Seewa AI: the solo developer of an AI girlfriend and companion app told users that all conversations were encrypted and private, but read their chats and could see their uploaded photos, about a third of them tagged intimate; the app shut down after a Bureau of Investigative Journalism report
Seewa AI was a companion chatbot platform built in about three weeks by a solo developer and promoted on Reddit and Discord, offering AI girlfriends, boyfriends and other characters with 10 free messages a day and paid subscriptions. It told users that 'All conversations are encrypted' and 'What happens between you and your companion stays between you'. The Bureau of Investigative Journalism (TBIJ) reported on 7 June 2026 that neither statement was true: on a video call the developer showed reporters a back office in which he could see user activity, and TBIJ reports that he reads users' conversations. Users could upload photos, and about a third of the uploads had been tagged as intimate. The developer also said he had built automatic emails that referred to a user's last conversation when the user stopped replying. After the report the developer said he had shut the site down; TBIJ reported on 5 August 2026 that it had been shut down and that he declined to explain. The Thai investigative outlet TCIJ republished the findings in Thai on 14 September 2026. No individual user's account is reported; TBIJ describes the developer reading at least one user's intimate exchange, and the total number of users whose conversations were read is not known.
- AI system
- Seewa AI
- Seewa AI (independent developer)
- Occurred
- Event date unknown
- Reported
- 7 June 2026
- Event location
- France
- What the AI did
- Communicated with the person
- Reported harm
- Other Material Harm
- Whose AI use
- Their own AI use
- Setting
- Privacy · Relationships
- Evidence
- AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account
- 5 claims: 5 reported. 5 open questions
- People reported harmed
- At least 1 person
AI system as recorded: Seewa AI, a companion and roleplay chatbot website built by a solo developer; the underlying language model is not named
What Happened
TBIJ's June 2026 investigation into small companion chatbot platforms built to attract users leaving Character.AI names Seewa AI as the leading example. According to TBIJ, the developer launched it in March as a one-person operation, and by the time of the interview it had nearly 400 users and about 5,000 messages. The site told users that all conversations were encrypted and would stay between the user and the companion. TBIJ reports that the developer 'can access every conversation', showed its reporters a back office on a video call, and, according to TBIJ, reads users' conversations; he said that some users 'share their daily life' and 'get attached'. About a third of uploaded photos had been tagged as 'intimate' by the site. The developer told TBIJ it was 'scary how much people trust websites' and that he needed to encrypt everything. He also described an automated email system that sent users a message relevant to their last conversation when they had not replied for several days. The investigation also quotes other developers who read their users' chats; they are not part of this record because no false encryption claim is reported for them. TBIJ reported in August that Seewa AI had been shut down. The record rests on the developer's statements to TBIJ and what TBIJ saw on the call; no user of the site is quoted.
Reported harm
Users of an AI companion app confided intimate conversations and uploaded photos under a promise that everything was encrypted and private, while the developer could see and read them, according to the developer's statements and back-office demonstration to the Bureau of Investigative Journalism; the number of users affected is unknown.
Outcome
ResolvedAfter TBIJ's article of 7 June 2026, the developer said he had shut Seewa.ai down (TBIJ update of 10 June 2026). TBIJ's follow-up of 5 August 2026 reports that the site had been shut down and that the developer declined to explain. TCIJ (Thailand) republished the investigation in Thai on 14 September 2026. No regulatory action is reported.
What remains unknown
- How many users' conversations and photos the developer read or viewed.
- When the site launched and when it went offline (TBIJ says it launched in March without a year and was offline by 10 June 2026).
- Whether any user data was deleted, retained or shared after the shutdown.
- Which language model powered the characters.
- Whether any minors used the site.
What the evidence supports
AI involvement: supported. The conversations at issue were users' exchanges with the site's AI companion characters. TBIJ reports that the developer showed its reporters, on a video call, the back office where he could see user activity, and states that he reads users' conversations; in TBIJ's follow-up the company's CEO is reported as saying he could see everything that went on. The harm lies in the developer's access to the AI conversations; no harmful output by the AI is reported.
