How to Get Your Data From an AI Companion App - Step by Step

Privacy & safety

If you live in the EU, the UK or one of a growing number of US states, you can make an AI companion company tell you exactly what it holds about you - and then delete it. Few users ever ask. It takes ten minutes, and the answer is often revealing.

We may earn a commission from links on this page. It never changes a rating.

A data request - a "subject access request" under GDPR - is the most direct privacy check there is. Instead of reading a policy about what a company might do, you get a copy of what it actually has.

Who has these rights

Map-style summary of data rights: GDPR in the EU and EEA, UK GDPR in the UK, CCPA in California, and comprehensive privacy laws in a growing list of other US states

Where you live decides which law you use - not where the company is.

  • EU and EEA: GDPR gives you rights to access, correct, delete and export your data, and to object to certain uses.
  • UK: UK GDPR, the same rights.
  • California: the CCPA, as amended, gives rights to know, delete, correct and opt out of sale or sharing.
  • Other US states: a growing list - including Virginia, Colorado, Connecticut, Texas and others - have comprehensive privacy laws with broadly similar rights. Some apply only above certain company sizes.

If none of these apply to you, ask anyway. Many companies handle all requests the same way because it is simpler.

What to ask for

RightWhat you getWhen to use it
AccessA copy of your data and how it is usedAlways start here
PortabilityYour data in a reusable formatMoving to another app
DeletionRemoval of your dataLeaving, or after a breach
Objection / opt-outStop certain uses, such as training or ad sharingStaying, but on your terms
CorrectionFix inaccurate dataWrong age, wrong email, merged accounts

A request you can copy

Send it from the email address on your account, to the privacy address in the company's privacy policy (often privacy@ or dpo@), or through its privacy form.

Subject: Data access request

I am requesting access to the personal data you hold about me, under Article 15 GDPR / the California Consumer Privacy Act (delete as appropriate). My account email is [address] and my username is [username].

Please provide: a copy of all personal data you hold about me, including conversation history, generated or uploaded images, voice recordings, memory or profile data derived from my chats, payment records and device data; the purposes of processing; who you have shared it with, including advertising and AI model providers; how long you will keep it; and whether my data has been used to train or improve AI models.

Please respond within the statutory deadline.

For deletion, replace the first paragraph with a request to erase all personal data and confirm when it is done, including backups and copies held by processors.

What a good answer looks like

A careful company sends a downloadable archive: your chats, a list of stored "memories" about you, images, payment and login history, and a written explanation of who received what. Pay attention to two sections in particular:

  • Derived data. Summaries, personality notes and "facts about you" the app has inferred. These are often the most revealing part, and they explain how AI companion memory works in your specific case.
  • Recipients. Model providers, analytics companies and advertising partners. Compare this with what the policy said - see do AI girlfriend apps sell your data.

When they ignore you

  1. Send a reminder after the deadline, quoting the date of your original request.
  2. Complain to the regulator. In the EU, your national data protection authority; in the UK, the ICO; in California, the California Privacy Protection Agency or the Attorney General.
  3. Keep records of every message and date. Regulators ask for them.

Regulators do act in this category. Italy's data protection authority fined the company behind Replika €5 million in 2025, partly for a privacy policy that did not clearly explain its processing.

Before you delete: export first

If you might want your character or history later, request access or use the app's export tool before asking for deletion. Deletion is permanent, and some apps take backups out of rotation only after weeks - the full order is in deleting an AI companion account.

Why it is worth doing even if you stay

A data request is a quiet test of a company. One that answers clearly and on time is telling you something about how it treats the rest of your data. One that ignores you is telling you something too - and you will have learned it before, not after, a breach.

Frequently asked questions

How long does a company have to answer?

Under GDPR, one month, which can be extended by two more months for complex requests if the company tells you why. Under California's law, 45 days, extendable once by another 45. Other US state laws have similar timelines.

Do I have to pay for a data request?

No. Requests are free in normal circumstances under both GDPR and California law. A company can only charge, or refuse, if requests are clearly unfounded or excessive.

What if the company is outside Europe or the US?

GDPR applies to companies anywhere that offer services to people in the EU, and UK GDPR works the same way for the UK. Enforcement against small overseas operators is harder, but the right still exists and many companies comply to keep access to the market.