AI Companion Privacy Scorecard 2026: 15 Apps Graded

Policies reviewed on September 19, 2026 - re-graded quarterly

Close-up of a young woman's face crossed by a thin red laser scan line, a visual metaphor for personal data being collected.
What 15 AI companion privacy policies say about your chats, as of September 19, 2026.

Conversations with an AI companion can include relationship details, health worries or sexual preferences. What happens to those chats is set out, or left out, in each company's privacy policy. On September 19, 2026 we read the public privacy documents of 15 AI companion and AI girlfriend apps and graded every one on the same eight criteria, from whether chats are used to train AI models to whether the operator names itself.

Each criterion is scored 0, 1 or 2, for a maximum of 16 points and a grade from A to F. Every score is tied to the company's own documents: a passage we can point to or, where a topic is missing, a search of the documents that found nothing on it. The notes below quote and link the key passages. This is a desk review of what the documents say: we did not test the apps or audit any company's systems, and claims such as encryption are the companies' own statements, not something we verified. Companies that think we misread their documents can ask for a re-review; see Right of reply.

Key findings

  • Highest grades: Candy.ai and Replika (B, 12/16), followed by Kindroid (B, 11/16). No app earned an A.
  • Lowest grades: CrushOn.AI and Sweetdream.ai (D, 7/16). No app got an F; the other 10 apps graded C.
  • AI training is the biggest gap: 14 of 15 apps scored 0. Only Character.AI describes a training-specific opt-out, and no policy says chats are kept out of training or used only with opt-in consent.
  • Sensitive data: 6 of 15 policies scored 0 because they do not address sensitive or special-category data, such as health or sex life, at all. Only 2 (Candy.ai and Replika) scored full marks by saying companion data may be sensitive and stating specific protections for it.
  • Sale and ad sharing: no app earned full marks. 13 scored 1 and 2 scored 0 (Chai and Sweetdream.ai).
  • Age checks: 4 of 15 describe an age check beyond self-declaration. Sweetdream.ai scored 0 because its privacy policy states no minimum age.
  • Chat access: only 3 of 15 (Candy.ai, Replika and Kindroid) explain who can access chat content and limit that access to named purposes.
  • Zero scores by criterion: AI training 14, sensitive data 6, sale and ad sharing 2, minimum age 1. No app scored 0 on the other four criteria.
  • The one universal strength: all 15 identify the company behind the app and its country or address, although three (Kindroid, CrushOn.AI and Sweetdream.ai) name the company only in their terms or the page footer, not in the policy text.

Method: desk review of each app's public privacy documents on September 19, 2026, scored 0-2 on eight criteria (16 points maximum). We grade what the documents say, not audited behavior.

The scorecard: 15 AI companion apps graded

Apps are sorted by total score, ties alphabetically. Select an app name to jump to our notes on it, or download the scorecard (CSV).

Legend:2 meets the criterion in full, 1 meets it in part, 0 does not meet it or does not address it. What each score means for each criterion is spelled out in How we graded.

AI companion privacy scorecard, policies reviewed September 19, 2026
AppOperator (country)GradeScore /161. Operator2. AI training3. Sale & ads4. Deletion & retention5. Chat access6. Sensitive data7. Age checks8. SecurityPrivacy policy (last updated)
Candy.aiEverAI Limited
Malta
B1220122221Candy.ai privacy policy
July 30, 2026
ReplikaLuka, Inc.
United States
B1220122212Replika privacy policy
May 27, 2026
KindroidBeautifully Incorporated
United States (Los Angeles, California)
B1120122112Kindroid privacy policy
June 28 2024 (Privacy Policy effective date)
OurDream.aiDream Studio USA, Inc.
United States
C1020111122OurDream.ai privacy policy
August 26, 2026
Character.AICharacter Technologies, Inc.
United States
C921111111Character.AI privacy policy
July 1, 2026 (effective date)
Kupid.aiSNB Technologies LTD
Cyprus
C920121111Kupid.ai privacy policy
02/05/2023
Nomi.aiGlimpse.ai, Inc.
United States (Maryland corporation)
C920121012Nomi.ai privacy policy
April 27, 2026
TalkieSUBSUP PTE. LTD.
Singapore
C920111112Talkie privacy policy
12/09/2025
ChaiChai Research Corp.
United States (Delaware corporation; registered office Palo Alto, California)
C820021111Chai privacy policy
July 2nd, 2026
EVA AINOVI LIMITED
Cyprus
C820111021EVA AI privacy policy
June 3, 2026
Janitor AIJanitorAI Inc.
United States
C820111012Janitor AI privacy policy
September 17, 2026
JOI.comNOVI LIMITED
Cyprus
C820111021JOI.com privacy policy
4 June, 2026
SecretDesiresPlayhouse Media LLC
United States
C820111111SecretDesires privacy policy
October 24th, 2024
CrushOn.AITECHIEPIE LTD (named in the Terms of Use and the page footer; the policy text itself names no entity)
Cyprus (footer also lists a Dover, Delaware address)
D720111011CrushOn.AI privacy policy
March 6, 2025 (last modified)
Sweetdream.aiTetractys Development Ltd
United Kingdom (London, England)
D720021002Sweetdream.ai privacy policy
January 15, 2024
Apps scoring 2150073247
Apps scoring 101138127108
Apps scoring 0014200610