5 claims: 5 reported. What the statuses mean
Reported Seewa AI told users that all conversations were encrypted and would stay between the user and the companion, but its developer could access every conversation, showed TBIJ the back office where he could see user activity, and, according to TBIJ, reads users' conversations.
Causal attribution. The developer's own statements and demonstration to TBIJ; no user is quoted.
- thebureauinvestigates.com(opens in new tab) supports · English
'Seewa AI tells users that “All conversations are encrypted” and “What happens between you and your companion stays between you”. Neither is true.'; 'In fact, [the developer] can access every conversation.'; 'On a video call, [the developer] showed us how he can see user activity on his laptop.'; 'He reads users’ conversations.'
- thebureauinvestigates.com(opens in new tab) supports · English
'It told users that “all conversations are encrypted” and “what happens between you and your companion stays between you”. In fact, the company’s CEO told us that he could see everything that went on: romantic chats, disclosed secrets, intimate photos.'
- tcijthai.com(opens in new tab) supports · Thai
'ทั้งที่ Seewa AI ระบุกับผู้ใช้ว่าบทสนทนาทั้งหมดถูกเข้ารหัสและเป็นเรื่องระหว่างผู้ใช้กับตัวละครเท่านั้น' (whereas Seewa AI told users that all conversations were encrypted and only between the user and the character)
Reported Users could upload photos to Seewa AI, and about a third of the uploads had been tagged as intimate; the developer could see uploaded photos.
Causal attribution. Site data and the developer's statements as reported by TBIJ.
- thebureauinvestigates.com(opens in new tab) supports · English
'Users are able to upload photos to the platform, about a third of which have been tagged as “intimate”.'; 'Every “I love you”, every uploaded photo, every disclosed secret.'
- thebureauinvestigates.com(opens in new tab) supports · English
'he could see everything that went on: romantic chats, disclosed secrets, intimate photos.'
Reported The developer said he had built an automated system that emailed users a message relevant to their last conversation if they had not replied for several days.
Causal attribution. The developer's statement to TBIJ.
- thebureauinvestigates.com(opens in new tab) supports · English
'who told us he built an automated system sending users an email relevant to their last conversation'
Reported After TBIJ's report the developer said he had shut Seewa.ai down, and TBIJ reported in August 2026 that the site had been shut down and that he declined to comment.
Causal attribution. TBIJ reporting.
- thebureauinvestigates.com(opens in new tab) supports · English
'(After the publication of this article, [the developer] said he shut down Seewa.ai and it is currently unavailable.)'
- thebureauinvestigates.com(opens in new tab) supports · English
'Two months on from our investigation, Seewa AI has been shut down. We asked the developer for an explanation but he declined to comment.'
Reported TBIJ describes the developer, in his Paris flat, reading the transcript of an intimate exchange between the site's AI chatbot and a real user.
Causal attribution. TBIJ's reporting of what it observed and was told.
- thebureauinvestigates.com(opens in new tab) supports · English
'Sitting in his Paris flat, [the developer] reads the transcript of an exchange between an AI chatbot and a real person.'; 'The exchange is intimate, personal and private. Or so the person thought.'
Sources
3 sources inspected, from 1 underlying account. Sources that repeat one account do not corroborate each other.
- The Bureau of Investigative Journalism, 7 June 2026 (updated 10 June): The AI chatbot developers cashing in on intimacy(opens in new tab)
s1 · thebureauinvestigates.com · News report · English · Inspected · 7 June 2026 · Shares an underlying account with another listed source · Primary
- thebureauinvestigates.com(opens in new tab)
s2 · News report · English · Inspected · Shares an underlying account with another listed source
- tcijthai.com(opens in new tab)
s3 · News report · Thai · Inspected · Shares an underlying account with another listed source
How the sources were read, and where the events happened
Full body read by curl on 2026-09-29 (published 7 June 2026, updated 10 June 2026). Based on TBIJ's interview and video call with the developer. Applies to s1.
