OpenAI is connecting what you do on ordinary websites to your ChatGPT account. Researcher Buchodi reproduced the mechanism on a phone, verified it with two independent capture methods, and cross-checked months of traffic covering 936 distinct advertiser pixels across 1,029 hostnames.
Here is the plain version. Companies that buy ads on ChatGPT drop a piece of OpenAI tracking code on their own sites, the same way they already drop Meta and Google pixels. That code sends a cookie called __obi back to OpenAI along with data about the page you are on. Products you search. Articles you read. Purchase behavior. Then OpenAI can join that activity to the ChatGPT identity sitting on your account.
How the __obi cookie gets on your device
It starts on chatgpt.com. The client generates 16 random bytes and posts them to OpenAI’s backend. The backend hands back a short-lived signed token, an RS256 JWT that expires in 60 seconds. That token binds your account identifier to a value called obi. OpenAI’s internal name for the ads platform is bazaar, which is why the collector lives at bzr.openai.com. The issuing service is called wadi.
The client then posts that token cross-site to bzr.openai.com. The response sets the cookie:
- Name: __obi
- Domain: .openai.com
- HttpOnly and Secure
- SameSite=None, which is the setting that lets a cookie travel on cross-site requests
- Max-Age: 31536000 seconds, which is one year
That cookie value matches the obi value inside the token. From that point on, the identifier is sitting on OpenAI’s domain, built to leave chatgpt.com and show up elsewhere.
What advertiser sites send back to OpenAI
Any company that buys ChatGPT ads can install OpenAI’s measurement pixel on its own site. On a phone that already had __obi in the cookie jar, Buchodi saw the identifier go out on three kinds of requests:
- The script load itself from bzrcdn.openai.com/sdk/oaiq.min.js
- Conversion events posted to bzr.openai.com/v1/sdk/events
- The SDK’s so-called no-credentials path, which still carried the cookie
The script load is the ugly part. The browser attaches cookies to that request before any of OpenAI’s code even runs. Just loading the tag discloses the identifier.
On the same advertiser pages, every other OpenAI cookie got blocked. Session cookies failed on domain mismatch. Cookies like oai-did were SameSite=Lax. __obi was the only OpenAI identifier configured with SameSite=None.
What else rides along with the cookie
The SDK does not just ping home. It also collects identity from the advertiser’s page. OpenAI labels four sources. One is values the advertiser passes on purpose. The other three are values the SDK scrapes from form fields, rendered page text, and the tag-manager bus.
In the observed traffic, scraped identity beat advertiser-supplied identity 685 events to 255. The tag-manager bus was the largest source of email. The SDK replaces window.dataLayer.push with its own function, also reads adobeDataLayer, and finds renamed Google Tag Manager layers by parsing the gtm.js script tag.
Here is what got sent:
- Email, phone, first name, and last name were SHA-256 hashed before transmission
- Country, region, city, and postal code went in the clear
- Postal code was the most-harvested form field, 100 events across 28 sites
- URLs were cut down to origin plus path. None of 23,929 observed events carried a query string
- Paths that still reached the collector included a medical condition, a debt-solutions funnel, and a litigation intake form
Automatic matching was on for 638 of 881 pixels with a known setting, including every credit and lending advertiser in the set. OpenAI controls that from Ads Manager. There is a denylist for passwords, one-time codes, card numbers, SSN, date of birth, medical history, diagnosis, and court fields. That is a list. It is not the same thing as leaving the rest of your life alone.
It follows you even when you are logged out
On Buchodi’s device, one __obi value went to OpenAI from 12 commercial websites under 13 distinct pixel IDs. The list included Chewy, Wayfair, ThriftBooks, Eventbrite, HelloFresh, Coursera, and SeatGeek. Every request came back 202, which means the collector accepted it.
In the broader traffic, 12 of 30 distinct __obi values showed up under more than one advertiser. One showed up under ten.
It is not just logged-in users. Across 932 decoded sync tokens, 736 carried subject_type account_user and 196 carried anonymous. The anonymous subject was as stable as the account subject: one per device, lasting at least 27 days.
OpenAI calls this analytics, not marketing
OpenAI’s cookie policy lists __obi under Analytics cookies, one year, on chatgpt.com and openai.com. It is the only entry in that section. The policy says analytics cookies help OpenAI understand how its services perform and are used.
OpenAI splits consent into two buckets, oai_consent_analytics and oai_consent_marketing. Every sync token Buchodi decoded carried consent_decision: analytics_allowed. If you allow analytics and refuse marketing, you still get this cookie. That is not some blogger’s theory. That is how they labeled it.
Buchodi sent the mechanism and two questions to press@openai.com and privacy@openai.com on 14 September: why is __obi classified as an analytics cookie, and does a user who grants analytics and refuses marketing still receive it. OpenAI Support acknowledged the inquiry, said the observations would be shared internally for review, and answered neither question.
What this actually means for regular people
This is standard adtech plumbing. Meta built the structural equivalent years ago: a logged-in account, third-party cookies on pixel fires, off-site conversions resolved to a profile. Buchodi is clear about that. What has no precedent is running it on an AI chat product.
People tell ChatGPT things they would not put on Facebook. Health questions. Money problems. Legal messes. Then they go shop, read, or fill out a form on some other site that bought ChatGPT ads, and the same company that heard the chat now gets a signal from that page, tied to the same identity.
Advertisers cannot even see this. __obi belongs to a domain their scripts cannot read. They installed a conversion pixel and have no way to know their visitors are being resolved to a ChatGPT identity. There is a different cookie, __obref, that lives on the advertiser’s own domain. Each site gets a different value. Of 2,860 values observed, 2,828 appeared under exactly one advertiser. That one is not the cross-site glue. __obi is.
A few limits matter so nobody oversells this. It was observed on Chrome for Android. Safari’s Intelligent Tracking Prevention blocks all third-party cookies, and Chrome on iOS runs on WebKit, so this mechanism does not operate on any iOS browser. Desktop Chrome was untested. Roughly one ChatGPT session in five produced a sync token. ChatGPT’s mobile web client serves ads without syncing at all. And a 202 from the collector means the event was accepted with the cookie attached. That OpenAI resolves it to the account on the server follows from the design. Buchodi did not watch the join happen.
What you can do about it right now
- If you use ChatGPT, treat analytics consent as the switch for this cookie, not the marketing toggle
- On Android Chrome, third-party cookies are how this travels. Blocking them, or using a browser that already does, cuts the cross-site path
- iPhone and iPad users are already outside this particular mechanism because of WebKit
- Do not assume logging out of ChatGPT saves you. The anonymous identifier was stable for weeks
- If you run a small business site, understand that dropping an OpenAI ads pixel is not just measuring your own conversions. You are helping OpenAI stitch visitors to ChatGPT identities you cannot see
I have spent 30 years watching companies tell regular people a cookie is just analytics while it does something else. This one is built to cross sites, lasts a year, and sits on an AI product people treat like a private conversation. That is not a feature for you. That is a system working exactly as designed, for them.
Primary Source: https://www.buchodi.com/chatgpt-now-knows-what-you-do-on-other-websites-via-ad-collector/
