AI Companion Privacy Scorecard 2026: 15 Apps Graded
Policies reviewed on September 19, 2026 - re-graded quarterly

Conversations with an AI companion can include relationship details, health worries or sexual preferences. What happens to those chats is set out, or left out, in each company's privacy policy. On September 19, 2026 we read the public privacy documents of 15 AI companion and AI girlfriend apps and graded every one on the same eight criteria, from whether chats are used to train AI models to whether the operator names itself.
Each criterion is scored 0, 1 or 2, for a maximum of 16 points and a grade from A to F. Every score is tied to the company's own documents: a passage we can point to or, where a topic is missing, a search of the documents that found nothing on it. The notes below quote and link the key passages. This is a desk review of what the documents say: we did not test the apps or audit any company's systems, and claims such as encryption are the companies' own statements, not something we verified. Companies that think we misread their documents can ask for a re-review; see Right of reply.
Key findings
- Highest grades: Candy.ai and Replika (B, 12/16), followed by Kindroid (B, 11/16). No app earned an A.
- Lowest grades: CrushOn.AI and Sweetdream.ai (D, 7/16). No app got an F; the other 10 apps graded C.
- AI training is the biggest gap: 14 of 15 apps scored 0. Only Character.AI describes a training-specific opt-out, and no policy says chats are kept out of training or used only with opt-in consent.
- Sensitive data: 6 of 15 policies scored 0 because they do not address sensitive or special-category data, such as health or sex life, at all. Only 2 (Candy.ai and Replika) scored full marks by saying companion data may be sensitive and stating specific protections for it.
- Sale and ad sharing: no app earned full marks. 13 scored 1 and 2 scored 0 (Chai and Sweetdream.ai).
- Age checks: 4 of 15 describe an age check beyond self-declaration. Sweetdream.ai scored 0 because its privacy policy states no minimum age.
- Chat access: only 3 of 15 (Candy.ai, Replika and Kindroid) explain who can access chat content and limit that access to named purposes.
- Zero scores by criterion: AI training 14, sensitive data 6, sale and ad sharing 2, minimum age 1. No app scored 0 on the other four criteria.
- The one universal strength: all 15 identify the company behind the app and its country or address, although three (Kindroid, CrushOn.AI and Sweetdream.ai) name the company only in their terms or the page footer, not in the policy text.
Method: desk review of each app's public privacy documents on September 19, 2026, scored 0-2 on eight criteria (16 points maximum). We grade what the documents say, not audited behavior.
The scorecard: 15 AI companion apps graded
Apps are sorted by total score, ties alphabetically. Select an app name to jump to our notes on it, or download the scorecard (CSV).
Legend:2 meets the criterion in full, 1 meets it in part, 0 does not meet it or does not address it. What each score means for each criterion is spelled out in How we graded.
| App | Operator (country) | Grade | Score /16 | 1. Operator | 2. AI training | 3. Sale & ads | 4. Deletion & retention | 5. Chat access | 6. Sensitive data | 7. Age checks | 8. Security | Privacy policy (last updated) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Candy.ai | EverAI Limited Malta | B | 12 | 2 | 0 | 1 | 2 | 2 | 2 | 2 | 1 | Candy.ai privacy policy July 30, 2026 |
| Replika | Luka, Inc. United States | B | 12 | 2 | 0 | 1 | 2 | 2 | 2 | 1 | 2 | Replika privacy policy May 27, 2026 |
| Kindroid | Beautifully Incorporated United States (Los Angeles, California) | B | 11 | 2 | 0 | 1 | 2 | 2 | 1 | 1 | 2 | Kindroid privacy policy June 28 2024 (Privacy Policy effective date) |
| OurDream.ai | Dream Studio USA, Inc. United States | C | 10 | 2 | 0 | 1 | 1 | 1 | 1 | 2 | 2 | OurDream.ai privacy policy August 26, 2026 |
| Character.AI | Character Technologies, Inc. United States | C | 9 | 2 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | Character.AI privacy policy July 1, 2026 (effective date) |
| Kupid.ai | SNB Technologies LTD Cyprus | C | 9 | 2 | 0 | 1 | 2 | 1 | 1 | 1 | 1 | Kupid.ai privacy policy 02/05/2023 |
| Nomi.ai | Glimpse.ai, Inc. United States (Maryland corporation) | C | 9 | 2 | 0 | 1 | 2 | 1 | 0 | 1 | 2 | Nomi.ai privacy policy April 27, 2026 |
