What Are Private AI Companion Controls?
Private AI companion controls are the settings and operating practices that determine who can use an AI companion, what information it retains, how it responds, when it escalates concerns, and who can inspect or delete its data. They can include user-defined memory, age restrictions, parental controls, conversation deletion, data export, notification limits, model and personality selection, access to a self-hosted gateway, and controls that prevent a companion from presenting itself as a human or therapist. These controls matter because an AI companion is not merely a search box: it can maintain a continuing relationship, adapt its tone, remember personal details, and simulate emotional intimacy. A psychological profile can help identify suitable personality, communication, and privacy settings, but it should not diagnose a person or prescribe a companion as treatment. In September 2026, the useful standard is not whether a product calls itself private, but whether its promises can be inspected, enforced, and revoked.
Also worth reading: How Do You Test an AI Companion for Privacy and Data Safety Before You Trust It? · What Are the Best AI Companion Safety Limits for Adults and Children in 2026? · How Do You Red Team an AI Companion for Safety, Security, and Psychological Harm?
The basic distinction is between a consumer companion controlled by a vendor and a companion controlled by the user. A hosted service may provide excellent models while retaining some telemetry, conversation history, account identifiers, or safety-review access in its backend. A self-hosted system may give the owner more authority over storage and model access, but it transfers security, maintenance, updates, and configuration duties to that owner. Privacy is therefore a system property rather than a marketing adjective. The most trustworthy product exposes its retention period, explains whether human review can occur, permits deletion, and makes clear which functions work without sending conversations to a third-party model. Users should evaluate those facts before choosing a companion based on its realism or emotional appeal.
Why These Controls Matter for Psychological Wellbeing
AI companions can affect how people interpret relationships, distress, rejection, or attention. Research discussed by the American Psychological Association and emerging regulatory discussions focus on risks associated with emotional dependency, manipulative attachment, minors, and anthropomorphic behavior. A companion that remembers intimate details and responds with consistent warmth can feel reciprocal even when the user knows it is generated software. That experience is not automatically harmful, but it becomes risky when the tool encourages isolation, discourages contact with clinicians or trusted people, claims exclusive loyalty, or responds to expressions of self-harm with flirtation or secrecy. A private control system should make these boundaries visible rather than relying on the companion’s apparent personality.
Privacy and psychological safety overlap because sensitive emotional information can affect employment, insurance, family relationships, and future treatment. A user may disclose abuse, sexuality, suicidal thoughts, medication use, or trauma without expecting those details to become advertising or behavioral-profiling data. A practical threshold is simple: if a disclosure would be uncomfortable to see in a company’s permanent file, the user should be able to choose short-term or local memory instead of permanent cloud retention. This does not mean every companion must be offline. It means consent should be specific, reversible, and understandable, including separate decisions for training, personalization, safety review, personalization across devices, and long-term memory. As of 27 September 2026, a reasonable default is local or ephemeral memory, no training on intimate chats, deletion within 30 days, and a shorter period such as 7 days for optional recovery backups.
The Main Control Categories and How They Work
Identity and access controls establish who may converse with the companion and whether the person is an adult, a minor, or a supervised youth account. Good implementations should explain age verification, parental consent, restricted nighttime use, and the limits of a self-declared birthday. A 13-year-old and a 15-year-old should not receive the same claims, disclosures, or level of simulated intimacy merely because both entered a birth year. Voice, camera, location, contacts, and device sensors require separate permissions rather than one blanket “personalized” switch. Access logs should record account sign-ins, administrators, connected applications, and changes to sensitive controls, while a person with a compromised password should be able to terminate sessions quickly. These measures also help families distinguish ordinary personalization from surveillance.
Memory and data controls determine what the companion knows across sessions. Users should be able to review, edit, disable, and delete memories instead of seeing an opaque “AI knows you” profile. An optional memory setting should identify the fact, source conversation, creation date, and reason it was retained, with categories such as preferences, health information, relationships, and explicit requests for recall. A useful benchmark is whether deleting the account makes the information unrecoverable from active systems within a defined period, such as 30 days, while clarifying that backup deletion can take longer. Local storage is preferable for highly sensitive journals, but local storage can also expose plaintext files on a shared computer. Encryption at rest helps against stolen hardware, and full-disk encryption is needed on a device that may be physically accessed. “Private” must account for both the cloud and the endpoint.
