
The Rabbit R1 initially stored user data by keeping chat logs on the device with no option to erase them. Additionally, stored pairing data allowed the R1 hardware to access and read the Rabbithole journal, potentially exposing users' saved requests, photos, and more. This raised security concerns and prompted Rabbit to release a software update addressing these issues.

The Rabbit R1 AI assistant device faced a security issue where users' sensitive information was accessible due to hardcoded API keys. This vulnerability allowed third parties to access text prompts sent through the R1, potentially revealing personal information. Additionally, the device was storing chat logs on-device without an option to erase them, which has been addressed in a software update that added a Factory Reset option.