| Talkie | SUBSUP PTE. LTD. Singapore | C | 9 | 2 | 0 | 1 | 1 | 1 | 1 | 1 | 2 | Talkie privacy policy 12/09/2025 |
| Chai | Chai Research Corp. United States (Delaware corporation; registered office Palo Alto, California) | C | 8 | 2 | 0 | 0 | 2 | 1 | 1 | 1 | 1 | Chai privacy policy July 2nd, 2026 |
| EVA AI | NOVI LIMITED Cyprus | C | 8 | 2 | 0 | 1 | 1 | 1 | 0 | 2 | 1 | EVA AI privacy policy June 3, 2026 |
| Janitor AI | JanitorAI Inc. United States | C | 8 | 2 | 0 | 1 | 1 | 1 | 0 | 1 | 2 | Janitor AI privacy policy September 17, 2026 |
| JOI.com | NOVI LIMITED Cyprus | C | 8 | 2 | 0 | 1 | 1 | 1 | 0 | 2 | 1 | JOI.com privacy policy 4 June, 2026 |
| SecretDesires | Playhouse Media LLC United States | C | 8 | 2 | 0 | 1 | 1 | 1 | 1 | 1 | 1 | SecretDesires privacy policy October 24th, 2024 |
| CrushOn.AI | TECHIEPIE LTD (named in the Terms of Use and the page footer; the policy text itself names no entity) Cyprus (footer also lists a Dover, Delaware address) | D | 7 | 2 | 0 | 1 | 1 | 1 | 0 | 1 | 1 | CrushOn.AI privacy policy March 6, 2025 (last modified) |
| Sweetdream.ai | Tetractys Development Ltd United Kingdom (London, England) | D | 7 | 2 | 0 | 0 | 2 | 1 | 0 | 0 | 2 | Sweetdream.ai privacy policy January 15, 2024 |
| Apps scoring 2 | 15 | 0 | 0 | 7 | 3 | 2 | 4 | 7 | ||||
| Apps scoring 1 | 0 | 1 | 13 | 8 | 12 | 7 | 10 | 8 | ||||
| Apps scoring 0 | 0 | 14 | 2 | 0 | 0 | 6 | 1 | 0 | ||||
Grade distribution: A 0, B 3, C 10, D 2, F 0. Policy dates are shown the way each document states them. On a phone, scroll the table sideways.
How we graded
Each criterion is scored 0-2 from what the app's own documents say: the privacy policy first, and terms of service, cookie, AI or safety policies or help-center pages only where the privacy policy refers to them. We grade disclosure and stated practice, not audited behavior.
The eight criteria and the 0/1/2 rubric
- Operator identity
operator- 2 names the legal entity AND its country or registered address
- 1 names an entity without location (or location without entity)
- 0 no identifiable operator
- AI training
training- 2 says chat content is NOT used to train/improve AI models, or only with opt-in consent
- 1 chats are used for training/model improvement but an opt-out is described
- 0 used without a described opt-out, or not addressed at all
- Sale and ad sharing
sale_ads- 2 says personal data is not sold AND not shared for targeted / cross-context behavioural advertising
- 1 says no sale but shares with advertising/analytics partners, or offers an opt-out of sale/sharing
- 0 sells or shares personal data for advertising without a described opt-out, or not addressed
- Deletion and retention
deletion_retention- 2 users can delete their account AND chat history (self-serve or on request) AND a concrete retention period or rule is given
- 1 deletion possible but no concrete retention rule (or a retention rule but no deletion route)
- 0 no deletion route described
- Chat access
chat_access- 2 explains who can access chat content (staff, contractors, vendors / AI model providers) and limits it to named purposes (e.g. safety, legal, support)
- 1 says chats may be reviewed or processed by staff/vendors without clear limits
- 0 not addressed
- Sensitive data
sensitive_data- 2 acknowledges chats may contain sensitive data (e.g. sexual life, health) AND states specific limits or protections for it (e.g. explicit consent, not used for ads)
- 1 mentions sensitive / special-category data only generally
- 0 not addressed
- Minimum age and age checks
minors_age- 2 a minimum age is stated AND an age-assurance measure beyond self-declaration is described (verification, estimation)
- 1 minimum age stated (self-declaration only)
- 0 no minimum age stated
- Security measures
security- 2 names specific measures (e.g. encryption in transit AND at rest, access controls)
- 1 only generic "reasonable / industry-standard" measures
- 0 not addressed
Grade bands
The eight scores add up to a total of 0-16 points, which converts to a grade:
- A 14-16 points
- B 11-13 points
- C 8-10 points
- D 5-7 points
- F 0-4 points
Limitations
- Documents, not behavior. We grade what each policy says. A policy that describes a good practice earns the points for describing it; whether the company follows it in practice is beyond what a document review can show.
- Claims are not verified. Statements about encryption, de-identification, access controls or age verification are the companies' own. We did not test them.
- Which documents count. The privacy policy comes first. Terms of service, cookie notices and other pages count only where the privacy policy refers to them. SecretDesires' Trust Hub page and Sweetdream.ai's Terms of Service are not counted for that reason; the notes on each app say what those pages state.
- General legal rights are not a training opt-out. Where a policy only lists the general GDPR right to object, we did not count it as a described opt-out from AI training.
- Policies change. This is a dated snapshot. Several of the policies we graded carry older dates: Kupid.ai (02/05/2023), Sweetdream.ai (January 15, 2024), Kindroid (June 28, 2024), SecretDesires (October 24th, 2024) and CrushOn.AI (March 6, 2025).
- Access. The Janitor AI and CrushOn.AI policy pages returned HTTP 403 errors to our automated requests. We read their live text through a text-rendering service on September 19, 2026.
Findings by criterion
1. Operator identity: all 15 scored 2
Every app names the legal entity behind it and its country or address, the only criterion on which all 15 earned full marks. Replika's policy, for example, names “Luka, Inc., with its registered office at 490 Post Street, Suite 526, San Francisco, CA 94102, United States”. In three cases the company name sits outside the policy text itself: Kindroid and CrushOn.AI name their companies in their Terms of Use, and Sweetdream.ai's operator appears in the footer of its privacy policy page. Janitor AI names its company and says it is based in the United States but gives no street address. EVA AI and JOI.com name the same data controller, NOVI LIMITED.
2. AI training: 14 of 15 scored 0
This is the weakest criterion in the scorecard. No app scored 2: none of the policies says chats are excluded from model training or used only with opt-in consent. Character.AI is the only app that scored 1. Its Regional Privacy Disclosures state: “With specific regard to the processing of your personal data for the purpose of training and improving our AI models, you have the right to opt out at any time.”
Most of the other 14 policies say chats or collected data are used to train, fine-tune or improve AI models, and none describes a training-specific opt-out. CrushOn.AI's policy says “We may use User Content from character chats to train AI models.” Candy.ai, Replika, Chai and Sweetdream.ai say the data is de-identified, anonymized or stripped of personal identifiers first; the rubric does not award points for that. Kindroid's and Kupid.ai's policies do not say whether chats are used for training at all, and Talkie's says messages let the chatbot learn from your interactions without saying whether they train the underlying models. The rubric scores "not addressed" as 0. SecretDesires' separate Trust Hub page says conversations are never used to train AI models, but its privacy policy, which does not refer to that page, lists model training as a use.
3. Sale and ad sharing: no app scored 2
Thirteen apps scored 1 and two scored 0. The typical pattern is a statement that personal data is not sold, next to disclosures about advertising or analytics partners, tracking cookies or an opt-out. Kindroid, for instance, says “We will not sell or share your Personal Data, and have not done so over the last 12 months.” It also lists analytics partners and says some disclosures may count as a sale under state law, which keeps it at 1. Replika and Talkie say that some disclosures to advertising partners may count as a sale or sharing of personal information, Character.AI's US notice lists sales of some data categories to advertising providers, and all three describe an opt-out.
Chai and Sweetdream.ai scored 0. Chai's policy says ads are shown to free users based on consent, and that usage patterns may be shared with advertising partners “to evaluate the performance of their campaigns and ensure accurate attribution”. It does not say whether personal data is sold and describes no opt-out from this sharing beyond the general EU/UK right to object. Sweetdream.ai's policy does not address sale or ad sharing at all. Some policies draw a line around chat content: Replika says conversations are never shared with advertising partners, and Character.AI and Talkie list chat or message content as not sold.
