AI Girlfriend Coach
Home / Blog / What your AI girlfriend knows
Research notes ยท AI Girlfriend Coach

What Does Your AI Girlfriend Know About You?

She remembers what you tell her. So does the company behind her. I read the privacy policy and terms of every app I've reviewed to find out what they keep.

Your AI girlfriend remembers things. Your name, your job, the way you take your coffee. That's the point. I've spent months testing how well these apps remember, and the good ones are unsettlingly good at it.

But she's not the only one who knows. Behind every AI girlfriend is a company, and that company keeps what you tell her too. The privacy policy and terms of use are supposed to explain what happens to it. Most of us scroll right past them, because they're long and written for lawyers. On most websites, that's a small risk. On an app where we sometimes say things we've never told anyone, it isn't.

So I read the privacy policy and terms of use of every AI companion app I've reviewed and translated them into plain English: what they know because you told them, what they learn from your chats, what they figure out without you saying a word, who else gets to see it, and how long they keep it.

Policies reviewed: 19 apps · Last updated: September 25, 2026

This is a living guide. Every time I review a new app, I read its policies and add it here.

  • 19apps' policies and terms read
  • 9say chat data can train their AI
  • 11say humans may review chats
  • 7give a concrete retention period

How I read these policies

I went through each app's current privacy policy and terms of use, line by line, and recorded what each one says about the same questions. A few ground rules kept this honest:

  • If a policy doesn't mention something, I say "not stated," not "no." Silence isn't a promise either way.
  • This is about what the policies say, not what the apps actually do. I can't see inside their servers. I can hold them to their own words.
  • This isn't a ranking. A detailed policy isn't automatically a safe one, and a short one isn't automatically hiding something.

Every number below is "X of the 19 apps I've reviewed so far," and it will move as the list grows.

What she remembers is a feature. What the company keeps is the question.

When your AI girlfriend remembers your dog's name, that's her memory system doing its job. It's the reason people stay with one app for months, and it's something I test in every review.

This guide is about something else: the copy the company keeps. Every one of the 19 apps collects your chats. Every one collects your device and IP information. Every one that takes payment keeps a record of it. None of that is surprising, and it's not what this guide is about. The interesting part is everything beyond it.

What they know because you told them

Signing up is where most apps ask the least. Many only want an email, often through a Google, Apple or Discord login. A few ask for more.

Your age and identity. Nomi asks for your date of birth. Replika asks for your birth date, your pronouns and, optionally, your work status. Crushi goes the other way: it says it doesn't collect a date of birth or an ID document at all, and where the law requires age verification, a separate provider checks a live selfie and keeps the photo on its side.

Government ID numbers. Nectar AI is the one outlier here. Its privacy policy lists government-issued identification numbers among the data it may collect, including Social Security, passport and driver's license numbers, as part of "Know Your Customer" checks. The policy doesn't say which users are asked for them.

Payment details. Most apps pass your card to a payment processor and keep only a record. Candy AI's policy is the most detailed about this, naming each processor. If you pay by bank transfer, one of them collects your bank account number.

Your voice and photos. If you use voice features, some apps keep more than you'd expect. Secrets AI deletes the audio but keeps the transcript. Crushi lists voice recordings. Replika uses your phone's face tracking for its AR features but says that data never leaves your device.

"Government-issued identification numbers, such as national identification number (e.g. Social Security Number, tax identification number, passport number)..."
The policy says · Nectar AI
At least one app lists your government ID number as something it may collect.
What this means

What they know from your chats

This is where AI girlfriend apps differ from almost every other app on your phone. You don't fill in a form. You talk. And the policies are uneven about what that means.

Your preferences for her. Candy AI records what you choose for your companion: ethnicity, age, body type, personality, relationship type. Its policy says something most don't: your gender combined with those preferences "may constitute sensitive personal data," and it asks for consent where the law requires it.

Sexual and sensitive details. Sexual content is the whole purpose of some of these apps, yet the policies treat it very differently. 7 of the 19 apps explicitly recognize sensitive categories like your sex life or sexual orientation. 7 don't mention sensitive data at all. The rest fall in between, and that middle ground is where it gets strange.

  • Crushi is the most direct. It says your chats "will often include information about your sexual preferences and orientation" and that you give explicit consent to process it by creating an account.
  • Replika names sex life and sexual orientation, tells you not to share them, and then says that if you keep sharing after seeing that notice, you've consented.
  • DreamGF asks for GDPR consent to process data about your sex life or sexual orientation. In the same passage, it says: "We do not collect or process consciously sensitive personal data."
  • GirlfriendGPT copies the list of sensitive categories from European privacy law, the categories it says it will never ask you for. The list includes race, politics, religion, genetics and health. It leaves out two: sex life and sexual orientation. That's on an app whose own footer describes it as a platform for sexting.
  • Kindroid and Nomi take the simplest approach: they ask you not to share sensitive personal information at all.
"We do not collect or process consciously sensitive personal data, so you should decide by yourself whether and how you provide us with such information."
The policy says · DreamGF
The policy asks for your consent to handle your sexual data, then says it doesn't knowingly handle it. Both sentences are in the same section.
What this means

What they know without you telling them

This is the part users never see, and for me it was the most eye-opening. Several apps don't just store what you say. They draw conclusions from it.

