AI companion privacy settings determine how a chatbot handles conversation history, voice files, memory, account details, and information shared with third parties. They do not automatically guarantee privacy, because protections vary by product, jurisdiction, subscription plan, and whether the service uses cloud processing, human review, advertising, or model training. The safest approach in 2026 is to combine careful configuration with data-minimizing habits, periodic account reviews, and a clear understanding of which controls are technical rather than merely promises. As of September 27, 2026, users should assume that anything entered into a general-purpose AI companion may be stored unless the provider explicitly states otherwise.
No single setting controls every privacy risk. Memory controls may reduce personalization without deleting server-side records, while “do not train” controls may not prevent abuse monitoring, fraud prevention, legal retention, or service analytics. Consumer AI products may also change their terms or defaults during a subscription, so a setting that looked protective in January may not remain equally protective in September. The practical objective is not to find a fictional zero-risk button; it is to limit what the system collects, restrict how it uses that information, shorten retention, and make unwanted disclosure difficult.
Also worth reading: How Do Ambient AI Scribes Impact Patient Privacy and Regulatory Compliance in Mental Health Settings? · How can organizations protect privacy while implementing AI psychological profiling? · How Should RAG Systems Protect Psychological Data and AI Profiles in 2026?
What AI Companion Privacy Settings Actually Control
The most useful controls usually fall into several categories, even if each provider labels them differently. Conversation history controls determine whether past messages appear when the companion starts a new session. Memory controls decide whether the system extracts durable facts—such as a preferred name, health concern, relationship status, workplace, or location—and recalls them later. Training controls state whether conversations may be used to improve models, including human review in some circumstances. Voice, image, and file controls can determine whether uploads enter model processing, cloud storage, or third-party systems used for speech recognition, transcription, safety, or content moderation.
Account controls also matter because deletion in the chat window is not always deletion from the service. A trustworthy workflow should provide access to stored data, a deletion request mechanism, and information about backups or legal exceptions. Some products offer temporary or 30-day memory, while others retain selected data indefinitely for security and regulatory reasons. Controls governing connected apps, plugins, search, calendar, email, health integrations, and smart-home devices can matter as much as the chatbot itself, because a companion may receive information indirectly rather than through a typed prompt.
Users should distinguish pseudonymous, private, confidential, and local. “Private” may mean that a message is not visible to other people in the ordinary interface. “Confidential” may indicate that a company promises not to disclose content except under specified conditions. “On-device” processing means inference or a particular operation happens on the device, but it does not necessarily prove that no network connection occurs. “End-to-end encrypted” has a precise meaning in messaging systems, but AI services often cannot use that full model if the provider must read prompts on its servers; consequently, some companies may use encrypted transport while still processing conversations on backend servers.
The relevant unit of privacy is not only the model. Provider logs, content-moderation systems, analytics tools, customer-support platforms, payment processors, and contractors may all process information. Reading every control in a consumer interface can be difficult, so users should look for a plain-language privacy notice, data export, deletion, opt-out, and training settings. If those materials conflict, account-specific controls and the provider’s current terms deserve close attention, though changing terms may still require contacting support or filing a formal privacy request.
How to Review and Configure an AI Companion Safely
Begin with an account dedicated to the companion rather than sharing a profile used for banking, work, social media, or health services. Enable a unique password and, where offered, multi-factor authentication; security is part of privacy because stolen conversations can expose intimate details. Review active sessions, connected applications, recovery email addresses, and devices with account access. Remove integrations that are not necessary, especially email, contacts, cloud storage, location, calendar, and health platforms. Two-factor authentication is particularly important where the account contains payment methods or highly personal conversations, although some companion services may not yet offer that feature.
Next, turn off human-style memory unless it is genuinely useful and the retention period is clear. Do not assume that deleting a remembered fact immediately removes it from conversational logs, embeddings, analytics, or backups. Select the shortest reasonable history period, avoid uploading identification documents, and prevent training or human review on content when the service provides that option. For a paid plan, confirm that the training opt-out applies to the plan the user actually has, not only to a separate business or enterprise tier. If the provider requires a formal request, ask whether that request covers account identifiers, voice recordings, attachments, inferred memories, and data shared with processors.
A practical test is to open the privacy or data-control page and ask whether the companion should remember a harmless but distinctive fact. After confirming, begin a new conversation and test whether it recalls the fact. This does not prove the underlying policy, but it can reveal whether memory is immediate, delayed, or reselected by the system. Users should also test attachment deletion and history deletion, and they should take a screenshot or export account data before requesting deletion. A data export can help a user identify stored dates, device information, or unexpectedly broad inferred categories that were not obvious from the interface.
