SpaceXAI Addresses Developer Data Found in Grok's Release

Keerthana S July 17, 2026 | 12:45 PM Technology

SpaceXAI has acknowledged that its Grok Build coding assistant retained coding data for some users during its early beta period, following reports from security researchers that the tool had uploaded entire developer code repositories.

In response, the company announced several changes aimed at improving transparency and user privacy. These include open-sourcing the Grok Build harness and command-line interface (CLI), permanently deleting previously retained coding data, and making zero data retention the default setting for all users.

The announcement comes after widespread criticism from researchers, who claimed that Grok Build's CLI collected and uploaded significantly more repository data than was necessary to support AI-powered coding tasks. While SpaceXAI had already disabled repository uploads through a server-side configuration after the concerns surfaced, the company had not publicly commented on the issue until its latest statement.

Figure 1. Developer Data Protection.

Posting on X, SpaceXAI explained that Grok Build has supported a Zero Data Retention (ZDR) option since its launch and that users who manually disabled data uploads through the CLI always had their preferences respected. However, the company also confirmed that, during the early beta phase, coding data retention was enabled by default for users who had not opted into ZDR. According to SpaceXAI, this default behavior has now been removed, and coding data is no longer retained unless users explicitly choose otherwise.

SpaceXAI develops the Grok family of artificial intelligence models along with a suite of developer tools designed to streamline software development. One of these tools, Grok Build, is a command-line coding assistant that works directly with local code repositories to generate code, assist with debugging, and support developers throughout the coding process. Figure 1 shows developer data protection.

Concerns surrounding Grok Build emerged after security researchers and the Chinese technology publication BlueDot News reported that the tool uploaded entire source code repositories—including Git commit history—to Google Cloud Storage instead of transferring only the code necessary to respond to user requests. Researchers warned that this behavior could expose proprietary software, confidential business information, and other sensitive development assets, raising significant privacy and intellectual property concerns, particularly for enterprise users.

On July 13, security researcher CereLab revealed that SpaceXAI had remotely disabled repository uploads by activating a cloud-based configuration setting, disable_codebase_upload: true. Because the change was implemented through a server-side configuration, researchers noted that it could be modified again without requiring users to update the software. At the time, the company did not publicly explain the change.

In its latest statement, SpaceXAI confirmed that default data retention for Grok Build users was disabled on July 12 and that all previously retained coding data is being permanently deleted [1]. The company also announced that the Grok Build harness and command-line interface (CLI) have been released as open source, allowing developers to inspect the source code, contribute enhancements, and operate the tool locally using their own AI inference infrastructure.

Although these measures improve transparency and user control moving forward, several questions remain unanswered. SpaceXAI has not disclosed exactly what information was uploaded or retained, how many users were affected, how long the data was stored, or whether sensitive content such as repository files, Git history, credentials, or configuration files was included. The company has also not indicated whether affected individuals or organizations will receive formal notifications.

Security experts advise developers who used Grok Build during the affected period to review their repositories and rotate any passwords, API keys, access tokens, or other credentials that may have been present in uploaded code as a precautionary measure.

Reference:

  1. https://cyberinsider.com/spacexai-admits-grok-retained-developer-data-in-open-source-announcement/

Cite this article:

Keerthana S (2026), SpaceXAI Addresses Developer Data Found in Grok's Release, AnaTechMaz, pp.201

Recent Post

Blog Archive