Privacy News · OffgridScribe
50 Million People Thought Their AI Chats Were Private. They Weren't.
August 2026
In January, an independent security researcher found something they weren't supposed to be able to find: an exposed database belonging to Chat & Ask AI, an AI chat app with more than 50 million users across the App Store and Google Play. Inside were roughly 300 million messages from around 25 million people — full chat histories, timestamps, even which AI model each conversation used.
Some of those conversations covered exactly the kind of thing people assume stays private when they're talking to an AI: personal struggles, requests for help with sensitive situations, things typed late at night to a chatbot because it felt safer than saying them to a person.
"Private conversation" often means "sent somewhere else"
Chat & Ask AI isn't unusual in how it works. It's what's called a wrapper app — it doesn't run any AI itself, it just passes your messages along to other companies' models (in this case, a mix of providers) and shows you the response. That's a completely normal way to build an AI app. The problem isn't that the messages went somewhere. It's that "somewhere" turned out to be a database anyone could find, and nobody outside the company knew that until a researcher stumbled onto it.
This is the gap between what an app implies and what it actually does. "Chat privately with AI" reads like a promise. In practice, it usually means: your words leave your device, get processed by a server you don't control, get logged somewhere for debugging or model improvement, and stay in a database until either the company deletes it or — as happened here — someone else finds it first.
Where OffgridScribe is different
OffgridScribe doesn't send your recordings or transcripts to any server, ours or anyone else's. Transcription runs on your iPhone using an on-device model. There's no database of your conversations sitting somewhere waiting to be exposed, because there's no database at all — the text stays on your device, full stop. We've tested this ourselves and published the raw results rather than just asserting it.
The takeaway isn't "avoid AI apps"
It's worth being specific about what this incident does and doesn't mean. Plenty of AI apps handle data responsibly, and sending information to a server isn't inherently reckless — most software works that way. The actual lesson is narrower: if privacy matters for what you're using an app for, check whether "private" describes a promise or an architecture. A promise can be broken by a misconfigured database. An architecture where the data never leaves your device can't leak from a server, because there's no server holding it.
More from Offgrid Studio
Also read: What Popular Transcription Apps Actually Do With Your Recordings and We Tested OffgridScribe on a Phone Call.