Inferences. Crushi's policy lists "inferences drawn from other personal information (such as preferences and interests in adult content...)." Character.AI generates "inferences about use of the Services, such as your preferences and interests." Nectar AI goes a step further: it classifies "preferences that are generated based on the data you submit" as non-personal information, which its policy says it can share with "partners, advertisers and other third parties at our discretion."

Tracking beyond the app. CrushOn's policy describes the heaviest tracking of the 19: retargeting, Google Analytics for "remarketing and behavioral targeting," and advertising code inside its mobile app that builds a profile of you. In its own words, these advertisers "may be able to identify you across sites, devices, and over time." GirlfriendGPT says it can collect data "if you visit other websites employing our cookies," and treats your IP address and location as non-personal data.

Data from elsewhere. Several apps receive information about you from ad networks and social logins. Character.AI and Crushi both say they collect information from the public internet, including for training their AI.

"These parties may be able to identify you across sites, devices, and over time."
The policy says · CrushOn AI
Advertisers working with the app can recognize you on other websites and other devices.
What this means

Someone may be reading your AI girlfriend chats, and the rules for when vary widely

Most people assume their chats are private. The policies describe a spectrum, from almost never to anytime.

11 of the 19 apps say humans may review chats in some circumstances, usually when content is flagged by automated moderation or reported. 2 limit it to narrow cases. 6 don't say either way.

  • DreamGF has the narrowest rule: it reserves the right to review your chats "only if you have reported a problem related to it in our support center."
  • Kindroid says your chats are encrypted and that it can't view them "in our normal operation of the business." It keeps the right to decrypt them for legal reasons or to enforce its terms.
  • Candy AI allows human review of flagged content, and also during training: preparing datasets "may include human review of de-identified and/or anonymized interactions."
  • SpicyChat has the widest rule. Its terms include a section titled "Electronic Communications Not Private."
"Users or operators of the Service may read all messages You send to the Service regardless of whether they are intended recipients."
The policy says · SpicyChat terms
Staff can read your chats. SpicyChat's terms also say employees are barred from "unauthorized" access, so both things are true at once: access is possible, and it's supposed to be controlled.
What this means

Your messages often leave the app, and most policies won't say where

Many apps don't run their own AI. They send your messages to an outside AI company to generate her replies. 7 of the 19 apps say they use outside AI models. Only 3 name them:

  • Ruby Chat: Google Cloud AI, Anthropic, xAI and OpenAI, which receive your inputs, the replies and personal information.
  • PovChat AI: ChatGPT or Claude as possible models, without explaining what data is sent.
  • Xeve.ai: Together AI, DeepInfra, OpenAI, ElevenLabs and AtlasCloud.

Candy AI, Replika, HeyGF and CrushOn say they use outside models without naming them. CrushOn calls its provider the "operator of the AI basic model."

The bigger question is whether those outside companies can train their own AI on your chats. Only 2 of the 19 policies answer it, and both say no. Replika contractually bars its providers from training on your data. Xeve says its providers process messages only to generate replies. The other 17 are silent.

One fairness note: sending your message to an outside model to get a reply is not the same as that company training on it. The concern is that most policies don't say either way.

What they do with what they know: training their AI

This is the question most people ask me first. The answer depends entirely on which app you pick.

9 of the 19 apps say your chats or chat-derived data can be used to train their AI. 1 acknowledges a training archive without explaining it. 8 don't mention training at all. 1 explicitly says no.

  • Chai says it uses "personal data derived from your in-app conversations" to "fine tune the artificial intelligence models," after removing personal identifiers.
  • CrushOn says it "may use User Content from character chats to train AI models," and that chat content is "not link[ed]... to specific users."
  • Crushi trains its models "to generate adult content," and its terms license your character's replies and dialogues for that purpose.
  • Replika uses "small portions" of messages, immediately anonymized, to train safety systems and improve its chatbot.
  • Candy AI, Secrets AI, HeyGF, OurDream and Character.AI also say chat data can be used for training, most after removing or reducing personal details.
  • Nomi refers to "training archives" that survive account deletion but doesn't describe what's in them.
  • Xeve.ai is the only app that explicitly says it doesn't train on chats.

