Meta Just Turned Off Instagram Encryption to Feed Its AI

Popular AI chatbot apps are sending your private conversations to Meta, TikTok, and Google through embedded trackers, raising serious privacy concerns for users.

Eliza Crichton-Stuart

Eliza Crichton-Stuart

•

Updated

Web3 Gaming Generic Graphic
Advertisement

Your private conversations with AI chatbots might not be as private as you think.

Researchers have found that a significant number of popular AI chatbot apps contain embedded third-party trackers that transmit user data, including chat content, to companies like Meta, TikTok, and Google. This is not a theoretical vulnerability. It is happening in apps that millions of people use daily to ask questions, vent frustrations, plan their schedules, and yes, discuss games.

Third-party trackers in AI apps

Third-party trackers in AI apps

EXCLUSIVE OFFER

Use code TRYHARD33 at checkout to redeem this offer before code expires again.

Get 33% Off GAMES+ Subscription

What the trackers are actually collecting

The issue centers on software development kits (SDKs) that app developers bundle into their products, often to enable analytics, advertising, or social login features. These SDKs can silently collect far more than developers intend to share. In the case of several AI chatbot apps, security researchers identified that conversation data was being passed through these trackers before any meaningful anonymization.

Here is the thing: most users assume that a chatbot conversation is between them and the app. The reality is that the data pipeline often includes several stops along the way, and not all of them are disclosed clearly in a privacy policy buried three scrolls deep in the app store listing.

Meta has also made moves recently that expand its legal ability to use private message data for AI training purposes. As of early May, Meta removed end-to-end encryption defaults on Instagram direct messages, a change that technically allows the company to read and process message content. Meta has stated it is not currently using private messages to train its AI models, but the policy change gives it the legal framework to do so in the future. That distinction matters.

The before and after of chatbot privacy expectations

A year ago, the general assumption was that AI chatbot apps operated in relative isolation. You typed something in, the model responded, and the conversation stayed on the platform. The business model was subscriptions or ads. Simple enough.

That picture has shifted considerably. As AI apps compete for users and advertising revenue, many have integrated the same ad-tech infrastructure that powers social media platforms. The result is that a chatbot app can now function as a data collection tool for third-party advertisers, even if that was never the primary pitch to users.

What most players miss in this conversation is that the risk is not just about embarrassing messages getting leaked. It is about behavioral profiling. If a tracker knows you regularly ask an AI for help managing anxiety, researching medical symptoms, or navigating relationship problems, that information has real commercial value, and potentially real consequences if it ends up in the wrong hands.

Why this matters more for gamers and web3 users

Gamers and web3 users are arguably more exposed here than the average person. AI tools have become genuinely useful for gaming, from asking chatbots for build advice and strategy help to using them for in-game lore research and community moderation assistance. Many players also discuss account details, wallet addresses, and platform credentials in chatbot sessions without thinking twice.

The key here is understanding that the chatbot interface is a front end, not a vault. Anything typed into a third-party app is subject to that app's data practices, and those practices are often shaped by the SDKs and ad networks running underneath.

For context on how data practices vary across gaming platforms and tools, our gaming guides section covers platform security and account safety topics that are increasingly relevant as AI tools become part of the everyday gaming toolkit.

What is actually being done about it

Regulators in the EU have been the most aggressive in pushing back. Under GDPR, companies are required to disclose data sharing arrangements and obtain explicit consent. Several AI app developers have faced inquiries over their SDK usage, though enforcement has been slow relative to how fast the apps are spreading.

In the US, there is no equivalent federal framework, which means the burden falls on individual users to read privacy policies and make informed choices. That is a high bar when most policies are deliberately opaque.

App stores have started tightening their data disclosure requirements, with both Apple and Google updating their privacy nutrition label standards to require more specific declarations about third-party data sharing. Whether developers accurately self-report remains a separate question.

For those looking to stay informed on which tools and platforms are holding up their end of the bargain, checking our game reviews and coverage of gaming-adjacent software can surface red flags before they become personal data incidents.

The pressure on AI companies to be transparent about data pipelines is not going away. With the EU AI Act beginning to take effect and US state-level privacy laws expanding, the next 12 months will likely force a reckoning for apps that have been quietly generous with user data. Until then, treat every chatbot session like a postcard, not a sealed letter.

Reports

updated

May 11th 2026

posted

May 11th 2026

Advertisement

Related News