Control
What people tell an AI chat or assistant reaches ad targeting or third-party trackers
In any AI chat or assistant, the text people type or say, the files they share in the conversation, and topics, interests, or intents a model extracts from them do not feed ad selection, ad-server targeting keys, audience or lookalike lists, or third-party analytics, pixels, and session replay; telemetry about conversations carries event names, counts, and timings only. Narrower controls cover mental health chatbots where specific law applies.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
The guard to add
Build ad targeting and third-party telemetry only from allowlisted, non-conversation fields, and keep pixels and unmasked session replay off chat pages.
Consider keeping the ad path and third-party telemetry separate from the conversation: code that decides whether to show an ad, which one, or how, and every call to an ad server, pixel, or analytics SDK, reads only an allowlist of non-conversation fields (page section, placement, plan, event name, message count, latency) and has no access to messages, chat history, uploaded files, conversation embeddings, or topics and interests a model extracts from them. Route chat telemetry through one helper that enforces the allowlist, do not load ad pixels on chat pages, and configure session replay to mask the transcript and the input box. House ads for the product itself and contextual placements with no user features stay available.
Where it goes: 1 application source code, 6 API calls and integrations, 9 AI output handling, 10 logs and telemetry.
What reviewers look for: no data flow from request messages, chat_history, prompts, uploaded files, or extract_topics(messages) into googletag setTargeting or setConfig({ targeting }), pbjs.setConfig({ ortb2 }) keywords, fbq('track'), ttq.track, gtag('event'), analytics.track, mixpanel.track, amplitude.track, posthog.capture, or an internal select_ad; chat events whose properties are counts and timings only; session replay with the chat transcript and input masked; no ad pixel loaded on chat routes.
Example (Next.js + PostHog + Google Publisher Tag), before:
posthog.capture('chat_message', { message: input, reply: completion });
const topics = await extractTopics(messages); // LLM-derived interests
googletag.cmd.push(() => googletag.pubads().setTargeting('interests', topics));After:
posthog.capture('chat_message', { length: input.length, turn, latency_ms: latencyMs }); // no text
googletag.cmd.push(() => googletag.setConfig({ targeting: { section: 'assistant' } })); // page context onlyEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Keep what people tell an AI out of ad targeting and third-party trackers TwinEthos derivation — guardrail.ethics-conversation-content-out-of-ads-and-trackers · advisory
Related incidents
- Meta says it will use people's interactions with Meta AI to personalize content and ads (2025-10; disclosed by the operator). On October 1, 2025 Meta announced that from December 16, 2025, in most regions, it would use people's interactions with AI at Meta to personalize the content and ads they see, with notifications to users starting October 7, 2025. Meta says that when people have conversations with Meta AI about topics such as their religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, or trade union membership, it does not use those topics to show them ads, and it points people to Ads Preferences and feed controls to adjust what they see. The entry records the operator's own description of its practice. Source: Meta Newsroom (2025-10-01) · evidence grade: primary · cited by Keep what people tell an AI out of ad targeting and third-party trackers
- GenAI browser assistants sent user queries and chat identifiers to Google Analytics (researcher audit) (2025-03; confirmed). Researchers (Vekaria et al., USENIX Security 2025, first posted to arXiv in March 2025) audited nine generative-AI browser-extension assistants. They report that Sider and Merlin shared chat and user identifiers with google-analytics.com and TinaMind with analytics.google.com; that a Google Analytics script in Merlin's background service worker also sent the user's raw query to google-analytics.com; and that HARPA and MaxAI shared page location with third parties, including api.mixpanel.com. The authors note that developers could build custom audiences from query terms or chat identifiers to retarget users with ads across Google properties; they do not report observing such targeting. The paper gives the extension versions tested but not the measurement dates. Source: Vekaria, Canino, Levitsky, Ciechonski, Callejo, Mandalari, Shafiq, 'Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants' (arXiv, original researchers) · evidence grade: primary · cited by Keep what people tell an AI out of ad targeting and third-party trackers