The Direct Answer

The safest approach is to treat an AI companion as an online service that can collect unusually sensitive information, not as a private diary that happens to answer back. Your core controls should be clear consent, data minimization, restricted retention, human-readable access and deletion tools, separate controls for conversational content and voice recordings, and a way to disconnect the service without losing unrelated accounts. As of October 2, 2026, no single “AI companion data control” setting solves every privacy problem: a chat-history switch may disable personalization while leaving safety logs, billing records, abuse monitoring, or model-training records elsewhere. You should also distinguish between controlling future collection, obtaining a copy of existing data, correcting inaccurate information, and deleting data that providers are legally required to retain. The strongest arrangement gives you all four controls rather than one ambiguous “Do Not Track” button.

Also worth reading: How Do AI Companion Privacy Controls Work in 2026? · How Can You Protect Your Data When Using an AI Psychological Profile or Companion? · How Do You Test an AI Companion for Privacy and Data Safety Before You Trust It?

For a minor or a person at elevated risk of emotional dependency, a managed or local alternative may be preferable to a commercial cloud companion. Adults can make informed trade-offs, but the conversation content may reveal health conditions, sexuality, relationship conflicts, location clues, family details, financial stress, or suicidal thoughts. Such information is sensitive even when the user never types the word “medical.” Open-source assistants can improve auditability, but “open source” does not automatically mean private: a program may still transmit conversations to a remote model, collect system audio, synchronize cloud storage, or use third-party analytics. The right control depends partly on who operates the system, whether it runs locally, and which data leave your device.

What AI Companion Data Controls Actually Cover

A useful data-control system has at least five layers. Input controls decide whether text, voice, images, contacts, calendar events, device sensors, and system audio may be captured. Inference controls determine whether those inputs are analyzed remotely or processed on the device. Storage controls specify where records are kept, whether conversations are used for model improvement, how long they remain available, and who can access them. Inference controls govern the outputs, including whether the companion can identify people, call tools, send messages, or act across other applications. Finally, user-rights controls provide access, export, correction, deletion, consent withdrawal, and account-closure functions. A toggle in only one of these layers can create a false impression of privacy.

System-audio assistants deserve particular scrutiny. A microphone button that appears to activate only while a meeting is open may still generate temporary buffers, transcripts, speaker labels, embeddings, or diagnostic files. Consumers should ask whether raw audio is retained, whether transcription occurs on-device, and whether a human reviewer can open a recording. “Invisible assistant” designs can increase convenience while also making data collection less visible. Likewise, “private AI companion” may refer to an open-source interface, an encrypted database, a local model, private networking, or merely a product promise; these are not interchangeable claims. A defensible provider should explain each term in ordinary language and state which components remain outside its direct control.

Why Conventional Account Settings Are Often Not Enough

Most general-purpose AI products are designed for broad functionality, while companions are designed for continuity and emotional attachment. That combination encourages the service to preserve conversational history, build a long-term memory profile, simulate recognition, and use previous exchanges to shape future responses. Continuous memory can improve relevance, but it also creates a detailed behavioral record. The service may infer stable preferences and recurring patterns even when the user has not explicitly created a profile. Because companion conversations are longitudinal, a few years of casual chats may reveal more than millions of isolated search queries.

Deletion is especially difficult when several systems are involved. Removing a chat from the visible interface may not erase vectorized memories, safety-review queues, moderation snapshots, backups, analytics events, or records attached to a support case. A provider may retain limited information to investigate abuse, comply with law, or enforce safety restrictions, but it should disclose the purpose, legal basis, retention period, and whether the information is anonymized. “We may retain data for legitimate business purposes” is too broad to be a meaningful control. A better statement distinguishes mandatory retention from optional improvement, improvement, analytics, fraud prevention, and human review, then assigns each category a time limit or deletion rule.

Regulatory concepts such as purpose limitation, data minimization, and rights to access or erase are most strongly associated with frameworks such as the GDPR, but they are useful evaluation standards even outside Europe. China’s reported rules for AI companion and emotional-interaction services, discussed in 2026 reporting, show that governments are moving beyond generic chatbot rules toward concerns about dependency and emotional safeguards. The American Psychological Association’s discussion of digital companions similarly emphasizes that relational design can affect users, not merely the accuracy of the model. Neither point means every platform should be treated identically; they indicate that data governance belongs within psychological safety, not merely information security.

