Chat & Ask AI, an AI chatbot app with more than 50 million users on the Google Play and Apple App stores, left hundreds of millions of user conversations exposed in an unsecured database, according to an independent security researcher who goes by Harry and reporting by 404 Media. The exposed chats reportedly included users asking the app how to harm themselves, requests to write suicide notes, and questions about how to make illegal drugs and hack other apps.
Harry said he had access to roughly 300 million messages from more than 25 million users in the exposed database and extracted a sample of 60,000 users and about a million messages to verify the vulnerability. Chat & Ask AI functions as a "wrapper" app that connects users to underlying large language models from OpenAI, Anthropic and Google, and is developed by the Istanbul and Barcelona-based company Codeway.
The exposure was not limited to Chat & Ask AI. Harry said the vulnerability affected data across other popular apps developed by Codeway. He disclosed the flaw to the company on January 20, 2026, and Codeway fixed the issue across all of its apps within hours. Codeway's website states that it takes data protection seriously, citing SSL certification, GDPR compliance and ISO standards, but the company did not respond to a request for comment from 404 Media.
Source: Business & Human Rights Resource Centre, citing 404 Media -- https://www.business-humanrights.org/en/latest-news/millions-of-peoples-privacy-rights-reportedly-compromised-in-ai-apps-data-breach/