers" begins?