Sensitive information should be generalized before it reaches the service. Replace an exact address with a neighborhood, remove dates of birth and full names, and describe symptoms without attaching medical records. A companion may be useful without knowing a worker’s exact employer, children’s school, diagnosis, legal case number, or authentication code. One-time email addresses and separate payment instruments can reduce linkage, but aliasing should not be presented as a complete defense: prompt content, behavioral patterns, files, IP addresses, and device identifiers may still permit association.
Cloud AI, Local AI, and Other Alternatives Compared
Local and on-device models generally give the user more direct control over data because prompts need not leave the machine for inference. This can materially reduce cloud exposure, but it does not make local AI automatically private. Local applications may download models from external repositories, enable crash reports, sync settings, or connect to web search. Hardware limitations can also push a “local” product toward remote inference when context is too long or the device lacks sufficient memory. Users should test network behavior with a trusted technical tool or a reputable reviewer rather than relying on the word “local.”
| Feature | Consumer cloud companion | Local or on-device model | Enterprise/private cloud service |
|---|---|---|---|
| Server processing | Usually available and may be unavoidable | Often avoidable for inference | Usually available under contractual controls |
| Setup effort | Lowest; generally ready after registration | Higher; hardware, software, and updates are the user’s responsibility | Moderate to high; requires procurement and administrator configuration |
| Memory and history | Often available with adjustable settings | User manages history and model memory more directly | Governed by organization policy, contract, and retention schedule |
| Training use | May be allowed unless the user opts out | Offline inference generally avoids model-training upload | Commonly contractually restricted, but verify terms and exceptions |
| Cost | Often free to about $20-$30 per month for individual plans | Roughly $0 software plus hardware, power, and possible upgrade costs | Usually negotiated and priced above consumer subscriptions |
| Best fit | General use with strong account controls | Sensitive experimentation, writing, or confidential offline prompts | Organizations handling regulated or business-sensitive data |
A no-AI option may be best for conversations involving ongoing harassment, child safety, domestic violence, medical decisions, or legal advice. A human professional can still have confidentiality duties, but clients should verify licensure, jurisdiction, and record-retention rules. AI companions can provide low-pressure interaction or help users organize thoughts, yet they are not equivalent to licensed mental-health care. The product’s claimed memory feature, safety promise, or recommendation quality does not establish clinical competence or independent clinical validation.
Data Retention, Security, and What a Toggle Does Not Promise
Deletion is one area where marketing language often exceeds technical detail. A “Delete chat” button may remove a message from the visible timeline while leaving operational logs, safety records, invoices, or backup copies for a stated period. Legal and security systems may retain records related to abuse, fraud, or law enforcement even when a user requests deletion. Providers may also retain anonymized or de-identified data, although determining whether modern data is truly anonymous is difficult when it can be combined with account, device, or behavioral information. A credible answer should specify categories and retention periods rather than claiming that deletion is instantaneous.
Transport encryption should not be confused with encryption that prevents the provider from processing content. Most cloud AI services use HTTPS or TLS to protect data while moving between a user’s device and servers. That reduces interception risk on the network, but the service must still receive readable prompts if its model is hosted remotely. Some products offer customer-managed keys or limited server-side encryption controls; those features differ from end-to-end encryption. Users should ask who holds keys, which functions can access plaintext, and whether key management also applies to safety pipelines and backups.
Authentication and software integrity are equally important. An AI companion may create powerful actions through connected email, shopping, calendar, messaging, or coding tools. Users should require confirmation before external actions, restrict spending limits, and avoid giving the assistant unrestricted access to private accounts. A privacy setting that disables training will not protect information if a connected search tool sends a query to a third party. Reviewing connected tools is therefore a recurring task, not a one-time onboarding step.
Voice and video can add separate exposure. A text message may be deleted through a chat-history control, while an audio recording may be kept for transcription, moderation, or quality improvement. Camera input may persist in a device buffer or be transmitted to a remote multimodal service. Users should disable automatic saving where available, delete source files, and watch for the microphone or camera indicator. Device-level permissions, application caches, operating-system cloud backup, and screenshots can remain outside the companion provider’s control.
Common Privacy Mistakes That Still Look Like Good Practice
One common mistake is treating a friendly or “private mode” label as proof that data is not collected. Another is assuming that a memory opt-out means no personalization occurs; the system may still infer patterns during a session and store short-term context. Some users also assume deleting the app removes cloud records, even though the account and server-side history may remain. This is particularly problematic when a phone is replaced or a relationship ends: linked identifiers, old conversations, and connected accounts can persist.