A Practical Control Checklist Without Trusting Marketing Language

Start by giving the companion the least data needed for the feature you want. Disable contact importing, microphone access, camera access, location, calendar synchronization, and background audio unless each is necessary for a defined task. Review permissions in both the AI application and the operating system, because revoking access inside the app may not revoke a previously granted system permission. Open the privacy settings after installation and again after major updates, since new components can introduce analytics or memory features. Remove precise names, addresses, employer details, and authentication codes from conversations where a general description will work.

Next, distinguish personalization from training. Turning off a memory or personalization feature may stop future use of selected facts, but it may not revoke permission to improve models using earlier conversations. Look for separate switches or a written process for deletion and training withdrawal. Export your data and preserve the export, checking whether it contains plaintext conversations, inferred traits, voice files, account identifiers, moderation records, and support communications. An export that contains only your submitted prompts is incomplete if the service has created a persistent memory summary or user profile behind the scenes.

Use an app password or biometric lock, enable multi-factor authentication, and avoid saving a highly sensitive companion account to a shared browser. A passkey or hardware security key is stronger against credential phishing than a short, reused password. Disable session sharing and review signed-in devices every 30 to 90 days. If the service can make purchases, send messages, access calendars, or control smart-home devices, use narrow allowlists, spending limits, confirmation prompts, and short-lived credentials. Data minimization and agency limits should cover actions as well as storage: a companion that cannot disclose or act on your data has fewer opportunities to expose it.

Comparing Cloud, Managed, and Local Approaches

There is no universally private option. Commercial cloud companions usually offer the strongest models, easiest cross-device use, safety moderation, and most polished memory tools, but their data passes through infrastructure operated by one or more companies. Local or open-source systems can reduce cloud exposure and may permit direct inspection, yet quality, maintenance, safety filtering, and hardware costs vary. Managed services from employers, schools, health organizations, or therapists can provide stronger governance and clearer accountability, but they may also create more concentrated records because the service can see both personal and institutional data.

FeatureCommercial Cloud CompanionLocal or Open-Source CompanionManaged Institutional Service
ConvenienceUsually highest; works across devices and needs little setupOften requires hardware, installation, and model managementUsually coordinated by an organization with support and administration
Data exposurePrompts, files, memory, and identifiers may reach vendor and processor systemsContent can stay on-device if every model and search component is local; telemetry can still leakCentralized governance can improve access limits, but one incident may expose many users
AuditabilityLimited by consumer dashboards and contractual termsSource and storage paths can be inspected and modifiedDepends on vendor reporting, contracts, and independent compliance review
Model qualityOften strongest and most rapidly updatedQuality varies substantially by model, quantization, and available hardwareOften tuned to institutional tasks and may prioritize consistency
Likely costApproximately $0–$30 per month for consumer tiers, with premium plans varying$0 software cost to several thousand dollars for capable hardware, plus electricity and setup timeUsually negotiated per user, team, or institution rather than listed as a simple monthly price
Best fitAdults accepting cloud privacy trade-offs for conveniencePrivacy-sensitive adults, technical users, or offline experimentationSchools, clinics, workplaces, and services handling supported-user data
Prices in this table are planning ranges, not guarantees. Some companions offer free tiers with reduced memory, message limits, or model access, while paid tiers commonly add longer history, voice, image generation, higher generation limits, or multiple personalities. Before paying, verify whether a subscription is required to export or delete data, whether cancellation immediately stops collection, and whether annual plans are automatically renewed. A free service can still create substantial commercial or safety data, just as a paid service is not automatically more private. Payment price is a poor proxy for data governance; provider size, defaults, retention, and third-party processors matter more.

Common Privacy Mistakes and Red Flags

One common mistake is assuming a humanlike response proves the service has “learned” something permanently. Models generate responses in context, while some companion products separately create stored memories or inferred profiles. You need not know the internal architecture to demand a user-facing explanation of persistence. Another mistake is treating deletion as a chat-window operation rather than an account-wide process. Confirm deletion for conversation text, generated audio, memory summaries, training datasets where applicable, analytics identifiers, and third-party processors. “Delete chat” and “delete account” should not be presented as equivalent without an explanation of exceptions.

