AI Companion Privacy: What These Apps Actually Do With Your Conversations
You tell a companion things you would not tell your friends. It is worth knowing where those words go.
Updated August 2026 — includes the 2025–2026 enforcement actions and the arrival of age verification.
People tell AI companions things they've never said out loud. That's the whole appeal, and it's also what makes the privacy question different here than it is for a shopping app. A leaked shopping history is embarrassing. A leaked companion history is something else.
This article is the version of that conversation nobody in this industry particularly wants to publish, us included. It covers what actually happens to your messages, what the regulatory record of the last two years shows, and the five things worth checking before you get attached. Where we describe our own practices, we've tried to be specific enough that you could hold us to it.
Where Your Message Actually Goes
Start with the mechanic that nearly every app glosses over. When you send a message to an AI companion, that text is almost always transmitted to a large language model running on someone else's computers — often a third-party AI provider rather than the companion company itself. That's not a scandal; it's how the technology works, and building your own model from scratch is beyond nearly everyone. But it means the honest answer to "who can see this?" is usually "more parties than you assumed."
The four questions that separate apps from each other are these:
- Is your conversation stored, and where? On your device, on the company's servers, or both.
- Is it used to train models? Some policies permit this explicitly. It's usually a line in the terms rather than something you'll be asked.
- Who else receives it? AI providers, analytics tools, ad networks.
- Can you get it back or get rid of it? Export and deletion, and whether deletion actually deletes.
One thing no major companion app currently offers, as far as we can determine: end-to-end encryption of the kind Signal gives your messages. It isn't really possible while an AI has to read your words to answer them. Anyone claiming otherwise deserves a follow-up question.
What the Last Two Years Actually Showed
This isn't theoretical anymore. There's a public record now, and it's worth reading before you decide who to trust.
In May 2025 the Italian data protection authority fined Luka Inc., the company behind Replika, €5 million. The findings included processing user data without a valid legal basis, failing to meet transparency obligations, and having no functioning age verification. A separate investigation into whether user conversations were used to train the model was opened alongside it.
In 2025 Australian regulators published findings on several companion services. Nomi's operator reported having no dedicated trust and safety staff or moderators at all. That's a safety finding rather than strictly a privacy one, but it tells you something relevant: how much institutional attention is being paid to what happens inside those conversations.
And in the United States, a federal inquiry into companion chatbots opened in late 2025, while California's SB 243 came into force in January 2026 with requirements around AI disclosure and crisis protocols. Regulation has arrived. Most of these companies were built before it did.
The Newest Trade-off: Proving You're an Adult
Age verification swept the category through 2026. Character.AI closed open-ended chat to under-18s and verifies adults through a third-party identity service; Kindroid added checks in April; others use platform-level age APIs.
The intent is good and the pressure behind it is legitimate. But notice what it means for privacy: to use a service you chose partly because it felt anonymous, you may now hand over a selfie or a government ID. Your companion app can end up holding a stronger proof of who you are than your gym does — attached to the most personal conversation log you own. Adults have also reported being misclassified by these systems and locked out while appealing, which is its own kind of exposure.
This isn't an argument against age checks. It's an argument for knowing that the anonymity many people came here for is quietly ending, and for choosing accordingly.
Alma is free to try without an account at all — no email, no card, no ID.
Start Talking →Five Things to Check Before You Share Anything Real
- Search the privacy policy for the word "train." You're looking for a clear statement that your conversations are not used to train models. Vagueness here is a choice someone made.
- Find the delete button before you need it. Can you delete your account and data yourself, or does it require emailing support and hoping? The difference tells you how the company thinks about your data.
- Check whether there's an export. Being able to take your history with you is a good sign in itself — companies that plan to hold you hostage don't build export features.
- Ask who pays. If an app is free with no subscription and no ads, the money is coming from somewhere. That question has a real answer and you're entitled to it.
- Look at what it asks for up front. An app that wants your phone number, contacts or ID before you've sent a single message has told you its priorities.
Our fuller checklist, including the emotional-safety side, is in are AI companion apps safe?
What Alma Does — Specifically
It would be convenient to claim we're the private one and move on. Here's the actual shape of it, including the parts that aren't flattering.
Your messages are sent to an AI provider. They have to be, for a reply to come back. This is true of us and of every competitor listed above, and any app implying otherwise is being loose with you.
If you don't make an account, nothing syncs. You can use Alma as a guest, and your conversation stays in your browser. No email, no card, no identity check.
If you do make an account, your conversation history is stored on our servers — that's what makes it appear on your laptop as well as your phone. It's protected by row-level security, meaning the database itself enforces that only your account can read your rows. We don't sell it, we don't use it for advertising, and we don't train models on it.
You can see what Alma remembers. The memories she keeps about you are visible in a journal, and you can edit or remove them. Memory you can't inspect is memory you can't correct — we think that's the more important right, and it's covered in more depth in how companion memory works.
None of this makes us uniquely virtuous. It makes us legible, which is the most any app in this category can honestly offer. The right posture toward every AI companion, ours included, is the one you'd take toward a new acquaintance who is a very good listener: warm, glad they're there, and not yet telling them everything.
Common Questions
Do AI companion apps save your conversations?
Most do, at least for account holders, because storing conversations is what lets a companion remember you and appear on more than one device. The important questions are where they are stored, whether the company uses them to train models, and whether you can export and delete them. Some apps keep conversations only on your device until you create an account.
Are AI companion conversations private?
They are private from other users, but not private in the way an encrypted messenger is. Your messages have to be sent to an AI model to generate a reply, which usually means a third-party AI provider receives them too. No major companion app currently offers end-to-end encryption, because the AI has to be able to read your words to answer them.
Has an AI companion company ever been fined over privacy?
Yes. In May 2025 the Italian data protection authority fined Luka Inc., the company behind Replika, €5 million for processing user data without a valid legal basis, transparency failures and the absence of age verification, and opened a separate investigation into whether user conversations had been used to train its model.
Do AI companion apps train their AI on my conversations?
It varies, and the answer is usually in the terms rather than in the app. Some policies explicitly permit it. Search any privacy policy for the word "train" before sharing anything sensitive — a clear statement that conversations are not used for training is a meaningful signal, and vagueness is a choice the company made.
Do I have to give an AI companion app my ID?
Increasingly, some ask. Age verification spread across the category in 2026, and several services escalate to a selfie or government ID to confirm you are an adult. It is a real privacy trade-off: proving your identity to a service you chose because it felt anonymous. Apps that let you start without an account avoid this at the cost of not syncing across devices.