Are AI companion apps private?
Usually not by default. When Mozilla reviewed 11 romantic AI chatbot apps, 90 percent could share or sell personal data and ten failed its minimum security standards. Three checks separate the trustworthy apps: whether your chats train AI models, whether you can read what is stored about you, and whether deletion is real. Cave, an AI companion with real memory, was built to pass all three.
The stakes are higher than for a search engine, because of what you put in. A companion app does not hold your queries. It holds the fight with your mother, the doubt about your job, the health scare you have told no one. The research below covers what companies actually do with that data, what regulators found, and how to check any app in ten minutes.
Do AI chatbots use your conversations for training?
Many do, and by default. The standard pattern in consumer AI is that conversations may be used to improve or train models unless you find the setting and switch it off.
OpenAI documents the policy plainly, which makes it the clearest example. Consumer ChatGPT conversations feed model improvement by default, and the opt-out is a settings toggle called "Improve the model for everyone". Business and enterprise tiers are excluded from training automatically. Read that split as an admission: no company asks a paying organization to tolerate training on its data, but consumers get it as the default.
Companion apps tend to be worse, because most publish less. Mozilla's review of romantic AI chatbots found minimal transparency about how chats feed the companies' models, and an opt-out existed only in some apps.
What "used for training" means in practice:
- Your words may be sampled, processed, or reviewed to improve future models.
- Once trained into a model, the data cannot be meaningfully pulled back out. Deleting the chat log does not delete what the model absorbed.
- The policy can change, especially after an acquisition.
So look for one plain sentence in the privacy policy: "We do not use your conversations to train AI models." If that sentence is missing, assume the opposite. Cave's answer is that sentence, stated as mission language rather than a settings toggle: your memory is yours, and memory on Cave is never used for training.
How do AI chat apps handle user data?
Carelessly, on the best evidence available. Mozilla's Privacy Not Included team reviewed 11 romantic AI chatbot apps in February 2024 and gave every single one its privacy warning label — a result the team compared to the worst product categories it had ever reviewed.
The concrete findings from that review:
- 90 percent of the apps may share or sell personal data.
- Ten of the eleven failed Mozilla's minimum security standards. Some accepted "1" as a password.
- The apps fired an average of 2,663 ad trackers per minute of use. The worst, Romantic AI, fired 24,354 trackers in one minute.
- Only about half guaranteed every user the right to delete their personal data.
The tracker counts answer the business-model question. A free companion app running thousands of ad trackers has a paying customer, and that customer is not you. The product is the profile of a person who tells an app their feelings, which is the exact profile advertisers pay the most for.
Who else can read your AI companion conversations?
More people than the chat window suggests. The realistic list of readers: company staff, the model providers the app runs on, ad networks, and whoever breaches the database.
- Employees and contractors. Many AI companies allow human review of conversations for safety, moderation, or quality. Check whether the policy admits it and whether you can opt out.
- Third-party model providers. Most companion apps run on another company's AI model. Your words transit each organization's servers, each with its own retention rules.
- Ad networks. Mozilla's tracker counts show data flowing from companion apps to advertisers at industrial volume, thousands of times per minute.
- Anyone, after a breach. Stored chats are readable to whoever gets in.
- Courts. Chat logs a company holds can be subpoenaed, in a divorce case as easily as a criminal one.
The breach risk is not hypothetical in this category. In September 2024, the AI girlfriend service Muah.AI was breached, exposing 1.9 million email addresses together with the prompts users had typed. Many prompts were sexual. Many of the email addresses were personal accounts carrying real names. That is the specific shape of companion-app harm: not a leaked password, but your most private words attached to your identity.
Should parents worry about teens using AI chatbots?
About the data, yes. In a 2025 Common Sense Media survey of 1,060 US teens, run by NORC at the University of Chicago, 72 percent had tried an AI companion and 52 percent used one regularly.
Those teens are producing diary-grade data inside the app category with the worst privacy record Mozilla has measured. Regulators have started moving. Italy's data protection authority fined Replika's developer 5 million euros in May 2025, in part because the app had no age verification at all. In September 2025, the US FTC ordered seven companies running consumer AI companion chatbots to report on their advertising claims, monetization, safety testing, and age restrictions.
The practical move for a parent is not a ban but a joint audit. Sit down with the teenager, open the app's privacy policy, and run the same three checks: does it train on chats, can you both read what it has stored, does deletion actually delete. An app that fails all three is keeping an un-erasable diary of a fifteen-year-old, written in their own words.
