Grok Build, a development tool, was flagged by security researchers and developers for transmitting complete codebases to SpaceX servers without adequate safeguards. The tool also sent sensitive data including SSH keys and password manager databases, exposing users to serious security risks.
The company has since disabled this functionality and committed to permanently deleting all data transmitted before the change was made. SpaceX highlighted the "/privacy" command, which allows users to disable data retention and remove information already synchronized with their servers. Users concerned about their data exposure should use this command immediately.
The incident underscores the importance of scrutinizing data handling practices in development tools, particularly those that access repositories and sensitive credentials. Developers should review their tool settings and understand what data is being collected and where it is being stored.

