Delete Means Delete: Inside the Google AI Studio Fake-404 Flaw and the 60-Second Bug Bounty Close
A researcher says AI Studio's Delete button only strips a JSON pointer while prompt data lives on Google's backend — and Google's AI VRP closed the report as 'Intended Behavior' in about a minute.
The button says Delete. The interface returns a 404. And according to an independent security researcher, that is where the deletion at Google AI Studio ends — while the prompt data itself lives on, intact, somewhere on Google’s backend infrastructure.
The allegation, laid out in a Medium post by researcher Istokovics György and currently circulating on Hacker News, is technically specific: AI Studio’s Delete action removes only a JSON pointer — the small piece of metadata that maps a conversation to your account — while the underlying prompt content persists in server-side storage. Restore the pointer, and the “deleted” conversation comes back whole. The UI reports 404 because the pointer is gone; the data behind it never left.
If that sounds like a dry technicality, consider what AI Studio actually is. This is Google’s developer playground for Gemini models — the place where engineers paste API keys to test integrations, drop customer documents in for a quick summary, and prototype against frontier models before anything reaches production. It is, by design, the least careful environment in the AI toolchain. And the entire value of a Delete button in that context rests on one assumption: that deletion is real.
What the researcher actually claims
The core of the claim is architectural. When a user hits Delete in AI Studio, the interface behaves as though the resource is gone: subsequent requests return a 404, the conversation vanishes from the sidebar, and from the user’s chair the action looks complete. But the deletion, per the researcher, only touches the layer that references the data — the JSON pointer that ties the stored conversation to your identity. The prompt text, the model outputs, the files you attached: all of it remains in persistent server-side state.
The researcher’s framing is blunt. “Deletion means deletion,” he writes. “There is no such thing as ‘we didn’t delete it just in case you did it by accident.’” The argument is that Google’s UI promises a permanent removal that the server side does not perform — and that the gap between the two is not a bug in the classic sense but a design decision dressed as one.
This is not the first time the issue has surfaced. Forum threads on Google’s own developer discussion site date back months, including a “Comprehensive Forensic & Legal Report” thread from late August 2026 that frames the same behavior as systematic, and an earlier June thread in which a formal GDPR complaint was described as submitted to Google’s Data Protection Officer. The current wave of attention is newer: the Medium post landed on Hacker News and sits at 46 points, with parallel discussion erupting across developer communities.
The 60-second close
The part of this story that may outlive the technical claim is how Google handled the report.
The researcher submitted his findings through Google’s AI Vulnerability Reward Program — the bug bounty channel that exists precisely to catch problems like this. By his account, the program closed the report in roughly 60 seconds, with the disposition label “Intended Behavior.”
Sixty seconds is not a triage timeline. It is barely enough time for a human to read the report’s title. Whatever process produced that label, it was automated or near-automated — and the message it sends is that data-deletion-integrity reports in the AI era will be sorted by the same machinery that handles missing UI elements and off-by-one errors.
There is a reasonable counterargument, and it deserves air. A soft-delete with a recovery window is standard product behavior — Gmail’s trash, GitHub’s restorable repositories, the undo-timers on nearly every modern app. One Hacker News commenter, jasonkester, pushed back along exactly these lines: that delayed or reversible deletion is the industry norm rather than deception. If AI Studio’s retention is bounded, documented, and disclosed, the pattern is unremarkable.
But that defense has a condition attached, and it is the condition Google has not met: disclosure. Google has not published what AI Studio actually does with deleted prompts — not the retention window, not the storage scope, not whether deletion ever propagates to backend state at all. An undisclosed soft-delete is a very different animal from a documented one. The first is a governance gap; the second is a product feature.
