Submit incident
Documented

Two AI Companion Apps Left 400,000 Users' Intimate Data Completely Exposed

January 1, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC2142View source ↗
LinkedInX

What happened

Two AI companion applications built by Imagime Interactive Limited exposed the private conversations, images, and personal data of more than 400,000 users in 2025. The apps, Chattee Chat and GiMe Chat, were available on iOS and Android and designed to encourage users to share personal thoughts, feelings, and intimate content with an AI system. That intimacy became a liability when the company's backend infrastructure was found to have no authentication, no access controls, and no encryption protecting what users had shared.

The exposure covered not just text conversations but more than 600,000 images and videos. While the leak did not surface explicit email addresses or legal names, it included IP addresses, device identifiers, purchase logs, and authentication tokens, each of which can be cross-referenced with other data sets to re-identify individuals. People whose content was exposed face potential extortion and the lasting psychological burden of knowing their most private exchanges are no longer private.

The cause was not a sophisticated attack. Investigators described the failure as leaving the front doors open to anyone who knew the address. Imagime Interactive's systems had no barrier between the data and the outside world. The company appears to have prioritized deploying features over establishing basic security foundations, a pattern common in fast-growing consumer app markets where competitive pressure consistently overrides security-by-design principles.

What makes the incident more than a simple data breach is the gap between what Imagime Interactive told users and what it actually built. The company's published privacy statements promised robust protections. The infrastructure delivered none of them. Users who trusted these apps with their most sensitive content were not only let down by a technical failure, they were misled about the level of care being applied to their data.

AI companions are designed to provoke disclosure. The more trust a user extends, the more sensitive the data sitting in the company's servers. When that dynamic is not paired with security infrastructure that matches the level of risk those disclosures create, the disclosure itself becomes the harm. A provable record of what a system stored, how it was protected, and who had access to it would make the gap between stated policy and actual practice visible before a breach turns it into news.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
Two AI Companion Apps Left 400,000 Users' Intimate Data Completely Exposed
2025