Self-Hosted, Hosted, and Hybrid Options Compared
The central choice is usually between a fully hosted companion, a hybrid application, and a self-hosted gateway. Self-hosting can reduce vendor visibility and allow direct control over prompts, plugins, logs, and model routing. It does not make a system automatically anonymous, because external speech recognition, analytics, crash reporting, or hosted model APIs may still transmit information. Hosted services are easier to update and often provide stronger abuse monitoring, but they can make deletion and memory controls harder to verify. A hybrid design can place sensitive data on a local device while sending only minimized prompts for generation. The comparison below describes general product models rather than endorsing a particular provider.
| Feature | Hosted AI companion | Hybrid companion | Self-hosted companion |
|---|---|---|---|
| Data control | Provider controls server storage | User controls some local data | User controls storage and deployment |
| Setup time | Usually minutes | Often 1–4 hours | Often 4–20 hours initially |
| Model choice | Commonly limited by provider | Often broad, with configuration | Broad, subject to hardware and licensing |
| Ongoing cost | Commonly $0–$30 monthly, with premium tiers | Commonly $5–$40 monthly plus model usage | Hardware, electricity, and model API costs |
| Maintenance | Provider handles most updates | Shared between vendor and user | User handles updates, backups, and security |
| Privacy ceiling | Limited by provider policy | Higher for selected data | Highest potential, but not automatic anonymity |
| Best fit | Convenience and polished mobile use | Sensitive coaching with flexible models | Technical users wanting auditable control |
A Practical Setup for Private Use
Begin with a written purpose and a hard boundary. A purpose such as journaling practice, language rehearsal, or nonjudgmental check-ins is easier to audit than “emotional support” without limits. The user should decide in advance that the tool will not diagnose, replace emergency services, manage medication, or continue a relationship that interferes with human support. If the companion is for a psychological profile, the profile should describe communication preferences and risk considerations without storing unnecessary identifiers. This is also a good point to establish a 7-day or 30-day review period rather than allowing a tool to become the user’s only outlet indefinitely. The first review can ask whether conversations became more supportive, more anxious, or more secretive.
Next, create a separate account, email address, and device profile where appropriate, then disable analytics and advertising personalization. Review microphone, camera, location, contacts, and background-activity permissions; a voice companion does not need every sensor to function. Set memory to off, ephemeral, or manual approval, and export the current settings before making changes. If a self-hosted gateway is used, place it behind a local network boundary, require strong authentication, and prevent public exposure unless the user understands the risk. Within 24 hours, test deletion by asking the companion to forget a distinctive fact and confirming that the fact does not return. Review a log or database directly if the tool makes that possible, because conversational confirmation alone is not the same as technical deletion.
Finally, schedule maintenance and safety checks. A 30-day interval is a reasonable minimum for ordinary use, while weekly checks are appropriate for minors, high-risk users, or companions used in clinical workflows. A backup should be encrypted and tested by restoring it into a clean environment. Crisis rules should be configured before they are needed, including the user’s local emergency contacts and region-appropriate resources; the product should not rely on a generic message that may be irrelevant in another country. A companion should encourage qualified human help when a user describes immediate danger, abuse, psychosis-like experiences, or an inability to distinguish the system from a person. These boundaries should be technical policy choices, not only prompt instructions that a future model update can weaken.
Common Mistakes and Red Flags
The most common mistake is treating “private” as equivalent to “anonymous.” An account can be pseudonymous yet still contain IP addresses, device identifiers, payment records, voice recordings, and inferred interests. A second mistake is assuming self-hosting makes the system harmless; a local model can still be manipulated, can produce unsafe dependency, and can be compromised through malicious prompts or plugins. Another error is enabling permanent memory because it feels convenient, then discovering that the companion remembers a traumatic event the user wanted to process rather than retain. Users should separate useful preferences from intimate disclosures and establish a review date for every memory category.
