We reviewed the privacy policies of 27 AI companion apps and scored each one across 23 safety dimensions. The results aren’t encouraging. Of the 11 most popular apps, only two score above a D grade on the CompanionWise Safety Index. The gap between apps that take privacy seriously and apps that don’t is enormous, and it’s buried in thousands of words of legalese that almost nobody reads. This comparison strips away the legal language and shows you exactly what each app does with your data, who they share it with, and whether you can actually get it deleted.
Key Takeaways
- Pi AI earns the highest safety score (B/55) among 11 major apps. Most score D or F, meaning the majority of popular AI companions carry significant privacy risks.
- Only Kindroid encrypts chat data at rest. Every other app confirms only in-transit encryption, leaving stored conversations potentially accessible.
- Character AI claims a perpetual, irrevocable license to all user content. Your conversations can be used to train AI models indefinitely, even after account deletion.
- Chai AI keeps your data for 5 years after you delete your account. That’s the longest post-deletion retention period of any app we reviewed.
- Every single app relies on self-reported birthdates for age verification. None require government ID, phone verification, or biometric age estimation.
AI Companion Privacy Comparison Table
The table below compares privacy practices across the 11 most popular AI companion apps, based on our review of each app’s privacy policy, terms of service, and third-party scanning data from The Markup’s Blacklight tool. Apps are ordered by CompanionWise Safety Index score, highest to lowest. For the full methodology behind these scores, see how we rate AI companion apps.
| App | Safety Grade | Data Collection | Third-Party Sharing | Deletion Rights | Encryption | GDPR/CCPA | Ad Tracking |
|---|---|---|---|---|---|---|---|
| Pi AI | B / 55 | Moderate: inputs, usage data, device info, third-party auth | Service providers only; no sale for targeted ads | Account deletion available; no specific timeline | In transit confirmed | Both | Minimal |
| Replika | C / 38 | Extensive: messages, photos, voice, AR face data (on-device), usage, payments | De-identified data to LLM providers; email to marketing; website data to ad partners | In-app deletion; 60-day retention post-deletion | In transit (SSL/TLS); no E2E | Both | Google, Facebook, Hotjar session recording |
| Kindroid | B- / 50 | Moderate: profile, chat content (encrypted), payment data, device/IP, demographics | Service providers and analytics; explicit “will not sell” pledge | Email request; CCPA deletion rights; export once per 180 days | At rest AND in transit (can decrypt for legal) | CCPA | Google, Facebook, ByteDance scripts; 0 ad tracker pixels |
| Candy AI | D / 25 | Extensive: conversations, AI preferences (ethnicity, body type), voice calls, generated images, device/IP | LLM providers, payment processors, Klaviyo, Yandex, Google Analytics, Hotjar, Mixpanel | Request available; 3-year retention after last activity | Claims E2E on homepage; policy says “appropriate measures” only | Both | 8 trackers + Hotjar session recording |
| Nomi AI | D / 32 | Moderate: email, name, DOB, all chat content, customizations, payment, device/IP | Claims no selling/renting; shares de-identified data for research; M&A clause | Account deletion within 28 days; training archives survive | In transit only (Google Play); policy silent on encryption | Neither documented | 0 trackers, 0 cookies |
| Talkie AI | D / 30 | Extensive: messages, voice data, account info, device/IP, geolocation, inferences | Advertising and analytics vendors receive identifiers, internet activity, geolocation | Account deletion via settings; no specific timeline | In transit only | CCPA only | Acknowledges ad sharing may constitute CCPA “sale” |
| Anima AI | D / 25 | Moderate: name, email, device IDs (IDFA, AAID), Facebook ID, carrier, hardware ID | Not explicitly documented beyond standard service providers | Erasure available via email; no timeline | In transit confirmed; at-rest undetermined (Mozilla PNI) | GDPR referenced | Not documented |
| Character AI | F / 22 | Extensive: identifiers, demographics, chat content, voice data, images/video, device IDs, browsing behavior, geolocation | Affiliates, advertising partners, analytics providers; personal info for tailored advertising | Account deletion via profile; popular characters may persist | No encryption commitments in policy | Both mentioned | 12 trackers (Criteo, Lotame + 10 others); double the average |