4. Deletion and retention: 7 scored 2, 8 scored 1
Every policy describes some route to delete or close an account, so no app scored 0. What separates a 2 from a 1 is a concrete retention rule, and the rules vary widely:
- Replika: profile information, messages and content are processed for up to 60 days after the contract ends; account, financial and automatically collected data are kept for at least 10 years.
- Nomi.ai: deleting the account deletes personal information within about 28 days, except material in training or communications archives, which the policy says is no longer attributable to the user after deletion, and data needed for legal proceedings.
- Kindroid: chats and generated media are kept until the user deletes the specific AI or the account.
- Sweetdream.ai: users can delete individual conversations or their entire chat history, and inactive accounts are deleted after 2 years.
- Candy.ai: account data is kept for three years after the last account activity unless deletion is requested; financial data for ten years, marketing data for two years and log files for 30 days.
- Chai: data is kept “not exceeding, in any case, the duration of the account and five (5) years following its deletion”.
- Kupid.ai: personal information is usually stored for six years after the account is closed.
The other eight describe deletion or account closure but give no concrete retention period. OurDream.ai and SecretDesires add that popular public Characters may be kept after account deletion, Character.AI says public Characters may stay active, and Janitor AI says some records may remain in its deleted-account records.
5. Chat access: 3 scored 2, 12 scored 1
Only Candy.ai, Replika and Kindroid explain who can access chat content and limit that access to named purposes. Candy.ai says third-party LLM providers and hosters “may receive the content of your messages exchanged with our chatbot”, and names the situations in which people access content: moderating flagged content, random quality checks, reviewing de-identified interactions for training datasets and support investigations. Replika says de-identified conversation data goes to third-party AI model providers only to generate replies and that those providers are contractually barred from using it for their own training. Kindroid says chats are encrypted so the company cannot view them in normal operation, while reserving the right to decrypt and disclose them for legal requirements and to enforce its terms.
The other 12 describe sharing with staff, vendors or affiliates in general terms. OurDream.ai and SecretDesires use the same sentence: information may go to “employees, consultants, and other vendors who need access to such information to carry out work or perform services on our behalf” (same wording at SecretDesires). CrushOn.AI's policy lists the operator of the AI basic model among its sub-processors but does not limit their access to chat content to named purposes.
6. Sensitive data: 2 scored 2, 7 scored 1, 6 scored 0
Companion chats can easily include health, sexuality or relationship details. Replika addresses this most directly: “We understand that the nature of conversations with an AI companion may lead you to incidentally share such information.” It adds that sensitive information and conversation content will not be used for marketing or advertising, with explicit-consent wording for the EEA, UK, Brazil and certain US states. Candy.ai also scored 2: its policy says companion preferences may be sensitive personal data and that it will ask for consent where applicable, although that passage covers companion preferences rather than message text.
Seven policies scored 1. Six of them mention sensitive data without stating specific protections for it; Talkie states some limits, but only in region-specific sections, and does not acknowledge that chats may contain sensitive data. Kindroid, for instance, asks users to “please refrain from providing any sensitive personal information, whether to your AI Companion or otherwise through the Services”. OurDream.ai and SecretDesires acknowledge that chats may reveal sensitive information such as sexual orientation, but their only limit is a reference to California law (CCPA), which we scored 1. The policies of Nomi.ai, EVA AI, Janitor AI, JOI.com, CrushOn.AI and Sweetdream.ai do not address sensitive or special-category data at all.
7. Minimum age and age checks: 4 scored 2, 10 scored 1, 1 scored 0
Four apps describe an age check beyond self-declaration. Candy.ai and OurDream.ai refer to third-party age estimation or verification depending on location or where the law requires it, JOI.com says it uses external service providers to conduct age checks, and EVA AI's Terms describe an AI system that can block accounts it believes belong to under-18s until proof of age is provided.
Ten state a minimum age but describe no check beyond self-declaration. A typical statement is Replika's: “If we discover that minors under the age of 18 are using the Apps, we will promptly block their access and delete their account.” Replika, Talkie and Character.AI name age verification as a purpose but describe no method, Kindroid's Terms reserve the right to request proof of age, and Nomi.ai's Terms say it intends to add age verification. None of these is a described measure in use, so all score 1. Minimum ages differ: most apps set 18, but Talkie sets 14 (or higher where local law requires it), Character.AI sets 13 (16 in the EEA and UK), and Kindroid's Privacy Policy says 16 while its Terms of Use on the same page say 18. Sweetdream.ai scored 0 because its privacy policy states no minimum age. Its separate Terms of Service require users to be 18, but the policy does not refer to them; if they counted, the score would be 1.