Grade distribution: A 0, B 3, C 10, D 2, F 0. Policy dates are shown the way each document states them. On a phone, scroll the table sideways.

How we graded

Each criterion is scored 0-2 from what the app's own documents say: the privacy policy first, and terms of service, cookie, AI or safety policies or help-center pages only where the privacy policy refers to them. We grade disclosure and stated practice, not audited behavior.

The eight criteria and the 0/1/2 rubric

  1. Operator identity operator
    • 2 names the legal entity AND its country or registered address
    • 1 names an entity without location (or location without entity)
    • 0 no identifiable operator
  2. AI training training
    • 2 says chat content is NOT used to train/improve AI models, or only with opt-in consent
    • 1 chats are used for training/model improvement but an opt-out is described
    • 0 used without a described opt-out, or not addressed at all
  3. Sale and ad sharing sale_ads
    • 2 says personal data is not sold AND not shared for targeted / cross-context behavioural advertising
    • 1 says no sale but shares with advertising/analytics partners, or offers an opt-out of sale/sharing
    • 0 sells or shares personal data for advertising without a described opt-out, or not addressed
  4. Deletion and retention deletion_retention
    • 2 users can delete their account AND chat history (self-serve or on request) AND a concrete retention period or rule is given
    • 1 deletion possible but no concrete retention rule (or a retention rule but no deletion route)
    • 0 no deletion route described
  5. Chat access chat_access
    • 2 explains who can access chat content (staff, contractors, vendors / AI model providers) and limits it to named purposes (e.g. safety, legal, support)
    • 1 says chats may be reviewed or processed by staff/vendors without clear limits
    • 0 not addressed
  6. Sensitive data sensitive_data
    • 2 acknowledges chats may contain sensitive data (e.g. sexual life, health) AND states specific limits or protections for it (e.g. explicit consent, not used for ads)
    • 1 mentions sensitive / special-category data only generally
    • 0 not addressed
  7. Minimum age and age checks minors_age
    • 2 a minimum age is stated AND an age-assurance measure beyond self-declaration is described (verification, estimation)
    • 1 minimum age stated (self-declaration only)
    • 0 no minimum age stated
  8. Security measures security
    • 2 names specific measures (e.g. encryption in transit AND at rest, access controls)
    • 1 only generic "reasonable / industry-standard" measures
    • 0 not addressed

Grade bands

The eight scores add up to a total of 0-16 points, which converts to a grade:

  • A 14-16 points
  • B 11-13 points
  • C 8-10 points
  • D 5-7 points
  • F 0-4 points

Limitations

  • Documents, not behavior. We grade what each policy says. A policy that describes a good practice earns the points for describing it; whether the company follows it in practice is beyond what a document review can show.
  • Claims are not verified. Statements about encryption, de-identification, access controls or age verification are the companies' own. We did not test them.
  • Which documents count. The privacy policy comes first. Terms of service, cookie notices and other pages count only where the privacy policy refers to them. SecretDesires' Trust Hub page and Sweetdream.ai's Terms of Service are not counted for that reason; the notes on each app say what those pages state.
  • General legal rights are not a training opt-out. Where a policy only lists the general GDPR right to object, we did not count it as a described opt-out from AI training.
  • Policies change. This is a dated snapshot. Several of the policies we graded carry older dates: Kupid.ai (02/05/2023), Sweetdream.ai (January 15, 2024), Kindroid (June 28, 2024), SecretDesires (October 24th, 2024) and CrushOn.AI (March 6, 2025).
  • Access. The Janitor AI and CrushOn.AI policy pages returned HTTP 403 errors to our automated requests. We read their live text through a text-rendering service on September 19, 2026.

