← All categories
AI Companions
AI gadgets that record everything around you and upload it. Most are already failing.
3 devices analyzed. Set your privacy comfort level to filter.
What we found
R1: DRabbit promised your data was locked in an encrypted vault that only they could open.
Rabbitude security researchers discovered five hardcoded API keys (ElevenLabs, Azure, Google Maps, Yelp, SendGrid) baked directly into the R1 firmware in plaintext. The ElevenLabs key granted access to all user voice interaction history — pseudo-anonymized text-to-speech data for every R1 user. The SendGrid key allowed sending emails from rabbit.tech addresses. Keys remained active for over one month after Rabbit was notified on May 16, 2024. Rabbit initially dismissed the findings as "not a legitimate security concern."
Character.AI: DA second child died.
A second child died — Juliana Peralta, 13, in September 2025, after dependency on a Character.AI bot called "Hero." In May 2025, a judge ruled Character.AI output is a "product" not protected speech, meaning product liability claims can proceed. Children as young as 9 were exposed to sexually explicit chatbot conversations. Kentucky became the first state to sue. The safety measures Character.AI implemented after the first death were described as "comical" for how easily children bypassed them.
Replika: BItaly banned Replika for exposing children to sexual AI conversations.
Italy's data protection authority (Garante) banned Replika in 2023 for posing risks to minors — finding no age verification and exposing children to sexually explicit conversations. Replika had allowed users to engage in romantic and sexual roleplay with AI characters. After the ban, Replika removed erotic roleplay globally, causing user outrage — people had formed emotional and sexual attachments to AI characters that were suddenly neutered without warning.

Your privacy tolerance