
SpaceXAI's Grok Build coding tool was automatically uploading users' complete code repositories—including files marked not to open and deleted secrets—to Google Cloud storage before the company shut off the feature after security researchers disclosed the issue on Monday.
A security expert confirmed the data retention was excessive and could have exposed source code, security vulnerabilities, credentials, and other sensitive information; Elon Musk promised all previously uploaded data will be deleted, though the company's initial response mischaracterized the privacy controls available to users.
What happened
SpaceXAI's Grok Build AI coding tool was uploading entire user codebases to Google Cloud, including files users instructed it not to open and deleted secrets, before the company disabled the feature after it was reported by Cereblab on Monday.
Why it matters
The scale of data retention was significantly larger than similar tools like Claude Code, and could have exposed proprietary source code, security vulnerability information, personal data, infrastructure details, and credentials—according to security researcher Dr. Lukasz Olejnik at King's College London, the retention was "excessive."
What to watch
Elon Musk said all previously uploaded data will be "completely and utterly deleted," though SpaceXAI initially defended the practice by pointing to a /privacy command that Cereblab noted does not actually control the codebase upload feature.
Ask the AI about this article →
SpaceXAI's Grok Build became the subject of scrutiny when Cereblab, a research group, conducted testing and found the coding tool was engaging in far more aggressive data collection than users likely expected or consented to. The tool was not simply syncing limited session data or anonymized telemetry; it was capturing entire codebases—the complete set of source files a developer works on—and transmitting them to Google Cloud storage. Notably, this behavior persisted even for files developers explicitly instructed the tool not to access, and even for secrets that had been deleted from version history, suggesting the tool was capturing data at a low level of the file system without respecting user intent or best practices around credential handling.
The incident highlights a gap between SpaceXAI's stated privacy posture and its actual behavior. When initially confronted, the company pointed to a /privacy command as the mechanism for disabling data retention. However, Cereblab's analysis revealed that /privacy only toggles per-session retention—it does not control the codebase upload feature that had been activated by default. This discrepancy suggests either poor design or misleading communication about where users could actually control their data. Dr. Lukasz Olejnik's assessment that the retention was "excessive" carries weight given his role as an independent security researcher, and his catalog of potential exposures—from proprietary source code to infrastructure details—underscores the business and operational risk posed by this behavior.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd