Research draft: this guide is readable locally, but it remains excluded from search and the sitemap. Its evidence scope, editorial clarity, privacy/safety language, accessibility, legal scope, and publication decision still require accountable human review.

AI companion chat privacy · six lifecycle questions

Private-feeling is not the same as private.

Do not assume an AI companion chat is private because it feels personal or because a provider publishes a privacy policy. Before sharing, check separately what enters the service, who may handle it, why it may be used, how it persists, what controls say, and how exit and response work. A documented statement is not proof of confidentiality, security, complete deletion, or legal compliance.

Authority record adjudicated . No account, chat, permission, network request, provider control, cancellation, export, deletion, or erasure workflow was tested for this guide.

Lifecycle decisions
6
Authority sources
6
Product privacy facts
0
Privacy scores
0
Inferred data flows
0
First-hand tests
0

Your 30-second privacy path

Start with what you are about to do.

Choose the situation closest to yours. These are cautious next steps—not a claim that any provider is private, secure, compliant, or unsafe.

I have not started chatting yet

Decide what the service does not need.

Before sharing identifying, financial, health, location, contact, or intimate information, check what enters the service and who the current documents say may handle it. Leave unanswered questions unresolved.

Start with inputs

I already use the companion

Review use, retention, and controls separately.

You do not need to paste a conversation here. Check stated purposes, persistence, human or vendor handling, and what each available setting actually says it changes.

Review the middle of the lifecycle

I am changing settings or leaving

Preserve first; treat billing and deletion separately.

Keep permitted material you may need, check the original billing channel, and read the exact export, cancellation, and deletion scopes before acting. A documented route is not proof of a completed outcome.

Plan exit and response
Want the evidence behind the questions?The complete six-stage framework, 18 practical checks, six scoped authority notes, and source ceiling continue below.

The most important reading rule

Finding a privacy policy answers only one question: a policy source exists.

In Companion Curator’s product evidence, a present policy means only that a usable checked source record contains a privacy policy. It is a locator, not a verdict.

To understand a particular provider, the next step is to read its current record field by field and preserve silence, conflict, and ambiguity as unknown.

Follow the information—not the feeling

Check all six stages. A reassuring answer in one stage cannot erase an unknown in another.

Inputs

What information enters the service before the conversation even feels personal?

Practical answer: Separate account identifiers, chat and memory, voice and media, permissions, device or usage data, payment metadata, and information about another person. Do not assume a named provider collects any category without a current product source.

Three checks

  1. List the categories the current provider record actually names; leave silence and ambiguous language unknown.
  2. Minimize identifying, intimate, credential, financial, health, legal, workplace, and third-party information before sharing.
  3. Treat text, voice, images, video, permissions, device data, payment metadata, and companion memory as separate inputs.
Place privacy inside the broader safety decision

Establishes: The six separate pre-use safety decisions and their authority limits.
Does not establish: A product privacy grade, current provider data flow, or safety verdict.

Open this check

Handlers

Which organizations or people may handle each data category?

Practical answer: Distinguish the companion provider, model or API provider, infrastructure and processors, moderators or support staff, advertising or analytics parties, and legally compelled recipients only where a current source explicitly does so.

Three checks

  1. Name a handler only when a current first-party or otherwise eligible product source names it.
  2. Keep automated model processing, provider personnel, moderators, support, vendors, and third parties separate.
  3. Do not turn a policy link, role label, or authority checklist into proof that a person or company accessed a conversation.
Locate current product policy and account-control records

Establishes: Whether a usable checked source record contains the documented product path.
Does not establish: Policy meaning, confidentiality, security, handling, compliance, or successful workflow completion.

Open this check

Purposes

Why does the current provider say each category may be used?

Practical answer: Keep conversation delivery, personalization, safety or moderation, service improvement, model training, advertising, and other stated uses separate. Silence is unknown—not permission to assume either use or non-use.

Three checks

  1. Bind every stated purpose to the exact current product source and wording that supports it.
  2. Do not collapse service improvement, model improvement, personalization, safety, moderation, and advertising into one training label.
  3. Keep a user's feeling of emotional privacy separate from institutional control over platform data.
Inspect evidence states and claim limits

Establishes: How inquiry questions, institutional syntheses, studies, preprints, product sources, and unknowns remain separate.
Does not establish: A legal conclusion, technical audit, current product fact, or first-hand workflow result.

Open this check

Persistence

What remains visible, remembered, retained, copied, or recoverable—and for how long?

Practical answer: Visible chat history, companion memory, server retention, backups, de-identification or pseudonymization, deletion, and security or encryption language are different facts. No one label proves confidentiality or irreversible erasure.