Another mistake is believing that paid means private. Subscription plans may improve model access, memory capacity, or privacy controls, but price is not evidence of deletion, encryption, or no-training policies. Premium consumer services can cost roughly $10 to $30 per month, with higher tiers sometimes reaching $50-$200 per month, yet none should be marketed as private by price alone. Conversely, free services are not automatically unsafe. Their business model may rely on advertising, data retention, limited support, or training permissions, so the decisive issue is the documented data flow.
Users also make mistakes by pasting full records “for context,” using a companion for illegal or regulated activity, or trusting a generated security instruction. A prompt saying “forget this” cannot be assumed to delete server-side data. Sharing another person’s private information without permission can create privacy and legal concerns even if the person involved is the user’s partner, child, friend, or coworker. For child users, a parent or guardian should check age requirements and applicable child-safety rules, because a chatbot’s adult-content setting does not establish that the service is safe for a minor.
Finally, users often review consent only after an account has accumulated years of history. Set a calendar reminder every 3-6 months to inspect connected apps, recent logins, memory, training choices, plan changes, and updated terms. For highly sensitive use, quarterly review may be too slow, so a monthly check is reasonable. If the companion changes service owner, makes a major policy update, begins serving a new country, or adds persistent memory, review again immediately.
When You Should Act and What It May Cost
Immediate action is appropriate after a suspected account compromise, unwanted memory creation, accidental upload of health or identity data, or a policy change that alters the training default. A user should change the password, revoke unfamiliar sessions, remove unauthorized integrations, request account data, and ask for deletion of unintended content. If exposed material includes identity documents, payment data, or precise location, the user should also follow the relevant financial institution’s fraud guidance or contact a local privacy regulator. Evidence such as screenshots, timestamps, and request confirmations can help document what occurred, although screenshots are not a substitute for a formal record.
A person should consider migrating away before entering a new category of sensitive information. A reasonable test is whether the conversation would expose someone to discrimination, physical danger, financial loss, medical consequences, or loss of legal rights. If the answer is yes, a local model or trusted human professional may be more appropriate. A formal deletion request is also warranted when a person no longer wants their relationship history, inferred personality profile, or intimate content connected to an account. State privacy laws and provider procedures can change the exact route and deadline, so users should confirm current requirements rather than rely on an old article.
Individual configuration generally costs no more than an existing subscription, while local models can be free at the software layer. A capable local setup may require a modern computer, solid-state storage, and additional memory or graphics capacity; costs vary widely, and current price checking is necessary before purchase. Some services charge a few dollars for export or enhanced privacy features, while others include them in all plans. Private enterprise contracts can range from hundreds to millions of dollars, so they are not directly comparable to consumer subscriptions. The appropriate cost measure includes the data at risk, not merely the monthly fee.
For a 30-minute audit, users can first disable training where available, turn off nonessential memory, remove connected apps, enable multi-factor authentication, select a short history period, and request a current data export. That is enough for a baseline, but not a permanent guarantee. Repeat the audit every 3-6 months and whenever a feature changes. The safest configuration is one the user can explain, verify, and continue to maintain.
The 2026 Practical Standard for AI Companion Privacy
The best privacy posture combines minimal disclosure, shortest workable retention, restricted access, and verification. Keep regulated or identifying data out of consumer companion tools unless the business case justifies the exposure. Prefer services that explain training, human review, memory, deletion, subprocessors, and security in language a non-lawyer can interpret. Keep account security strong and treat the companion as software that may be wrong, not as a trusted confidant merely because its responses feel attentive.
There is no universal guarantee across providers as of September 27, 2026. A product may improve controls while another may expand retention or add connected-agent capabilities, so a comparative review should be repeated before switching or paying for a new feature. The user should ask four direct questions: Does my conversation train models? What personal information is remembered? Where is that information stored? What remains after I delete it? Written answers are stronger than assumptions, but contractual terms and actual account settings must be checked together.
For psychprofile users, the point of these controls is not to discourage honest reflection with AI. Psychological profiles can help users notice patterns, record goals, compare responses, or prepare for a licensed professional’s appointment, provided the tool does not impersonate clinical assessment. Privacy is part of psychological safety: a person should not suppress candid discussion solely because the service might retain, infer, or expose it. A cautious setup permits useful exploration while giving the user meaningful control over the underlying record.
The defensible 2026 standard is therefore practical rather than absolute. No tool can promise zero exposure in every jurisdiction and architecture, and no subscription tier eliminates all vendor or device risk. Users can still make informed choices by checking dated privacy terms, testing memory, limiting uploads, deleting unused data, and selecting the least data-intensive option that meets the need. A service that cannot answer basic retention and training questions should not receive highly sensitive information merely because it is convenient or emotionally engaging.