mypresio
All postsCreate your AI companionCreate Companion
MyPresio · Blog

Are AI Companions Private? 5 Policies Compared (2026)

August 4, 2026

No cloud-based AI companion is completely private. To answer you, the service normally has to store or process your messages, send some data through its infrastructure, and retain enough context to create memories. Depending on the company, conversations may also be used to improve AI models, checked by safety systems, or handled by outside providers.

That does not mean every app treats data the same way. We compared the published privacy terms for MyPresio, Replika, Nomi, Kindroid, and Character.AI. Replika gives the most specific assurances about what its outside AI providers may do with chats. Character.AI states most directly that content can train its models and offers a training opt-out for new chats to users in the EEA and UK. Kindroid explicitly describes chat encryption and export. Nomi promises deletion in approximately 28 days but leaves an important exception for de-identified training or communications archives. MyPresio says it does not use conversation content for advertising and will delete or anonymize account data within 30 days after a deletion request, subject to legal exceptions.

Those are policy disclosures, not independent security test results. A well-written policy can tell you what a company promises, but it cannot prove that its systems have never been breached, that every internal control works, or that an AI will never reveal something unexpectedly.

Editorial disclosure: MyPresio publishes this comparison and is one of the services covered. We applied the same questions to every policy, included limitations in MyPresio's own wording, and linked the primary sources so readers can verify the findings. Policies were checked August 4, 2026.

AI companion privacy comparison at a glance

Service How chats may improve AI Outside processing disclosed Advertising disclosure Deletion and retention Export or access
MyPresio Conversations may improve model quality, safety, and accuracy; publicly shared models are not trained on conversation data without anonymization LLM, speech-to-text, text-to-speech, image, safety, hosting, analytics, payment, and support providers Conversation content is not shared for advertising Delete or anonymize within 30 days after account deletion, except where law requires retention Access and deletion can be requested by email; no self-service portable export is promised in the policy
Replika Interactions personalize the companion; de-identified or minimized content is sent to AI providers that are contractually barred from training their own models on it AI model, hosting, analytics, payment, support, security, and other providers Chats are not used or disclosed for marketing or advertising; separate website activity may support targeted advertising Profile, messages, content, and preferences may remain up to 60 days after termination; some account and transaction records can remain longer Access, correction, deletion, and a portable copy are described
Nomi Information may be used to enhance the experience and improve the system; the policy also refers to de-attributed data in training archives after deletion Hosting and other contractors may process data, but the policy is less specific about model-provider restrictions Says personal information is not sold or rented; its website terms leave room for advertising networks Personal data is generally removed about 28 days after deletion, while support, communications, or training archives may remain in de-attributed form Access and deletion rights depend partly on location; no prominent self-service export promise found
Kindroid Private content may be de-identified or aggregated to build and improve services Cloud, analytics, payment, security, support, and other service providers are described Says it has not sold or shared personal data as those terms are legally defined Chats and media remain until the relevant Kindroid or account is deleted; limited logistical data may remain to prevent abuse A portable export can be requested, generally once every 180 days
Character.AI User content can train and improve AI models; EEA and UK users may opt out of using new chat content for generative-model training Storage, content, moderation, analytics, support, security, advertising, and other providers receive relevant categories of data Some identifiers, demographics, location, device data, and inferences may be used for targeted advertising; chat content is not listed as sold for that purpose Retention lasts as needed for the stated purpose and legal obligations; a public Character's characteristics may survive account deletion Account deletion and data access or portability are available; exceptions can apply

The short version: “we do not sell your data” does not mean “your data never leaves the company,” and “encrypted” does not automatically mean end-to-end encrypted. Model hosts, speech services, cloud storage, moderation vendors, and payment processors can all be necessary recipients without the company selling anything.

How we compared the policies

Privacy pages use different language, so we asked the same six questions about each service:

  1. Does the company say chats can improve or train AI?
  2. Are outside AI or infrastructure providers involved?
  3. Can conversation data be used for advertising?
  4. How long can data remain after deletion?
  5. Can a user access or export their data?
  6. Does the policy describe encryption or other concrete security controls?

We used the policies in effect on August 4, 2026, plus official help pages where they clarified deletion or training choices. We did not inspect private infrastructure, commission penetration tests, or attempt to verify compliance from inside the companies. Absence of a promise in a policy is not proof that a feature does not exist; it means a user should not rely on that feature as a contractual disclosure without asking the provider.

1. MyPresio privacy: multiple AI processors and a 30-day deletion promise

MyPresio's policy says conversations are stored for continuity and memory and may be used to improve the quality, safety, and accuracy of its AI models. It also says conversation data will not train models shared publicly without anonymization. This is not the same as a complete training opt-out: the current policy still allows internal improvement uses.

The policy is explicit that different features require different processors. Relevant messages and memories can go to a large language model provider; call or voice-note audio goes to speech-to-text; replies go to text-to-speech; and photos or image prompts can go to an image provider and safety model. Hosting, analytics, payments, and customer support may involve additional service providers.

MyPresio says it does not sell personal data and does not share conversation content for advertising. Automated screening can examine content for safety, and authorized personnel may review a conversation when there is reason to suspect a Terms of Service violation.

After account deletion, the policy promises deletion or anonymization within 30 days, except where the law requires retention. Users can request access, correction, or deletion by contacting support. The policy does not currently promise a downloadable, machine-readable archive or name every AI provider, so users who need those details should ask before sharing sensitive material.

What the policy does well: It identifies the types of AI processing involved, separates advertising from operational sharing, and provides a defined deletion window.

What remains unclear: It does not offer a conversation-training opt-out, a self-service data export, or a provider-by-provider retention table.

2. Replika privacy: the clearest limits on third-party AI providers

Replika's privacy policy, updated May 27, 2026, says the companion learns from interactions to personalize conversations. It collects messages and other submitted content, including photos, videos, voice, and text, along with account, payment, device, and usage information.

Its most useful disclosure concerns outside model providers. Replika says it sends them de-identified or minimized conversation data, contractually prohibits them from using that data to train their own models, and requires them to delete or return it. The policy describes this processing as transient. That is a more specific restriction than a generic promise that contractors are “trusted.”

Replika also states that conversation content is never used or disclosed for marketing or advertising. Its website can still use device or browsing information for targeted advertising, so the protection is specific to the conversation rather than all data connected with the company.

Retention is unusually detailed. Profile information, messages, content, and preferences may be retained for up to 60 days after termination. Some account and financial records may remain for at least ten years where legal requirements apply, while certain de-identified trend data is deleted within a year. Users can request access, a portable copy, correction, or deletion, and Replika says deletion requests extend to its providers.

The policy says data is encrypted in transit with SSL and stored on secure servers with access controls. It does not claim that chats are end-to-end encrypted, which would prevent the service itself from reading the content.

What the policy does well: It sets concrete provider restrictions, separates chat data from advertising data, gives category-specific retention periods, and describes portability.

What remains unclear: Users still have to trust Replika and its processors to apply those controls; the published policy is not an independent audit.

3. Nomi privacy: no sale promise, but ambiguous training archives

Nomi's April 27, 2026 policy says it collects account information, date of birth, chats, companion customizations, payment information, support communications, and technical usage data. It states that personal information is not sold or rented.

The company can use information to operate the service, enhance the user's experience, and improve its system. It says information is shared only as needed for legitimate business purposes and de-identified when possible. Compared with Replika, however, the policy gives less detail about whether an outside foundation-model provider receives chats, how long that provider retains them, or whether the provider can use them for its own training.

Nomi says personal data is generally removed about 28 days after account deletion. The important qualification is that support communications and certain communications or training archives may not be changed or deleted. The policy says information left in training archives will no longer be attributable to the user after deletion. That is better than leaving identifiable chats attached to an account, but it also means account deletion may not erase every derivative or archived copy.

The policy provides privacy rights that vary by jurisdiction. It does not make a universal, prominent promise of an immediate machine-readable conversation export.

What the policy does well: It makes a clear no-sale commitment, gives an approximate deletion timeline, and acknowledges that chat and customization data are collected.

What remains unclear: “Training archives” is broad language, and the policy does not spell out the same model-vendor restrictions or retention detail that Replika does.

4. Kindroid privacy: encryption and export, with access still possible

Kindroid's legal page says it collects messages and content from AI conversations, as well as profile, contact, payment, device, IP, and analytics data. It states that chats and sensitive application data are encrypted at rest and in transit.