How do you check if an AI chat app is private?
Read the privacy policy against six questions. Ten minutes answers most of them.
- Training. Does the policy plainly say conversations are not used to train AI models? Is that the default, or an opt-out buried in settings?
- Visibility. Can you open and read everything the app has stored and remembered about you — the whole file, not a summary? This is where memory design and privacy meet: the same architecture that makes an AI actually remember you is what makes its memory auditable. Cave keeps memory readable on purpose. Everything it knows about you is organized by topics you can open, read, and edit, like a document about you that you co-wrote.
- Deletion. Does the policy state what deletion means and how long it takes? Mozilla found only about half of companion apps guarantee every user that right.
- Human access. Do employees or contractors ever read conversations, and under what conditions?
- Business model. Subscription, or free with ads? Mozilla's figure of 24,354 trackers in a minute is one answer to the question of who is paying.
- Retention. How long are chats kept? Indefinite retention of diary-grade data is a standing liability, breach after breach.
An app does not need a perfect score. Clear, findable answers to the first three — training, visibility, deletion — are the load-bearing ones. We run this same checklist when comparing the best AI companion apps, because in this category privacy is half the review.
What can no privacy policy promise?
Three risks survive even an honest policy, and a fair answer has to name them.
Policies change. An app that does not train on chats today can be acquired tomorrow, and the new owner can rewrite the terms. Your real protection is the exit: an app whose memory you can fully read and delete lets you leave with nothing stranded.
Breaches ignore policy. Muah.AI's users were not exposed by its terms of service but by its security. A policy tells you a company's intentions; it cannot tell you its competence. Mozilla's finding that ten of eleven apps failed baseline security is the more predictive number.
And no policy makes it wise to outsource a crisis. An AI companion is a good place to think out loud about ordinary weight. Persistent hopelessness, panic, or anything involving safety deserves a professional, not an app.
Sources
- Mozilla Foundation. "Romantic AI Chatbots Don't Have Your Privacy at Heart." Privacy Not Included, February 2024.
- Have I Been Pwned. "Muah.AI data breach." October 2024.
- Associated Press, via Insurance Journal. "Italy's Data Watchdog Fines AI Company Replika's Developer $5.6 Million." May 2025.
- TechCrunch. "72% of US teens have used AI companions, study finds." July 2025.
- DLA Piper. "AI companion bots: Top points from recent FTC and government actions." September 2025.
- Tom's Guide. "Keep your ChatGPT data private by opting out of training — here's how."
FAQ
Are AI companion chats private?
Not by default, and often not at all. When Mozilla reviewed 11 romantic AI chatbot apps in 2024, all 11 earned its Privacy Not Included warning label: 90 percent could share or sell personal data and ten failed minimum security standards. Privacy varies sharply by app, so check three things in any privacy policy: whether chats train AI models, whether you can read what is stored, and whether you can delete it.
Do AI chatbots use conversations for training?
Many do, by default. Consumer ChatGPT uses conversations to improve models unless you turn off a setting called "Improve the model for everyone," while business tiers are excluded automatically. Companion apps are usually less transparent: Mozilla found minimal disclosure about training across the apps it reviewed, with opt-outs only in some. Look for a plain policy sentence ruling training out. If it is missing, assume your chats are training data.
Can I delete what an AI companion app knows about me?
Sometimes. Mozilla found only about half of the romantic AI apps it reviewed guarantee all users the right to delete personal data. Read what "delete" means in the specific app: removing a chat from your screen, removing it from company servers within a stated window, or neither. Data already used to train a model cannot be pulled back out afterward, which is why the training question comes before the deletion question.
Is it safe for my teenager to use an AI chatbot?
Treat any specific app as unsafe until its policy proves otherwise. 72 percent of US teens have tried AI companions (Common Sense Media, 2025), yet Italy fined Replika's developer 5 million euros in 2025 partly for having no age verification. Read the app's privacy policy together, check training, visibility, and deletion, and keep one rule regardless of the app: a crisis belongs with a person, not a chatbot.
Which AI companion apps don't train on your chats?
The ones that say so in one plain sentence, with no tier conditions attached. Cave, an AI companion with real memory, states it as mission language: your memory is yours, and memory on Cave is never used for training. Cave also keeps that memory open — organized by topics you can read and edit — so you can verify what is stored instead of trusting a black box. For any other app, search its privacy policy for the word "train."