Recommended guardrail
Keep what people tell an AI out of ad targeting and third-party trackers
Advisory. In any AI chat or assistant, keep conversation text, files shared in the conversation, and topics, interests, or intents a model extracts from them out of ad selection, ad-server targeting keys, audience lists, and third-party analytics, pixels, and session replay; conversation telemetry carries event names, counts, timings, and opaque first-party identifiers such as a conversation ID, never content. Detect conversation content flowing into ad or tracker calls, and tracker or ad-targeting calls in chat code whose properties carry message, prompt, or extracted-interest fields.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs. Ethical-use guardrails are optional practices, never reported as violations.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Related law in force in 1 jurisdiction · 2 graded incidents.
Advisory ethical-use recommendation, not law: an optional practice, never reported as a violation. Where binding law applies, the law governs. No binding law on this control itself is in force in the corpus; binding law in provisions cited as convergence, which cover part of the control or a related one, is in force in 1 jurisdiction (US-UT). 2 graded incidents cited.
Related law in force (cited as convergence; not on this control itself)
- Mental health chatbots must not use what users type to choose, target, or tailor ads (Utah HB 452) (Utah (US-UT); Utah Code 13-72a-202(2); cited)
- Mental health chatbots must not sell or share users' input or health information with third parties (Utah HB 452) (Utah (US-UT); Utah Code 13-72a-201(1); cited)
Family “What people tell an AI chatbot is used for ads or shared with third parties”: binding law on related controls is in force in Utah (US-UT). Context only: it does not change this guardrail's grade.
Graded incidents
- Meta says it will use people's interactions with Meta AI to personalize content and ads (2025-10; disclosed by the operator) Meta Newsroom (2025-10-01) · evidence grade: primary
- GenAI browser assistants sent user queries and chat identifiers to Google Analytics (researcher audit) (2025-03; confirmed) Vekaria, Canino, Levitsky, Ciechonski, Callejo, Mandalari, Shafiq, 'Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants' (arXiv, original researchers) · evidence grade: primary
The guard to add
Build ad targeting and third-party telemetry only from allowlisted, non-conversation fields, and keep pixels and unmasked session replay off chat pages.
Consider keeping the ad path and third-party telemetry separate from the conversation: code that decides whether to show an ad, which one, or how, and every call to an ad server, pixel, or analytics SDK, reads only an allowlist of non-conversation fields (page section, placement, plan, event name, message count, latency) and has no access to messages, chat history, uploaded files, conversation embeddings, or topics and interests a model extracts from them. Route chat telemetry through one helper that enforces the allowlist, do not load ad pixels on chat pages, and configure session replay to mask the transcript and the input box. House ads for the product itself and contextual placements with no user features stay available.
Example (Next.js + PostHog + Google Publisher Tag), before:
posthog.capture('chat_message', { message: input, reply: completion });
const topics = await extractTopics(messages); // LLM-derived interests
googletag.cmd.push(() => googletag.pubads().setTargeting('interests', topics));After:
posthog.capture('chat_message', { length: input.length, turn, latency_ms: latencyMs }); // no text
googletag.cmd.push(() => googletag.setConfig({ targeting: { section: 'assistant' } })); // page context onlyControl: What people tell an AI chat or assistant reaches ad targeting or third-party trackers. Engineering guidance, not legal advice.
Why
People tell AI assistants things they would not tell an advertiser: symptoms, debts, relationship trouble, beliefs. Feeding a conversation into ad targeting, or copying it to third-party trackers, turns a private exchange into a marketing profile, and once it has reached a tracker the product cannot take it back. A responsible integration keeps the conversation out of both, whatever the product's subject. Researchers auditing generative-AI browser assistants report that some sent users' raw queries or chat identifiers to Google Analytics, and note that such data could be used to retarget users with ads; Meta has said that from December 2025, in most regions, it would use people's interactions with its AI to personalize content and ads, while not using conversations about sensitive topics such as health, religion, or sexual orientation to show ads.
Class: ethical use · set: ethical use · maturity: reviewed · confidence: medium · id guardrail.ethics-conversation-content-out-of-ads-and-trackers