Findings by criterion

1. Operator identity: all 15 scored 2

Every app names the legal entity behind it and its country or address, the only criterion on which all 15 earned full marks. Replika's policy, for example, names “Luka, Inc., with its registered office at 490 Post Street, Suite 526, San Francisco, CA 94102, United States”. In three cases the company name sits outside the policy text itself: Kindroid and CrushOn.AI name their companies in their Terms of Use, and Sweetdream.ai's operator appears in the footer of its privacy policy page. Janitor AI names its company and says it is based in the United States but gives no street address. EVA AI and JOI.com name the same data controller, NOVI LIMITED.

2. AI training: 14 of 15 scored 0

This is the weakest criterion in the scorecard. No app scored 2: none of the policies says chats are excluded from model training or used only with opt-in consent. Character.AI is the only app that scored 1. Its Regional Privacy Disclosures state: “With specific regard to the processing of your personal data for the purpose of training and improving our AI models, you have the right to opt out at any time.

Most of the other 14 policies say chats or collected data are used to train, fine-tune or improve AI models, and none describes a training-specific opt-out. CrushOn.AI's policy says “We may use User Content from character chats to train AI models.” Candy.ai, Replika, Chai and Sweetdream.ai say the data is de-identified, anonymized or stripped of personal identifiers first; the rubric does not award points for that. Kindroid's and Kupid.ai's policies do not say whether chats are used for training at all, and Talkie's says messages let the chatbot learn from your interactions without saying whether they train the underlying models. The rubric scores "not addressed" as 0. SecretDesires' separate Trust Hub page says conversations are never used to train AI models, but its privacy policy, which does not refer to that page, lists model training as a use.

3. Sale and ad sharing: no app scored 2

Thirteen apps scored 1 and two scored 0. The typical pattern is a statement that personal data is not sold, next to disclosures about advertising or analytics partners, tracking cookies or an opt-out. Kindroid, for instance, says “We will not sell or share your Personal Data, and have not done so over the last 12 months.” It also lists analytics partners and says some disclosures may count as a sale under state law, which keeps it at 1. Replika and Talkie say that some disclosures to advertising partners may count as a sale or sharing of personal information, Character.AI's US notice lists sales of some data categories to advertising providers, and all three describe an opt-out.

Chai and Sweetdream.ai scored 0. Chai's policy says ads are shown to free users based on consent, and that usage patterns may be shared with advertising partners “to evaluate the performance of their campaigns and ensure accurate attribution”. It does not say whether personal data is sold and describes no opt-out from this sharing beyond the general EU/UK right to object. Sweetdream.ai's policy does not address sale or ad sharing at all. Some policies draw a line around chat content: Replika says conversations are never shared with advertising partners, and Character.AI and Talkie list chat or message content as not sold.

4. Deletion and retention: 7 scored 2, 8 scored 1

Every policy describes some route to delete or close an account, so no app scored 0. What separates a 2 from a 1 is a concrete retention rule, and the rules vary widely:

  • Replika: profile information, messages and content are processed for up to 60 days after the contract ends; account, financial and automatically collected data are kept for at least 10 years.
  • Nomi.ai: deleting the account deletes personal information within about 28 days, except material in training or communications archives, which the policy says is no longer attributable to the user after deletion, and data needed for legal proceedings.
  • Kindroid: chats and generated media are kept until the user deletes the specific AI or the account.
  • Sweetdream.ai: users can delete individual conversations or their entire chat history, and inactive accounts are deleted after 2 years.
  • Candy.ai: account data is kept for three years after the last account activity unless deletion is requested; financial data for ten years, marketing data for two years and log files for 30 days.
  • Chai: data is kept “not exceeding, in any case, the duration of the account and five (5) years following its deletion”.
  • Kupid.ai: personal information is usually stored for six years after the account is closed.

