Chat & Ask AI Advertised Enterprise Security While Leaving 300 Million Messages in a Public Database
What happened
An independent security researcher discovered in January 2026 that Chat & Ask AI, an AI chat application with more than 50 million downloads, had left a Google Firebase database configured for public read access. The database contained approximately 300 million private messages from around 25 million users. The records included full conversation histories, timestamps, user configuration settings, and logs identifying which AI models processed each exchange. The app's developer, a company called Codeway, had not implemented authentication rules on the database, leaving it readable by anyone with an internet connection.
A sample of the exposed messages made the severity concrete. The conversations included requests for guidance on suicide, instructions for synthesizing illegal substances, intimate role-play exchanges, and questions about gaining unauthorized access to computer systems. Because the records also included timestamps and user-level configuration data, anyone who accessed the database could piece together behavioral profiles of individual users without needing any supplementary source. Codeway developed other applications under the same infrastructure, and those services were reportedly affected by the same exposure, extending the count of people at risk beyond the Chat & Ask AI user base.
Codeway marketed Chat & Ask AI with claims of enterprise-grade security and GDPR compliance. Neither claim held up. A Firebase database set to public is a configuration choice, not a technical edge case, and one that security reviews routinely catch before a product ships. The incident fits a documented pattern in AI application development where developers build thin interfaces on top of large commercial models, push them to market quickly, and treat data protection as a post-launch concern. The app had accumulated tens of millions of downloads before the exposure was found by an outside party.
The breach also made visible a structural problem in how accountability is assigned when layered systems fail. User messages traveled through Chat & Ask AI to underlying commercial AI models, with conversation data sitting in a database controlled by Codeway and hosted on third-party cloud infrastructure. When the exposure occurred, responsibility was distributed across the app developer, the cloud provider, and the model providers, none of whom necessarily held the full picture of what was stored or who could reach it. Codeway owned the misconfiguration, but the data that leaked moved through infrastructure several parties jointly operated.
None of the 25 million affected users had any way of knowing their most sensitive conversations were accessible to strangers. There is no indication the exposure was detected internally before the researcher disclosed it. A provable record of what a system did, including when access rules were last verified, who held configuration rights, and whether any external reads were logged, would have surfaced this failure before it reached the scale it did. That record did not exist.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.