Three checks

  1. Separate what a user sees from what a provider says it retains elsewhere, including copies or backups.
  2. Record exact durations, triggers, exceptions, and account-versus-chat scope only when the current source states them.
  3. Do not treat de-identification, pseudonymization, encryption, deletion, or disappearance from the interface as interchangeable.
See what Companion Curator itself stores and sends

Establishes: This publication's current browser-local tool and disabled-analytics boundary.
Does not establish: Any companion provider's collection, retention, sharing, security, training, or deletion behavior.

Open this check

Controls

What documented control exists—and what outcome remains untested?

Practical answer: Separate permission settings, use or training opt-outs, access, correction, export, chat deletion, account deletion, privacy erasure, and appeal or contact routes. A documented path is not a tested result.

Three checks

  1. Record the exact control, surface, scope, billing channel, prerequisite, and current source date.
  2. Keep access, correction, export, cancellation, refund, chat deletion, account deletion, and privacy erasure as separate actions.
  3. Save confirmations when you act, but do not treat a request or confirmation as proof that every copy was changed or erased.
Locate current product policy and account-control records

Establishes: Whether a usable checked source record contains the documented product path.
Does not establish: Policy meaning, confidentiality, security, handling, compliance, or successful workflow completion.

Open this check

Exit and response

What should you preserve, stop, request, or escalate before access changes?

Practical answer: Minimize before disclosure, preserve only what matters, record current terms and confirmations, and keep renewal cancellation, export, deletion, erasure, and incident response separate.

Three checks

  1. Create a minimal local continuity note before an irreversible account action; do not upload intimate history to make the note.
  2. Cancel renewal through the actual billing channel and save confirmation before deleting an account.
  3. Use the provider's current contact or incident path where appropriate, and seek qualified local help for legal, safety, or acute high-stakes decisions.
Use the preservation-first account-action order

Establishes: A sequence for preservation, export, renewal cancellation, refunds, deletion, and erasure questions.
Does not establish: A completed cancellation, refund, export, deletion, erasure, or incident response.

Open this check

This guide’s own privacy boundary

You do not need to paste a conversation here.

This page asks for no personal or intimate input. It is a static reading sequence, not a scanner or privacy grader.

Reader inputs collected
No
URL payload
None
Browser storage
None
Analytics event
None
Affiliate SubID
None
Tool network request
None

Seven bounded next actions

Move from a broad privacy question to the exact evidence or action you need.

Place privacy inside the broader safety decisionThe six separate pre-use safety decisions and their authority limits.Does not establish: A product privacy grade, current provider data flow, or safety verdict.Locate current product policy and account-control recordsWhether a usable checked source record contains the documented product path.Does not establish: Policy meaning, confidentiality, security, handling, compliance, or successful workflow completion.Use the preservation-first account-action orderA sequence for preservation, export, renewal cancellation, refunds, deletion, and erasure questions.Does not establish: A completed cancellation, refund, export, deletion, erasure, or incident response.Create a private continuity noteA browser-local way to keep only the role, tone, boundaries, durable preferences, and restart note the reader chooses.Does not establish: Provider export coverage, direct companion transfer, deletion, or confidentiality outside this tool.See what Companion Curator itself stores and sendsThis publication's current browser-local tool and disabled-analytics boundary.Does not establish: Any companion provider's collection, retention, sharing, security, training, or deletion behavior.Inspect evidence states and claim limitsHow inquiry questions, institutional syntheses, studies, preprints, product sources, and unknowns remain separate.Does not establish: A legal conclusion, technical audit, current product fact, or first-hand workflow result.Read the editorial and monetization boundariesThe publication's evidence, correction, inclusion, and commission-independence rules.Does not establish: Human approval of this draft or a provider privacy outcome.

Exact authority ceiling

Six sources, each kept inside its method and scope.

The source list is not a vote and six records do not create a confidence score. Inquiry questions, institutional syntheses, interviews, and selected public discourse remain different evidence states. None supplies a current product privacy verdict.

preprint public discourse studypreprint public discourse observation

Tracing Users' Privacy Concerns Across the Lifecycle of a Romantic AI Companion

arXiv · 2026-03-25 · Retrieved

Population or scope
2,909 public Reddit posts from 79 selected subreddits collected for 2024-11-07 through 2025-11-07.
Method
Purposive app and subreddit discovery, keyword-filtered PRAW collection, preliminary labels from 100 random posts, ChatGPT-assisted filtering with final human relevance verification, and qualitative consolidation into four lifecycle themes; usernames and profile links were excluded.
Product/version limit
Bounded public discourse across a selected ecosystem and period; not platform truth, product telemetry, policy interpretation, or a provider audit. arXiv v2 dated 2026-03-25 and marked in submission at a conference.
Key limitation
Purposive discovery, selected communities, keyword filtering, and public posts do not establish representativeness, prevalence, or all-user experience.
Do not infer
Do not infer product behavior, technical data flow, effective deletion, prevalence, or truth of a quoted allegation.
preprint qualitative studypreprint observation