The other eight describe deletion or account closure but give no concrete retention period. OurDream.ai and SecretDesires add that popular public Characters may be kept after account deletion, Character.AI says public Characters may stay active, and Janitor AI says some records may remain in its deleted-account records.

5. Chat access: 3 scored 2, 12 scored 1

Only Candy.ai, Replika and Kindroid explain who can access chat content and limit that access to named purposes. Candy.ai says third-party LLM providers and hosters “may receive the content of your messages exchanged with our chatbot”, and names the situations in which people access content: moderating flagged content, random quality checks, reviewing de-identified interactions for training datasets and support investigations. Replika says de-identified conversation data goes to third-party AI model providers only to generate replies and that those providers are contractually barred from using it for their own training. Kindroid says chats are encrypted so the company cannot view them in normal operation, while reserving the right to decrypt and disclose them for legal requirements and to enforce its terms.

The other 12 describe sharing with staff, vendors or affiliates in general terms. OurDream.ai and SecretDesires use the same sentence: information may go to “employees, consultants, and other vendors who need access to such information to carry out work or perform services on our behalf” (same wording at SecretDesires). CrushOn.AI's policy lists the operator of the AI basic model among its sub-processors but does not limit their access to chat content to named purposes.

6. Sensitive data: 2 scored 2, 7 scored 1, 6 scored 0

Companion chats can easily include health, sexuality or relationship details. Replika addresses this most directly: “We understand that the nature of conversations with an AI companion may lead you to incidentally share such information.” It adds that sensitive information and conversation content will not be used for marketing or advertising, with explicit-consent wording for the EEA, UK, Brazil and certain US states. Candy.ai also scored 2: its policy says companion preferences may be sensitive personal data and that it will ask for consent where applicable, although that passage covers companion preferences rather than message text.

Seven policies scored 1. Six of them mention sensitive data without stating specific protections for it; Talkie states some limits, but only in region-specific sections, and does not acknowledge that chats may contain sensitive data. Kindroid, for instance, asks users to “please refrain from providing any sensitive personal information, whether to your AI Companion or otherwise through the Services”. OurDream.ai and SecretDesires acknowledge that chats may reveal sensitive information such as sexual orientation, but their only limit is a reference to California law (CCPA), which we scored 1. The policies of Nomi.ai, EVA AI, Janitor AI, JOI.com, CrushOn.AI and Sweetdream.ai do not address sensitive or special-category data at all.

7. Minimum age and age checks: 4 scored 2, 10 scored 1, 1 scored 0

Four apps describe an age check beyond self-declaration. Candy.ai and OurDream.ai refer to third-party age estimation or verification depending on location or where the law requires it, JOI.com says it uses external service providers to conduct age checks, and EVA AI's Terms describe an AI system that can block accounts it believes belong to under-18s until proof of age is provided.

Ten state a minimum age but describe no check beyond self-declaration. A typical statement is Replika's: “If we discover that minors under the age of 18 are using the Apps, we will promptly block their access and delete their account.” Replika, Talkie and Character.AI name age verification as a purpose but describe no method, Kindroid's Terms reserve the right to request proof of age, and Nomi.ai's Terms say it intends to add age verification. None of these is a described measure in use, so all score 1. Minimum ages differ: most apps set 18, but Talkie sets 14 (or higher where local law requires it), Character.AI sets 13 (16 in the EEA and UK), and Kindroid's Privacy Policy says 16 while its Terms of Use on the same page say 18. Sweetdream.ai scored 0 because its privacy policy states no minimum age. Its separate Terms of Service require users to be 18, but the policy does not refer to them; if they counted, the score would be 1.

8. Security measures: 7 scored 2, 8 scored 1

Seven policies name specific measures. Kindroid, OurDream.ai and Sweetdream.ai state that chats or data are encrypted at rest and in transit. Replika and Talkie say transmitted data is encrypted and name firewalls and role-based access controls, but do not say stored data is encrypted. Janitor AI lists encryption, access controls and regular security assessments, and Nomi.ai names network-traffic monitoring, staff training and need-to-know access without mentioning encryption.