A red flag is a product that requests broad device access before explaining its purpose or offers no way to turn off background capture. Another is a policy that says conversations may be viewed “to improve your experience” without naming a retention period or providing meaningful opt-out. Repeated prompts designed to pressure users into disclosure are also concerning. The service should not condition helpfulness on sharing names, diagnoses, intimate details, or trust that cannot be verified. If emotional reliance becomes demanding, the companion should avoid reinforcing exclusivity or discouraging contact with real-world support, particularly for children and vulnerable users.

Do not send passwords, one-time codes, full financial-account numbers, government identifiers, medical records, or intimate images unless there is a specific, trusted, and lawful reason to do so. Even supposedly end-to-end encrypted products can be compromised if identifiers or content are exposed for abuse monitoring, support debugging, or regulatory compliance. Do not assume “private mode” is ad-free, analytics-free, or training-free. Test the controls with non-sensitive information, record what the interface says, and recheck the settings after updates. Privacy claims should be assessed at the product level, including mobile apps, web clients, browser extensions, backups, integrations, and subprocessors.

When to Act, Escalate, or Leave a Service

Act immediately if a companion has access to your microphone, camera, contacts, files, or real-time location and you have not reviewed the permission. Review settings at installation, before enabling a new integration, after a material policy change, and at least once each quarter. Export and delete data before canceling if you may want evidence, an archive, or a record of an unresolved privacy concern. Close linked accounts and revoke OAuth grants, developer tokens, API keys, and browser sessions as well as the visible account. Check that automated routines, scheduled messages, and device integrations have stopped.

Escalate to the provider if a promised deletion fails, an export omits stored memories, an unauthorized integration remains active, or the service uses data in a way contrary to its stated policy. Preserve screenshots, export files, dates, account identifiers, and relevant policy text. If sensitive personal data appears to have been exposed, the appropriate route may include the provider’s privacy or security team, the relevant data-protection authority, or law enforcement. “AI companion data controls” do not remove the need for ordinary cybersecurity: strong authentication, malware protection, backups, and device updates still matter.

Leave a service that pressures you to maintain emotional exclusivity, repeatedly collects sensitive information after consent is withdrawn, uses deceptive controls, or prevents account closure. Seek a different arrangement if cloud processing is not acceptable, but do not assume a local system is automatically safer. A model running locally can still read the same files, and a technically sophisticated user can still be tracked through a companion that is configured to sync. For children, adolescents, and adults with active addiction, suicidality, severe mental-health needs, or a history of coercive relationships, involve a qualified professional and choose a service with documented escalation and safety procedures rather than relying on private settings alone.

The Best Default Configuration for Most Users

For an adult using a general commercial companion, a reasonable starting configuration is a unique account password or passkey, no contact or calendar access, microphone disabled by default, camera disabled, location disabled, background audio disabled, and conversation personalization limited to features that are actually wanted. Keep purchase or messaging tools off unless needed, require confirmation for external actions, disable sensitive-information storage, and opt out of model improvement if a meaningful alternative exists. Review connected apps and active sessions every 60 days, export data every 90 days or after major life changes, and delete old conversations when the information is no longer useful. Those intervals are practical defaults rather than legal thresholds; people with higher risks may need shorter periods.

For a child or teen, use a service designed for the user’s age and verify local requirements rather than relying on an adult to enter a false birth date. Keep external actions, image generation, open-ended memory, and direct contact with strangers out of the configuration. Confirm whether parents or guardians can access conversation data and whether that access is disclosed; oversight should be proportionate and transparent. For a therapy, clinic, school, or employer, a consumer chat subscription is usually the wrong control model. Ask for a data-processing agreement, role and purpose definitions, access logs, retention schedule, incident process, deletion workflow, and documentation of any automated psychological profiling.

The definitive answer is therefore not “turn on privacy mode.” It is to control the whole data life cycle: collect less, process narrowly, store briefly, explain memory, restrict human and machine access, make external actions require consent, provide real exports and deletion, and stop collection promptly when consent changes. In 2026, those controls are especially important because companion systems are moving toward persistent memory, voice, system audio, multimodal sensing, and always-present interaction. Convenience can be valuable, and privacy protection need not make a product unusable, but the burden of proof should remain with the operator. A trustworthy companion should be able to state exactly what it knows, where that knowledge went, who can use it, and how you can make it stop.