Can you opt out? Rarely. HeyGF offers an opt-out in account settings. Character.AI offers one only to users in Europe and the UK, and only for new chats. Crushi says you can control "certain aspects" in your settings without saying which.

One more worth knowing: Kindroid never mentions training, but its terms let it de-identify your private chats and "freely use such de-identified and/or aggregated content for any purpose."

"We use personal data derived from your in-app conversations with chatbots to enhance and fine tune the artificial intelligence models on which these chatbots operate."
The policy says · Chai
Your conversations, with your name and identifiers removed, help train the AI.
What this means

"We don't sell your data" means less than it sounds

Almost every policy says some version of "we don't sell your data." What it means depends on the definition of "sell."

Under several US state laws, sharing your data with advertisers can legally count as a "sale," even when no money changes hands. That's why policies can say both things at once.

  • Crushi has the clearest disclosure in the set. It says it doesn't sell data "for monetary consideration," then publishes a table showing what it "sold" in the legal sense over the past year: identifiers, location, device and activity data, the characters you interact with, the content you like, and inferences about your adult-content preferences, all to advertising networks specializing in adult content. Your chats and sensitive data are marked as not sold.
  • Character.AI, Replika and Kindroid acknowledge that some of their disclosures "may be considered" or "may constitute" a sale under state law.
  • CrushOn's no-sale promise covers financial data only.
  • Nectar AI and GirlfriendGPT sidestep the question by classifying some of your data as "non-personal": your inferred preferences for Nectar, your IP address and location for GirlfriendGPT.
  • Nomi, Xeve.ai and AI Angels say plainly that they don't sell your data.
"While these disclosures may be considered sales under certain state laws, we do not sell personal information for monetary consideration."
The policy says · Crushi
They don't get paid per record, but advertisers still receive data about you, including what they've inferred about your tastes.
What this means

How long they remember you

Only 7 of the 19 apps give a concrete retention period for your data. 2 tie it to the life of your account. 10 say they keep it "as long as necessary."

The 7 apps that give a concrete retention periodWhat each policy says about keeping your data.
AppWhat the policy says about keeping your data
ReplikaMessages and content: up to 60 days after you leave
NomiDeleted within about 28 days of account deletion, except training and support archives
KindroidChats kept until you delete that character or your account
Secrets AIUntil you permanently delete your account
Xeve.ai12 months after your last message
ChaiUp to your account's lifetime plus 5 years after deletion
GirlfriendGPTUsually 6 years after you close your account

Deleting your account doesn't always delete everything. Nomi's training archive survives, though it says the data is no longer attributable to you. Crushi, PovChat AI and Kindroid can keep public characters you created active after you leave. Some apps don't even have a delete button: CrushOn, Crushi and Kindroid handle account deletion by email.

"...not exceeding, in any case, the duration of the account and five (5) years following its deletion."
The policy says · Chai
Chai can keep your data for up to five years after you delete your account.
What this means

What they're allowed to do with it

The privacy policy explains how they handle your personal data. The terms of use cover something different: what rights they claim over what you create, which can include your chats. Those licenses are almost always bigger than people expect.

Most of these apps use the same legal formula: a license that's worldwide, royalty-free, perpetual, irrevocable, transferable and sublicensable. In practice that means it lasts forever, can't be taken back, and can be passed on to other companies.

  • SpicyChat names your chats directly: it "has the right to and will use, sell, license the content generated through chats for the proper working of the Service, promotion and this License," while stating it doesn't own them.
  • GirlfriendGPT's license includes the right to "sell," and any version it modifies becomes "the singular and exclusive property of GirlfriendGPT."
  • CrushOn includes the right to "offer to sell, sell" your submissions, which it defines to include "messages."
  • Crushi licenses your character's replies and dialogues, including for AI training, and says ending your account doesn't end those rights.
  • Kindroid, DreamGF and OurDream also hold perpetual, irrevocable licenses, though DreamGF limits its to "the operation of the Website."
"SpicyChat.AI has the right to and will use, sell, license the content generated through chats for the proper working of the Service, promotion and this License."
The policy says · SpicyChat terms
SpicyChat claims the right to use and sell content from your chats for running and promoting its service. It says you still own them.
What this means

Some of these policies weren't finished

Reading 19 policies back to back, I noticed something I didn't expect: a few of them look like templates nobody finished filling in. That doesn't prove anything about how an app handles your data. But a policy is a company's formal promise to you, and it's fair to ask how carefully it was written.

