ICYMI: A viral app called Neon, which pays you to record your phone calls so your audio can be used to train AI, has gone offline after I discovered a security lapse exposing users' phone numbers, call recordings, and call transcriptions.

Anyone could download users' raw audio recordings because the web links were publicly accessible from the web.

https://techcrunch.com/2025/09/25/viral-call-recording-app-neon-goes-dark-after-exposing-users-phone-numbers-call-recordings-and-transcripts/

Exclusive: Neon takes down app after exposing users' phone numbers, call recordings, and transcripts

Call recording app Neon was one of the top-ranked iPhone apps, but was pulled offline after a security bug allowed any logged-in user to access the call recordings and transcripts of any other user.

TechCrunch
@zackwhittaker who could think it may be a bad idea, right?
@zackwhittaker this is sort of hilarious but also if you took that money you are an inconsiderate (and possibly criminal depending on the state) moron so kinda hard to feel bad
@zackwhittaker lol. Any chance it was vibe coded?

@zackwhittaker The stupidity of the people really knows no bounds.

And thank you for protecting even those who do not deserve it 😉

@zackwhittaker Crazy that people actually did this. Sure...go ahead...sign your life away for a few bucks, maybe a discount. It's worth it, right? Nope!
@zackwhittaker Okay but this doesn't even sound like an app that ever should've been a thing in the first place. I'm glad it's gone, but also WTF
@zackwhittaker huh, that’s not good. I think. That’s not good, is it, guys?
@zackwhittaker Oh I had a small panic attack after reading the headline. I Neon for my website, which is a database management software.
@zackwhittaker speed running the data collection to data breach process. I only heard about neon yesterday.
Why is this so common? Vibe coding?

@maxoakland
Here's a wild theory.

Suppose you have a commercial idea for deeply invasive data collection, but you want to actually monetise the data somewhat outside the lines of what you have consent to do or maybe the law.

Simple. Start a fake company to collect the data, make the security of their database deniably shit. Get "hacked", have your real company use the data for whatever you like.

@zackwhittaker "pays you to record your phone calls so your audio can be used to train AI"

I cannot fathom the degree of thoughtlessness that would lead someone to think "Why, sure, what've I got to lose?".

@zackwhittaker nice one! great work! sadly this reminds me awfully about the video ident you need todo in germany if you want to activate a prepaid sim card by certain providers...
they are forced to ask if you are okay to have the call recorded, BUT you cant decline! if you do they end the call and don't unlock the damn thing. -.-

@zackwhittaker

I was not aware of its existence until your report.

It was an amazing stupid user trick.

@zackwhittaker holy crap. also, don't do this!!