AI Companion Privacy: A 12-Question Checklist
Before you open up to an AI companion, check how messages, memories, model training, human review, retention, deletion, analytics, and safety work.
AI companion privacy starts with a simple fact: a personal conversation can reveal far more than a profile form. Names, routines, relationships, worries, health details, photos, voice notes, and future plans can all appear in an ordinary thread.
Before opening up, read the service's privacy policy with twelve questions in mind. You do not need to be a lawyer. You need concrete answers written plainly enough to compare.
1. What does the service collect?
Look beyond the messages themselves. An AI companion may collect your phone number or email, setup answers, time zone, conversation content, media, message timestamps, delivery status, subscription details, device information, IP address, analytics events, and support emails.
The policy should separate information you provide, information collected automatically, and information received from vendors. “We collect information needed to provide the service” is not a useful inventory.
2. Who processes your messages?
The company whose name is on the product may rely on other companies for AI models, cloud hosting, messaging, phone verification, analytics, payments, and customer support.
A privacy policy does not always list every vendor by name, but it should explain the categories and purposes. For a text-based companion, remember that messaging platforms and mobile carriers may also handle data in transit. A conversation appearing in a familiar app does not mean all processing stays on your device.
3. Are conversations used to train AI models?
“Training” can refer to several different things, so read the exact sentence.
Ask whether your content is used to train publicly available foundation models, whether a model provider may train its own systems on it, and whether the companion company uses conversations to evaluate or improve its specific product. Those are separate practices.
Also look for opt-outs, de-identification, sampling, and retention. A broad “we do not sell your data” statement does not answer the training question.
4. How does long-term memory work?
An AI companion with memory may extract facts or inferences from messages and store them separately so they can return in later conversations.
Find out what kinds of memory are created, whether they can include sensitive details, and how you can correct or delete them. Ask what happens when an extracted memory is wrong. Deleting a message and deleting a stored memory may be different operations.
5. Can a person review the conversation?
Do not assume “AI chat” means no human can ever access it.
Limited review may occur for safety investigations, quality evaluation, abuse detection, support requests, legal obligations, or incident response. The policy should describe the circumstances, access controls, and whether reviewers see identified or minimized data.
Human review is not automatically irresponsible; hidden or unrestricted review is the problem. The useful standard is clear purpose, least access, logging, and a policy that matches the product's actual operations.
6. What website analytics can see?
Companion websites may use cookies, event analytics, advertising tools, or session replay. Check whether form values and sensitive account areas are masked or blocked, whether consent is required in your region, and whether the chat itself occurs on a tracked website or somewhere separate.
Session replay deserves particular attention because it can capture clicks, scrolling, and visible interface content. A strong implementation blocks personal answers and sensitive screens rather than relying only on a promise that analysts will ignore them.
7. How long is data kept?
Retention should be tied to a purpose, not “as long as necessary” with no examples.
Look for separate periods for account data, conversation history, extracted memories, billing records, support tickets, security logs, verification attempts, analytics, and backups. Some records may need to remain after account deletion for tax, fraud, dispute, or legal reasons. The policy should say which ones and why.
Dates matter. “Deleted” may mean removed from active systems promptly and from backups on a later cycle.
8. What can you access, correct, export, or delete?
At minimum, find the request method and identity-verification process. Depending on where you live, the policy may describe legal rights to access, correct, delete, restrict, or obtain a portable copy.
Product-level controls can go further than the legal minimum. Useful questions include:
- Can I delete one memory without deleting everything?
- Can I delete conversation history but keep the account?
- Can I export the thread in a readable format?
- Does account deletion notify service providers holding copies?
- How long should a request take?
If the only route is an email address, check that the company explains what subject line or verification it needs.
9. How do you stop proactive messages?
For an AI friend that texts first, privacy includes attention and communication control.
The service should explain how to stop conversational texts, turn off marketing, cancel a paid membership, and delete the account. Those are not interchangeable. Replying STOP may end text delivery without ending billing. Canceling a subscription may stop renewal without deleting past conversations.
Clear products name each action and its result before you need it.
10. What happens in a safety event?
Some AI companions try to recognize language suggesting self-harm or immediate danger and respond with crisis resources. That requires processing—and sometimes inferring—sensitive information.
The company should publish what the system does and does not do. Can it contact emergency services? Does it notify another person? Is a safety flag retained? Can a human review the event? What happens if the system misses the meaning?
Never assume an AI companion is monitoring the conversation like a trained human. If you need immediate help, contact local emergency services or an appropriate crisis line directly.
11. What protections and limits are stated?
Look for security measures described at a useful level: encryption in transit and at rest where applicable, access controls, logging, vendor review, incident procedures, and account verification.
No company can promise perfect security. Be cautious of absolute claims such as “completely private” or “unhackable.” Also consider the device itself: anyone with access to your unlocked phone may be able to read a message thread.
12. Is the policy consistent with the experience?
Compare the policy to the signup flow, paywall, settings, and marketing copy.
If a landing page says “we never read messages” while the policy permits quality review, the contradiction matters. If deletion is promised but there is no working request route, the control is theoretical. If the service describes the AI as private but gives no account of model providers, keep looking.
Trust comes from the same facts appearing everywhere, not from finding one reassuring sentence.
A five-minute privacy scorecard
| Check | A useful answer includes |
|---|---|
| Collection | Specific data categories and sources |
| Providers | AI, messaging, hosting, analytics, payment, and support purposes |
| Training | Public models, provider models, product improvement, and opt-outs |
| Memory | Extraction, inference, correction, and deletion |
| Review | Exact reasons people may access content |
| Retention | Concrete periods or events for each major data type |
| Control | Access, correction, export, history deletion, and account deletion |
| Messaging | Separate instructions for texts, marketing, billing, and deletion |
| Safety | Published protocol and clear limitations |
| Consistency | Policy, product, and marketing say the same thing |
One unclear line is a reason to ask. Several missing sections are a reason not to share sensitive information yet.
How Warmth answers these questions
Warmth's Privacy Policy names what Mia collects, why it is used, the categories of provider involved, the role of AI processing and memory, the limited cases for human review, retention periods, analytics behavior, and the rights available to users.
In particular, Warmth does not sell conversations or use their content to train publicly available foundation models. Contracted model providers are prohibited from training their own models on the content. Warmth may use conversations to operate, evaluate, and improve Mia, including limited safety and quality review, with minimization and de-identification where possible. The full wording—and its exceptions—belongs in the policy, not a summary, so read that source before deciding what to share.
Warm conversation and clear privacy can coexist. The clarity has to come first.