Chatting with Confidants or Corporations? Privacy Management with AI Companions

arXiv · 2026-01-13 · Retrieved

Population or scope
Fifteen users of companion platforms such as Replika and Character.AI.
Method
In-depth interviews interpreted through Communication Privacy Management and horizontal user-AI versus vertical user-platform privacy.
Product/version limit
Participant experiences with companion platforms; not a current product or policy audit. arXiv v1 submitted 2026-01-13; the arXiv-issued DOI and displayed related DOI do not establish a peer-reviewed version of this manuscript.
Key limitation
Preprint status and a small qualitative sample prevent consensus, prevalence, causal, or universal claims.
Do not infer
Do not label the record peer reviewed without a verified version of record.
regulator technology assessmentinstitutional synthesis

AI companions

European Data Protection Supervisor · Date not exposed · Retrieved

Population or scope
Category-level technology assessment; no sampled user population.
Method
EDPS TechSonar explanatory assessment with linked research and examples.
Product/version limit
AI companions as a category; not a current audit of a named Companion Curator product. Live page retrieved 2026-07-21; no reliable publication date is exposed in the visible record.
Key limitation
This institutional assessment is not a controlled study, legal opinion, prevalence estimate, or current product audit.
Do not infer
Do not infer a provider's actual collection or reuse, GDPR compliance or violation, biometric outcome, or current product verdict.
institutional research briefinginstitutional synthesis

The spread of AI companions and the challenges they generate

European Parliamentary Research Service · 2026-05 · Retrieved

Population or scope
Category-level institutional synthesis; no single sampled user population.
Method
Ten-page Members' Research Service synthesis of uses, cited studies, reported incidents, lawsuits, provider examples, EU frameworks, and policy questions.
Product/version limit
Category-level synthesis with examples; not an audit of a named product or version. European Parliament briefing PE 789.299 published May 2026 and retrieved 2026-07-21.
Key limitation
The briefing synthesizes cited material and policy questions rather than independently auditing products or adjudicating incidents.
Do not infer
Do not infer that every provider trains on chats, that an alleged incident is adjudicated, or that a named product currently leaks data.
regulatory inquiryinquiry question

FTC Launches Inquiry into AI Chatbots Acting as Companions

United States Federal Trade Commission · 2025-09-11 · Retrieved

Population or scope
Seven named consumer-facing chatbot companies; the inquiry emphasizes children and teens.
Method
Compulsory FTC Section 6(b) information orders for a wide-ranging study without a specific law-enforcement purpose; the applicable period begins 2022-01-01 and continues through compliance.
Product/version limit
The seven order recipients and responsive products; neither the entire companion category nor the Companion Curator catalog. Inquiry announcement and order template published 2025-09-11; no company responses or later FTC findings are included.
Key limitation
The order asks questions and contains no provider response, adjudicated finding, violation, prevalence estimate, or product test.
Do not infer
Do not infer an answer, violation, product behavior, data flow, legal conclusion, effective control, or category-wide practice.
peer reviewed qualitative studyqualitative observation

Privacy in Human-AI Romantic Relationships: Concerns, Boundaries, and Agency

ACM CHI 2026 · 2026-04-13 · Retrieved

Population or scope
Seventeen participants with human-AI romantic relationship experience.
Method
Semi-structured interviews across exploration, intimacy, and dissolution plus analysis of general and privacy-related features and policies for platforms participants reported using.
Product/version limit
Participant-reported platforms across 14 platform entries; not a current technical or policy audit of those products. Published in the CHI 2026 proceedings on 2026-04-13; DOI 10.1145/3772318.3791237. The accessible arXiv v2 author manuscript is dated 2026-02-13.
Key limitation
The small qualitative sample is not representative and supplies no prevalence or universal user outcome.
Do not infer
Do not infer prevalence, backend access, confidentiality, current product behavior, or technical or legal agency.

How to use this guide honestly

A useful question framework is not a technical audit.

Use these six stages to identify what a current product source would need to answer. Do not convert a policy link, institutional concern, interview observation, or public discussion into a provider data flow or legal finding.

Inquiry ≠ answer

The FTC record lists questions sent to seven companies. It contains no company response or adjudicated finding.

Synthesis ≠ audit

EDPS and EPRS organize privacy questions. They do not establish current behavior for every provider.

Interview ≠ prevalence

Small qualitative studies expose useful boundary questions without showing how common an experience is.

Discourse ≠ operations

Selected public discussion can reveal concerns without verifying provider systems, policy meaning, or control outcomes.