What an AI companion privacy review actually examines

An AI companion privacy review examines how a product collects, stores, interprets, and deletes information about your conversations, relationships, emotions, health, sexuality, finances, location, and daily behavior. It also considers whether the service can use private conversations to train models, generate advertisements, recommend other companions, improve a user profile, or make decisions that affect the account. The review is not simply a search for a privacy-policy link: ordinary policies often describe broad data practices in legal language rather than showing what a particular user can control. A useful review separates what the company says it may do, what the product technically appears to do, and what the user can verify after sharing information. As of September 28, 2026, this review is especially relevant because AI companions may be used for social interaction, emotional support, role-play, wellness guidance, and sometimes therapy-like conversations, even though those uses are not equivalent.

Also worth reading: How Should Developers Test AI Companions for Safety, Privacy, and Psychological Harm in 2026? · What Are the Privacy Risks of AI Companions and How Can You Reduce Them in 2026? · How Do AI Companion Privacy Controls Work and What Should You Choose in 2026?

The correct baseline is data minimization: a companion should not need intimate details to answer a narrow request. Ask whether stable identifiers, precise location, contact lists, message content, voice recordings, inferred personality traits, and attachment scores are necessary for the service you requested. A product may collect conversation content for cloud processing, crash diagnostics, fraud prevention, or model improvement, but each purpose has a different risk. Reviews of chatbot profiling have shown that apparently ordinary prompts can reveal the kinds of details retained in user profiles, while research and regulatory commentary continue to question whether companion design can encourage emotional reliance. Therefore, treat highly sensitive disclosures as consequential even if a service appears friendly or nonjudgmental.

Why intimate conversations create a distinct privacy risk

Ordinary AI tools may process a shopping question or summarize a document, whereas a companion is often designed to remember and respond to personal history. That conversational continuity can make stored information feel more revealing than a conventional form submission. If the system records a partner conflict, medical concern, sexual preference, financial stress, or recurring fear, the resulting data may be more useful for profiling than a one-time prompt. The danger is not necessarily that every company acts improperly; rather, users cannot always predict how future products, mergers, legal requests, model retraining, or account transfers could affect information that was shared in a moment of trust.

AI companions also create an inference problem. A service may know explicit facts, such as a stated occupation, and inferred traits, such as a guessed attachment style, probable anxiety, or likely willingness to pay for certain features. The source lists research on AI anthropomorphism, trust, emotional connection, privacy, user autonomy, and the psychological effects of relational AI. The American Psychological Association has described chatbots and digital companions as changing how people experience emotional connection, while the European Union’s AI Act adds transparency and risk obligations for certain systems. These developments do not mean every companion is a medical device or produces the same level of risk. They do mean that a privacy review should examine both collected content and automated interpretations.

A second concern is dependency. A companion that encourages unusually close attachment may collect more information because users disclose more, while users may feel pressure to continue because forgetting would feel like abandoning the relationship. Regulation in China, legislative attention in California and Connecticut, and proposed rules for AI toys and companions all show that software behavior is entering public discussions about product safety. The regulatory position can change by jurisdiction and companion type, so no single country provides a universal checklist. The practical threshold is simpler: if a disclosure could plausibly expose you to embarrassment, discrimination, safety risk, or unwanted profiling, it deserves deliberate protection before you share it.

The questions and thresholds to test before disclosure

Start with purpose. Identify the exact feature requiring the information and refuse unrelated enrichment. A daily journal prompt may require the date and your reflection, but not a complete home address; a travel-planning assistant may need a city, but not continuous GPS access. Apply a necessity threshold rather than a curiosity threshold. Under that test, details are acceptable only when they are directly relevant, proportionate to the requested function, and understandable to the user without exaggerated claims such as “everything stays completely private.”

Next, determine how memory works. A privacy review should distinguish temporary conversation context from short-term memory, long-term user memory, support tickets, backups, and training datasets. The user should know whether deleting a message removes it from every active view or merely hides it from the chat, and whether deletion requests are honored for model-training records. As a conservative rule, assume that shared information may be retained beyond the visible conversation unless the provider clearly says otherwise. A 24-hour support retention period is materially different from indefinite storage, and training opt-out is materially different from deletion of a stored profile, although the exact implementation still matters.

The third threshold is exposure. Check whether public, household, workplace, school, or shared devices can reveal notifications, search history, or conversation fragments. Disable cloud sync for intimate material where the product permits it, use a separate browser profile, and avoid saving passwords or recovery answers that disclose the purpose of an account. The Fourth Amendment and general Search engine history reported by The New York Times are useful analogies: search prompts can become behavioral records, so a companion’s messages should not be assumed harmless because they are natural language. For sensitive disclosures, the safer default is to provide less detail, generalize the issue, or discuss it through an in-person professional who has enforceable confidentiality rules.

