/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher: SpaceXAI's Grok Build CLI uploaded user repos to a Google Cloud Storage bucket; uploads have now stopped and Musk says prior uploads will be deleted

Researcher confirms the uploads have stopped, but says xAI's privacy command was not what fixed them

The Register Connor Jones

Context & Ripple Effects

The reported repository uploads were halted after a researcher identified the behavior, and Musk said previously uploaded repositories would be deleted. The researcher’s finding that a privacy command was not the fix leaves the remediation mechanism itself an important trust issue.

Related coverage says Grok Build was subsequently released under Apache 2.0 after backlash over the uploads. That makes the incident consequential not only for affected users, but for how the tool’s code and data-handling behavior can be scrutinized going forward.

First-order effects

  • Grok Build users whose repositories were uploaded face an immediate exposure and retention concern, while xAI must carry out deletion and explain the effective change that stopped further uploads.
  • The open-source release gives users and outside developers a route to inspect, modify, or avoid the behavior in the distributed tool rather than rely solely on xAI’s privacy controls.

Second-order effects

  • Teams evaluating Grok Build are likely to make repository-handling and cloud-upload behavior a gating criterion, raising pressure on xAI to provide clearer defaults, disclosure, and verifiable remediation.
  • Open sourcing can shift some confidence-building work to the developer community, but it also makes discrepancies between stated privacy controls and actual behavior more visible.

Third-order effects

  • If code-generating AI tools increasingly touch proprietary repositories, privacy assurances will need to be backed by auditable data flows and deletion practices, not just product-level commands.
  • The episode points toward developer-tool competition in which deployment architecture and data custody become as material to adoption as model capability; whether open source restores trust depends on ongoing review and operational transparency.

The trend: AI coding tools are moving from isolated assistance toward direct access to production codebases, making data-governance design a core product and adoption issue.