8. Security measures: 7 scored 2, 8 scored 1
Seven policies name specific measures. Kindroid, OurDream.ai and Sweetdream.ai state that chats or data are encrypted at rest and in transit. Replika and Talkie say transmitted data is encrypted and name firewalls and role-based access controls, but do not say stored data is encrypted. Janitor AI lists encryption, access controls and regular security assessments, and Nomi.ai names network-traffic monitoring, staff training and need-to-know access without mentioning encryption.
The other eight describe their security measures only in general terms; the one specific item in Candy.ai's policy is that passwords are stored encrypted. Candy.ai and Kupid.ai use the identical sentence “We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorized way…” Character.AI's Privacy Policy has no section on security measures; the only statement is a parenthetical in its Regional Privacy Disclosures: “(adopting required technical and organisational measures)”. None of the security claims in this scorecard were independently verified.
App-by-app notes
Each entry lists the operator as its documents name it, the date the policy shows, the grade and the points that shaped it. Quotes link to the document they come from; the criterion in brackets is the score it affected.
Candy.ai
- Third-party LLM providers and/or hosters “may receive the content of your messages exchanged with our chatbot”. The policy names the situations in which people access content: moderating flagged content, random quality checks, reviewing de-identified interactions for training datasets and support investigations (chat access: 2).
- Chat exchanges may be de-identified and used to “train and develop our AI models and moderation technologies”, and dataset preparation “may include human review”. No training-specific opt-out is described, only the general right to object (AI training: 0).
- The policy says account data is kept “for three years after your last Account activity” unless you request deletion, and log files are “automatically deleted after 30 days” (deletion and retention: 2). Results of third-party age estimation or verification are processed “as applicable based on your location” (age checks: 2).
- The policy says personal data is not sold or transferred without consent, but the Cookies Notice it incorporates says third-party targeting cookies may build interest profiles to show ads on other sites, subject to consent in the cookie banner (sale and ads: 1). The security section describes only “appropriate security measures”; the one specific item is that passwords are stored encrypted (security: 1).
Our full review: Candy.ai review
Replika
- The policy says de-identified conversation data goes to third-party AI language model providers “solely to generate conversational responses within the app's core functionality”, and those providers are contractually barred from using it for their own training. The policy does not describe access by Replika staff (chat access: 2).
- On sensitive information shared in companion chats: “We will not use your sensitive information — or any content of your conversations — for marketing or advertising purposes.” (sensitive data: 2)
- Messages and content are processed “for up to 60 days after termination of the contract”; account, financial and automatically collected data are kept for at least 10 years. “You can delete your account in your account settings.” (deletion and retention: 2)
- The policy says small anonymized portions of messages are used “to train our proprietary safety algorithms, enhance chatbot performance”, with no training-specific opt-out described (AI training: 0). The policy says website visitor data shared with advertising partners may count as a sale or sharing and describes an opt-out (sale and ads: 1). The minimum age is 18; the policy names verifying the age of registered users as a purpose but does not describe how age is checked (age checks: 1).
Our full review: Replika review
Kindroid
- The policy says chats are encrypted at rest and in transit, “so we will not be able to view any of said data in our normal operation of the business”. The company reserves the right to decrypt and disclose chats for legal requirements and to enforce its terms (chat access: 2, security: 2). We did not verify the encryption claim.
- “We retain your chat conversation and generated media until you delete a specific AI or delete your account.” (deletion and retention: 2)
- The policy does not say whether chats are used to train AI models. De-identified data may be used “to analyze, build and improve the Services”, and no opt-out is described (AI training: 0). It says personal data is not sold or shared, but lists analytics partners and says some disclosures may count as a sale under state law (sale and ads: 1).
- The minimum age differs within the same legal page: 18 in the Terms of Use and 16 in the Privacy Policy. The Terms say “We reserve the right to request proof of age at any time”, but describe no age check in use (age checks: 1). The policy asks users not to share sensitive information and states no specific protections for it (sensitive data: 1).
OurDream.ai
- Collected information, which includes chat communications, may be used “to train our artificial intelligence/machine learning models”. No opt-out is described (AI training: 0).