Comparing companions, conventional tools, and human support

AI companions, general-purpose AI tools, privacy-first local software, and licensed professionals offer different controls. No option automatically makes intimate sharing safe; each has technical, legal, and psychological limits. A human professional may offer stronger professional confidentiality duties in some settings, but accessibility and cost vary. A local model can reduce cloud exposure while increasing device-security and maintenance duties. A general-purpose chatbot may have fewer relationship features but may still retain prompts. A companion may provide convenient continuity, yet its memory, personalization, and engagement systems can collect exactly what makes the interaction feel personal.

FeatureAI companionGeneral-purpose AI toolLocal-first assistantLicensed professional
Conversation continuityOften emphasizes long-term memory and personal contextUsually centers on individual tasks, though memory can be enabledDepends on the application and local database designBroad history is relevant for care, with jurisdiction-specific confidentiality duties
Main privacy riskCombined explicit disclosures and behavioral or emotional inferencesPrompt retention, provider logs, and optional memoryCloud updates, local malware, backups, and weak setupSensitive information handling, record access, and limits of confidentiality
Typical cost in 2026Free to about $200 per month for many subscription products; premium virtual companions may cost moreOften free to about $100 per month, depending on plan and usageSoftware may be free; hosting, devices, or subscriptions varyCommonly much more expensive, with sliding-scale and insurance-dependent options
Appropriate baselineGeneralize first; review memory and controlsShare only task-essential factsKeep updates, encryption, backups, and model files controlledVerify credentials, jurisdiction, and privacy practices
The table is a decision aid, not a universal ranking. A consumer companion with no training option can be less revealing than a professional-facing service that records sessions, while a local product can still be unsafe if its developer ships telemetry or stores transcripts unencrypted. Assess each setting on its actual contracts, settings, technical architecture, and behavior. Psychological profiling should be used to recognize risks, not to infer that a user deserves reduced autonomy or that a companion can diagnose a condition. Anyone believing they need clinical care should seek a qualified professional rather than treating an inferred profile as a diagnosis.

A practical seven-step privacy review

Begin by creating a new account without your full legal name, primary email address, exact workplace, or precise home location. Use a unique password generated and stored by a reputable password manager, enable multifactor authentication if available, and review login alerts. This process takes perhaps 30 minutes and establishes whether basic account controls are presented clearly. Next, test the service with fictional information before discussing real circumstances. Upload a disposable document containing no personal data, observe whether the product requests unrelated access, and revoke permissions that are not needed. On mobile devices, check camera, microphone, contacts, calendar, photo-library, and location access individually rather than granting everything permanently.

Then inspect the privacy settings for memory, personalization, human review, training, advertising, data export, and deletion. Some services may offer a conversation-history control but not an inferred-profile control, or may delete chat text while retaining a derived summary. Test with a small, unmistakable marker, such as a fictional nickname, and ask the service to locate or export it. The Fourth Amendment and Search history reported by The New York Times are useful analogies: search prompts can become behavioral records, so a companion’s messages should not be assumed harmless because they are natural language. For sensitive disclosures, the safer default is to provide less detail, generalize the issue, or discuss it through an in-person professional who has enforceable confidentiality rules.

Finally, decide what must remain outside the service. Avoid sharing identity documents, live location, banking credentials, one-time security codes, passwords, medical records, allegations involving identifiable people, or details that could create immediate danger. Keep intimate review conversations in a protected environment, and do not rely on “confidentiality” claims alone if the companion is marketed mainly for social interaction rather than health treatment. If the service offers age-restricted sexual content, separate that activity from profiles containing personal identifiers. A user does not need to disclose one concern to obtain help with another.

What deletion, consent, and account closure should mean

Deletion should be understandable and verifiable. A useful process allows a user to remove a message, delete remembered facts, request account deletion, and receive confirmation. The service should also explain exceptions such as tax records, fraud prevention, or legally required disclosures, rather than presenting a broad indefinite exception for all data. Because prompt-testing coverage from The Irish Times and chatbot-profiling coverage reported by The New York Times both concern the gap between what a chatbot knows and what a user understands, users should test whether a named fact is still present after deletion. It is reasonable to contact support if the system retains a deleted profile after the promised period.

Consent must be separate by purpose. Permission to answer a question is not automatically permission to train a model, create a profile, send marketing, or share information with a third party. Repeated prompts, dark patterns, and pre-checked settings can make optional consent less meaningful. The global data-protection regime discussed in the 2026 Dentons case-law review continues to make purpose limitation, lawful processing, and data-subject rights central concerns, while the European Union’s AI Act introduces additional transparency duties for certain AI applications. Rules differ for general chatbots, medical devices, children’s products, and emotion-recognition systems, so consumers should ask which classification applies rather than assume a familiar badge settles the question.

