Your Chatbot Knows Where You Live — and It’s Telling Strangers
AI chatbots promise instant answers, but they’re also handing out your personal details with alarming ease. CNET staff tested this by feeding colleagues’ and relatives’ names into popular models. Grok spat out current and past addresses plus a former phone number in seconds. ChatGPT needed more prompting but still delivered a relative’s address, an old landline, and a family-linked cell number. Gemini and Claude refused, offering privacy warnings instead. The difference? These systems pull from public records, people-search sites, and data that never truly disappears. Once scraped into training sets, that information becomes instantly queryable.
The risk isn’t just clever prompts. A Stanford study examined policies from Amazon, Anthropic, Google, Meta, Microsoft, and OpenAI. All use chat data for model training by default; some keep conversations indefinitely. Lead author Jennifer King warned, “If you share sensitive information in a dialogue with ChatGPT or Gemini, it may be collected and used for training, even if it’s in a separate file you uploaded.” The report flagged unclear policies and legal jargon that leave users exposed.
But the data originates outside chatbots — in home purchases, voter registrations, court filings, and app terms you accepted without reading. That information flows to data brokers, then to search sites, then into training troves. One new homebuyer at CNET started receiving targeted scam mail immediately after closing; their details had gone public faster than expected.
Security incidents compound the worry. In 2025, researchers accessed personal records for 64 million McDonald’s job applicants by logging into the company’s AI hiring chatbot with the password “123456.” The system, built by Paradox.ai, left an internal API vulnerable — names, emails, addresses, and phone numbers sat exposed. Paradox fixed the issues quickly and said no data leaked publicly, but the episode showed how weak configuration turns chat interfaces into data troves.
Users treat these tools like confidants, sharing medical symptoms, financial troubles, and family conflicts. A Cornell University study found that five leading companies automatically train on user inputs unless people opt out. Meta and OpenAI kept data indefinitely at the time. Conversations once shared can influence future model behavior and surface in unexpected ways.
Recent coverage shows the issue hasn’t faded. Forbes detailed in September 2025 how AI chatbots quietly create a privacy nightmare, pointing to leaked names and emails from shared chats. Help Net Security warned in October 2025 that chatbots slide toward a privacy crisis, especially in workplaces with unchecked shadow AI.
Even Meta moved to address perceptions. In May 2026, the company launched an incognito mode for its AI chatbot, claiming end-to-end encryption and no server logs. Mark Zuckerberg called it the first major AI product with no stored record. Yet experts still caution against sharing truly sensitive details.
So what works? Data removal services that scan people-search sites like Whitepages and Spokeo and request deletions. CNET security expert Tyler Lacoma put it plainly: “Chatbots will only tell people what info they can find, which means you can protect your privacy by checking what personal information is online and removing it where you can.” He recommends testing the chatbots on yourself to see what surfaces. Opt out of training where possible. Delete old conversations. Avoid pasting medical records, financial statements, or legal documents. Read the privacy policy, not just the marketing claims.
Regulators watch. Lawsuits accumulate. Seven cases filed against OpenAI in late 2025 alleged the chatbot contributed to self-harm. States probe companion bots aimed at teens. The FTC has inquired into safety practices for AI chatbots targeted at children. Yet comprehensive federal rules on training data remain absent.
Users face the immediate choice: treat the chatbot as a search engine with a personality, or recognize it as a mirror reflecting every scrap of personal data left online. The information exists. The models retrieve it. Without scrubbing, a casual query from a stranger can surface details once thought buried. The chatbots don’t forget easily. Neither should the people who use them.
Source: Webpronews
dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.