| Chai AI | F / 18 | Extensive: all chat messages, usage data, IP, browser type, login times, push notifications | Authorized staff and data processors; AI training on “legitimate interest” basis | Data retained 5 years after deletion; training data is permanent | At-rest unconfirmed (Mozilla PNI: “Can’t Determine”) | GDPR referenced | Not documented |
| Romantic AI | F / 13 | Extensive: personal info, face images for character creation, device data, usage | Google and Yandex scripts detected; policy lacks detail on sharing | In-app deletion, but “may elect to keep” data afterward | VeriSign/McAfee certificates only; no E2E or at-rest | GDPR referenced | Google, Yandex scripts |
| Eva AI | F / 10 | Extensive: text/voice messages, images, personal facts, interests, device IDs, hobbies, people mentioned | Mintegral ad SDK, external object recognition service, affiliates; claims “no selling” | In-app deletion, but data persists in “cached pages” and third parties | Mozilla PNI: “cannot confirm encryption”; Play Store says transit only | Both mentioned | Mintegral ad SDK shares usage data |
Look at that table and a pattern jumps out. The three apps with the strongest privacy practices (Pi AI, Replika, and Kindroid) all have documented data handling procedures, specific retention timelines, and at least partial compliance with major privacy regulations. The eight apps in red? Vague retention policies, unconfirmed encryption standards, and broad licenses to use conversation data for AI training.
CompanionWise scores each app across 23 safety dimensions covering data privacy, content moderation, transparency, crisis response, and user control. Privacy is one of six weighted dimensions in our scoring framework, which ranges from F (0-19) to A+ (88-100). Of the 11 apps in this comparison, only Pi AI clears the Yellow/Caution threshold into the Green/Safe tier for overall safety. Nine apps sit in the Red/Unsafe tier. For a broader look at how these scores translate to overall safety, see our safest AI companion apps ranking.
Which AI Companion Apps Are Best for Privacy?
Pi AI leads the field with a B/55 safety rating, the only app in this comparison to reach the Green tier. Inflection AI, the company behind Pi, is structured as a Public Benefit Corporation, which creates a legal obligation to consider societal impact alongside profit. That structure shows up in Pi’s privacy policy: the company explicitly states it does not sell or share personal information for targeted advertising (Pi Privacy Policy, 2026). Pi collects standard data like inputs, device info, and usage patterns, but its third-party sharing is limited to service providers with no advertising partnerships documented.
Replika, despite its regulatory history, has the most detailed privacy protections of any app in the comparison. Its policy specifies that conversation data sent to LLM providers is de-identified and minimized, and those providers are contractually barred from using the data for their own training. Replika’s post-deletion retention period is 60 days for messages and content, with a clear statement that account deletion is permanent and immediate for associated data. The app also supports full GDPR Article 17 right to erasure and CCPA compliance.
Where does Replika fall short? The Italy Garante fined its parent company Luka, Inc. EUR 5 million in April 2025 for persistent GDPR violations, including inadequate age verification and a vague privacy policy (EDPB, 2025). Replika also runs Hotjar session recording on its website and shares website visitor data (not conversation content) with advertising partners. See the full Replika review for details.
Kindroid is the only app in this comparison with documented chat encryption at rest, not just in transit. In our review, Kindroid stood out for describing encrypted storage for chats and other sensitive application-layer data, plus a deletion flow that removes data after the last Kindroid is deleted. It also documents no-sale language and CCPA-style deletion and export rights. The caveat: Kindroid reserves the right to decrypt data for legal compliance or ToS enforcement, and it grants itself a license to de-identify and aggregate user content for any purpose. Still, that’s more transparency than most competitors offer. For the full picture, see our Kindroid review.
Nomi AI deserves a mention for one specific metric: it has zero ad trackers and zero third-party cookies, per our Blacklight scan. That’s the cleanest tracker profile of any app in this comparison. However, Nomi’s overall D/32 safety score reflects weaknesses elsewhere, including a training archive that survives account deletion and a January 2026 revelation that the app scans conversations in real time for self-harm expressions, contradicting earlier public statements. Our Nomi AI review covers the full breakdown.
