Most privacy conversations on the internet are theatre — dense policy pages nobody reads, a cookie banner people click through, a checkbox at signup. AI companion apps deserve better attention than that, because the conversations you have with them are usually more personal than the average website ever sees. This is a short, practical checklist for evaluating an AI companion's privacy story before you start typing.
Why AI companion privacy is different
A regular app sees your name, email, maybe a payment card. An AI companion sees whatever you tell it — which, in a good product, is a lot. Over weeks and months, an active user will share things they would not put in a text message: fears, opinions, personal history, relationship details. The privacy stakes are correspondingly higher, and the industry norms are still being written.
The good news is that the same four or five questions cover almost every meaningful privacy concern. The bad news is that most privacy policies are structured in a way that hides the answers.
The five questions worth asking
1. Is my chat used to train future models by default?
This is the single most important question. If your conversations are added to the training data for future versions of the underlying model, small fragments of what you wrote can, in theory, be reproduced by the model later. Every serious platform now offers a training opt-out; the question is whether it is on or off by default and how easy it is to find.
Look for a settings page called "Data & Privacy" or "Training Data". If the toggle is on by default, you can usually turn it off — but the sign that a company respects your data is that it was off to begin with. If you cannot find the toggle, ask support directly. A platform that will not tell you is one you should not trust with private chat.
2. How long are conversations stored, and can I delete them?
Two separate questions, both worth asking. Storage retention: how long the company keeps your messages on its servers by default. "Indefinitely" is common and lazy. "As long as your account exists, plus 30 days after deletion" is a healthier signal. Deletion: whether you can remove individual conversations, and whether "delete" actually removes the data from backups or just hides it in the UI.
3. Where is the data physically stored, and under whose laws?
This matters because it determines which laws apply to your data. A US-hosted service is subject to US legal process; an EU-hosted service is subject to GDPR. Neither is inherently safer, but they behave differently. If you live in the EU, GDPR gives you specific rights — data portability, deletion on request, an actual regulator to complain to — that US law does not. If you live in the US, you can effectively be tracked by any government agency with a subpoena, and there is no equivalent to the EU's data protection commissioners.
The other jurisdiction question worth checking: is the data ever moved outside your home region? Cross-border transfers are legal, but they usually degrade whatever protections you had at home.
4. Is anything sensitive shared with third parties?
Two categories to check. Analytics providers: does the app send event data to Amplitude, Mixpanel, Google Analytics, etc.? If so, does it strip your chat content before sending, or does the third party see raw messages? Payment providers: whoever processes your card sees who you are and that you paid this specific app — which, for adult-oriented companions, some users care about. Look for a "subprocessors" or "third parties" section in the privacy policy.
5. What happens to my data if the company shuts down?
AI companion companies come and go. The good ones commit in writing to notifying users before shutdown, offering data export, and destroying user data after a wind-down period. The bad ones just disappear and take your data with them (sometimes to a buyer). This is buried in almost every privacy policy under "changes to this policy" or "transfer of business" — worth reading before you get emotionally attached to a character.
Signals that a platform is serious about privacy
- Training opt-out is off by default, not just available.
- Individual conversation deletion works and syncs across devices within minutes.
- The privacy page uses short sentences and specifics, not lawyer boilerplate.
- There is an explicit statement about what employees can and cannot access.
- A GDPR data-export tool exists even for non-EU users.
- A named data protection officer or contact email you can actually reach.
Signals that should worry you
- The privacy policy is more than 8,000 words and mostly boilerplate.
- There is no mention of the underlying LLM provider at all — you have no idea whose infrastructure your conversations pass through.
- The "delete account" flow requires an email exchange with support.
- Data is described as retained "as necessary" without a specific window.
- The app requests permissions it does not need (contacts, calendar, precise location) on install.
What to do before you type anything sensitive
- Read the privacy summary page (not the full legal policy — most companies now offer a plain-language summary).
- Set the training opt-out to off before your first message.
- Add a fake email suffix on signup if the platform does not require verification (many do not).
- Test the deletion flow with a throwaway conversation on day one. If it fails, you know now.
- Pay with a card you can cancel easily, or through a wallet like Apple Pay or PayPal that shields your primary card number.
A note on adult / romantic companions
The same checklist applies with two extra items. First, the discretion of the billing descriptor on your card statement — some companies bill under a generic parent-company name specifically for this. Second, whether the app supports a PIN or biometric lock on the phone; the answer being yes is a small feature but a real one.