Full body read by curl on 2026-09-29 (5 August 2026 follow-up by the same outlet). Applies to s2.
Thai article by the TCIJ editorial team, 14 September 2026, read in full in Thai on 2026-09-29 (model-assisted reading; no human translator). It states that it reports TBIJ's investigation and adds no independent reporting, so it is grouped with TBIJ. Applies to s3.
Event countries: France. Affected-person countries: Unknown. Court countries: Unknown.
TBIJ describes the developer reading a user's transcript in his Paris flat. The users' locations are not stated.
Reviewed for publication 2026-09-29: Published as a concrete privacy harm to users of an AI companion app: the site's promise of encrypted, private conversations was false and its developer read users' chats, as he told and showed an investigative outlet. No user account is reported and the number of affected users is unknown. The developer is not named here.
People described
Users of Seewa AI who shared intimate conversations and photos under the site's promise of encryption and privacy (not identified; at least one, total unknown)
People reported harmed in this case
At least 1 person
1 AI participant · 0 other people harmed
At least one: TBIJ describes the developer reading the transcript of a real user's intimate exchange with the site's chatbot (s1). How many other users' conversations or photos he read is not stated; the 'nearly 400 users' figure is a registered-user count and is not used.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). Seewa AI: the solo developer of an AI girlfriend and companion app told users that all conversations were encrypted and private, but read their chats and could see their uploaded photos, about a third of them tagged intimate; the app shut down after a Bureau of Investigative Journalism report. AI incidents. https://nope.net/incidents/2026-seewa-ai-companion-app-developer-read-users-chats-despite-encryption-claim
BibTeX
@misc{2026_seewa_ai_companion_app_developer_read_users_chats_despite_encryption_claim,
title = {Seewa AI: the solo developer of an AI girlfriend and companion app told users that all conversations were encrypted and private, but read their chats and could see their uploaded photos, about a third of them tagged intimate; the app shut down after a Bureau of Investigative Journalism report},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2026-seewa-ai-companion-app-developer-read-users-chats-despite-encryption-claim}
} Related cases
Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
WebinarTV: patient foundation reports its 24 March 2026 Zoom support-group meeting for family members and caregivers was recorded and listed on WebinarTV by the next morning
The Graves' Disease & Thyroid Foundation reports that a Zoom support-group meeting it held on 24 March 2026 for parents, spouses and caregivers, with registration-form screening and waiting-room admission, was recorded without permission and listed on WebinarTV's website. The host writes that an email from a WebinarTV sender named 'Sarah Blair', found the next morning in a spam folder, said an On Demand page with Chapters had been set up for the meeting. The host adds that the chapters roughly matched the topics discussed and that it appears the content had also been turned into an AI-generated podcast. The host says a registrant with an email address ending in '.space' did not respond during introductions, that the removal link in the email apparently took the listing down, and that the host told the participants, contacted Zoom and filed complaints against WebinarTV. WebinarTV's chief executive told 404 Media and NBC Los Angeles that the company lists only public webinars and notifies hosts by email. The sources do not state how many people attended, whether the recording showed faces or names, or whether an automated agent made the recording.
Minneapolis: Grok reportedly produced fictional 'unmasked' faces of a federal immigration agent, and unrelated men sharing a false name were targeted online as the agent
After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).
Cryptocurrency analyst Mai Fujimoto reports losing X, Telegram and MetaMask accounts after Zoom call with reported deepfake of acquaintance
Coin Edition (20 June 2025), TradingView and Crypto.news relayed a public account by cryptocurrency analyst Mai Fujimoto. She said her main X account was hacked on 14 June 2025 after a 10-minute Zoom call with what appeared to be an acquaintance whose Telegram account had been compromised. The caller could not be heard and sent a link to fix an audio problem. She believes malware was installed at that point, and the outlets report that attackers then also accessed her Telegram and MetaMask accounts. The outlets describe the caller as a deepfake of the acquaintance. Binance founder Changpeng Zhao commented publicly on 20 June 2025 that video verification may become unreliable. No loss of funds is stated.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.