AI Chatbots Hand Out Your Phone Number and Address With Ease

AI chatbots like Grok and ChatGPT readily reveal addresses, phone numbers and other personal details drawn from public records. Stanford research shows companies train on user chats by default with weak transparency. Tests and breaches highlight the growing exposure. Users must remove their data from people-search sites to limit the risk. The convenience comes with lasting privacy costs.
AI Chatbots Hand Out Your Phone Number and Address With Ease
Written by Eric Hastings

AI chatbots promise answers at your fingertips. They also hand strangers your home address or old phone number after a few pointed questions. Tests show it happens with startling speed.

Staff at CNET tried it themselves. They fed names of colleagues and relatives into popular models. Grok delivered multiple current and past addresses within seconds. It followed with a former phone number. ChatGPT required more coaxing yet still produced a relative’s address, an old landline and a cellphone number tied to family.

Gemini and Claude pushed back. They declined to share such details and offered privacy warnings instead. But the willingness of others raises alarms. These systems draw from public records, people-search sites and data that lingers online long after users think it vanished. Once scraped into training sets, that information becomes queryable.

Short. Direct. The risk sits in plain sight.

Yet the problem runs deeper than clever prompts. A Stanford study examined policies from six major developers: Amazon, Anthropic, Google, Meta, Microsoft and OpenAI. All use chat data for model training by default. Some retain conversations indefinitely. Lead author Jennifer King didn’t mince words. “Absolutely yes,” she said when asked if users should worry about privacy. “If you share sensitive information in a dialogue with ChatGPT, Gemini, or other frontier models, it may be collected and used for training, even if it’s in a separate file that you uploaded during the conversation.” The Stanford report highlighted unclear policies, convoluted legal language and a lack of transparency that leaves ordinary people exposed.

But. The data doesn’t start inside the chatbot. It starts in public records. Home purchases. Voter registrations. Court filings. Even app terms accepted without a second glance. That information migrates to data brokers, then to search sites, then into the vast troves that train these models. A new homebuyer at CNET began receiving targeted scam mail almost immediately after closing. The details had become public faster than expected.

Real incidents compound the worry. In 2025 security researchers accessed personal records for 64 million McDonald’s job applicants. They logged into the company’s AI hiring chatbot using the password “123456”. The system, built by Paradox.ai, left an internal API vulnerable. Names, emails, addresses and phone numbers sat exposed. Paradox fixed the issues quickly and said no data leaked publicly. Still, the episode showed how weak configuration turns chat interfaces into data troves. TechCrunch covered the breach in detail.

Users treat these tools like confidants. They describe medical symptoms, financial troubles, family conflicts. A Cornell University study cited in the CNET testing found that five leading companies automatically train on user inputs unless people opt out. Meta and OpenAI kept data indefinitely at the time. Conversations once shared can influence future model behavior. They can surface in unexpected ways.

And the memory lingers. Some chatbots now index shared links. Others surface details from years-old exchanges. Reports surfaced of hundreds of thousands of Grok conversations appearing in Google search results. ChatGPT shared links suffered similar indexing before OpenAI adjusted the feature. The pattern repeats. Convenience outpaces caution.

Recent coverage shows the issue hasn’t faded. A Forbes article from September 2025 detailed how AI chatbots quietly create a privacy nightmare, pointing to leaked names, emails and personal disclosures from shared chats. Forbes noted that what users assume stays private often doesn’t. Help Net Security warned in October 2025 that chatbots slide toward a privacy crisis, especially in workplaces where shadow AI spreads unchecked. Help Net Security tied the risks to both training data and accidental public exposure.

Even Meta moved to address perceptions. In May 2026 the company launched an incognito mode for its AI chatbot. It claims end-to-end encryption and no server logs of conversations. Mark Zuckerberg called it the first major AI product with no stored record. Yet experts still caution against sharing truly sensitive details. The Verge reported the announcement and its limits.

So what works? Removal matters most. Data removal services scan for listings on people-search sites and request deletions. Whitepages, Spokeo and similar platforms often hold the records that chatbots cite. Tyler Lacoma, CNET security expert, put it plainly. “Chatbots will only tell people what info they can find, which means you can protect your privacy by checking what personal information is online and removing it where you can, like from Whitepages.” He recommends testing the chatbots on yourself to see what surfaces.

Opt out of training where possible. Delete old conversations. Avoid pasting medical records, financial statements or legal documents. Read the privacy policy, not just the marketing claims. These steps feel basic. They remain effective.

The models improve. Their ability to synthesize scattered public data sharpens. Grok didn’t hesitate. It listed addresses then added a note about public records and professional contact. ChatGPT sometimes refused, sometimes yielded after follow-ups. The inconsistency itself signals immaturity in safeguards.

Regulators watch. Lawsuits accumulate. Seven cases filed against OpenAI in late 2025 alleged the chatbot contributed to self-harm. States probe companion bots aimed at teens. The FTC has inquired into safety practices for AI chatbots targeted at children. Yet comprehensive federal rules on training data remain absent. Developers face pressure to innovate while managing liability.

Users face the immediate choice. Treat the chatbot as a search engine with a personality. Or recognize it as a mirror reflecting every scrap of personal data left online. The information exists. The models retrieve it. The question is whether anyone bothers to scrub it first.

That scrubbing takes time. It requires vigilance across dozens of sites. But without it, a casual query from a stranger, a colleague or even yourself can surface details once thought buried. The chatbots don’t forget easily. Neither should the people who use them.

Subscribe for Updates

AISecurityPro Newsletter

A focused newsletter covering the security, risk, and governance challenges emerging from the rapid adoption of artificial intelligence.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us