Do AI Girlfriend Apps Sell Your Data?

Privacy & safety

Rarely in the way people picture it - nobody is auctioning chat logs by the gigabyte. The real exposure is quieter: advertising trackers, clauses about partners and affiliates, and policies that reserve rights the app may never use but never gives up.

We may earn a commission from links on this page. It never changes a rating.

Ask the question in a forum and you get two confident answers: "of course they sell everything" and "that would be illegal". Both are wrong, and the gap between them is where the useful information sits.

"Selling" covers three different things

Selling the content of your chats. Handing conversation logs to a third party for money is rare, would be legally risky in most markets, and would be a headline the day it leaked. Operators deny it loudly, and there is no public evidence of a mainstream companion app doing it.

Sharing usage data with advertisers. This is the common one. Advertising and analytics code embedded in an app or website - a software development kit, or "SDK" - reports what you do, when, and on which device. Under California's privacy law, passing personal information to others for cross-context behavioural advertising counts as "sharing", and exchanging it for anything of value can count as a "sale". So an app can truthfully say it never sold your conversations while still selling you, in the legal sense.

Passing data to service providers. The company hosting the servers, the model provider generating replies, the payment processor charging your card. These transfers are necessary for the product to work and are not a sale, but they are still copies of your data in someone else's systems.

There is a fourth route people forget: a change of owner. Almost every policy says your data transfers to a buyer if the business is sold. The companion app Soulmate changed hands shortly before it was shut down in 2023 - see when your AI companion changes overnight.

What the one systematic audit found

In February 2024 the Mozilla Foundation reviewed 11 romantic AI chatbots for its Privacy Not Included guide, including Replika, Chai and EVA AI. Together they had an estimated 100 million downloads on Google Play. Every one of them received Mozilla's privacy warning label.

Bar chart of Mozilla's 2024 findings for 11 romantic AI chatbots: 10 of 11 may share or sell personal data, 10 of 11 failed minimum security standards, 73 percent said nothing about handling vulnerabilities, 64 percent said nothing clear about encryption, 54 percent did not let users delete personal data, about 45 percent allowed weak passwords

Share of the 11 apps Mozilla reviewed in February 2024 that met each finding. Source: Mozilla Foundation, Privacy Not Included.

The tracker numbers were the most striking part. Mozilla counted an average of 2,663 trackers in the first minute of use across the apps - an average pulled up heavily by one app, Romantic AI, which triggered 24,354 in a single minute. The next highest, EVA AI, triggered 955.

Two caveats before drawing conclusions. It was a snapshot from early 2024, and policies change. And several apps that dominate the category today were not in the sample. The value of the audit is less the verdicts on particular apps than what it shows about the category's defaults.

Reading a privacy policy for the answer

You do not need to read the whole thing. Search it for a handful of phrases and read the paragraph around each.

If the policy saysIt usually meansWorth worrying about?
"We do not sell your personal information"No sale in the narrow sense. Check for "share" separatelyOnly if "share" appears too
"Advertising partners", "targeted advertising"Trackers build an ad profile from your usageYes - opt out where possible
"Our affiliates"Other companies under the same owner, sometimes many appsDepends who the owner is
"To improve our services", "train"Your conversations may be used to train modelsYes - look for an opt-out
"Merger, acquisition or sale of assets"A buyer gets your data if the company is soldStandard, but remember it
"Where we believe disclosure is necessary"Disclosure to authorities without a court orderYes, if it says nothing narrower

A footer link labelled "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" is a useful tell in its own right. California requires it from businesses that sell or share personal information, so its presence is an admission that some sharing happens - and a button to stop it.

A five-minute check you can do tonight

  1. Search the policy for sell, share, advertis, train and affiliate. Five searches, five paragraphs.
  2. Look at the store labels. Apple's "Data Used to Track You" section and Google Play's "Data safety" section are filled in by the developer, so they are claims rather than audits - but an app that admits tracking there is not going to be better in practice.
  3. Turn on Global Privacy Control in your browser if you use the web version. California's rules require businesses to treat that signal as an opt-out of sale and sharing.
  4. Refuse the tracking prompt on iPhone, and reset your advertising ID on Android.
  5. Notice whether the app shows ads. If it does, your attention and data are part of how it pays its bills - see how AI companion apps make money.

Where the law helps, and where it stops

If you are in California, or one of the growing list of US states with a comprehensive privacy law, you can demand to know what was collected, stop its sale or sharing, and ask for deletion. In the EU and UK, GDPR gives you the same and more, and regulators use it: Italy fined Replika's operator €5 million in 2025, partly for a privacy policy that did not explain what it was doing with users' data.

The new state laws on AI companions, covered in AI companion laws in the US, focus on disclosure and crisis handling and add little about data. The main exception is narrow: Utah's law on mental-health chatbots bars them from selling or sharing users' health information and from targeting ads based on what users type.

The honest answer

Most companion apps do not sell your conversations. Many do let advertising and analytics companies watch how you use them, and almost all of them keep the right to do more than they currently do. The difference between a careful app and a careless one is visible in its policy and settings, and it takes five minutes to find. That is five minutes well spent before you type anything you would not want in someone else's database - and our four privacy checks cover the rest.

Frequently asked questions

Does Replika sell my data?

Replika says it has never sold user data and has never supported advertising. Mozilla's 2024 review criticised it for sharing behavioural data and allowing weak passwords. Both statements can be true at once: sharing usage data with analytics or marketing partners is not the same as selling conversations. Read the current policy rather than either headline.

Can I stop an app from sharing my data?

Partly. Use the "Do Not Sell or Share" link if the app has one, turn on Global Privacy Control in your browser, refuse tracking prompts on your phone, and switch off model training if the setting exists. Deleting the account ends future collection but does not always erase what was already shared.

Is a paid app safer than a free one?

Not automatically, but the incentives are better. An app funded by subscriptions has less reason to carry advertising trackers than one funded by ads. The policy, not the price, is what tells you.