OpenAI's ad pixel now appears in CircleCI's cookie policy

Stani Mihov
Founder & CEO
·

TL;DR
What changed:
CircleCI's cookie policy, last updated October 4, 2026, now has nine entries tied to OpenAI's ad pixel, including cookies from bzr.openai.com and bzrcdn.openai.com.
OpenAI's documentation names those two domains as the ones that load its Measurement Pixel and receive its events, and says advertisers add the pixel to their own pages to measure results from ads in ChatGPT.
The two sources disagree on one cookie: CircleCI lists __obref as a session cookie, and OpenAI says it expires 365 days after creation.
OpenAI's own cookie policy shows the same measurement in the other direction: its September 10, 2026 update added nine Snapchat marketing cookies on chatgpt.com.
OpenAI says it does not currently use data collected through the pixel for user-level personalization.
What to do: If a site's cookie list names bzr.openai.com or a cookie with oaiq in its name, that is OpenAI's ad pixel, and the site's cookie settings are the first place to look if you want to refuse it.
The change
CircleCI, the continuous integration platform, updated its Cookie Policy on October 4, 2026. Among the edits are nine new entries that point to OpenAI: six from bzr.openai.com and bzrcdn.openai.com, and three cookies set on circleci.com itself. The September version of the policy did not mention OpenAI at all.
Those two domains belong to OpenAI's Measurement Pixel, which OpenAI describes as "a browser SDK for measuring website events that can be attributed to ads in ChatGPT." An advertiser installs it on its own website. So this is a change in one vendor's policy that shows another vendor's measurement code arriving on its pages.
What changed
CircleCI sorts its cookies into categories, and the new entries landed in three of them:
Strictly necessary. Two Cloudflare cookies, __cf_bm and _cfuvid, are each listed once for bzr.openai.com and once for bzrcdn.openai.com.
Targeting. oaiq_cs:# from bzrcdn.openai.com, and __oaiq_domain_probe and __obref on circleci.com. All three carry the same description: the cookie tracks "the conversion rate between the user and the advertisement banners on the website." The pixel's script is named oaiq, and __obref is a cookie OpenAI documents.
Unclassified. oaiq_consent from bzrcdn.openai.com and __oaiq_consent on circleci.com, with no purpose given. CircleCI says unclassified cookies are ones "that we are in the process of classifying."
The same update also removed a ZoomInfo telemetry cookie and a gstatic.com targeting cookie, and added one YouTube and one Reddit entry.
What OpenAI says the pixel does
OpenAI's documentation is written for advertisers, and it is specific. The script loads from bzrcdn.openai.com and sends events to bzr.openai.com. The advertiser adds it to "every page where you want to capture conversions." The events it can report include page views, added items, started checkouts, orders, leads, registrations, subscriptions, and trials.
Customer details. An advertiser can pass a visitor's email, phone number, name, and an external ID as hashed values, along with country, city, region, and postal code. An optional feature "automatically detects supported customer information from your website" and hashes it in the browser. OpenAI adds that "Raw customer information is not sent to OpenAI through automatic advanced matching."
Cookies. The documentation names two first-party cookies. __oppref stores an attribution identifier taken from the landing page address and lasts 30 days. __obref stores "a randomly generated browser reference for your website" and expires "365 days after creation."
Consent. The pixel starts with consent switched on unless the site sets it to off or the pixel finds a stored refusal. OpenAI's instruction to advertisers is: "If consent is required to track conversion events, use the Pixel's consent feature."
A stated limit. "OpenAI does not currently use data collected via the measurement pixel for user-level personalization."
Where the two documents do not match
Read side by side, CircleCI's table and OpenAI's documentation leave four open points:
CircleCI lists __obref with an expiration of "Session." OpenAI says it expires 365 days after creation.
CircleCI's table has no entry for __oppref, the cookie OpenAI says holds the attribution identifier for 30 days.
oaiq_cs:#, __oaiq_domain_probe, oaiq_consent, and __oaiq_consent are in CircleCI's table but are not described on OpenAI's pixel page.
The Cloudflare cookies from OpenAI's pixel domains sit under strictly necessary cookies, which CircleCI says "cannot be switched off in our systems."
None of this shows that either company is doing something its documents do not allow. It shows that a cookie table and a vendor's documentation can describe the same code in different ways, and that a reader who compares them is left to work out which one is right.
What OpenAI's own cookie policy shows
OpenAI's cookie policy covers OpenAI's own sites, such as chatgpt.com and openai.com. It does not list the pixel's domains, since the pixel runs on advertisers' sites. What it does show is the measurement OpenAI runs on its own pages, and its September update added to it.
The version dated September 10, 2026 added nine Snapchat cookies for chatgpt.com, each with the purpose "Marketing measurement" and five of them lasting 13 months. They sit in a section the policy introduces this way: "These cookies help us support and understand the efficacy of our marketing efforts." They join entries from LinkedIn, Google, Reddit, TikTok, Meta, and Bing that were already there.
