Where Do Your AI Companion Chats Go? Privacy Compared
Your AI companion chats go to the vendor's servers, stay there under a retention policy you have probably never read, may be seen by human safety reviewers, and β at some apps β may be used to improve the models. That's the plain answer. The interface feels like a diary with a heartbeat; legally and technically it's much closer to feedback flowing into a software service. This piece compares what the five majors say they do with your words, flags the red-line patterns, and gives you a five-minute method for auditing any companion policy yourself.
Intimacy is exactly why this matters. People tell companions things they tell no one else β that's the product working as intended. Which makes this the one software category where the gap between how private something feels and how private it is deserves a full article.
The journey of a message
- Your message leaves the device over an encrypted connection. Transport encryption is standard everywhere and tells you almost nothing.
- It lands on the vendor's servers, where the model must read it in plain form to reply. True end-to-end encryption is generally impossible for this product type β the question is never whether the company can access your chats, but who else can, and what the company does with them.
- It is retained. Retention windows range from clearly stated to entirely unspecified.
- It may be sampled for safety review, quality checks or β where policy permits β model training.
- Around the conversation sit analytics and, in free ad-supported apps, advertising SDKs that observe usage even if they never see message content.
- Backups and logs can outlive the conversation you deleted.
Memory features raise the stakes further: the better a companion remembers you, the more of you is retained by design. That trade-off is the closing argument of our memory test, and it is why the memory leaderboard and this article should be read together.
What the five majors say
Everything in this table is a snapshot of public policies and app-store disclosures as of this writing. Policies in this category change frequently β several majors have updated theirs within the past year β and stated commitments are not audited ones. Verify before you rely.
| App | Training on your chats (per policy) | Human review | Deletion path | Export | Notes |
|---|---|---|---|---|---|
| Nomi | States chats are not used to train shared models | States not routine | Account deletion available | Limited | Strong stated stance from a small team |
| Kindroid | States chats are private and not read by staff | States no | In-app account deletion | Limited | Privacy is a core marketing pillar; unaudited |
| Replika | States conversations are not sold or used for ads; training language has shifted over the years | Safety review possible | Account deletion plus data-request route | Limited | Italian regulator action over age checks and legal basis |
| Character.AI | Policy permits using content to improve services | Possible | Account deletion available | Limited | Frequent policy updates amid safety scrutiny |
| Talkie | Broad content-license language | Unclear | In-app plus web form | Unclear | Ad partners in the free tier; reviewers have raised ownership and data-residency questions |
Two fairness notes. First, we found no evidence that any of these vendors violates its own policy; the differences above are differences in what the policies permit. Second, the category's baseline is low β a well-known 2024 review by Mozilla's Privacy Not Included team flagged romantic AI apps broadly for trackers, weak security disclosures and vague policies β which makes the stronger postures at the privacy-forward end genuinely notable rather than merely adequate.
Red flags in any companion privacy policy
- Silence on model training. A policy that never mentions training either way was written by someone who chose not to answer the question.
- Deletion instructions that only cover the app. Uninstalling deletes nothing; if account deletion isn't described, assume it's difficult.
- Advertising SDKs inside an intimacy product. Your message content may be safe while your usage patterns β when, how often, how long β feed ad systems.
- Sharing with unnamed partners and affiliates. Named recipients can be checked; unnamed ones cannot.
- No age-assurance process in an adult-capable app. Beyond the obvious problem, it signals weak governance overall β regulators have already acted on exactly this point in this category.
- A free product with no visible business model. Servers and model inference are expensive; if you cannot see what pays for them, consider what might.
The five-minute policy check
- Open the privacy policy in a browser and search for train, improve and machine learning. You are looking for an explicit statement about whether conversation content trains models, and whether you can opt out.
- Search retain and delete. A good policy describes account deletion, what it covers, and a timeframe. Note whether chat deletion and memory deletion are treated separately.
- Search share, partners and advertising. Count how many recipients are named versus gestured at.
- Compare the app-store privacy label against the policy. Labels are self-reported, but a mismatch between label and policy is itself a finding.
- Find the privacy contact or data-request email. Rights created by GDPR and CCPA-style laws are often extended to all users in practice; if you can't locate the mailbox to exercise them, that's your answer about how seriously they're taken.
Five minutes, no legal training required, and it will place any companion app on the spectrum above.
Data hygiene for companion users
- Sign up with a pseudonym and a dedicated email address. The companion experience loses nothing.
- Share patterns, not identifiers. A companion needs to know you hate early meetings, not your employer's name; that you live near the coast, not your street.
- Treat photos and voice notes as the most identifying data you can send, because they are. Skip face photos and documents entirely.
- Remember that deletion means account deletion, requested through the proper path β not archiving a chat, and never just removing the app.
- Re-read the policy when something big changes: an acquisition, a new model, a feature overhaul. Policy updates ride along with product updates, and consent boxes are easiest to click through at exactly those moments.
Two scenarios your policy read should survive
The acquisition. In most privacy policies, user data is an asset that transfers in a merger, acquisition or bankruptcy β the clause is usually one bland sentence filed under business transfers. In a young, consolidating category, that sentence deserves more attention than it gets: privacy commitments made by a small, principled team are only as durable as that team's ownership. When an app you use changes hands, re-read the policy that same week, and treat any quiet policy update in the following months as a prompt to re-decide, not just to re-consent.
The account takeover. Your chats are also only as private as your login. Companion accounts are a soft target β rich personal content, rarely protected the way people protect a bank account. Use a unique password from a password manager, turn on two-factor authentication where it's offered β support varies across the category β and look for an active-sessions or sign-out-everywhere control. No vendor policy can protect a conversation from someone holding your credentials, and no amount of corporate good faith substitutes for basic account hygiene on your side.
The bottom line
As of this writing, Kindroid and Nomi make the strongest stated privacy commitments in the category, Replika sits in the middle with a scrutinized but improved posture, Character.AI's policy keeps its training options open, and Talkie's free-tier economics show up in its data practices. None of it is audited, all of it can change, and your own hygiene is worth more than any vendor's promise.
Privacy rarely decides which companion app people choose β memory and personality do, as our overall rankings show. But it should be the tiebreaker, and it is one more reason the honest flat-subscription apps in our pricing guide tend to be the better citizens: when you're the customer, you're less likely to be the product.
We re-check these policies on a rolling basis and flag every material change. One email a month, no noise: join the free monthly digest.
Frequently asked questions
Are AI companion chats private?
Less private than they feel. Every major app stores conversations on its servers, retention is governed by policy, safety review by humans is possible at several apps, and some policies permit using chats to improve models. Treat the chat window as a service, not a diary.
Do companion apps train AI models on my conversations?
It varies. As of this writing, some policies explicitly permit using content to improve services, while apps like Nomi and Kindroid state that chats are not used to train shared models or read by staff. These are stated commitments, not audited ones β verify the current policy yourself.
Can I delete everything an AI companion knows about me?
Usually you can delete your account, which policies say removes associated data within a stated window. But deleting individual chats may not delete derived memories, and backups can persist briefly. Uninstalling the app deletes nothing at all.
Is it safe to send photos or voice notes to a companion app?
They are governed by the same policies as text but are far more identifying. We recommend against sending face photos, documents or anything you would not upload to a stranger's server, whatever the app's stated posture.
Which AI companion app is best for privacy?
As of this writing, Kindroid and Nomi make the strongest stated commitments β no staff reading, no training of shared models on chats. Neither claim is independently audited, so the honest answer is: those two, verified against their current policies, combined with your own data hygiene.