AI Companion Privacy Checklist 2026
Before paying for any AI companion app, verify seven things: data export, permanent deletion, whether chats train the model, encryption, payment privacy, account-less or anonymous sign-up options, and the company’s regulatory record. Kindroid currently scores best on these; always confirm on the app’s own privacy page.
Use this checklist before you pay for any AI companion app. Each item maps to something you can verify on the app’s own privacy policy — not a third-party summary. It expands the four-question test in our safety guide into a practical pre-purchase routine.
The 7-point checklist
- Export. Can you download your full chat history in a usable format?
- Deletion. Can you permanently delete your data, and is there a stated timeline for it being purged from backups?
- Training opt-out. Are your conversations used to train the underlying model? Is there an opt-out, or a default no-train policy?
- Encryption. Is data encrypted in transit and at rest? Are “private” chats handled differently?
- Payment privacy. How does billing appear on your statement? (Candy AI, for example, bills as “Everai.”) Does the processor receive more than necessary?
- Sign-up footprint. Can you use the app without linking more identity than you’re comfortable with?
- Regulatory record. Has the company faced fines, complaints or lawsuits? (See Replika’s GDPR fine and FTC complaint, and Character.AI’s safety lawsuits.)
How the leading apps score on privacy
| App | Privacy posture | Notes |
|---|---|---|
| Kindroid | Strongest | Encrypted private chats; states it does not train base models on your chats |
| Nomi AI | Standard | Data used to improve the AI; no strong E2E encryption |
| Candy AI | Standard | Billing appears as “Everai”; check export/deletion |
| Character.AI | Standard | 2026 changes focused on age assurance |
| Replika | Most history | €5M GDPR fine; 2025 FTC complaint (advocacy groups, not an FTC action); 2026 state laws |
See the full methodology for how privacy is weighted (20% of the total score).
A quick rule of thumb
If an app can’t clearly answer export, deletion and training in its own policy, treat that as a red flag — those three are the baseline for an intimate-conversation product in 2026.
The five-minute prepay audit
Before you subscribe, open three pages in separate tabs: the privacy policy, the terms of service and the pricing or subscription page. Search each page for “delete”, “training”, “retention”, “share”, “processor”, “children”, “refund” and “cancel”. If those words are missing or vague, the app is asking you for intimate data without giving you normal buyer visibility.
For adult or romantic companion apps, also check whether generated images, voice clips or call-style features are stored differently from text. A text chat and a generated image are both personal data, but the risk profile is not the same. If a company only explains chat deletion and says nothing about media, ask support before paying.
What good answers look like
A strong privacy page should tell you:
- Whether chats are used for training by default
- Whether you can opt out of training
- Whether private chats are encrypted
- How long deleted data remains in backups
- Where to send a formal privacy request
- Which payment or analytics processors receive account data
- Whether minors are blocked, age-gated or handled differently
Short policies are not automatically bad. Vague policies are. “We may use information to improve services” is common legal wording, but for AI companions it should trigger a follow-up question: improve which service, with which data, and can the user opt out?
How to handle unclear apps
If an app is unclear but you still want to test it, keep the test disposable:
- Use a new account email.
- Do not share names, addresses, work details or health information.
- Avoid uploading face images or voice clips.
- Stay monthly, not annual.
- Export and delete before the test becomes a habit.
This is especially important for newer visual girlfriend apps where pricing, media retention and training policy can be harder to verify from public pages. Low documentation does not prove bad behavior, but it does lower confidence.
Where this appears in our reviews
Every review maps privacy evidence back to the same 20-point rubric. Apps with stronger deletion controls, clearer training language and fewer regulatory issues can score well even if they are not the flashiest product. Apps with great visuals but unclear privacy stay lower because the data is more intimate and harder to unwind.
For incident history, see the AI companion privacy and safety incident tracker. For app-level deletion steps, use data deletion by app.
Frequently asked questions
What should I check before subscribing to an AI companion app?
Check that you can export and permanently delete your data, whether your chats are used for training, whether data is encrypted, how billing appears on your statement, and the company’s regulatory record. Run these checks on the app’s own privacy policy, not third-party summaries.
Do AI companion apps train on my conversations?
Some do and some don’t. Several apps use conversations to "improve the AI." Kindroid states it does not train base models on your conversations, which is currently the strongest stated position among the apps we rank.