A mobile app called Chat & Ask AI has been found to have exposed around 300 million private chatbot messages linked to more than 25 million users.
The app has over 50 million users across Google Play and the Apple App Store, which is almost double the population of Australia.
The issue was identified by an independent security researcher.
How the Chat & Ask AI data leak was discovered
The researcher was not using the app in a personal capacity when he found this. He was conducting broader checks for exposed Firebase databases across mobile apps, a known and recurring cloud security issue.
Firebase is a common backend platform used by developers to store app data. If its security rules are set incorrectly, databases can be left open to the internet without authentication. Researchers and cyber teams have been flagging this type of issue for years.
In this case, the researcher had built or used a tool to scan mobile app backends for publicly accessible Firebase databases. If a database responds without credentials, it is flagged for review.
Chat & Ask AI was identified during his sweep. After confirming the database was accessible, he reviewed a sample of the data to understand the scope before disclosing it to the developer.
What information was exposed in the AI chat database
The exposed records reportedly included full chat histories, timestamps, selected AI models and user defined chatbot names. Some of the messages seen in sampled data included questions about suicide, drug production and hacking.

Chat & Ask AI, developed by Codeway
Chat & Ask AI doesn’t run its own AI model. It connects users to large language models built by companies such as OpenAI, Anthropic and Google. While those companies power the responses, the app itself stores the conversations. The issue in this case was not with the models, but with how those stored chat records were secured.
According to reporting, Codeway secured the database across its apps within hours of being notified. There is no public evidence at this stage that the data has been weaponised, but once information is accessible on the open internet it can be exploited quickly.
Why AI chat privacy risks are increasing
We covered a separate AI incident late last year involving NSW flood victims’ data being uploaded into ChatGPT. Sensitive government information ended up inside a public AI system during routine work.
This exposure happened differently, but it sits in the same space. AI tools are being used more often, while conversations about storage and access control tend to come later.
For people working in security or research, the way this was uncovered is familiar. Checking for exposed cloud storage is standard practice.
What’s different in this case is the volume of data. When an AI chat app stores full conversations, that database can grow so quickly, and the content is generally a lot more personal than what you would see in a typical mobile app backend.
What organisations should review when using AI tools
If your staff or students are using AI tools, it’s worth knowing where those conversations are stored and who controls access to them. Many AI chat apps retain complete, full histories. Over time it can become a very detailed record of someone’s internal thinking, personal issues and operational context.
In this instance, 300 million messages were accessible because of a backend configuration setting. When AI usage grows alongside cloud storage, the exposure surface grows with it.
Continuous monitoring of cloud assets and exposed services is what picks this up early. It’s the same reason managed cybersecurity services and detection programs focus on continuous monitoring rather than reacting after damage is done.