Why this lands on GDPR territory
Under GDPR Article 17, EU users have the right to erasure — the right to have personal data deleted, not hidden from view. If AI Studio’s Delete action only strips a pointer while retaining the underlying content, the question of whether that satisfies Article 17 is not rhetorical. The forum threads arguing exactly this violation cite GDPR Articles 5, 12, 17, and 25 — transparency, access, erasure, and data protection by design.
The researcher says he escalated along every available path. He wrote to NOYB, the Austrian privacy nonprofit famous for forcing Meta and others into compliance actions, and to the Irish Data Protection Commission — and by his account got nowhere, with correspondence going silent. He also claims collateral fallout on Google’s own developer forum: “They deleted around 140 of my technical posts,” he writes, describing the removal of his threads raising the issue.
The escalation trail matters because GDPR enforcement is complaint-driven in practice. A right that no regulator acts on is a right that exists on paper. If both NOYB and the Irish DPC decline to engage with a documented, reproducible deletion-integrity claim, the backstop isn’t a backstop.
The honest caveats
This story is thinly sourced in one important sense: nearly everything traces back to a single researcher’s posts and the surrounding discussion. Google has not commented publicly. The strongest version of the claim — that deleted prompts are trivially recoverable by restoring a JSON pointer — has not been independently replicated with published network traces. A 404 screenshot proves the interface changed; it does not, by itself, prove what the backend retains.
MindPattern’s assessment of the story gets the epistemics right: “One researcher, no confirmation from Google past the VRP’s boilerplate close” means the strong version stays a claim, not a finding. But the weak version requires no confirmation at all, because it is a statement about absence: Google has never published AI Studio’s deletion and retention behavior. Until it does, the safe assumption for any user is that Delete changes what you see, not what Google keeps.
The two things to watch next are whether Google issues an actual retention statement — rather than a bounty disposition label — and whether a second researcher publishes an independent network capture showing the same resurrection behavior. One report plus a fast bounty close is an anecdote. Two independent captures is a pattern, and a pattern is something even a 60-second triage bot cannot label “Intended Behavior” and move on.
What teams should actually do
For any organization routing real data through AI Studio, the practical guidance is straightforward and costs nothing:
Treat AI Studio’s Delete as a UI-level action until Google clarifies retention publicly. Do not paste API keys, credentials, customer PII, or regulated data into test prompts under the assumption that deletion cleans up after you. If your compliance posture requires provable erasure, the free playground is the wrong venue — route regulated workloads through paid API tiers where data-processing terms are contractual and retention is documented.
And for governance leads, the AI Weekly editor’s note is worth internalizing: an AI vulnerability program that auto-closes deletion-integrity reports as “Intended Behavior” is itself a signal about how the entire category of data-retention claims will be triaged going forward. The gap between “we take your privacy seriously” and a one-minute close on an erasure claim is where trust actually gets decided.
The story arrives amid a wider run of scrutiny on frontier-lab data handling — the same week as state-media attacks on Anthropic’s privacy policy overhaul and reporting on OpenAI contractors reading real user prompts under default-on settings. Every major lab’s data defaults are now a story somewhere. What distinguishes this one is the precision of the allegation: not that data is collected, but that its disappearance is performed. A delete button that lies is a smaller thing than a data breach, and in some ways a larger one — because it breaks the contract at the exact moment a user tries to take data back.
Sources
- [1] https://aiweekly.co/alerts/google-vrp-banned-researcher-in-60s-over-ai-studio-delete-claim
- [2] https://mindpattern.ai/s/2026-09-20-a-researcher-claims-google-ai-studio-s-delete-only-strips-a-pointer-and-the-vrp-close
- [3] https://medium.com/@istokovicsgyorgy79/your-prompts-are-not-deleted-they-are-just-hidden-e0016bd43eaf
- [4] https://discuss.ai.google.dev/t/comprehensive-forensic-legal-report-google-ai-studio-google-drive-systematic-data-retention-fraud-gdpr-article-17-violation/180264
- [5] https://blog.buildfastwithai.com/ai-news-today-september-21-2026