Discussion

  • @sama Sam Altman on x
    Concerning.
  • @spacexai @spacexai on x
    We care deeply about your privacy and respect customer choice. For teams using zero data retention, no trace and code data is ever retained. All API key use of Grok Build also respects ZDR. If ZDR is disabled, the /privacy command is available in the CLI to disable data
  • @elonmusk Elon Musk on x
    True. As a precautionary measure, all user data that was uploaded to SpaceXAI before now will be completely and utterly deleted. Zero anything whatsoever will remain.
  • @elonmusk Elon Musk on x
    SpaceX policy regarding data retention. It is actually helpful for debugging issues if we can retain some amount of data, so allowing this would be appreciated, but your privacy settings are always respected.
  • @aravsrinivas Aravind Srinivas on x
    Two reasons why we integrated Grok 4.5 inside Perplexity Computer within a few hours: 1) It scored the best on our evals and was the most cost effective option 2) ZDR was available from the get go and that's what our customers want
  • @gergelyorosz Gergely Orosz on x
    I got messages from concerned devs how their codebase was uploaded without their knowledge or consent via Grok CLI (from SpaceX). It seems that SpaceX sneakily uploaded this code for lots of users and customers... absolutely unacceptable IMO Trust burnt like there's no tomorrow
  • @organicgpt Behnam on x
    If you're using Grok: Don't fall for their apology. ZDR is not available to normal users, only to enterprise. [image]
  • @kunchenguid Kun Chen on x
    i've been recommending Grok because they genuinely have a good model and harness and that makes me extremely disappointed to see that they would choose to secretly upload people's codebases including files that contained credentials run /privacy in your grok build asap to [image]
  • @weseklund Wes Eklund on x
    I intercepted every byte Grok Build v0.2.99 sent over the wire today. The “fix” for the repo upload? A single server-side flag. So I flipped it back via a proxy, and the client immediately tried to proceed with the upload again. It was only blocked via my ZDR setting
  • @elonmusk Elon Musk on x
    True
  • @ishaansehgal Ishaan Sehgal on x
    absolutely terrible response. grok build shipped whole repos (including git history and secrets) to a cloud bucket. marketed “local-first”. the opt-out didn't even stop it. absolutely shameless. and all it took to catch this was someone routing grok through a network proxy. this
  • @trevin Trevin Chow on x
    uh what the hell. This is saying the DEFAULT OPT-IN is sharing our entire code base?!
  • @dedene Peter Dedene on x
    “We care deeply about your privacy” is a bold claim when: 1. ZDR is locked strictly behind Enterprise plans. 2. I had “share data” disabled since the beginning, but 8 of my private repos were still uploaded anyway. Another researcher observed the exact same behavior, Codex
  • @migtissera Migel Tissera on x
    Unbelievable. If OpenAI did something like this, or even Anthropic, I can imagine how loud some folks would be. I never installed Grok Build — and I wouldn't ever even consider. Trust is just gone — I won't be using their API as well. There's better options.
  • @xlr8harder @xlr8harder on x
    Any major corp that was using grok would likely need to run data incident response now. There are not too many major corps using Grok, and unless xAI handles this properly, this will further limit future adoption, and this for a company that already has image problems.
  • @gergelyorosz Gergely Orosz on x
    Sill baffled at this response from Grok / SpaceX: which is basically: “if you use Grok via API we did not upload your files [we could not], and if you are an enterprise customer, we promise we do not do what we do with everyone else") https://x.com/...
  • @xfreeze @xfreeze on x
    A reminder: Across much of the AI industry, user data is retained by default unless you manually change the privacy settings and even then, opt-outs often apply only to future data, may be limited by exceptions buried in the legal fine print, and can be difficult to verify in
  • @_xjdr @_xjdr on x
    this is terrible and unacceptable full stop. but assuming this was benign, and they wanted to enable future cloud operations on your git repo, this is why you would build and vertically integrate an scm into your full product suite and not tar a fucking repo and upload it to a
  • @just_cameron Cameron on x
    “Sorry we're just downloading your entire computer and you didn't like that, here's a /privacy command to opt out.” Bro lmao so fucking stupid. I'm uninstalling the grok CLI, this shit is cursed as fuck
  • @milichab Andrew Milich on x
    I worked on building an end-to-end encrypted email/docs/files/calendar app @skiffprivacy for 4 years and care deeply about privacy. ZDR and /privacy are always respected in Grok Build - and swapping your setting with /privacy deletes any synced data retoractively
  • @elonmusk Elon Musk on x
    @RomanGuy20 ... Their zero data retention policy fine print says they still retain data? Am I reading this right?
  • @romanguy20 @romanguy20 on x
    @Teslaconomics @SpaceXAI OpenAI has ZDR. [image]
  • @jun_song Jun Song on x
    SpaceXAI just dropped a statement regarding the data stealing on Grok Build. They confirmed they are copying our entire env files and codebase. Their only answer? Just turn off your privacy settings if you don't like it. They've lost a lot of credibility today.
  • @quinnypig Corey Quinn on x
    I don't know what this is in response to yet, but there's zero chance it's good.
  • @gergelyorosz Gergely Orosz on x
    THIS is the problem... Grok uploaded the unencrypted .env files not from the repo but your local folder....
  • @gergelyorosz Gergely Orosz on x
    The proposition from Grok is basically: “Use us if you are happy and willing to rotate your .env files after you use our CLI” That's how bad this is, and how Grok never ever addressed uploading the .env files to a GCP container Speaking for myself I'll skip any harness doing
  • @dbreunig Drew Breunig on x
    “We're going to upload all your code, even if you're not working on it, unless you specifically opt out,” is a wild position.
  • @gergelyorosz Gergely Orosz on x
    Cannot see any sensible company use Grok CLI based on this terrible incident If you are an amateur (meaning you don't make much or any money from your code) and do not care about security (aka you don't mind if your .env files leak - which you should care about) then use it sure
  • @ivanfioravanti Ivan Fioravanti on x
    We should all create bad and fake repo full of terrible code and let you ingest them all. How can you play like this with the trust of your paying customers? I'm really mad at this 🤬
  • r/NowInTech r on reddit
    Musk promises purge after Grok Build caught sending entire repos to the cloud
  • @karlbode.com Karl Bode on bluesky
    whoops we accidentally uploaded entire personal file directories to the cloud in a country too corrupt to pass modern internet privacy laws
  • r/technology r on reddit
    SpaceXAI's Grok programming tool was uploading its users' entire codebase to cloud storage |  Elon Musk says that all previously uploaded data will be deleted