Ask the question in a forum and you get two confident answers: "of course they sell everything" and "that would be illegal". Both are wrong, and the gap between them is where the useful information sits.
"Selling" covers three different things
Selling the content of your chats. Handing conversation logs to a third party for money is rare, would be legally risky in most markets, and would be a headline the day it leaked. Operators deny it loudly, and there is no public evidence of a mainstream companion app doing it.
Sharing usage data with advertisers. This is the common one. Advertising and analytics code embedded in an app or website - a software development kit, or "SDK" - reports what you do, when, and on which device. Under California's privacy law, passing personal information to others for cross-context behavioural advertising counts as "sharing", and exchanging it for anything of value can count as a "sale". So an app can truthfully say it never sold your conversations while still selling you, in the legal sense.
Passing data to service providers. The company hosting the servers, the model provider generating replies, the payment processor charging your card. These transfers are necessary for the product to work and are not a sale, but they are still copies of your data in someone else's systems.
There is a fourth route people forget: a change of owner. Almost every policy says your data transfers to a buyer if the business is sold. The companion app Soulmate changed hands shortly before it was shut down in 2023 - see when your AI companion changes overnight.
What the one systematic audit found
In February 2024 the Mozilla Foundation reviewed 11 romantic AI chatbots for its Privacy Not Included guide, including Replika, Chai and EVA AI. Together they had an estimated 100 million downloads on Google Play. Every one of them received Mozilla's privacy warning label.

Share of the 11 apps Mozilla reviewed in February 2024 that met each finding. Source: Mozilla Foundation, Privacy Not Included.
The tracker numbers were the most striking part. Mozilla counted an average of 2,663 trackers in the first minute of use across the apps - an average pulled up heavily by one app, Romantic AI, which triggered 24,354 in a single minute. The next highest, EVA AI, triggered 955.
Two caveats before drawing conclusions. It was a snapshot from early 2024, and policies change. And several apps that dominate the category today were not in the sample. The value of the audit is less the verdicts on particular apps than what it shows about the category's defaults.
Reading a privacy policy for the answer
You do not need to read the whole thing. Search it for a handful of phrases and read the paragraph around each.
| If the policy says | It usually means | Worth worrying about? |
|---|---|---|
| "We do not sell your personal information" | No sale in the narrow sense. Check for "share" separately | Only if "share" appears too |
| "Advertising partners", "targeted advertising" | Trackers build an ad profile from your usage | Yes - opt out where possible |
| "Our affiliates" | Other companies under the same owner, sometimes many apps | Depends who the owner is |
| "To improve our services", "train" | Your conversations may be used to train models | Yes - look for an opt-out |
| "Merger, acquisition or sale of assets" | A buyer gets your data if the company is sold | Standard, but remember it |
| "Where we believe disclosure is necessary" | Disclosure to authorities without a court order | Yes, if it says nothing narrower |
A footer link labelled "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" is a useful tell in its own right. California requires it from businesses that sell or share personal information, so its presence is an admission that some sharing happens - and a button to stop it.
A five-minute check you can do tonight
- Search the policy for sell, share, advertis, train and affiliate. Five searches, five paragraphs.
- Look at the store labels. Apple's "Data Used to Track You" section and Google Play's "Data safety" section are filled in by the developer, so they are claims rather than audits - but an app that admits tracking there is not going to be better in practice.
- Turn on Global Privacy Control in your browser if you use the web version. California's rules require businesses to treat that signal as an opt-out of sale and sharing.
- Refuse the tracking prompt on iPhone, and reset your advertising ID on Android.
- Notice whether the app shows ads. If it does, your attention and data are part of how it pays its bills - see how AI companion apps make money.
Where the law helps, and where it stops
If you are in California, or one of the growing list of US states with a comprehensive privacy law, you can demand to know what was collected, stop its sale or sharing, and ask for deletion. In the EU and UK, GDPR gives you the same and more, and regulators use it: Italy fined Replika's operator €5 million in 2025, partly for a privacy policy that did not explain what it was doing with users' data.
The new state laws on AI companions, covered in AI companion laws in the US, focus on disclosure and crisis handling and add little about data. The main exception is narrow: Utah's law on mental-health chatbots bars them from selling or sharing users' health information and from targeting ads based on what users type.
The honest answer
Most companion apps do not sell your conversations. Many do let advertising and analytics companies watch how you use them, and almost all of them keep the right to do more than they currently do. The difference between a careful app and a careless one is visible in its policy and settings, and it takes five minutes to find. That is five minutes well spent before you type anything you would not want in someone else's database - and our four privacy checks cover the rest.