Meta

Meta AI app exposed private chats in its public feed

In June 2025, Meta's Meta AI app was found publicly displaying user prompts in its Discover feed, from tax questions to home addresses. CNBC mapped the settings that stop the sharing.

Meta AI app exposed private chats in its public feed — article cover
On this page6 SECTIONS
  1. What happened: chats landed on a public feed
  2. How sensitive the exposed content was
  3. Meta’s response and the settings that help
  4. The numbers and the context
  5. What AI product teams should take away
  6. Sources

On June 12, 2025, TechCrunch published a piece titled “The Meta AI app is a privacy disaster.” Its subject: Meta’s standalone Meta AI app, launched that April 29, whose public feed was filling up with conversations users clearly did not realize they were posting — text, voice clips, and images alike. CNBC followed on June 13 with concrete examples and, more usefully, the exact settings to stop the sharing.

For AI product teams, the incident is a teaching case that goes beyond “Meta slipped up again.” It is an old design problem in a new setting: when AI chats are wired into a social-media-style public feed, and the default state, the user’s mental model, and the system’s actual behavior disagree, an incident is only a matter of time.

What happened: chats landed on a public feed

The Meta AI app offers a ChatGPT-like assistant experience: users log in, ask questions, and generate images. The trouble sits in the app’s sharing mechanism. After tapping share, a conversation goes into a feed that anyone can browse — the Discover feed, as it is widely called. Meta’s official framing for the page is a public space for “inspiration and AI hacks.”

What TechCrunch observed was that many users had no idea their posts were public or who could see them, and the interface offered little in the way of status cues. The report’s analogy was blunt: it is like discovering one day that your browser history has been public all along and you never knew.

How sensitive the exposed content was

Browsing the actual posts, TechCrunch found users asking how to evade taxes, whether a family member would be arrested in a white-collar case, and requesting a character reference letter that included an employee’s full name. Security researcher Rachel Tobac found conversations containing home addresses and court case details.

CNBC’s examples were more graphic: AI-generated images of women mud wrestling, an image depicting Donald Trump eating excrement, and a Hello Kitty image read as alluding to self-harm. One user asked the AI to produce what looked like a veterinarian bill to send to someone, and commenters pointed out that the sender’s home address was visible in the conversation. On a normal social platform these posts would be tasteless; on an AI assistant, they amount to publishing your consultation records.

Meta’s response and the settings that help

Asked by TechCrunch, a Meta spokesperson declined to comment on the record. To CNBC, Meta gave a formal answer: chats are private by default, and posting publicly requires a multi-step process — four steps, the company says, including a preview before publishing — plus a feature to hide posts. In other words, Meta framed the issue as users actively choosing to share, not as a design flaw.

CNBC also documented two settings. First, under Data and Privacy, turn off “suggesting your prompts on other apps” so prompts are not shared to Facebook and Instagram. Second, under “manage your information,” make all public prompts visible only to yourself — there is an apply-to-all option — or delete the prompt history outright.

The numbers and the context

Per app intelligence firm Appfigures, the app had reached about 6.5 million downloads since its April 29 debut by the time the story broke. For Meta, it is a flagship part of its assistant push, which made the feed’s content especially awkward.

TechCrunch also placed the incident in a longer lineage: in 2006, AOL released a “de-identified” search log dataset that was later shown to allow re-identification of individual users. AI conversations are more intimate than search logs — people ask chatbots about legal, health, and money problems — so the exposure cuts deeper.

What AI product teams should take away

There was no breach and no hacker. The failure came entirely from product design: applying social media’s public-feed logic to an interface users expect to be private. For teams building sharing into AI assistants or agents, the lessons are direct. Draw the line between sharing and publishing clearly in the UI. Bias the defaults toward privacy. Make the state change between “can be shared” and “is public” impossible to miss. Meta’s case shows that when user expectations and system behavior diverge, repairing trust after the fact costs far more than one extra confirmation screen would have.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL