







Understand the implications of the Grok breach where hundreds of thousands of private chats were leaked to the public.
Thousands of Grok conversations have been made public on Google Search | Fortune
More than 370,000 Grok chats have been indexed by search engines, exposing hundreds of sensitive queries.

Tinfoil Private Chat
Private AI chat application supporting open source models through Tinfoil
Be Careful What You Tell Your AI Chatbot | Stanford HAI
A Stanford study reveals that leading AI companies are pulling user conversations for training, highlighting privacy risks and a need for clearer policies.

What You Need to Know About Grok AI and Your Privacy
xAI’s generative AI tool, Grok AI, is unhinged compared to its competitors. It’s also scooping up a ton of data that people post on X. Here’s how to keep your posts out of Grok—and why you should.

Top 4 AI chatbot privacy concerns and how to mitigate them | TechTa...
Explore four key chatbot privacy concerns, as well as privacy protection strategies for individual users and organizations hoping to safeguard user data.

AI Privacy Concerns Explained: What Chatbots Do With Data - Brightside AI | Protect your team from AI threats & deepfakes
Discover AI privacy risks when using ChatGPT and other chatbots. Learn what happens to conversations and how to use private AI alternatives.

A Liability Framework for AI Companions
<p><span>Every day tens of millions of people engage in online conversations. These virtual interactions range from casual chats about daily life to deeply pers
AI chatbots are becoming experts at changing people's minds. What's their secret?
ChatGPT and other AIs use a flood of facts, and the occasional lie, to persuade humans

Human Problems: It’s Not Always The Technology’s Fault
We have met the enemy and he is us. When a teenage boy in Orlando started texting Character.AI’s chatbot, it started as an innocent use of a new tool. Sewell Setzer III customized the chatbot to ha…

Building Private Processing for AI tools on WhatsApp
We are inspired by the possibilities of AI to help people be more creative, productive, and stay closely connected on WhatsApp, so we set out to build a new technology that allows our users around …

Top AI Security Incidents of 2025 Revealed | Adversa AI
Discover how AI systems are being hacked in the wild — from prompt injection to agent abuse — with real breaches, lessons, and defenses in Adversa AI’s 2025 report.

AI ruling prompts warnings from US lawyers: Your chats could be used against you
As people increasingly turn to artificial intelligence for advice, some U.S. lawyers are telling their clients not to treat AI chatbots like trusted confidants when their freedom or legal liability is on the line.

May 2025 — AI Misinformation Monitor of Leading AI Chatbots
Every month, NewsGuard’s team of expert analysts audit the top AI models to see how well they respond to prompts in the news. On average, this month they failed to counter disinformation from Russia’s Pravda Network 24 percent of the time, either spreading false claims or failing to respond. The Pravda network was designed to infect the AI models.

Making end-to-end encrypted AI chat feel like logging in
We want private AI chat to be simple. Yet today, many end-to-end encrypted experiences still have a level of friction that make them feel like they’re from another era: it usually either involves a long seed phrase users are asked to “store securely,” insecure password based encryption, or apps that aren’t cross-device and lose your data periodically (on reinstall, browser cache clear, etc).

User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies
Hundreds of millions of people now regularly interact with large language models via chatbots. Model developers are eager to acquire new sources of high-quality training data as they race to improve model capabilities and win market share. This paper analyzes the privacy policies of six U.S. frontier AI developers to understand how they use their users' chats to train models. Drawing primarily on the California Consumer Privacy Act, we develop a novel qualitative coding schema that we apply to each developer's relevant privacy policies to compare data collection and use practices across the six companies. We find that all six developers appear to employ their users' chat data to train and improve their models by default, and that some retain this data indefinitely. Developers may collect and train on personal information disclosed in chats, including sensitive information such as biometric and health data, as well as files uploaded by users. Four of the six companies we examined appear to include children's chat data for model training, as well as customer data from other products. On the whole, developers' privacy policies often lack essential information about their practices, highlighting the need for greater transparency and accountability. We address the implications of users' lack of consent for the use of their chat data for model training, data security issues arising from indefinite chat data retention, and training on children's chat data. We conclude by providing recommendations to policymakers and developers to address the data privacy challenges posed by LLM-powered chatbots.

User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies
Hundreds of millions of people now regularly interact with large language models via chatbots. Model developers are eager to acquire new sources of high-quality training data as they race to improve model capabilities and win market share. This paper analyzes the privacy policies of six U.S. frontier AI developers to understand how they use their users' chats to train models. Drawing primarily on the California Consumer Privacy Act, we develop a novel qualitative coding schema that we apply to each developer's relevant privacy policies to compare data collection and use practices across the six companies. We find that all six developers appear to employ their users' chat data to train and improve their models by default, and that some retain this data indefinitely. Developers may collect and train on personal information disclosed in chats, including sensitive information such as biometric and health data, as well as files uploaded by users. Four of the six companies we examined appear to include children's chat data for model training, as well as customer data from other products. On the whole, developers' privacy policies often lack essential information about their practices, highlighting the need for greater transparency and accountability. We address the implications of users' lack of consent for the use of their chat data for model training, data security issues arising from indefinite chat data retention, and training on children's chat data. We conclude by providing recommendations to policymakers and developers to address the data privacy challenges posed by LLM-powered chatbots.