Which AI Companion Apps Are Worst for Privacy?
Eva AI earns the lowest safety score of any app we’ve reviewed: F/10 out of 100. Its privacy policy allows the company to “elect to keep your personal data” even after you request deletion, and explicitly states that content “may persist in cached pages” and data already shared with third parties won’t be recalled. Mozilla’s Privacy Not Included project assessed Eva AI and concluded: “We cannot confirm encryption at rest and in transit for this app.” Eva AI shares usage data with Mintegral, an ad SDK, and sends user images to an external object recognition service. The company’s claim that it doesn’t sell data contradicts the documented Mintegral data sharing. See our Eva AI review.
Romantic AI (F/13) combines vague security claims with concerning data practices. The app’s privacy policy references “secure certificates from VeriSign and McAfee” as its primary security measure, but makes no claims about end-to-end encryption or encryption at rest. Our Blacklight scan detected scripts sending data to both Alphabet (Google) and Yandex LLC. The policy also includes a non-compete clause requiring users to “guarantee that you will never generate any databases, apps, software, legal entities, and services that compete with Romantic AI,” an unusual provision buried in a privacy-related document. Data retention is especially concerning: the policy says the company “may elect to keep” your personal data after deletion, with no stated timeline for when that data would actually be removed. Read the full Romantic AI review.
Chub AI (D/25) presents a different kind of privacy risk. Its privacy policy discloses broad data collection, but Apple’s iOS privacy labels reveal categories the policy omits. The eSafety Commissioner’s October 2025 transparency notice documented zero dedicated safety staff and 47 CSEA reports. See our Chub AI review for the full breakdown.
Chai AI (F/18) has the longest post-deletion data retention period of any app we reviewed: five full years. According to Chai AI’s privacy policy, data is “retained for duration of account plus 5 years after deletion,” with longer retention possible for “legal claims/disputes/compliance.” Data used for AI training is permanent, per the policy. Mozilla’s Privacy Not Included review found that encryption at rest could not be confirmed. The app processes AI training data under a “legitimate interest” legal basis rather than explicit user consent, and while the company claims to remove identifiers before training, that claim is unverifiable from the outside. Our Chai AI review covers additional safety concerns.
Character AI (F/22) collects one of the broadest data sets of any app in this comparison, including chat content, voice data, images, video, device identifiers, browsing behavior, and geolocation. The app’s terms of service grant Character Technologies a “nonexclusive, worldwide, royalty-free, fully paid up, transferable, sublicensable, perpetual, irrevocable license” for all submitted content. Our Blacklight scan found 12 ad trackers on Character AI’s website, including Criteo and Lotame, more than double the average of 7 found on popular sites. The company explicitly states that data is used to “train our artificial intelligence/machine learning models.” For the complete assessment, see our Character AI review.
What Data Do AI Companion Apps Actually Collect?
Every app in this comparison collects your conversation content. That’s the baseline. The differences start with what else they collect and how they use it. Our review of all 11 privacy policies found that data collection falls into five categories, and each app covers them differently.
Account information is standard across all apps: name, email, date of birth, and payment details if you subscribe. Some apps go further. Candy AI collects user preferences for AI companion appearance including ethnicity, age range, eye color, body type, and personality type. Replika collects face and head movement data for its AR features, though this data stays on-device and is not stored or transmitted.
Conversation content is where the biggest differences emerge. All 11 apps store your chat messages, but what happens to them varies enormously. Replika sends de-identified snippets to third-party LLM providers who are contractually barred from using them for their own training. Character AI feeds conversations directly into its model training pipeline under a perpetual license. Nomi AI keeps conversation data in “training archives” that survive account deletion but claims to strip identifying information.
Device and network data is collected by every app, typically including IP address, device type, operating system, and browser information. Talkie AI and Character AI go further by collecting geolocation data. Eva AI collects information about “people mentioned in chat,” which means references to real individuals in your conversations are stored alongside your own data.