Put the two policies together and the picture is symmetrical. OpenAI measures its own marketing on chatgpt.com with other companies' tags, and companies that advertise in ChatGPT measure theirs with OpenAI's.
What did not change
CircleCI's consent sentence is the same: "By continuing to visit our Site or use our Services, you are agreeing to the use of cookies and other similar technologies for the purposes we describe in this Policy."
CircleCI still says that, depending on where you are located, you may see a cookie notice and can set your preferences in it.
CircleCI still points to the industry opt-out pages for third-party targeting cookies.
OpenAI's cookie policy still says that where the law allows that control, you can change cookie settings on its sites.
Why this matters
Ads in ChatGPT are a new channel, and the measurement side of it is now reaching ordinary company websites. In September, OpenAI's US privacy policy began to say "We receive" information from advertisers, as we covered when OpenAI widened how it can use data from advertisers. The pixel is one documented way that information travels, and CircleCI's cookie table is a place where the arrangement becomes visible from the outside.
Every company that installs the pixel takes on a disclosure job: list the cookies, give them the right lifetime, put them in the right category, and connect the pixel to the consent banner, since it starts with consent switched on. CircleCI's update shows that work part of the way through, with two entries still unclassified. Cookie disclosures have been moving at larger companies too, as when Google said personalized ads may continue after you reject cookies and Uber said its ad partners may combine your data with other sources.
For anyone who relies on a vendor's site, the cookie policy is often the first document to show a new third party on the pages your team logs into. That is one reason to monitor vendor terms of service together with the smaller documents around them.
Potential impact
Depending on where you sit, the update raises different questions:
If you use ChatGPT and click an ad, do you check the cookie settings of the site you land on, now that it may report your visit back to OpenAI?
If your company advertises in ChatGPT, is the pixel listed in your cookie policy with the lifetimes OpenAI documents?
Is the pixel tied to your consent banner, given that it starts with consent switched on?
If automatic advanced matching is enabled, does your privacy notice say that hashed customer details go to OpenAI?
Which of your vendors' sites have added OpenAI's pixel, and did you learn it from them or from their cookie table?
How Venpo detected it
Venpo monitors the legal documents of both companies as part of continuous vendor risk monitoring. It recorded CircleCI's new cookie table and OpenAI's September cookie policy and marked each added and changed row. Every quote in this article was checked against those records, the live pages, and OpenAI's pixel documentation. The redlines are on the CircleCI change page and the OpenAI change page, and every monitored CircleCI document is listed on the CircleCI vendor profile.
Business outcome
Teams that track CircleCI saw OpenAI's domains appear in its cookie table when the policy changed. Teams that track OpenAI saw nine new rows in a table of more than a hundred. Neither edit is the kind anyone finds by rereading a policy, which is the practical difference between manual and automated vendor monitoring.
Key takeaway
OpenAI's ad pixel has reached a developer tool's cookie policy, and the table that lists it does not fully match what OpenAI's own documentation says about the same cookies. A new advertising partner usually surfaces as a few rows in a cookie table, which is why it pays to treat vendor legal changes as something to monitor continuously.
The change
CircleCI, the continuous integration platform, updated its Cookie Policy on October 4, 2026. Among the edits are nine new entries that point to OpenAI: six from bzr.openai.com and bzrcdn.openai.com, and three cookies set on circleci.com itself. The September version of the policy did not mention OpenAI at all.
Those two domains belong to OpenAI's Measurement Pixel, which OpenAI describes as "a browser SDK for measuring website events that can be attributed to ads in ChatGPT." An advertiser installs it on its own website. So this is a change in one vendor's policy that shows another vendor's measurement code arriving on its pages.
What changed
CircleCI sorts its cookies into categories, and the new entries landed in three of them:
Strictly necessary. Two Cloudflare cookies, __cf_bm and _cfuvid, are each listed once for bzr.openai.com and once for bzrcdn.openai.com.
Targeting. oaiq_cs:# from bzrcdn.openai.com, and __oaiq_domain_probe and __obref on circleci.com. All three carry the same description: the cookie tracks "the conversion rate between the user and the advertisement banners on the website." The pixel's script is named oaiq, and __obref is a cookie OpenAI documents.
Unclassified. oaiq_consent from bzrcdn.openai.com and __oaiq_consent on circleci.com, with no purpose given. CircleCI says unclassified cookies are ones "that we are in the process of classifying."
The same update also removed a ZoomInfo telemetry cookie and a gstatic.com targeting cookie, and added one YouTube and one Reddit entry.
What OpenAI says the pixel does
OpenAI's documentation is written for advertisers, and it is specific. The script loads from bzrcdn.openai.com and sends events to bzr.openai.com. The advertiser adds it to "every page where you want to capture conversions." The events it can report include page views, added items, started checkouts, orders, leads, registrations, subscriptions, and trials.
Customer details. An advertiser can pass a visitor's email, phone number, name, and an external ID as hashed values, along with country, city, region, and postal code. An optional feature "automatically detects supported customer information from your website" and hashes it in the browser. OpenAI adds that "Raw customer information is not sent to OpenAI through automatic advanced matching."
