What AI Companion Apps Collect and How to Check Privacy
AI companion apps invite you to type things you would not post anywhere else. That is the point of them, and it is also why privacy matters more here than in a notes app. This guide covers what these services typically collect, how long conversations stick around, and which sentences in a privacy policy are worth reading twice. It is general information, not legal advice.
What these apps typically collect
Most services in this category collect more than the chat itself. The table below lists the common categories and the question worth asking about each one.
| Data type | Why it is usually collected | Question to ask |
|---|---|---|
| Account data, such as email and date of birth | Login and age verification | Is the email verified, or reused from a social login? |
| Payment details | Billing and fraud checks | Does the payment processor hold the card, or the app? |
| Chat transcripts | Continuity, moderation, product improvement | Are they stored, for how long, and used for training? |
| Character and prompt text | Running the character you built | Is user-created content private or public by default? |
| Voice recordings and images | Voice features and avatars | Are uploads reused to train voice or image models? |
| Device and network data | Security and analytics | Which third-party analytics or ad SDKs are included? |
| Usage metadata | Rate limits and abuse detection | Is that metadata linked to your account or aggregated? |
The chat transcript is the sensitive part. Character text and voice samples are close behind, because they can identify a person even when the account name does not.
Where your conversations are stored
A single message can pass through several systems before it becomes a reply. Typically that means the app's own database, the model provider that generates the response, and one or more third parties for payments, moderation, analytics or crash reporting. Each one may keep its own copy under its own retention rules.
Check whether the policy names those processors, or only refers to "service providers" in general. A policy that lists categories but no names is not automatically bad, but it is harder to verify, and it tells you little about where data is physically stored.
Does deleting your account delete your data?
Not necessarily, and this is the most common misunderstanding in the category. Common patterns:
- Deleting the account removes the profile, but backups and logs may persist for a stated period.
- Deletion requests sometimes need an email to support rather than a button in settings.
- Aggregated or de-identified data may be kept indefinitely because it is no longer treated as personal data.
- Data already shared with a payment processor or analytics vendor is governed by that vendor's own policy.
Check whether the app states a retention window, and whether it offers an export or a full-deletion option instead of only "delete account". Keep a screenshot of the confirmation. If you cannot find a stated retention period, treat the data as retained until proven otherwise.
How to read privacy claims
Words like anonymous, private and encrypted carry different meanings depending on where they appear.
- Anonymous often means you did not give a name. It rarely means the service cannot connect your activity to an account or a device.
- Encrypted in transit is standard and says nothing about what happens after the message arrives. End-to-end encryption, where only your device can read the content, is a different claim.
- Encrypted at rest means stored data is protected on disk. The provider can usually still read it.
- No training on your data is a commitment about one specific use. Read whether it applies to all users, only paying users, or only to certain content.
- Deleted after X days describes a policy, not a technical guarantee.
A useful habit is to look for the sentence that says what the company will not do, and then check whether the section on data sharing contradicts it. Policies are often written by the same template, and the specific lines are what matter. Basic definitions of terms such as context window and memory are in the AI companion glossary, which helps when a policy describes what the model "remembers".
Payments, identity and account linking
A subscription links a chat identity to a real payment method. In practice that means:
- The billing name on the card is what a chargeback or refund process will reference.
- Some processors and app stores keep transaction records for years, independent of the app account.
- If the same card is used for several services, the providers may not share data, but the store front, such as the mobile app store, can see all of them in one billing profile.
- Cancelling a subscription is not the same as deleting an account. These are separate actions in most apps.
If you want to keep a chat identity separate from your regular identity, a dedicated payment method is the usual way people do it. That is a preference, not a guarantee. Read our notes on subscription traps and scam red flags before entering card details on a platform you have not used before.
What you read about these apps is often paid placement
A lot of the material that ranks for "best AI companion app" is affiliate content. Our own check on 2026-09-28 looked at 36 pages containing 96 links to candy.ai and found that 86% were nofollow or sponsored. That does not make any specific review wrong, but it does mean the ranking order you see is often a revenue decision rather than an editorial one. Treat roundups as leads, then read the privacy policy of the app itself.
A practical checklist
- Read the section on data sharing before the features list. It is usually near the end.
- Look for a named retention period for chats, voice and images.
- Check whether training on user data is on by default and whether you can turn it off in settings.
- Confirm the deletion path, including whether it requires an email request.
- Check the age requirement and whether you are comfortable with it.
- Use a separate email and, if you want, a separate payment method for this kind of service.
- Avoid sharing details you would not want processed by a third party, such as full names, workplaces or addresses.
- Re-check the policy after a major app update. Terms and data practices change quietly.
Key takeaways
- The chat transcript is the sensitive data, not the email address you signed up with.
- A message often passes through the app, a model provider and several vendors before you see a reply.
- Deleting an account does not always delete the data, especially backups and analytics records.
- Anonymous, private and encrypted are marketing words until the policy defines them.
- A payment method ties an anonymous account to a real billing identity.
- Treat app roundups as paid placement, and check the vendor's own policy instead. See what an AI companion actually is if you are new to the category.