What Your AI Girlfriend App Knows About You

Privacy & safety

These apps collect the most intimate text most people will ever type. Four checks, none of which take longer than ten minutes, tell you what happens to it afterwards.

We may earn a commission from links on this page. It never changes a rating.

People tell these apps things they have told nobody else. That is the product working as intended, and it is exactly why the handling of that text deserves ten minutes of attention before the first message rather than after a news story.

The one thing to be clear about first

End-to-end encryption is not possible here. For a companion app to reply, its servers must read what you wrote. Any app claiming end-to-end encryption on conversations is either describing transport encryption in misleading terms or describing something that is not the chat.

This is not a scandal — it is the architecture. It simply means the meaningful questions are about retention and access, not about cryptography.

Check 1: what is collected beyond the chat

The messages are obvious. The rest is not:

  • Account identifiers, and whether sign-up allows an email that is not your main one.
  • Payment records, which in this category are the most sensitive metadata you generate. A descriptor on a card statement has outed more people than any breach.
  • Device and usage telemetry, including when you open the app and for how long.
  • Generated images, which persist on their servers whether or not you saved them.

Check 2: whether it trains a model

Find the words "improve our services" or "train" in the privacy policy. Then look for an opt-out in the settings.

Three tiers exist in practice: no training on user content, training with an opt-out available, and training with no visible control. Any of the three can be acceptable — but not knowing which one you are in is not.

Check 3: retention and deletion

Two separate questions that policies often blur.

Retention is how long content is kept while your account is active. Deletion is what happens when you ask for it to go. An app may honour a deletion request for your conversations while keeping generated images, billing records, and backups on a longer cycle — all of which can be perfectly lawful and still not what you assumed.

Details are in deleting an AI companion account.

Check 4: what rights you actually have

If you are in the EU, the UK, or a US state with a consumer privacy law, you can demand a copy of your data and its deletion, and the operator must answer within a defined window. Our Dutch and French editions cover the same apps under GDPR.

The practical test is not whether the rights exist — they do — but whether the app gives you a self-service button or makes you write to an address and wait. That difference tells you how the company thinks about you.

A five-minute setup that costs nothing

Use a dedicated email address. Check what appears on your card statement before the second month. Turn off training if the option exists. And decide once, early, what you are not going to type into a service that must store it — your employer's name, your address, anything about a third party who did not consent to being in your chat log.

Replika and Nomi are the two apps in our ranking most likely to accumulate years rather than weeks of this material, simply because they are built for continuity. That makes the five minutes more worthwhile there, not less.

Nomi

4.4 Rating: 4.4 out of 5

The best long-term memory of anything we have tested, and the most natural dialogue.

Price
from $15.99/month
Free tier
Yes
Worldwide
Available

Replika

4.0 Rating: 4.0 out of 5

The most generous free version; the paid one feels dated next to newer apps.

Price
from $19.99/month
Free tier
Yes
Worldwide
Available

Frequently asked questions

Are my conversations encrypted?

In transit, yes, on any credible app. End-to-end is a different claim and almost never true here — the operator's servers must read your messages to generate a reply.

Can staff read my chats?

Assume some can. Moderation, abuse review and debugging all require it. The privacy policy will say so in general terms; the question is how narrowly access is scoped.

Is my data used to train models?

Often, unless you opt out. Whether an opt-out exists, and whether it is on by default, is one of the sharpest differences between apps.