That is a meaningful baseline, but it is not end-to-end encryption. Kindroid also says it can decrypt information to satisfy legal or contractual requirements and disclose it when required by law. If a company can decrypt a chat, the company—or a system acting for it—can technically access the plaintext in at least some circumstances.

Kindroid's terms allow private content to be de-identified or aggregated for service improvement and other business purposes. The privacy section lists cloud, analytics, payment, support, and security providers, but it does not offer the same focused explanation of foundation-model provider training restrictions found in Replika's policy.

Chats and media are retained until the user deletes the relevant Kindroid or account. Kindroid's help center says deleting the final Kindroid schedules account deletion after 24 hours, while some logistical data may remain to prevent abuse. Users can request a portable data export, generally limited to once every 180 days.

There is also a policy-maintenance issue worth noting. Kindroid's current Terms say the service is for adults aged 18 and older, while part of the privacy text still contains older child-consent language referring to users below 13 or 16. That inconsistency does not prove unsafe data handling, but it makes the document less clear than it should be.

What the policy does well: It explicitly covers encryption at rest and in transit, ties chat retention to user deletion, and offers portable export.

What remains unclear: It does not claim end-to-end encryption or provide detailed model-vendor retention and training terms in the public policy.

5. Character.AI privacy: direct training disclosure and regional opt-out

Character.AI's policy, effective July 1, 2026, says it collects chat communications, posted media, biographies, shared Characters, voice recordings, account and transaction details, technical activity, and inferred interests. It uses information to personalize and improve the service, including training AI and machine-learning models.

An official training explainer says user-generated content helps improve the model's creative writing, functionality, and conversations. It says Character.AI reduces personal information before training. Users in the EEA and UK can opt out of using new chat content for generative-model training through settings. That choice is region-specific in the current explanation, and even there, feedback, reports, safety-classifier work, search, and recommendation improvements can still involve relevant data.

Character.AI makes a careful distinction in its US disclosure. Certain identifiers, demographics, approximate location, device activity, and inferences may be disclosed to advertising providers in ways some state laws define as a “sale.” Chat communications are listed as going to operational vendors such as storage, content, moderation, analytics, and security providers, but not as sold for targeted advertising.

Users can delete an account and request access or a portable copy. The main policy does not promise one universal number of days for deletion; it retains information as long as necessary for its purposes and legal obligations. If a user created a Character that others can access, Character.AI reserves the right to preserve that Character's characteristics after the creator deletes the account, while advising creators not to put personal information in public Character definitions.

What the policy does well: It says plainly that content can train models, identifies a regional opt-out, and separates operational chat sharing from targeted-advertising categories.

What remains unclear: The training opt-out described in the official explainer is not presented as a worldwide choice, and the general retention rule is less precise than a fixed deletion window.

What these five policies reveal

1. Every useful AI companion needs some access to the conversation

A cloud service cannot generate a context-aware response without processing what you send. Memory requires even more: the product has to preserve facts, summaries, embeddings, recent messages, or some combination of them. A promise that “chats are private” therefore needs a definition. Private from other users? From advertisers? From employees? From model vendors? From law enforcement with valid process? Those are different questions.

2. “Not sold” is a narrow promise

All five services rely on some outside infrastructure. Sending a message to a model host under a service contract is not normally described as selling it. Neither is using a moderation provider or storing it in a cloud database. When evaluating privacy, read the service provider section as carefully as the data-sale section.

3. Encryption does not always stop the company from reading chats

Encryption in transit protects data while it moves across a network. Encryption at rest protects stored data if a disk or database is accessed without the key. End-to-end encryption is different: only the communicating users hold the keys. An AI service that must interpret a message on its servers generally needs access to readable content at some point.

None of the five policies reviewed here promises conventional end-to-end encryption for AI chats. Do not treat a lock icon or the word “encrypted” as proof that the operator cannot access a conversation.

4. Deleting an account may not delete every derivative immediately

Replika gives category-specific windows. MyPresio and Nomi publish roughly month-long deletion commitments. Kindroid connects retention to deleting the companion or account. Character.AI uses a purpose-based standard and may preserve public Character characteristics. Legal records, fraud-prevention records, backups, aggregated statistics, de-identified data, and trained model parameters can receive different treatment from the original chat history.

Before sharing something sensitive, assume that deleting it later may not instantly remove every backup or non-identifiable derivative.

