ChatGPT bug exposes other users’ conversation titles
OpenAI temporarily took ChatGPT offline after detecting a bug that allowed some users to see other people’s chat titles. The incident highlights privacy as an ongoing challenge for AI assistants.
On March 20, 2023, OpenAI temporarily took the ChatGPT web interface offline and reported an incident affecting history; at that date it had not yet published a complete technical explanation.
OpenAI temporarily took ChatGPT offline on Monday after detecting a bug that allowed some users to see titles from other people’s conversation histories. The company said it was already working on a fix.
This was not full access to the contents of the chats, but to their titles. Even so, those headings can reveal sensitive information: a medical question, a workplace issue, a personal problem or the name of a project. In an assistant designed specifically to receive questions in natural language, that exposure is enough to turn a technical failure into a privacy problem.
What happened
Affected users could find titles in the sidebar where ChatGPT stores conversation history that did not belong to their own chats. The error did not appear to display the full text of the exchanges or allow users to open them, but it undermined a basic expectation of the product: that each history is private and visible only to the person who created it.
OpenAI said it was investigating the source of the incident and chose to take the service offline while preparing a fix. It was a prudent measure, although it came after the data had already been exposed for part of the day.
ChatGPT gained popularity at an unusual pace after its public launch in late November. Millions of people use it to write, study, program or answer everyday questions. That adoption has taken the product beyond the realm of a technology demo: many people now give it context about their work, studies or private lives.
A title can also be sensitive information
The episode is a reminder of an important distinction between a private conversation and an anonymous one. A service may not ask for someone’s name in every message and still handle data that can identify them or describe a sensitive situation.
A title such as “Preparing for a job interview” might seem harmless on its own. Combined with other details, it could reveal that someone is looking for work. The same applies to questions about symptoms, family disputes, clients or internal documents. The risk does not depend only on whether a complete answer is visible; it depends on what can be inferred from any exposed fragment.
It also raises a practical question for companies and professionals. ChatGPT should not be treated as a local notepad or an internal work channel. Before pasting information into an external assistant, it is worth removing names, figures, client data and any detail that is not essential to getting help.
Security matters more after GPT-4
The failure came less than a week after OpenAI introduced GPT-4, its most advanced language model to date. The company has begun integrating the technology into ChatGPT for its Plus subscribers and has accelerated interest in its products among consumers and businesses.
The model’s capabilities are one part of the story; the reliability of the infrastructure serving it is the other. A model may write better, reason with more context or help with code, but the product will only be useful in professional settings if users trust that their data will not appear in someone else’s account.
In this case, OpenAI’s immediate response will be decisive: restore access once the error has been fixed and explain the scope of the incident precisely. For users, the lesson is already clear. AI assistants are powerful tools, but it is best to share the same information with them that one would share with any cloud service: what is necessary, and nothing more.
What was known that day and what remained open
The public status timeline recorded investigation, identification of a cause, gradual deployment of a fix and restoration of service while history remained unavailable. It did not yet explain the technical mechanism or full exposure. A story dated March 20 must preserve that boundary: describe reports of other users’ titles and an outage without importing explanations published later.
One sentence in the earlier text therefore needs correction: at that time OpenAI had not publicly attributed the incident to a particular library. The contemporaneous primary source supports saying that it was investigating the cause and working to restore history. Adding the later diagnosis would make the account more complete but false to the editorial date.
A title is metadata and may reveal as much as a sentence. Assess impact by asking which fields were visible, to whom, during what interval and whether they could be combined with other data. “The full chat could not be opened” narrows scope but does not prevent a heading containing a client name, symptom, project or employment intention.
How to minimise what is given to an assistant
Before pasting text, remove everything unnecessary for the task: names, identifiers, internal amounts, addresses, credentials and confidential clauses. If the goal is to improve style, replace entities with placeholders. If identity is essential, use an approved tool and document why.
An organisation also needs data classification. A colour or label should say what may enter an external service, what requires an enterprise contract and what must never leave. Useful control appears inside the workflow—templates, filters, permissions and training—not only in a policy nobody consults when rushed.
Incident response should preserve a timeline: first signal, containment, known scope, notification, remediation and verification. Do not wait to know everything before communicating, but separate fact from hypothesis in every update. The status record from that day is evidence for availability; it should not be presented as a forensic report.
The transferable skill is to minimise data before every conversation and read an incident according to what was known at each moment. Ask whether a field is necessary, substitute it where possible and preserve dated sources. Model power cannot compensate for an input that should never have left its system of origin.
Products generating titles automatically have a specific defence: do not build the heading from more sensitive information than necessary. A neutral user-selected name may leak less than a summary of the first message. History can also be hidden by default on shared devices and given a rapid deletion control.
Isolation tests use at least two accounts with clearly distinguishable data. Create conversations, induce load, cancellation and reconnection, then verify that every response and metadata field returns to the correct owner. The normal flow is not enough: network failures, retries and shared caches are precisely where boundaries can break.
After remediation, a negative test confirms that the former failure no longer reproduces and the fix did not mix another path. Keep technical identifiers without retaining more personal content than necessary. Useful transparency explains impact and measures without publishing details that enable abuse.
For individual users, the rule fits in one sentence: before writing, imagine the title visible on someone else’s screen. If that would cause harm or embarrassment, replace details or do not use the service. This does not remove provider responsibility, but reduces exposure while the product proves its controls.
That decision should be made before the first sensitive message is sent.
This article was produced with artificial intelligence under human editorial oversight.