If you're evaluating AI meeting assistants, you've probably come across Cluely — it's one of the most visible products in the category. And if you've searched for it recently, you've probably also seen mentions of a data breach.
Here's what actually happened, what was exposed, and what any buyer in this category should take away from it.
What happened
In mid-2025, a group calling itself Ivy Dark Agent accessed Cluely's database and exposed the data of more than 83,000 users.
The entry point wasn't a sophisticated exploit. According to reporting on the incident, admin credentials had been left in a public GitHub repository. The attackers found them, combined them with weak protections on the product's GraphQL API and a client-side paywall bypass, and got in.
What was exposed
This is the part that matters most, and it's why this breach was worse than a typical email-address leak.
Cluely's product works by capturing what's on your screen and what's being said during live sessions. So the breach exposed exactly that material:
- Audio transcripts from live calls
- Screenshots taken during sessions
- Screen contents from interviews, sales pitches, and business meetings
- Associated personal data
For users, this meant that private interview answers, confidential pricing discussions, and internal business conversations were sitting in an exposed database.
The separate vulnerability disclosure
There was a second issue. Security researcher Jack Cable found a flaw in Cluely's Electron desktop app — a postMessage handler vulnerability that allowed any website opened through the app to continuously capture screenshots without the user knowing.
The response to that disclosure drew its own criticism: rather than acknowledging the finding or shipping a fix, the company reportedly responded with DMCA takedown notices.
For a lot of security-conscious buyers, how a company handles a disclosure is as informative as the bug itself.
Is Cluely safe to use now?
That's a question only Cluely can answer with specifics about what they've changed, and it's fair to say that companies do improve after incidents. Plenty of well-known products have had breaches and gone on to build strong security practices.
But there's a structural point that no amount of remediation changes: Cluely's product model requires storing your call data. Screenshots, transcripts, and screen contents have to exist somewhere for the product to work the way it does. That means the risk surface is permanent. Better security reduces the odds of a breach; it doesn't remove what a breach would expose.
The real lesson for buyers
The useful takeaway isn't "avoid this one company." It's a question you should ask every AI meeting tool before you install it:
Does this product store my calls, and if so, where and for how long?
Then follow up with:
- Is the audio recorded, or processed in real time and discarded?
- Are transcripts stored? Can I delete them? Are they deleted when I cancel?
- Does the tool join my meeting as a participant, meaning the other side is being recorded too?
- Where is the data hosted, and who has access?
- What's the disclosure policy if a researcher finds a bug?
Most vendors answer the first question with something vague like "your data is encrypted." Encryption at rest doesn't help you when the credentials to the database are the thing that leaked.
The alternative model
There's a different way to build these tools: process the audio live, show the user the suggestion, and never write the conversation to disk.
That's how Zaasmi works. It runs on your machine, listens during the call, and shows suggestions only you can see — including while you're screen sharing. No audio is recorded. No transcripts are stored. The end-of-call summary is shown to you and not saved on our servers. Zaasmi doesn't join your meeting as a participant, so the people you're talking to aren't being recorded by a third party.
That design has real tradeoffs — you don't get a searchable archive of past calls, because there's nothing to search. If archive and analytics features are what you're buying, a recording-based tool is genuinely the better fit and you should choose one carefully.
But if your priority is "help me during the call and don't keep a copy," a tool that stores nothing is the only version of that promise that survives a bad day.
Compare for yourself
Zaasmi is available for Mac and Windows, with a free trial — 7 days or 2 hours of live-call usage, whichever comes first, no credit card needed.
Sources: Cluely Review (2026): Pricing, Breach, Honest Verdict, What Is Cluely AI? Data Breach, Pricing, and How It Works, Cluely Review: A Fine Line Between AI Productivity and Deception




