You tell an AI companion things you wouldn’t tell a friend. That’s rather the point of it. So the honest question isn’t whether these platforms are trustworthy in the abstract — it’s what actually happens to those messages after you hit send.
Here’s the mechanism, the one industry-wide finding worth knowing, and the four things to check before you type anything you’d mind seeing again.
Your conversations are stored. That’s not a flaw.
Start here, because a lot of confusion comes from expecting otherwise: these platforms retain your chat history by design. Not incidentally — mechanically.
The feature people value most is memory: a companion who remembers what you said last Tuesday. That memory is a database of your conversations. A platform that deleted your messages after each session couldn’t remember anything, and would be a worse product.
So the useful question is never “does it store my chats” — it always does. The questions are for how long, who can see them, and what else they’re used for.
The one number worth knowing
Mozilla’s Privacy Not Included team audited eleven popular romantic AI chatbots in 2024. Their finding: 90% reserved the right to sell or share user data, and more than half did not let users delete their own data.
We cite that because it’s an independent audit with a named methodology and a date — which is more than can be said for most numbers published about this category. It’s also two years old now, and the market has moved, so treat it as a description of industry norms rather than a verdict on any platform you’re looking at today.
Reporting from the same period found that opt-outs from training data were vanishingly rare — a single platform among those reviewed offered a workable one. That balance may have shifted since. It’s exactly the kind of thing worth checking yourself rather than assuming.
The four things to check, in order
You can do all of this in about five minutes on any platform’s own site, before creating an account.
1. Is there a training-data opt-out?
Search the privacy policy for “train”, “model” or “improve our services”. Most platforms reserve the right to use conversations to improve their models by default. A visible toggle in settings is the good outcome; a stated opt-out by email is workable; silence is an answer too.
2. Is a retention period stated?
Look for a specific duration — “we retain chat data for X months”. A policy that says data is kept “as long as necessary” is telling you it has no fixed limit. Neither is disqualifying, but one lets you plan and the other doesn’t.
3. Can you delete your account yourself?
A self-service delete button in settings is meaningfully different from an email request processed within thirty days. And deletion is not the same action as cancelling your subscription — cancelling stops the money, the data stays. We covered that distinction in our guide on cancelling properly.
4. What appears on your bank statement?
Billing discretion is a privacy question, not a financial one, and for many people it’s the one that matters most. Some platforms publish their billing descriptor. Most don’t, and you discover it after the first charge.
Assume a human could read it
This isn’t paranoia, it’s how hosted services work. Support tickets, moderation reviews, abuse investigations and debugging all involve people looking at data. Every serious platform has staff who can, under some circumstance, see conversations.
The practical consequence is a single sentence: don’t write anything you’d be harmed by losing control of. Not because a breach is likely on any given platform, but because the cost of being wrong is asymmetric — a leak of intimate conversation is not recoverable the way a leaked password is.
A baseline that costs you nothing
- Use a dedicated email address. Not your work address, not the one tied to your main accounts. It limits what a breach connects to.
- Don’t reuse a password. These platforms are attractive breach targets precisely because the data is sensitive.
- Keep real identifiers out of the conversation. Your companion doesn’t need your surname, employer, or the name of your street to feel personal.
- Check the payment channel before you subscribe. Paying through an app store means the platform never sees your card details — a genuine privacy advantage, and a cancellation complication.
- Screenshot the privacy policy section that matters to you. Policies get edited. Yours won’t.
What “private” claims usually mean
Several platforms market themselves as privacy-first. Some earn it. The claim is worth reading closely, because it’s used for several different things:
- Encrypted in transit — standard, and says nothing about what happens on the server.
- Encrypted at rest — better, but the platform still holds the keys and can read the data.
- Not used for training — this one is meaningful, and it’s the one to verify in the policy rather than the marketing page.
- Anonymous signup — genuinely useful, though payment usually re-identifies you.
A platform that states which of these it does, precisely, is more trustworthy than one claiming to be “100% private” without saying what that covers.
How Sexya evaluates this
Privacy and billing discretion sit deliberately outside our hundred-point score. Not because they don’t matter — because scoring them would let a platform earn credit for doing the legal minimum.
Instead we report them in full: what the policy actually says about training and retention, whether deletion is self-service, whether the deletion route works when we use it, and what descriptor appears on a real charge when we can observe one. Reported, dated, not scored.
Read the full protocol · See the companions under evaluation
Can anyone read my conversations with an AI companion?
Are my chats used to train the AI?
Does deleting my account really delete the conversations?
Is a free app less private than a paid one?
Choosing with privacy in mind?
We check retention, deletion and billing discretion on every platform we evaluate — and publish what we find, including when it’s inconvenient.
Find your AI companion →