ChatGPT search privacy: distinguish a query from a conversation

Inspect what the search query contains before claiming a prompt leak. Separate documented provider sharing, captured query strings and Search Console evidence.

Benjamin Tannenbaum, Founder and CEO, Aiso
By Benjamin Tannenbaum · Founder and CEO, Aiso · LinkedIn
5 min read

First published . Analysis updated September 9, 2026.

Check the text sent for search

OpenAI's search documentation says ChatGPT may send rewritten queries to search providers. Approximate location may also be shared, but OpenAI says the IP address itself and ChatGPT account information are not shared for the search. Relevant saved memories can influence query rewriting.

That distinction matters when assessing a privacy concern. A short rewritten search can still contain a sensitive detail. But observing a query is not the same as observing the entire conversation being transmitted. Review the actual text and identify the recipient rather than treating every use of search as a full-prompt leak.

This article replaces our earlier categorical claim that ChatGPT scrapes Google and exposes prompts through Search Console. The observations presented did not establish that general conclusion. They should not have been described as proof that every listed query was sent to Google or visible to a website owner.

Make a controlled capture without real secrets

Use a conversation you own, with synthetic details that are safe to disclose. Save the original request, the exposed query strings, the model or interface shown and the capture time. Repeat the test with and without the detail you are investigating. Do not use an employee's name, customer record or confidential project merely to make the test distinctive.

Our fan-out extraction guide shows where Aiso's parser looks for query metadata. Those fields are implementation-dependent. Missing metadata does not prove that no search occurred, and a conversation-level query collection is not automatically attributable to the latest user turn.

Evidence needed for different privacy claims
ObservationWhat it supportsWhat it does not establish
A string appears in exposed query metadataThe capture contains that search-related string.That every message, file or account detail accompanied it.
A provider is named in an attributable tool recordA provider attribution for that recorded action.The provider used for every other action or account.
A similar phrase appears in Search ConsoleA reported Google search term associated with that property.The identity of the searcher or a link to a particular private chat.
An answer reproduces an unusual phraseA phrase match worth investigating.Which copy of the text was retrieved, or whether retrieval was necessary.

Search Console is not a private-chat transcript

Google's query-report documentation explains that some queries are anonymized and omitted, and that data truncation also affects the rows shown. A website owner does not receive a complete list of every query that could have returned the site.

A natural-language phrase is a candidate for investigation, not a user identifier. Do not join a Search Console row to an individual chat on wording alone. Keep the collection periods and filters visible, and preserve alternative explanations such as a person manually searching the same phrase.

Act on the narrow result you can support

For a company workflow, decide which information is appropriate to send to an external search system before anyone starts a test. Use approved accounts and tools, remove unnecessary personal details, and review any record before sharing it. A raw browser export may contain unrelated conversation content or authorization information.

If a controlled capture exposes information that should not have been sent, keep the evidence private and report the specific behaviour through the provider's support or security process. Include the minimum reproducible synthetic example. Do not publish someone else's conversation as proof.

Report the test, not an unmeasured leak rate

Report how many eligible test runs exposed the detail, how many could not be inspected, and whether the recipient could be established. A handful of controlled tests is not an estimate of the proportion of all ChatGPT conversations affected. A safer business decision can follow from one reproducible problem without inflating it into a population statistic.

Explore the related measurement tools

See Aiso’s prompt, fan-out and source-analysis workflow, with its sampling and coverage limits.

Explore Aiso