The other eight describe their security measures only in general terms; the one specific item in Candy.ai's policy is that passwords are stored encrypted. Candy.ai and Kupid.ai use the identical sentence “We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorized way…” Character.AI's Privacy Policy has no section on security measures; the only statement is a parenthetical in its Regional Privacy Disclosures: “(adopting required technical and organisational measures)”. None of the security claims in this scorecard were independently verified.

App-by-app notes

Each entry lists the operator as its documents name it, the date the policy shows, the grade and the points that shaped it. Quotes link to the document they come from; the criterion in brackets is the score it affected.

Candy.ai

B12/16· Operator: EverAI Limited, Malta · Policy date: July 30, 2026 ·Privacy policy·Scorecard row

Our full review: Candy.ai review

Replika

B12/16· Operator: Luka, Inc., United States · Policy date: May 27, 2026 ·Privacy policy·Scorecard row

Our full review: Replika review

Kindroid

B11/16· Operator: Beautifully Incorporated, United States (Los Angeles, California) · Policy date: June 28 2024 (Privacy Policy effective date) ·Privacy policy·Scorecard row

OurDream.ai

C10/16· Operator: Dream Studio USA, Inc., United States · Policy date: August 26, 2026 ·Privacy policy·Scorecard row

Our full review: OurDream.ai review

Character.AI

C9/16· Operator: Character Technologies, Inc., United States · Policy date: July 1, 2026 (effective date) ·Privacy policy·Scorecard row

Our full review: Character.AI review

Kupid.ai

C9/16· Operator: SNB Technologies LTD, Cyprus · Policy date: 02/05/2023 ·Privacy policy·Scorecard row

Our full review: Kupid.ai review

Nomi.ai

C9/16· Operator: Glimpse.ai, Inc., United States (Maryland corporation) · Policy date: April 27, 2026 ·Privacy policy·Scorecard row

Our full review: Nomi.ai review

Talkie

C9/16· Operator: SUBSUP PTE. LTD., Singapore · Policy date: 12/09/2025 ·Privacy policy·Scorecard row

Chai

C8/16· Operator: Chai Research Corp., United States (Delaware corporation; registered office Palo Alto, California) · Policy date: July 2nd, 2026 ·Privacy policy·Scorecard row

EVA AI

C8/16· Operator: NOVI LIMITED, Cyprus · Policy date: June 3, 2026 ·Privacy policy·Scorecard row

Janitor AI

C8/16· Operator: JanitorAI Inc., United States · Policy date: September 17, 2026 ·Privacy policy·Scorecard row

JOI.com

C8/16· Operator: NOVI LIMITED, Cyprus · Policy date: 4 June, 2026 ·Privacy policy·Scorecard row

Our full review: Joi.com review

SecretDesires

C8/16· Operator: Playhouse Media LLC, United States · Policy date: October 24th, 2024 ·Privacy policy·Scorecard row

  • The privacy policy lists training as a use of collected information, including chat communications: “to train our artificial intelligence/machine learning models” (AI training: 0). A separate Trust Hub page (March 9, 2026) says conversations are never used to train AI models, but the privacy policy does not refer to it, so under our rubric the policy text is what we grade.
  • The policy says chats may reveal sensitive information such as sexual orientation, and its only limit is in its California section: “we do not use or disclose sensitive personal information other than for purposes for which you cannot opt out under the CCPA” (sensitive data: 1, lowered from 2 in our re-grading pass).
  • The policy says accounts can be deactivated, some information deleted on the profile page, and deletion requested, but gives no concrete retention period, and popular public Characters may be kept “even if you otherwise delete your data and your account” (deletion and retention: 1). Large parts of the wording match the OurDream.ai privacy policy.
  • The Terms of Service name Playhouse Media Trading Ltd. as the contracting party for EU residents; the privacy policy names only Playhouse Media LLC. The policy describes only generic technical, administrative and physical safeguards (security: 1).

Our full review: SecretDesires review

CrushOn.AI

D7/16· Operator: TECHIEPIE LTD (named in the Terms of Use and the page footer; the policy text itself names no entity), Cyprus (footer also lists a Dover, Delaware address) · Policy date: March 6, 2025 (last modified) ·Privacy policy·Scorecard row

Sweetdream.ai

D7/16· Operator: Tetractys Development Ltd, United Kingdom (London, England) · Policy date: January 15, 2024 ·Privacy policy·Scorecard row

Our full review: Sweetdream.ai review

What you can do

The grades point to a few practical habits. Our guides go into each one in detail.

