Skip to content
NNeoPioneer
AI & Modern ToolsJun 28, 2026 · 5 min read

Built an App With AI? You're One Setting From a Data Leak.

A guy built an app with AI, posted that he didn't write a single line of code, and then 4.75 million records walked out the door. The cause was one setting he didn't know he needed. Here's the short list that keeps you off that list, from someone who's been shipping software for 13 years.

A guy built an app with AI. He was proud of it. He posted, "I didn't write a single line of code. AI made it a reality."

Then researchers looked at it. One and a half million credentials. Tens of thousands of emails. Private messages with people's API keys, sitting there in plain text, readable by anyone who knew where to look. Around 4.75 million records in all.

The cause wasn't some genius hack. The database key was sitting right there in the app's code, in the browser, where anyone could grab it. And there was nothing protecting the data behind it. Someone just walked in and copied everything.

I've been writing software for 13 years. The scary part isn't that it happened. It's that the AI that built his app could have warned him, and didn't. And right now there are thousands of apps just like it, holding real people's data, with the exact same hole.

This isn't one guy who got unlucky

Someone scanned thousands of AI-built apps. One sweep of 5,600 of them turned up more than two thousand security holes, hundreds of them exposed secret keys. A wider scan found apps leaking the kind of personal data you really do not want loose: medical records, bank account numbers. And on one popular build-with-AI platform, about one in ten apps was actively leaking its users' data, right there for anyone who bothered to look.

And here's the part that should get your attention if you're building with AI right now: almost all of it comes down to the same one or two mistakes.

Why it keeps happening

Nobody tells the vibe-coding crowd this. AI builds exactly what you ask for. It does not build what you forgot to ask for.

You say, "make me an app where people can sign up." It does. It works. It looks great. You ship it. What you didn't say was, "and make sure one user can't read every other user's data." So it didn't. And the AI is not going to stop and say, "hey, you're about to leak everyone's email and probably break a law." It just builds the thing you asked for.

That gap, between what you asked for and what you actually needed, is where every one of these disasters lives. The only thing that fills it is someone who's done this before, knowing what to look for.

I ran the check on my own site

I'm not going to tell you my site is flawless. The opposite. There's a security screen built into the database tool I use. Think of it as a robot that walks in trying to break things, then hands you the list. I ran it on my own live site.

The good news: the big setting, the one that sank that first app, was already on across the board. I don't have that hole. But the screen still found two smaller things to tighten, and I fixed them in about two minutes. One of them let someone skip my signup form and write straight to the database. Not a leak, nobody could read anything, but it was a door I never meant to leave open.

That's the whole point. Nobody ships perfect. You ship checked. Screen, fix, screen again until it's quiet.

This is about to get expensive

It's also about to stop being just embarrassing. The rules around this kind of data keep tightening, in California and in the EU, and they carry real penalties now. The average breach that exposes personal data runs into the millions. You don't have to become a security expert. You have to know the handful of places things go wrong, and care enough to check.

So I wrote down the handful. Eight things, plain English, each one a few minutes to verify:

  • Is your database locked so users only see their own data?
  • Are any secret keys hiding in your frontend?
  • Are you storing data you don't actually need?
  • Do your private actions check who's asking, on the server?
  • Are your secrets in env vars and out of git history?
  • Are you validating what users send before it hits the database?
  • Does your privacy policy match what the code really does?
  • Has someone who's done this actually looked at it?

The printable below has the exact thing to verify for each one, plus the two-minute self-audit I ran on my own site. Grab it, run it on whatever you've built, and don't let your proudest post become the headline.

And if you've built something with AI, you're about to handle real customer data, and you want experienced eyes on it before you ship, that's literally what I do. Hit reply on the email and tell me what you're building.

letter · sundays only

The Frontier

One short letter every Sunday. The week's best move across the five pillars. No filler, no ads.

Free. Unsubscribe anytime. We use your email only for the letter — see our privacy policy.