teasaOpen Teasa

AI Companion Privacy: A Checklist Before You Chat

Conversations with an AI companion get personal fast. That's the point of the product — and it's why the privacy stakes are higher than for almost any other app category. People tell companions about their health, their relationships, their loneliness, their finances, things they haven't told anyone. All of it lands on someone's servers under a policy most users never read.

This is a checklist you can apply to any companion or character-chat app before you share anything that matters. You don't need to be a lawyer; you need about fifteen minutes and the willingness to close the app if the answers are bad. We build a companion platform ourselves (teasa, currently pre-launch), so we'll use it as one worked example below — but every item here is app-agnostic, and the checklist is worth running on our product too.

An adult holding a translucent ledger and keys before an open records cabinet

First, understand what "private" means here

An AI chat is not a diary on your device. In nearly every companion app, your messages are:

None of that is automatically sinister — generation genuinely requires processing your text. The question is what happens beyond the minimum: training, retention, sharing, and whether you can ever truly take it back.

The privacy policy: four things to actually check

Open the policy and search for these. If you can't find an answer, treat that as an answer.

1. Is your chat used to train models?

Search "train," "improve our models," "machine learning." The questions that matter: is training on your conversations on or off by default, can you opt out, and does opting out cover past messages or only future ones? Also check whether the third-party model provider trains on the data ("we don't train on your chats" can be true of the app and false of its vendor). Best answer: training on conversation content is off unless you explicitly opt in. Worst answer: silence, or consent buried in signup terms.

2. How long is data retained?

Look for concrete numbers — "deleted within 30 days," "retained for 90 days after account closure." Vague formulations ("as long as necessary for business purposes") mean indefinitely. Retention should be stated for chats, for backups, and for the model provider's copies separately.

3. Does deletion actually delete?

This is where companion apps most often fail quietly. Deleting a conversation from your screen is not deletion; the honest question is whether the derived data goes too — the memories the AI extracted, summaries, embeddings, analytics events built from your words. A policy (or help page) that distinguishes "hide" from "delete," states what deletion covers, and commits to a timeline is a good sign. Silence about derived data usually means it survives.

4. Can you export your data?

Export matters twice over: it's how you see what the app actually holds on you, and it's what makes leaving possible without losing your history. Look for a self-serve export that includes conversations and stored memories, not a support-ticket process with no deadline.

Account controls that matter

Policies describe intentions; controls are what you can verify. In the app itself, check for:

Red flags: when to walk away

Before you share something sensitive, ask yourself

  1. Would I be comfortable if this exact message appeared in a data breach with my email attached? Breaches happen to companies of every size.
  2. Does this need to be remembered, or just said? If just said, use an incognito/never-remember mode if one exists.
  3. Am I identifiable from what I've shared in aggregate — job, city, workplace details — even without my name?
  4. Is this a topic (health crisis, legal trouble, thoughts of self-harm) where I need a human professional rather than a product? A good companion app should itself redirect you; if it doesn't, that's telling.

Health details, real names of other people, financial specifics, and anything you'd hide from a subpoena deserve the most caution — other people in your life never consented to being in your chat logs at all.

One worked example: how teasa answers this checklist

Since we're asking you to grade every app this way, here's how ours is built to answer — noting honestly that teasa is pre-launch, so these are shipped design commitments you'll be able to verify at launch, not a track record. Training on conversation content is off by default. Memory is consent-gated: the companion proposes a memory and you approve, edit, or decline, with every decision recorded in an append-only consent ledger, and each stored memory shows its source, date, confidence, and scope. Deletion is two-stage — reversible soft delete at the edge, and real erasure at the core that includes derived data across conversation branches — and whole-account deletion shows its scope up front and produces a deletion receipt. Export is self-serve and covers your conversations and memories. And the anti-dark-pattern rules are product policy: no streaks, no guilt on exit, no threatened memory loss. If we ever fail this checklist, you should leave — that's what the export is for.

Judge any app — including ours — by the checklist, not the marketing. If you're still choosing a platform, our comparison pages (Replika alternatives, Character.AI alternatives) apply these same criteria, and if you're new to the category entirely, start with what an AI companion is.

FAQ

Is my AI companion chat private?

It's as private as the provider's policy and security make it — which varies enormously. Your messages are processed on servers and stored; "private" in marketing has no legal force. Run the checklist above: training defaults, retention, real deletion, export, and in-app controls.

Do AI companion apps train on my conversations?

Some do by default, some allow opt-out, a few keep training off unless you opt in. Check the policy for the app and for its underlying model provider, and check whether opting out covers past conversations. If the policy doesn't say, assume yes.

If I delete my account, is everything really gone?

Only if the app deletes derived data too — extracted memories, summaries, embeddings — and backup copies within a stated window. Look for a deletion process with a defined scope, a timeline, and a confirmation or receipt. A delete button with none of those may just be hiding data from you.

What should I never tell an AI companion?

Treat anything you'd be harmed by in a breach as off-limits by default: government ID numbers, passwords, financial account details, and identifying information about other people who haven't consented. For everything else, calibrate to the app's answers on this checklist — the better its controls, the more it has earned.

Keep reading

How to Write an AI Character Card (With Examples)
AI Roleplay Terms: A Plain-English Glossary
AI Companions and Loneliness: An Honest Guide