A data request - a "subject access request" under GDPR - is the most direct privacy check there is. Instead of reading a policy about what a company might do, you get a copy of what it actually has.
Who has these rights

Where you live decides which law you use - not where the company is.
- EU and EEA: GDPR gives you rights to access, correct, delete and export your data, and to object to certain uses.
- UK: UK GDPR, the same rights.
- California: the CCPA, as amended, gives rights to know, delete, correct and opt out of sale or sharing.
- Other US states: a growing list - including Virginia, Colorado, Connecticut, Texas and others - have comprehensive privacy laws with broadly similar rights. Some apply only above certain company sizes.
If none of these apply to you, ask anyway. Many companies handle all requests the same way because it is simpler.
What to ask for
| Right | What you get | When to use it |
|---|---|---|
| Access | A copy of your data and how it is used | Always start here |
| Portability | Your data in a reusable format | Moving to another app |
| Deletion | Removal of your data | Leaving, or after a breach |
| Objection / opt-out | Stop certain uses, such as training or ad sharing | Staying, but on your terms |
| Correction | Fix inaccurate data | Wrong age, wrong email, merged accounts |
A request you can copy
Send it from the email address on your account, to the privacy address in the company's privacy policy (often privacy@ or dpo@), or through its privacy form.
Subject: Data access request
I am requesting access to the personal data you hold about me, under Article 15 GDPR / the California Consumer Privacy Act (delete as appropriate). My account email is [address] and my username is [username].
Please provide: a copy of all personal data you hold about me, including conversation history, generated or uploaded images, voice recordings, memory or profile data derived from my chats, payment records and device data; the purposes of processing; who you have shared it with, including advertising and AI model providers; how long you will keep it; and whether my data has been used to train or improve AI models.
Please respond within the statutory deadline.
For deletion, replace the first paragraph with a request to erase all personal data and confirm when it is done, including backups and copies held by processors.
What a good answer looks like
A careful company sends a downloadable archive: your chats, a list of stored "memories" about you, images, payment and login history, and a written explanation of who received what. Pay attention to two sections in particular:
- Derived data. Summaries, personality notes and "facts about you" the app has inferred. These are often the most revealing part, and they explain how AI companion memory works in your specific case.
- Recipients. Model providers, analytics companies and advertising partners. Compare this with what the policy said - see do AI girlfriend apps sell your data.
When they ignore you
- Send a reminder after the deadline, quoting the date of your original request.
- Complain to the regulator. In the EU, your national data protection authority; in the UK, the ICO; in California, the California Privacy Protection Agency or the Attorney General.
- Keep records of every message and date. Regulators ask for them.
Regulators do act in this category. Italy's data protection authority fined the company behind Replika €5 million in 2025, partly for a privacy policy that did not clearly explain its processing.
Before you delete: export first
If you might want your character or history later, request access or use the app's export tool before asking for deletion. Deletion is permanent, and some apps take backups out of rotation only after weeks - the full order is in deleting an AI companion account.
Why it is worth doing even if you stay
A data request is a quiet test of a company. One that answers clearly and on time is telling you something about how it treats the rest of your data. One that ignores you is telling you something too - and you will have learned it before, not after, a breach.