AI Companion Data-Breach Tracker
AI companion apps invite some of the most intimate data a person ever types. This is a maintained, dated log of every documented breach, exposure and regulatory privacy finding in the category — what was exposed, how it happened, how serious it is, and the original source for each. We add incidents as they are reported.
Tap Cite on any figure to copy a sourced, linkable one-line citation — free to quote with attribution. Totals exclude regulatory fines (no records exposed).
| Date | App | Type | Scale | Severity | Status | Detail & sources |
|---|---|---|---|---|---|---|
| My Lovely AI Image-led app · My Lovely AI | Breach | ~106k accounts | High | Data circulating | OpenA 2.1 GB database from this NSFW image-generation companion was posted to a dark-web forum, exposing around 106,000 accounts: email addresses, links to generated images and roughly 113,000 explicit prompts, about 70,000 of them tied to individual user IDs. Have I Been Pwned flagged it as sensitive (not publicly searchable). The exposure contradicts the site’s marketing claim that it never shares user data. Exposed Email addresses113k explicit promptsLinks to generated imagesSome Discord / X usernames Cause Database exposed and posted to a dark-web forum. Sources Read our My Lovely AI review & privacy scorecard →
| |
| Chat & Ask AI General AI chat · Codeway | Exposure | ~300M messages · 25M users | Critical | Hole closed | OpenA security researcher found a misconfigured Google Firebase backend with no authentication and no encryption at rest, exposing roughly 300 million messages from about 25 million users of this popular general AI-assistant app (a wrapper over models from OpenAI, Anthropic and Google). The operator fixed the issue within hours of disclosure. Included for context: it is a general consumer-AI chat app rather than a dedicated companion, but its intimate-disclosure risk profile is the same. Exposed ~300M chat messagesFull chat historiesModel & settings metadata Cause Misconfigured Firebase database — no authentication, no encryption at rest. Sources
| |
| Chattee Chat & GiMe Chat Companion app · Imagime Interactive Limited | Exposure | 43M messages · 400k+ users | Critical | Hole closed | OpenResearchers found an unprotected Kafka streaming server handling two AI-companion apps from the same Hong Kong developer, exposing over 43 million messages and 600,000+ images and videos from more than 400,000 users. Names and emails were not in the data, but IP addresses and device identifiers were — enough to re-identify users when combined with other breaches. The server was secured after disclosure. Exposed 43M private messages600k+ images & videosIP addressesDevice identifiersIn-app purchase logs Cause Misconfigured Kafka broker left publicly accessible with no authentication. Sources
| |
| Replika Companion app · Luka, Inc. | Regulatory | €5M GDPR fine | High | Settled | OpenItaly’s data-protection authority (the Garante) fined Replika’s developer €5 million for GDPR violations: processing personal data without a valid legal basis, inadequate transparency, and — despite an adult, intimate product — no effective age-verification, so minors could access the service. A separate investigation into how the chatbot is trained was also opened. Not a data leak, but a formal finding that the company’s privacy handling broke the law. Cause No lawful basis for processing, weak transparency, no effective age assurance (regulator finding). Sources
| |
| Muah.AI Companion app · Muah.AI | Breach | ~1.9M accounts | Critical | Data circulating | OpenA hacker exfiltrated the AI-companion service’s database, exposing around 1.9 million email addresses tied to users’ chat and image-generation prompts. Reporters found tens of thousands of prompts describing child sexual abuse scenarios. The attacker described the backend as poorly secured, and the data was added to Have I Been Pwned. Exposed Email addressesChat promptsAI image prompts Cause Weak backend security; database accessed and exfiltrated. Sources
|
No incident matches every filter. Loosen one.
Each entry is research-assessed from public reporting and regulatory records, not a first-party security audit. Figures are stated as reported by the cited sources; where a source gives an approximate or a range, we record the conservative, widely-reported number. “Breach” means data was taken or leaked; “Exposure” means data was left publicly accessible through a misconfiguration; “Regulatory” is a watchdog finding or fine, not a leak, and is excluded from the exposure totals. Listing an app records a documented event at a point in time — it is not a claim about the app’s current security. Spotted an error or a missing incident? Tell us at info@companionscore.com.
Companion Score, AI Companion Data-Breach Tracker, companionscore.com/safety/data-breach-tracker (updated 22 June 2026). Free to cite and link with attribution under CC BY 4.0. Journalists and researchers: info@companionscore.com for the underlying data or comment.