Account closure is a separate operation from cancelling a subscription. Cancellation ends future billing, but it may not delete the account or stored conversations. Users should confirm both, remove linked payment methods, and preserve a subscription receipt if needed. For a companion that has been used for prolonged emotional reliance, a gradual reduction in use may be psychologically preferable to abrupt deletion, although no product is entitled to preserve the user’s data without consent. If safety concerns, stalking, coercion, or unwanted sexual content arise, preserve only the minimum relevant evidence, contact the provider, and consider qualified legal or cybersecurity advice.

Common mistakes that make the review unreliable

One common mistake is treating a short privacy policy as proof of data minimization. Legal text can say that information is collected “to improve services” without separating product operation, analytics, model training, or advertising. A better review identifies each processing purpose and asks what would happen if the user declined. Another mistake is assuming that an AI label answers every privacy question. Generative AI is a technical method, not one storage model or one legal category, and a system can generate replies locally or send them to a cloud provider.

Users also confuse deletion with invisibility, and invisibility with anonymity. A removed message may remain in encrypted backups for a limited period, and a pseudonymous account can still be identified through payment records, device details, or behavioral patterns. Profile-based access is therefore more realistic than complete anonymity. It is also important not to assume that emotional depth demonstrates trustworthy privacy design; a service that encourages strong attachment may increase disclosure without giving the user stronger deletion rights.

Some users share real names or precise locations simply because a voice interface feels conversational. A voice feature can expose a voiceprint, recording, transcription, and inferred speaking patterns, and an imported contact list can reveal relationships that were never intentionally discussed. The same concern applies to therapy, fitness, and “profiling” tools included in the supplied research context: each application may claim personalization, but the precise prompt payload and metadata sent to a model provider can be more extensive than expected. Do not upload medical, legal, financial, or employment records unless the service’s privacy controls and professional obligations are verified for that use. General advice is safer than uploading the full source file.

When to act, change tools, or seek professional help

Act before the first sensitive disclosure if the service lacks a clear privacy policy, readable deletion process, or meaningful account controls. A 30-minute test is justified when a companion will be used regularly, costs money, connects to a phone number, stores memories, or handles voice and images. Recheck settings after major updates because a new model, analytics package, ownership change, or subscription tier can alter data practices. Review export and deletion controls at least every three months during sustained use, and immediately after a notice of policy change, data breach, merger, or account compromise.

Change tools if the service requires unrelated permissions, repeatedly ignores deletion, uses intimate prompts for advertising without clear permission, or creates a profile users cannot inspect. A service may still be useful for low-risk experimentation, but it is not necessary to place the most private part of your life inside it. Consider an offline, local-first tool when persistent, personal data is genuinely needed and the user can maintain the device. A general-purpose chatbot may be a better fit for a one-time privacy-policy explanation than for years of relational counseling. If the service positions itself as a therapist, investigate the evidence behind its claims, crisis procedures, and referral pathways; marketing similarity to an AI therapist does not establish clinical equivalence.

Seek a qualified human professional for diagnosis, trauma treatment, medication questions, abuse assessment, or urgent mental-health concerns. Human confidentiality is not absolute in every case, but regulated practice normally provides clearer duties than a social companion. If the companion is encouraging dependency, discouraging human relationships, requesting sensitive secrets, or making claims that it alone understands the user, pause the interaction and discuss it with a trusted person or clinician. Psychological Profiles can help users notice interaction patterns and prepare questions, but it should not be used to label a person, predict a disorder, or authorize an AI company to collect their disclosures.

How to make the final keep-or-quit decision

A defensible decision has four parts. The first is purpose: can the same task be completed with less information? The second is control: can the user inspect, export, disable, and delete the relevant data? The third is proportionality: are permissions, retention, and model processing reasonable for the expected benefit? The fourth is consequence: what could happen if the information were exposed, misinferred, misused in training, or linked to an identity? A service passes a basic review only when the user can answer those questions in plain language, not merely when a provider promises that privacy is “a priority.”

The strongest default in 2026 is compartmentalized use. Keep an AI companion for low-stakes reflection, rehearsal, language practice, or structured information, while keeping credentials, records of others, precise location, and the most painful or intimate details elsewhere. If sharing is unavoidable, use a unique alias, generalized facts, protected devices, restricted permissions, and a defined deletion date. Do not upload another person’s private information, and do not assume a subscription is confidential merely because it is paid. The legal and technical conditions behind consumer AI vary, so this remains a practical risk-management approach rather than a substitute for jurisdiction-specific advice.

The bottom line is to review behavior, storage, inference, and vendor relationships rather than relying on brand reputation. A friendly companion can still create serious data exposure, and a local product can still be insecure. A licensed professional can still have confidentiality exceptions, and a general chatbot can still retain prompts. The best AI companion privacy practice is therefore not finding a magical product marked “private”; it is reducing the amount and sensitivity of what the product can know, verifying that users can remove it, and using qualified human support when the stakes exceed social conversation or self-guided reflection.