Behavioral and analytics data ranges from basic (page visits, session length) to invasive. Candy AI runs Hotjar session recording, which captures mouse movements, clicks, taps, scrolls, and network activity compiled into video replays and heat maps. Character AI shares identifiers, internet activity, and geolocation with advertising and analytics vendors. Talkie AI’s privacy policy acknowledges that its analytics and advertising practices “may constitute ‘sale’ or ‘sharing'” under the CCPA.
Voice and media data is collected by several apps but not all. Character AI collects voice data. Talkie AI collects voice and text messages. Candy AI stores voice call data and AI-generated images. Eva AI collects text messages, voice messages, and images sent to the virtual friend. If you’re particularly concerned about voice data, Pi AI and Nomi AI have the narrowest collection profiles in this category.
Can You Delete Your Data from AI Companion Apps?
Every app offers some form of account deletion, but what “deletion” actually means varies from 28 days to never. Our review found three distinct tiers of deletion practices across these 11 apps.
Clear timelines with meaningful deletion:
- Nomi AI: Personal data deleted within 28 days of account deletion. The catch: information in “training or communications archives” survives and becomes de-identified.
- Replika: Messages and content deleted within 60 days after account closure. Account info and financial records retained 10 years (legal requirement). LLM-transmitted data deleted by providers after generating each response.
- Candy AI: Account data retained 3 years after last activity, or until deletion request. Financial data kept 10 years. Marketing data retained until consent withdrawal or 2 years after last interaction.
Vague timelines with limited guarantees:
- Pi AI: Data stored “for as long as your account remains active.” No specific post-deletion timeline.
- Kindroid: Chat data retained until user deletes the AI or account. May retain data longer for legal compliance. Anonymous/aggregated data kept indefinitely.
- Anima AI: Retained “as long as reasonably necessary.” No specific timeframe.
- Talkie AI: No specific retention period stated.
Concerning retention practices:
- Chai AI: 5-year post-deletion retention. Data used for AI training is permanent.
- Eva AI: Company “may elect to keep” data after deletion. Content persists in “cached pages” and data already shared with third parties won’t be recalled.
- Romantic AI: “May elect to keep” personal data. No timeline for actual removal.
- Character AI: No specific retention period. Popular user-created characters may be preserved even after account deletion to avoid “impacting other users’ experience.”
On regulatory compliance, only Pi AI and Replika document both GDPR and CCPA rights with specific mechanisms for exercising them. Kindroid details CCPA rights but lacks explicit GDPR provisions. Several apps mention GDPR or CCPA in passing without providing clear procedures for data access, portability, or deletion requests. For guidance on how to read these policies yourself, see our guide on understanding AI companion privacy policies.
What the Privacy Policies Actually Say
Privacy policies are written by lawyers, not for you. So we pulled the passages that matter most and put them here in plain sight. These are the companies’ own words.
On using your conversations to train AI:
Character AI’s privacy policy states that data is used to “train our artificial intelligence/machine learning models” and to “develop new features, algorithms and machine learning models.” Its terms of service add that users grant a “nonexclusive, worldwide, royalty-free, fully paid up, transferable, sublicensable, perpetual, irrevocable license” for all submitted content. That license survives account deletion.
Candy AI’s policy is more specific about the process: conversations “may be aggregated, anonymized, and/or de-identified” for “quality assurance, internal research, training AI models, and developing moderation technologies,” which “may include human review of de-identified and/or anonymized interactions.” Human review of your conversations, even de-identified ones, is a detail most users wouldn’t expect.
Replika takes a different approach. Its policy states: “We will never use or disclose the content of your Replika conversations for marketing or advertising purposes.” Small portions of de-identified messages are used “only internally” for “proprietary safety algorithms” and are “not used to train third-party large language models or other AI systems.”
On what happens after you delete your account:
Nomi AI’s policy notes that while personal information is deleted upon account closure, information in “training or communications archives” survives and “would no longer be attributable to you.” Whether de-identification of archived conversation data is truly irreversible is a question no privacy policy can fully answer.