Cookies. The documentation names two first-party cookies. __oppref stores an attribution identifier taken from the landing page address and lasts 30 days. __obref stores "a randomly generated browser reference for your website" and expires "365 days after creation."
Consent. The pixel starts with consent switched on unless the site sets it to off or the pixel finds a stored refusal. OpenAI's instruction to advertisers is: "If consent is required to track conversion events, use the Pixel's consent feature."
A stated limit. "OpenAI does not currently use data collected via the measurement pixel for user-level personalization."
Where the two documents do not match
Read side by side, CircleCI's table and OpenAI's documentation leave four open points:
CircleCI lists __obref with an expiration of "Session." OpenAI says it expires 365 days after creation.
CircleCI's table has no entry for __oppref, the cookie OpenAI says holds the attribution identifier for 30 days.
oaiq_cs:#, __oaiq_domain_probe, oaiq_consent, and __oaiq_consent are in CircleCI's table but are not described on OpenAI's pixel page.
The Cloudflare cookies from OpenAI's pixel domains sit under strictly necessary cookies, which CircleCI says "cannot be switched off in our systems."
None of this shows that either company is doing something its documents do not allow. It shows that a cookie table and a vendor's documentation can describe the same code in different ways, and that a reader who compares them is left to work out which one is right.
What OpenAI's own cookie policy shows
OpenAI's cookie policy covers OpenAI's own sites, such as chatgpt.com and openai.com. It does not list the pixel's domains, since the pixel runs on advertisers' sites. What it does show is the measurement OpenAI runs on its own pages, and its September update added to it.
The version dated September 10, 2026 added nine Snapchat cookies for chatgpt.com, each with the purpose "Marketing measurement" and five of them lasting 13 months. They sit in a section the policy introduces this way: "These cookies help us support and understand the efficacy of our marketing efforts." They join entries from LinkedIn, Google, Reddit, TikTok, Meta, and Bing that were already there.
Put the two policies together and the picture is symmetrical. OpenAI measures its own marketing on chatgpt.com with other companies' tags, and companies that advertise in ChatGPT measure theirs with OpenAI's.
What did not change
CircleCI's consent sentence is the same: "By continuing to visit our Site or use our Services, you are agreeing to the use of cookies and other similar technologies for the purposes we describe in this Policy."
CircleCI still says that, depending on where you are located, you may see a cookie notice and can set your preferences in it.
CircleCI still points to the industry opt-out pages for third-party targeting cookies.
OpenAI's cookie policy still says that where the law allows that control, you can change cookie settings on its sites.
Why this matters
Ads in ChatGPT are a new channel, and the measurement side of it is now reaching ordinary company websites. In September, OpenAI's US privacy policy began to say "We receive" information from advertisers, as we covered when OpenAI widened how it can use data from advertisers. The pixel is one documented way that information travels, and CircleCI's cookie table is a place where the arrangement becomes visible from the outside.
Every company that installs the pixel takes on a disclosure job: list the cookies, give them the right lifetime, put them in the right category, and connect the pixel to the consent banner, since it starts with consent switched on. CircleCI's update shows that work part of the way through, with two entries still unclassified. Cookie disclosures have been moving at larger companies too, as when Google said personalized ads may continue after you reject cookies and Uber said its ad partners may combine your data with other sources.
For anyone who relies on a vendor's site, the cookie policy is often the first document to show a new third party on the pages your team logs into. That is one reason to monitor vendor terms of service together with the smaller documents around them.
Potential impact
Depending on where you sit, the update raises different questions:
If you use ChatGPT and click an ad, do you check the cookie settings of the site you land on, now that it may report your visit back to OpenAI?
If your company advertises in ChatGPT, is the pixel listed in your cookie policy with the lifetimes OpenAI documents?
Is the pixel tied to your consent banner, given that it starts with consent switched on?
If automatic advanced matching is enabled, does your privacy notice say that hashed customer details go to OpenAI?
Which of your vendors' sites have added OpenAI's pixel, and did you learn it from them or from their cookie table?
How Venpo detected it
Venpo monitors the legal documents of both companies as part of continuous vendor risk monitoring. It recorded CircleCI's new cookie table and OpenAI's September cookie policy and marked each added and changed row. Every quote in this article was checked against those records, the live pages, and OpenAI's pixel documentation. The redlines are on the CircleCI change page and the OpenAI change page, and every monitored CircleCI document is listed on the CircleCI vendor profile.
Business outcome
Teams that track CircleCI saw OpenAI's domains appear in its cookie table when the policy changed. Teams that track OpenAI saw nine new rows in a table of more than a hundred. Neither edit is the kind anyone finds by rereading a policy, which is the practical difference between manual and automated vendor monitoring.
Key takeaway
OpenAI's ad pixel has reached a developer tool's cookie policy, and the table that lists it does not fully match what OpenAI's own documentation says about the same cookies. A new advertising partner usually surfaces as a few rows in a cookie table, which is why it pays to treat vendor legal changes as something to monitor continuously.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
