Never ever ever use robots.txt to prevent indexing.
Robots.txt is only for preventing crawling. Rather detect bots from the user agent and throw a 404 header with a die and include a meta noindex as well just in case. Facebook recently got millions of secret URLS indexed in Google with emails in them - and yes crawling was blocked with robots.txt.