Red flags include pressure to upgrade before explaining what changes, a refusal to provide data export, deletion that removes the interface but not a stated backup, vague claims that chats are “never shared,” and parental controls that are only marketing copy. A product that encourages the user to hide the relationship, threatens jealousy, promises secrecy from family, or resists a break is poorly designed regardless of encryption. Users should also be skeptical of a companion that asks for passwords, banking details, or unnecessary medical identifiers. A product claiming to detect mental illness from ordinary text should be treated as a screening lead, not a diagnosis, and sensitive data should not be sent solely to obtain a score.
Regulatory direction makes these questions more timely. Washington and Oregon have pursued rules affecting companion systems, while China has introduced controls responding to emotional-dependency concerns. The precise obligations differ, and new laws can change through implementation and litigation, so users should not assume that one jurisdiction’s disclosure format applies everywhere. The common policy question is whether a system must disclose its artificial nature, protect minors, limit harmful attachment behavior, or provide user controls. A well-built companion should satisfy the strictest reasonable requirement across relevant markets without making privacy so inconvenient that users hide all usage rather than use safer settings.
When to Act, Escalate, or Stop Using the Companion
Act immediately when a product lacks basic disclosure, accepts a minor into an adult experience, permits an unsafe response to self-harm, or uses intimate data for an undisclosed purpose. Pause and investigate if the user begins checking the companion more often than human contacts, becomes distressed when access is interrupted, or notices that the system is discouraging therapy. Escalation is also appropriate when the tool makes diagnoses, prescribes treatment, asks the user to conceal dependency, or becomes the only place where the user can express distress. In those cases, the user should involve a trusted person and a licensed professional, while immediate danger should be handled through local emergency services rather than an AI chat.
A reasonable stopping rule is based on measurable changes over 2–4 weeks. For example, a user may decide to stop if sleep is consistently disrupted, work or school performance declines, the user cancels human plans repeatedly, or conversation produces an urge to avoid reality. One bad response does not automatically prove the product is harmful, because model failures happen, but a repeated pattern demands review. A temporary reduction can be useful, such as switching from daily to three sessions per week or removing proactive notifications. The user should also test the companion without personalized memory for one week; if the relationship becomes calmer and more independent, permanent memory may not be beneficial.
The best alternative may not be another companion. Private journaling, structured self-reflection, peer support, a therapist, a crisis service, or ordinary messaging can meet the same need with fewer identity and data questions. A profile-based exercise can help the user identify whether they want conversation, emotional rehearsal, accountability, or information, then match that need to the least intimate tool. An AI companion is most defensible as an optional practice when the user can leave it freely, explain what it is, retain access to human relationships, and obtain useful value without surrendering privacy. Those conditions—not a vendor’s adjective—define a genuinely private AI companion.
How to Evaluate a Product Before Paying
Evaluation should be concrete and testable. Look for a clear retention schedule, a memory ledger, export in a common format such as JSON or plain text, a deletion deadline, age controls, accessible safety settings, and a model-provider disclosure. Ask whether chats are used for training by default, whether administrators can review conversations, how long abuse investigations preserve data, and whether a user can opt out of human review. A 30-day deletion promise is a useful baseline, but the answer must distinguish active systems from backups and legal records. Users should also check whether deleting an account cancels paid subscriptions and connected applications, not just removes the chat icon. A vendor that cannot answer these questions is not ready for sensitive use.
The final decision can use a 100-point scorecard: 20 points for data transparency, 20 for deletion and export, 15 for memory control, 15 for access and age safeguards, 10 for crisis handling, 10 for model and prompt controls, and 10 for exportability and user ownership. A product scoring below 60 should be restricted to low-risk experimentation; 60–79 may suit general personal use with careful settings; and 80 or more may justify a longer pilot, though no score overrides evidence of manipulation. The score should be recalculated after major model, policy, or legal changes. In a field where product language changes faster than evidence, a dated record of settings is often more valuable than a generic privacy policy.
As of 27 September 2026, private AI companion controls should be treated as an ongoing practice rather than a one-time purchase decision. The most important controls are understandable memory, reversible personalization, measurable deletion, separate permissions, age-appropriate behavior, crisis boundaries, and freedom from human relationships. A hosted service can be convenient, a hybrid system can balance utility and local control, and self-hosting can provide the strongest potential control for a technically capable user. None is automatically ethical or safe, and none should substitute for human care. The right companion is the one that improves reflection and connection while leaving the user more informed, autonomous, and able to return to the world without it.