Guide

AI Companion Privacy: What Actually Happens to Your Chats

What AI companion apps store, who can read it, what 'delete' really removes, and the five clauses to check in a privacy policy before you type anything personal.

A phone showing a single chat bubble with a trash icon beside it, and behind it a stack of server drawers each still holding an identical copy of that bubble
A phone showing a single chat bubble with a trash icon beside it, and behind it a stack of server drawers each still holding an identical copy of that bubble

The privacy question that matters with an AI companion is not the one people usually ask. It is rarely “could someone hack this.” It is “what does this company do with the messages in the ordinary course of business, and who ends up seeing them by accident.”

The short answer: assume conversations are stored on a server, retained for a defined period, potentially readable by staff for moderation, and possibly used to improve the provider’s models unless the policy says otherwise. That is the default posture across the category. The differences worth choosing between are in the details — retention periods, training opt-outs, third-party processors, and how the charge appears on your card.

What these apps actually store

Four categories, roughly in order of sensitivity:

Conversation content. The messages themselves, usually retained indefinitely or until you delete them, because persistent memory is the product. An app that forgets everything nightly would not be much of a companion.

Derived profile data. Preferences, persona settings, relationship parameters, and in memory-capable apps a distilled summary of what the model has learned about you. This is often stored separately from raw messages — which matters, because deleting a conversation does not always delete what was derived from it.

Generated media. Images and voice clips, typically kept in object storage with long-lived URLs. Worth knowing: some services keep generated files accessible by direct link even after the associated chat is deleted.

Account and billing metadata. Email, IP addresses, device identifiers, payment records. The least interesting to you and the most likely to be retained the longest, because financial records carry statutory retention obligations that override any deletion request.

The five clauses worth reading

Privacy policies in this category are not usually deceptive; they are just long, and the interesting parts are near the bottom. Five things to search for:

  1. “Train” or “improve our models.” This tells you whether your conversations feed model development. Then check whether there is an opt-out, and whether it is on by default.
  2. A named retention period. “We retain data as long as necessary” means nothing. “90 days after account deletion” is a commitment you can hold someone to.
  3. Sub-processors. Which third parties receive data — hosting, analytics, moderation, payment. A provider running inference on someone else’s API has necessarily shared your messages with that company.
  4. Jurisdiction. Which country’s law governs, and where the servers sit. This determines what rights you actually have, and whether a GDPR-style deletion request is enforceable or merely a courtesy.
  5. Account deletion mechanics. Whether deletion is self-service or requires emailing support. The latter, in practice, means slower and less reliable.

What “delete” usually means

Worth setting expectations honestly, because this is where the gap between user assumption and reality is widest.

What you do What typically happens What usually persists
Delete one message Hidden from the thread Server copy until retention expires
Delete a conversation Thread removed from your account Derived memory, backups, generated media
Delete your account Profile and content queued for removal Billing records, moderation flags, aggregate analytics
Uninstall the app Nothing on the server side Everything

None of this is unique to companion apps — it describes almost every hosted service. It is worth spelling out because the intimacy of the content makes people assume stronger guarantees than the infrastructure provides.

The local-versus-hosted test

Some apps market themselves on privacy while still sending every message to a hosted model. There is a ten-second test that settles it: put the device in airplane mode and try to hold a conversation. If it works, inference is genuinely local. If it stalls, your messages travel to a server regardless of what the landing page says.

Genuinely local companions exist, and they trade quality for privacy in a way that is worth understanding rather than glossing over: a model small enough to run on a phone is meaningfully less capable than a hosted one. That is a real trade-off, not marketing.

Payment descriptors: the overlooked one

The most common privacy complaint in this category has nothing to do with data breaches. It is a card statement seen by a partner, a parent or an accountant.

Providers differ. Some bill under a neutral parent-company name; others use the product name directly. This is almost never mentioned in reviews and is frequently the detail that matters most in practice. If it matters to you, check the billing FAQ before subscribing, and consider a virtual card — many banks now issue single-merchant virtual cards for free, which also caps the damage if the provider’s payment processor is ever compromised.

A practical baseline

You do not need a threat model to use these apps sensibly. Four habits cover most of the realistic risk:

  • Use a dedicated email address. Not your work address, not the one tied to your main accounts. It costs nothing and cleanly separates identities.
  • Don’t type identifying details you would not put in a support ticket. Full name, employer, address, the name of your street. The model does not need them, and they raise the stakes of any future breach.
  • Check the training opt-out on day one, not after three months of conversations you would rather not have contributed.
  • Use a virtual card if the billing descriptor concerns you.

Where we stand on this

We check privacy handling as part of every review on this site and score it separately, because a companion app can be excellent conversationally and careless with data. Our per-product notes are in the individual reviews — Candy AI, Nomi AI and Kindroid each handle retention and training differently, and the differences are large enough to change which one suits you.

One caveat we apply to ourselves: privacy policies change without announcement. Anything written here or in our reviews reflects what the documents said when we read them, and re-reading the policy before you subscribe is a two-minute habit worth keeping.

Frequently asked

Are my companion chats used to train the model?

It depends entirely on the provider, and the answer is in the privacy policy rather than the marketing copy. Some apps state plainly that conversations may be used to improve their models; others offer an opt-out toggle; a few commit to not training on user chats at all. Assume training is the default until you have read otherwise, because that is the more common arrangement.

Does deleting a conversation actually delete it?

Usually it removes the conversation from your view. Whether the data is erased from backups, analytics pipelines and any third-party processors is a separate question that most policies answer vaguely. Look for a stated retention period after deletion — 30 or 90 days is common — rather than a promise of instant erasure.

Can a human employee read my conversations?

In most services, some staff can access user content for moderation, abuse investigation or debugging. That is normal for any hosted platform and is not itself a scandal — the meaningful question is whether the policy names the circumstances and whether access is logged. A policy that never mentions human access is less trustworthy than one that describes it honestly.

Is a local or on-device companion genuinely more private?

If inference truly runs on your own hardware, yes — nothing leaves the device, so there is no server-side retention question at all. The catch is that many apps advertised as private still send messages to a hosted model, keeping only the interface local. Check whether the app works fully offline in airplane mode; that test settles it in about ten seconds.

What is the single most important thing to check?

Payment descriptors. Not because the data is unusually sensitive, but because a card statement is the one place where the information is shared with people who never agreed to see it. Providers vary in how discreet the descriptor is, and it is often the least-considered privacy detail in this category.