- “All user and product data handled by Dream Studio is encrypted both at rest and in transit using industry-standard AES encryption and TLS 1.3 protocols.” (security: 2) Where the law requires age verification, “Verification is performed by a third-party age assurance provider” (age checks: 2).
- The policy says chats may reveal sensitive information such as sexual orientation, but its only limit is a California-only reference to the CCPA (sensitive data: 1, lowered from 2 in our re-grading pass, which moved the grade from B to C).
- Popular public Characters may be kept “even if you otherwise delete your data and your account”, and no concrete retention period is given (deletion and retention: 1). The policy says “we do not engage in advertising as of the date of this Policy” but also describes sharing online identifiers with advertising partners, with opt-out tools (sale and ads: 1).
Our full review: OurDream.ai review
Character.AI
- The only app in this scorecard with a described opt-out from model training. Its Regional Privacy Disclosures say that for training and improving its AI models “you have the right to opt out at any time” (AI training: 1).
- Its US notice lists "sales" to advertising providers of identifiers, demographics, geolocation, device data and inferences, and lists chat content as not sold. “To opt out of targeted advertising or the sale of personal information to third parties, please navigate to the Your Privacy Choices page” (sale and ads: 1)
- The minimum age is 13 (16 in the EEA and UK), and the US notice says the company may provide targeted advertising to minors over 13 in some jurisdictions, with consent where the law requires it. Age verification is named as a processing purpose, but no method is described (age checks: 1, lowered from 2 in our re-grading pass).
- The Privacy Policy has no section on security measures. The only statement is a parenthetical in the Regional Privacy Disclosures: “(adopting required technical and organisational measures)” (security: 1). Retention is described only as for the time necessary (deletion and retention: 1).
Our full review: Character.AI review
Kupid.ai
- “Usually, we will store your personal information for a period of 6 (six) years after you cease being a User of our Services”, counted from the date the account is closed (deletion and retention: 2).
- The policy does not say whether chats are used to train AI models and does not mention third-party AI model providers. It says personal data may be used “to adapt the Services to your needs and to develop new tools” (AI training: 0).
- “Our moderation team checks that you are in compliance with law”, but the policy sets no limits specific to chat content (chat access: 1). It mentions sensitive data only generally and describes only appropriate security measures (sensitive data: 1, security: 1).
- The revision date appears as a bracketed, placeholder-style value, “Date of Revision: [ 02/05/2023 ]”, and the third-party marketing clause names another company: “any company outside Usway for marketing purposes”.
Our full review: Kupid.ai review
Nomi.ai
- The policy says deleting your account in Account Settings “will delete all of your personal information, within 28 or so days of confirmation of deletion” (deletion and retention: 2).
- Material in “training or communications archives” is an exception: “Upon deletion, any information in our training archives would no longer be attributable to you.” No opt-out from training is described (AI training: 0).
- “We do not and will not sell or rent to any third party any of your personal information.” The policy reserves the right, not currently used, to have advertising networks serve interest-based ads on other websites (sale and ads: 1).
- The policy does not address sensitive or special-category data (sensitive data: 0) and does not mention encryption. It scores 2 on security for naming network-traffic monitoring, staff training and need-to-know access limits. The minimum age is 18; the Terms say the company intends to add age verification but describe none in use (age checks: 1).
Our full review: Nomi.ai review
Talkie
- “The Services are not intended for individuals under the age of 14 or under the applicable minimum age required by local law.” No age check beyond self-declaration is described (age checks: 1).
- The policy says identifiers, device data, geolocation and inferences are shared with advertising partners for targeted ads, and that “Our disclosure of information to these partners maybe considered a "sale" or "sharing" of personal information”. Message content is listed as not sold or shared, and an opt-out is described (sale and ads: 1).
- The policy says messages are used for “allowing your AI chatbot to learn from your interactions to improve your conversations”. The policy does not say whether chats train the underlying AI models and describes no opt-out (AI training: 0).
- “All transmitted data are encrypted during transmission.” The policy also names firewalls and role-based access controls but does not say stored data is encrypted (security: 2). The operator is a Singapore company; the policy says the Services are operated from the United States.
Chai
- “We use personal data derived from your in-app conversations with chatbots to enhance and fine tune the artificial intelligence models”, after removing personal identifiers. No training-specific opt-out is described (AI training: 0).
- The policy says ads are shown to free users based on consent and that usage patterns may be shared with advertising partners for campaign attribution. It does not say whether personal data is sold and describes no opt-out beyond the general EU/UK right to object (sale and ads: 0).