Chai AI’s retention clause is the most aggressive: data is retained for “the duration of account plus 5 years after deletion,” and Reddit users analyzing the policy concluded that “anything already used for AI training = permanent.”
Eva AI’s approach is the most troubling: “We may elect to keep your personal data, subject to the requirements of the law and legitimate interests of the Data controller.” The policy further warns that “changing or deleting your personal data will only change or delete the data in our database for purposes of future activities” and won’t affect data “already forwarded to other users or credit card companies or any other third parties.”
On selling your data:
Pi AI’s policy states explicitly that “Inflection does not sell/share personal info for targeted advertising.” Kindroid says it “will not sell or share your Personal Data, and have not done so over the last 12 months.” Nomi AI claims: “We do not and will not sell or rent to any third party any of your personal information.” Eva AI similarly claims “We neither rent nor sell your information to anybody,” though this conflicts with its documented Mintegral ad SDK data sharing.
Notice the gap between stated policy and actual practice? It shows up over and over. For a deeper look at how to evaluate these claims yourself, see our guide on how AI companion apps use your data.
Frequently Asked Questions
Which AI companion app has the best privacy policy?
Pi AI earns the highest privacy marks with a B/55 safety score on the CompanionWise Safety Index. As a Public Benefit Corporation, Inflection AI has legal obligations beyond profit that influence its data practices. Pi doesn’t sell data for targeted advertising and limits third-party sharing to service providers. According to Pi’s privacy policy, the company does not share personal information for advertising.
Do AI companion apps sell your data to advertisers?
Most claim they don’t, but the reality is more complicated. According to Talkie AI’s privacy policy, its analytics and advertising practices “may constitute ‘sale’ or ‘sharing'” under California’s CCPA. Character AI shares personal information with advertising partners for “tailored advertising.” Eva AI claims no selling but shares usage data through the Mintegral ad SDK. Pi AI and Kindroid have the strongest no-sale commitments.
Can AI companion apps read your conversations?
Yes. Every AI companion app collects and processes your chat messages to generate responses. According to Candy AI’s privacy policy, this process “may include human review of de-identified and/or anonymized interactions” for AI training purposes. Nomi AI confirmed in January 2026 that it runs real-time algorithmic scanning of conversations for self-harm expressions. Only Kindroid encrypts stored chat data at rest.
How long do AI companion apps keep your data after you delete your account?
Timelines range from 28 days to 5 years. Nomi AI deletes personal data within 28 days. Replika retains messages for up to 60 days post-deletion. According to Chai AI’s privacy policy, data is “retained for duration of account plus 5 years after deletion,” and data used for AI training is permanent. Eva AI and Romantic AI reserve the right to keep data indefinitely.
Are AI companion apps GDPR compliant?
Few meet the standard fully. Replika has the most documented GDPR compliance, but Italy’s Garante fined its parent company EUR 5 million in April 2025 for persistent violations, including inadequate age verification (EDPB, 2025). Pi AI documents both GDPR and CCPA rights. Most other apps mention GDPR in passing without clear compliance mechanisms.
Do AI companion apps use your conversations to train AI models?
Most do. Character AI explicitly states it uses data to “train our artificial intelligence/machine learning models” under a perpetual, irrevocable license. Chai AI trains on conversations using a “legitimate interest” legal basis rather than explicit consent. Replika uses small de-identified samples only for its own safety algorithms, not third-party models. According to Nomi AI’s privacy policy, conversation data in “training archives” survives account deletion.
Which AI companion apps use ad trackers?
Character AI leads with 12 ad trackers detected by The Markup’s Blacklight tool, more than double the average of 7 found on popular websites. Candy AI has 8 trackers plus Hotjar session recording. Replika runs Google, Facebook, and Hotjar scripts. On the other end, Nomi AI has zero ad trackers and zero third-party cookies, the cleanest tracker profile of any app in this comparison.
Privacy is one of six dimensions in our 23-sub-dimension safety scoring framework. An app with strong privacy practices can still score poorly if it falls short on content moderation, crisis response, or age verification. For the full picture on any individual app, check our app reviews and safety ratings, or take the Companion Matchmaker Quiz to find the app that fits your priorities.