  • SpicyChat's privacy policy was last updated in May 2023, three years before its current terms. It never mentions chats, and it identifies the company as "SpicyChat.AI, Corporate Address," a placeholder left unfilled.
  • Crushi's privacy contact reads "[Your Cyprus Address]." Its real address appears in the site footer. Several passages also match Character.AI's privacy policy almost word for word.
  • GirlfriendGPT's policy asks for your consent before sharing data "with any company outside Usway," a name that appears nowhere else. Its data controller is described only as someone "within our team."
  • CrushOn's documents point to four jurisdictions: a company registered in Cyprus, UK data law cited in the privacy policy, a statement that "we operate in the United States," and Hong Kong law governing the terms.
  • GirlfriendGPT and CrushOn both include a clause letting them bill you for the cost of responding to a subpoena about your account.
  • DreamGF's privacy policy and terms carry no date at all.

All 19 apps at a glance

What each policy says, app by appEach app name links to my living review of it.
AppTrains its AI on chatsOutside AI providersHuman reviewChat retention period
Candy AIYesYes, unnamedYesTied to account
Character.AIYes (opt-out EEA/UK only)Not statedYesNot stated
ChaiYesNot statedYesUp to 5 yrs after deletion
CrushOn AIYesYes, unnamedYesNot stated
Crushi AIYesNot statedYesNot stated
HeyGF.aiYes (opt-out)Yes, unnamedNot statedNot stated
OurDreamYesNot statedYesNot stated
ReplikaYes (small portions)Yes, unnamedNot stated60 days after leaving
Secrets AIYesNot statedYesUntil account deletion
NomiArchive, unexplainedNot statedNot stated~28 days after deletion
AI AngelsNot statedNot statedYesNot stated
DreamGFNot statedNot statedOnly if you report a problemNot stated
GirlfriendGPTNot statedNot statedYes~6 yrs after closing
KindroidNot statedNot statedLegal cases onlyUntil you delete
Nectar AINot statedNot statedNot statedNot stated
PovChat AINot statedYes, namedNot statedNot stated
Ruby ChatNot statedYes, namedYesTied to account
SpicyChatNot statedNot statedYesNot stated
Xeve.aiNoYes, namedNot stated12 months

"Not stated" means the policy doesn't say. It doesn't mean the answer is no.

What I check now before signing up for an AI companion

After reading all of these, I don't think the answer is to avoid AI companions. It's to spend five minutes on the fine print before you tell her anything personal. These are the six things I look for:

  1. Does it train on my chats, and can I opt out? Search the privacy policy for "train." If it's there, look for a setting to turn it off.
  2. Who can read my messages? Search for "review," "moderat" and "access." Flagged-content review is normal. "May read all messages" is not.
  3. Where do my messages go? Search for "third-party," "language model" or "LLM." Named providers are better than vague ones.
  4. How long do they keep it? Search for "retain" or "retention." A number of days or years is better than "as long as necessary."
  5. Can I actually delete my account? Check whether there's a delete button or only an email address, and what survives deletion.
  6. What does the license say? In the terms, search for "perpetual" and "sell." If both appear near "content," it probably covers your chats.
And the rule I follow myself: never use your real name, workplace or anything that could identify you. Whatever the policy says, the safest data is data you never typed.

Frequently asked questions

Do AI girlfriend apps read your messages?

Most can in some situations. 11 of the 19 apps I reviewed say humans may review chats, usually when automated moderation flags something or a user reports it. DreamGF limits review to problems you report yourself, and Kindroid encrypts chats and only decrypts them for legal reasons. SpicyChat's terms go furthest, saying operators "may read all messages You send."

Can an AI girlfriend app use my chats to train its AI?

Yes, for many of them. 9 of the 19 apps say chat data can be used to train their AI, usually after removing personal identifiers. Only Xeve.ai explicitly says it doesn't. Opt-outs are rare: HeyGF offers one, and Character.AI offers one only in Europe and the UK.

Does deleting my account delete my chats?

Not always. Replika deletes messages within 60 days, and Nomi within about 28 days, but Nomi keeps a training archive. Chai can keep data up to five years after deletion, and GirlfriendGPT usually keeps personal information for six years. Some apps can also keep public characters you created active after you leave.

Do AI companion apps sell your data?

Most say they don't sell it for money. But under several US state laws, sharing data with advertisers counts as a sale. Crushi, for example, discloses that it "sold" data including inferred adult-content preferences to adult ad networks in that legal sense, while marking chats as not sold.

Which AI companion apps explain their privacy most clearly?

Xeve.ai, Replika and Candy AI have the most detailed policies I've read, with named providers, specific retention periods or granular purpose tables. Detail isn't the same as safety, though. A clear policy tells you exactly what happens to your data, and some of what it tells you may still be more than you're comfortable with.

Policy log

  • September 25, 2026: Guide published covering 19 apps. Replika's policy updated May 27, 2026 and was read in its current version.

Sources

Each app's current privacy policy and terms of use, read September 2026.

Keep reading