5. Training choices are inconsistent

Character.AI offers the clearest explicit training opt-out we found, but its public instructions limit that option to EEA and UK users and to new chat content used for generative training. Replika focuses instead on preventing its third-party model providers from training on supplied data. Nomi and MyPresio permit improvement uses under their policies, while Kindroid allows de-identified or aggregated improvement uses.

The practical question is not simply “Does this company train AI?” Ask which model, using what data, in what form, with which opt-out, and whether the restriction also binds outside providers.

How to use an AI companion more privately

No privacy setting is as reliable as not sending unnecessary personal data. These habits reduce exposure across services:

  • Use a unique password and enable stronger account security where available.
  • Avoid real addresses, financial details, government identifiers, workplace secrets, account-recovery answers, and private information about other people.
  • Use a nickname if the service does not need your legal name.
  • Check whether a Character, voice, image, or post is public before adding personal details.
  • Review model-training, personalization, and advertising choices in settings—not only during signup.
  • Request your data before deleting the account if you want to see what can be exported.
  • Delete individual chats or characters you no longer need, then follow the separate account-deletion process.
  • Treat AI output as generated text, not confidential professional advice or a guaranteed factual record.

If a conversation involves a medical crisis, abuse, self-harm, legal exposure, or another high-stakes situation, use an appropriate human professional or emergency resource. An AI companion is not a therapist, attorney, doctor, or emergency service.

Which AI companion has the best privacy policy?

Replika has the most detailed public policy of the five on third-party model restrictions and category-specific retention. That is a judgment about disclosure quality—not proof that it has the strongest technical security in practice.

Other services lead on narrower points. Kindroid makes encryption and portable export explicit. Character.AI is the only one in this comparison with a clearly documented opt-out for new chat content used in generative-model training, although the option is described for EEA and UK users. Nomi and MyPresio publish shorter headline deletion windows than Replika's 60-day window for messages after termination, but both allow certain exceptions or anonymized improvement uses.

Choose based on the risk that matters to you:

  • For the clearest outside-model restriction, read Replika's policy first.
  • For an explicit portable export, compare Replika and Kindroid.
  • For a documented regional training control, check Character.AI's settings and eligibility.
  • For a defined roughly one-month account-deletion window, compare Nomi and MyPresio's exact exceptions.
  • For any service, avoid sharing data you could not tolerate being retained, reviewed for safety, or exposed in a breach.

The bottom line

AI companion conversations can feel private because they happen one-to-one, but the technology behind them is still an online service. Chats may pass through model, speech, image, storage, moderation, analytics, and support systems. Policies can limit those uses, yet they cannot make cloud processing disappear.

Read three sections before choosing an app: AI training, service providers, and deletion/retention. Then check whether the product offers an export, whether advertising uses exclude chat content, and whether “encryption” means more than protection in transit. The safest assumption is simple: share enough to make the companion useful, but not enough to make a data leak devastating.

Methodology & sources

This article compares written disclosures rather than conducting a technical audit. We reviewed the official sources below on August 4, 2026. Policies can change, and regional rights can differ. Readers should open the current version before making a decision.

  • MyPresio — Privacy Policy: https://mypresio.com/privacy
  • Replika — Privacy Policy (updated May 27, 2026): https://replika.com/legal/Privacy/en
  • Nomi — Privacy Policy (last updated April 27, 2026): https://nomi.ai/privacy-policy/
  • Kindroid — Kindroid Legal (privacy policy and terms): https://kindroid.ai/docs/article/kindroid-legal/
  • Kindroid — Common Issues (account deletion): https://kindroid.ai/docs/article/common-issues/
  • Character.AI — Privacy Policy (effective July 1, 2026): https://character.ai/privacy
  • Character.AI — Regional Privacy Disclosures: https://character.ai/regional
  • Character.AI — How Character.AI Improves Its Models: https://character.ai/model-training
  • Character.AI Help Center — How do I delete my account?: https://support.character.ai/hc/en-us/articles/15063461160475-How-do-I-delete-my-account

Related reading

  • Best AI Companion Apps in 2026
  • The Psychology of AI Companionship
  • Replika Review 2026
  • Nomi AI Review 2026
  • Kindroid Review 2026
  • Character.AI Review 2026
← All postsCreate your companion
MyPresio · support@mypresio.com · mypresio.com