  1. Assume your chats may be used to improve the AI. 14 of 15 policies either describe no training-specific opt-out or do not address training at all. Leave out details you would not want stored or reviewed; our guide on limiting what an AI knows about you shows how.
  2. Keep health and sexual details general. 6 of 15 policies do not address sensitive data at all, and only 2 (Candy.ai and Replika) scored full marks on it. Our AI companion privacy guide covers what to keep out of your chats.
  3. Use the opt-outs that exist. Where a policy offers an opt-out from ad sharing, through a Your Privacy Choices link, cookie settings or a request, use it. On Character.AI, the model-training opt-out is described in its Regional Privacy Disclosures. Our guide to GDPR and CCPA rights explains the rights behind these options.
  4. Check the deletion route and retention period before you start. Only 7 of 15 policies give a concrete retention rule, and some say they keep certain data for years after an account is closed or deleted. See how encryption and data deletion work in AI girlfriend apps.
  5. Treat encryption claims as claims. Seven policies name specific security measures, but none of them has been independently verified here. Our explainer on what end-to-end encryption claims really mean helps you read them.

Methodology and right of reply

This scorecard is a desk review of public documents. On September 19, 2026 we read each app's privacy policy and, where the policy refers to them, its terms of service, cookie notice or other policies. The grades draw only on those documents; no product testing, traffic analysis or system audit went into them.

Grading ran in two passes. In the first, each criterion was scored against the rubric and tied to a quote or, where a topic is not addressed, to a search of the documents. In the second, an adversarial re-grading pass checked every score and quote against the documents and tried to overturn it. That pass changed four scores, all downward, so that apps with the same level of detail are scored the same way: Character.AI's age score (2 to 1, because no verification method is described), Chai's chat-access score (2 to 1, because its access clause names no purposes), and the sensitive-data scores of OurDream.ai and SecretDesires (2 to 1, because their only limit is a California-only reference to the CCPA). The last change moved OurDream.ai from a B to a C. The pass also corrected the wording of one finding, Kindroid's age check, without changing its score. Where a call was close, the notes above say so.

Apps we could not grade

None in this edition. Every app we set out to review had a public privacy policy we could read on September 19, 2026, so all 15 were graded.

Right of reply and updates

We re-grade every app quarterly. If you represent one of these companies and believe a grade misreads your documents, or your policy has changed, contact us through our About page with the passage you want us to look at, and we will re-review it. If a re-review changes a score, we will update this page and its CSV and note the change. This scorecard describes what companies' documents say. It is not legal advice and not an assessment of whether any company complies with the law.

How to cite this page

Suggested citation:

AI Girlfriend World (2026). AI Companion Privacy Scorecard 2026: 15 Apps Graded. https://aigirlfriendworld.com/ai-companion-privacy-scorecard

HTML link:

<a href="https://aigirlfriendworld.com/ai-companion-privacy-scorecard">AI Companion Privacy Scorecard 2026</a> (AI Girlfriend World)

License: the scorecard data is licensed under CC BY 4.0. You are free to reuse it with a link back to this page. Quoted policy text belongs to the respective companies.

Download the scorecard (CSV): one row per app with operator, country, grade, total score, the eight criterion scores (columns score_operator to score_security, in rubric order), privacy policy URL, policy date and review date.

More research from AI Girlfriend World

AI companion privacy: frequently asked questions

Which AI companion app is best for privacy?

Judged on their documents alone, Candy.ai and Replika scored highest in our scorecard (B, 12 of 16 points), followed by Kindroid (B, 11). No app earned an A. The top three are strong on different points: Replika says sensitive information and conversation content will not be used for marketing or advertising, Kindroid says chats are encrypted so the company cannot view them in normal operation, and Candy.ai names the situations in which people access chat content and describes third-party age checks depending on location. All three scored 0 on AI training. Grades reflect what the policies say, not audited behavior.

Do AI girlfriend apps sell your data?

Is Replika safe for privacy?

Is Character.AI safe for privacy?

Do AI companion apps use your chats to train AI?

Which AI companion apps verify users' age?

Are AI girlfriend chats encrypted?