The three biggest exposures at AI companion services had one thing in common: no sophisticated attack. The data was either sitting where anyone could find it or was taken from a site with minimal protection. Understanding that pattern is the useful part.
Three incidents and what each cost users

Each incident as publicly reported.
Muah.ai (2024). An intruder took data from the "AI girlfriend" site and handed it to journalists. About 1.9 million email addresses were in it, each alongside the prompts its owner had typed to request pictures. Many prompts were sexual, and a few described abuse of children. Many addresses pointed to identifiable individuals. Troy Hunt, a security researcher, loaded the data into Have I Been Pwned and marked it sensitive. People named in the files were later targeted with extortion.
Chattee Chat and GiMe Chat (2025). A server belonging to the Hong Kong developer of both apps was sitting online with no password, and Cybernews researchers found it. It held 43 million-plus messages, along with upwards of 600,000 images and videos, tied to around 400,000 users, mainly American. Names and emails were not included. IP addresses, device identifiers and purchase logs were, and the logs showed that certain users had paid out thousands. Only after the server appeared on public search tools for exposed equipment did it get shut.
Secret Desires (2025). The platform's cloud storage was publicly readable, as reporters at 404 Media discovered. Nearly two million images and videos sat inside. Many were produced by a face-swap feature that inserted real women's photos (scraped from social media, graduation portraits, a yearbook) into sexual content. About an hour after the company was contacted, the storage was locked down. Secret Desires is on our review list, so readers who used its image tools should take note.
Why these apps attract attackers
- The data suits pressure campaigns. Sexual chats, fantasies and generated pictures are exactly what extortionists want.
- Operators are usually tiny. A fast-growing app with a handful of engineers, frequently assembled from open-source parts, often skips the security basics.
- Everything is retained. Remembering you means storing your history, and years of text accumulate; see what your AI girlfriend app knows about you.
- Images sit in cloud buckets. Misconfigured storage causes a great many leaks across the internet. For how companion pictures are kept, read where your pictures actually live.
A response plan if your data may be out
| Order | Action |
|---|---|
| 1. Look it up | Enter your email at haveibeenpwned.com; sensitive breaches ask you to confirm the address first |
| 2. Secure the account | Change the password here and wherever you reused it; turn on two-factor authentication |
| 3. Break the link | Re-register under an email address that carries neither your name nor your employer |
| 4. Brace for messages | Phishing and extortion emails that cite the breach are common afterwards, so expect some |
| 5. Hold your ground | Do not pay. Keep every message, then report it to the Canadian Anti-Fraud Centre (reportcyberandfraud.canada.ca or 1-888-495-8501) and to your local police |
| 6. Protect images | For intimate pictures, StopNCII.org can help participating platforms block them |
| 7. Ask the company | Find out what it holds on you and request deletion; see how to request your data |

Free to use. For sensitive breaches, you must first verify the address.
Limiting the damage in advance
- Use a throwaway-style email address with no trace of your name. No other habit helps as much, since it severs the connection between leaked data and your identity.
- Never upload your face or identifying details into images or generation tools.
- Do not name real people in chats, particularly a partner, a coworker or anyone placed in an explicit storyline.
- Delete what you do not need. Certain apps allow removal of individual chats or pictures, and nothing can leak from data that is gone. Deleting an AI companion account sets out what really disappears.
- Pick companies that answer security questions. Mozilla's 2024 review found that 73% of romance chatbot makers said nothing on handling security vulnerabilities. Publishing a security contact at least signals that a company wants to be told.
What Canadian law expects of the company
Under the federal privacy law, PIPEDA, an organization that suffers a breach of its security safeguards has to report it to the Office of the Privacy Commissioner of Canada, and tell the people affected, when it is reasonable to believe the breach creates a real risk of significant harm. The wording is "as soon as feasible" rather than a fixed number of days, and the company must keep a record of every breach for at least 24 months. Quebec's Law 25 works on a similar principle: a confidentiality incident that carries a risk of serious injury must be reported promptly to the Commission d'accès à l'information and to the individuals concerned.
The European 72-hour clock you may have read about does not apply here. A further caveat: how far these duties can be enforced against a small operator based overseas is uncertain, so do not wait for an email. Checking Have I Been Pwned yourself is the more dependable route. If you believe a company has mishandled your information, you can raise it with the Office of the Privacy Commissioner of Canada, or with the Commission d'accès à l'information if you live in Quebec.
The lesson of 2024 and 2025 is that private material held by a companion app is only as safe as that company's most careless employee. You cannot audit them. You can make sure that any leak would not lead to you.