300 Million Private AI Chats Just Leaked

One misconfigured server exposed 25 million people's most personal conversations. Here's the part nobody wants to say out loud: your AI chats were never really private to begin with.

What happened

In early 2026, a security researcher found roughly 300 million private messages from more than 25 million people sitting wide open on the internet. No password. No lock. Anyone who knew where to look could read them, change them, or delete them.

The messages came from a popular app called Chat & Ask AI, made by a company called Codeway. The app has been downloaded more than 50 million times. According to the researchers who reported it, the company's database had been left set to "public," so its entire contents were reachable by anyone with the web address. You can read the full write-up from Malwarebytes, with additional reporting from Fox News and Hackread.

To the company's credit, once they were told, they reportedly fixed the problem across their apps within hours. But "fixed within hours" doesn't answer the real question: how long was it open before anyone noticed? And who else looked while it was?

This wasn't just a list of email addresses. The exposed data reportedly included full chat histories — the names people gave their AI companions, discussions of mental health struggles, relationship details, work secrets, and, per the researchers, "deeply personal and disturbing requests." The kind of thing you'd only ever type because you believed no human would ever read it.

The real problem isn't one company

It's tempting to blame one careless setup. But the researcher who found this leak went on to scan 200 other apps — and found the same kind of open-door mistake in over 100 of them, exposing tens of millions more files. This isn't a fluke. It's the default.

Here's the uncomfortable truth about nearly every AI chat app on your phone: when you type a message, it doesn't stay on your device. It travels to a company's server, gets processed there, and — this is the important part — often gets stored there. Your late-night questions, your health worries, the draft of the email you'd never actually send, the thing you're too embarrassed to ask a real person. All of it lands in a database you don't own and can't see.

And a database that exists can be leaked. It can be hacked. It can be handed over. It can be sold when the company runs low on cash. It can be read by an employee having a bad day. You are trusting that every single person and system between your phone and that server does everything right, forever. This leak is what happens when one link in that chain slips.

The problem was never a bad password on one app. The problem is the model itself: your private thoughts are living on someone else's computer.

What if there were no server to leak?

This is exactly why we built VaultAI.

VaultAI is a private AI that runs entirely on your own computer. It comes on a drive you plug in and own. The AI lives on that drive. When you ask it something, your words are answered right there on your machine — they never leave. There is no account to sign up for. Nothing gets uploaded. Nothing gets stored on a company's server, because there is no company server in the picture at all.

Think about what that changes. You can't leak a database that doesn't exist. A researcher can't stumble onto your chat history in the cloud, because your chat history isn't in the cloud — it's on the drive in your hand.

No cloud, no leak

Your conversations stay on your device. There's no online database holding your chats, so there's nothing sitting out there to be exposed, hacked, or sold.

No account, no tracking

No sign-up, no email, no profile quietly following you around. VaultAI doesn't know who you are, and it doesn't need to.

Works fully offline

Unplug the internet and VaultAI keeps working. That's the simplest proof your words aren't going anywhere — there's no connection for them to travel on.

Yours to keep

One purchase, no subscription. Ask anything, without a censor and without a meter running. The AI is yours, the way owning a book is yours.

People turn to AI for the most human reasons — to think out loud, to get help they're nervous to ask for, to work through something private. That honesty is the whole point. It should never become a liability the moment a company forgets to lock a door.

The lesson from 300 million leaked messages

Every convenient AI app in the cloud is making you a quiet bet: trust us to guard your most private words, on our servers, indefinitely. Twenty-five million people just found out how that bet can go. Not because they did anything wrong — but because the words were somewhere they could be taken.

The only conversation that can't leak is the one that never left your side. That's the entire idea behind VaultAI: keep the power of AI, and keep it to yourself.

Get Private, Offline AI — $399

Latest Stories

This section doesn’t currently include any content. Add content to this section using the sidebar.
Powered by Omni Themes