- “All users, regardless of their location or country of residence, can delete their account and associated personal data directly within the APP.” Data may be kept for up to five years after deletion (deletion and retention: 2).
- The privacy notice itself states no minimum age. The EULA it calls integral does: “Chai AI is a platform strictly restricted to users aged 18 and older.” (age checks: 1). Its access clause covers all personal data without naming purposes for staff access (chat access: 1, lowered from 2 in our re-grading pass).
EVA AI
- The purpose given for text and voice messages sent to the virtual friend: “To improve the quality of text and voice messages of the virtual friend and to develop its AI.” No opt-out is described (AI training: 0).
- The iOS Terms describe an AI-based age check: “Our self-sufficient artificial intelligence may block your account if it has grounds to consider that you are under 18 years old.” They say the account is unblocked on proof of age (age checks: 2).
- “Communication with your virtual friends is not shared with any other company, except for our affiliate companies, legal representatives, or service providers.” The policy says staff in administration, sales, marketing, legal and system administration may access personal data, and sets no chat-specific purpose limits (chat access: 1). The Terms add that private communications may be disclosed to prove disputed charges.
- The policy does not address sensitive or special-category data (sensitive data: 0). The policy says session recordings are shared with Microsoft after in-app consent and that Microsoft may use that data for any purpose under its own privacy statement. It gives no concrete retention period, and deletion does not reach data already forwarded to third parties (deletion and retention: 1).
Janitor AI
- Among the uses of collected information, which includes chat conversations: “Conducting research and development to improve our AI systems and user experience.” The policy does not say whether chats are excluded and describes no training opt-out (AI training: 0).
- “These measures include encryption, access controls, secure development practices, and regular security assessments.” The policy also says HTTPS is used in transit (security: 2).
- The policy describes self-serve deletion under Settings > Security > Delete Account, but gives no concrete retention period, and “some records, including your email address and authentication-provider metadata, may remain in our deleted-account records” (deletion and retention: 1).
- The policy does not address sensitive or special-category data (sensitive data: 0). It says personal data is not sold as defined under the CCPA/CPRA and describes sharing with service providers for analytics and marketing, but does not say that data is not shared for cross-context behavioral advertising (sale and ads: 1). The policy page returned HTTP 403 errors to our automated requests, so we read the September 17, 2026 text through a text-rendering service.
JOI.com
- On age checks: “Yes, we use external service providers to conduct age checks.” The Terms of Service it references set a minimum age of 18 (age checks: 2).
- The purpose given for text and voice messages: “To improve the quality of text and voice messages of the virtual friend(s) and to develop its AI.” No opt-out is described (AI training: 0).
- “Our trusted partners help us serve advertising and analytics and may place cookies on your device.” The policy says personal data is never sold and lets users in certain US states opt out of targeted advertising on request (sale and ads: 1).
- The policy says chats are shared with affiliates, legal representatives and service providers, and that personal data may be accessible to staff including sales and marketing, with no chat-specific purpose limits (chat access: 1). The Terms of Service add that after a chargeback Joi AI “may be required to disclose any and/or all private communications”. The policy does not address sensitive or special-category data (sensitive data: 0). JOI.com and EVA AI name the same data controller, NOVI LIMITED.
Our full review: Joi.com review
SecretDesires
- The privacy policy lists training as a use of collected information, including chat communications: “to train our artificial intelligence/machine learning models” (AI training: 0). A separate Trust Hub page (March 9, 2026) says conversations are never used to train AI models, but the privacy policy does not refer to it, so under our rubric the policy text is what we grade.
- The policy says chats may reveal sensitive information such as sexual orientation, and its only limit is in its California section: “we do not use or disclose sensitive personal information other than for purposes for which you cannot opt out under the CCPA” (sensitive data: 1, lowered from 2 in our re-grading pass).
- The policy says accounts can be deactivated, some information deleted on the profile page, and deletion requested, but gives no concrete retention period, and popular public Characters may be kept “even if you otherwise delete your data and your account” (deletion and retention: 1). Large parts of the wording match the OurDream.ai privacy policy.
- The Terms of Service name Playhouse Media Trading Ltd. as the contracting party for EU residents; the privacy policy names only Playhouse Media LLC. The policy describes only generic technical, administrative and physical safeguards (security: 1).
Our full review: SecretDesires review
CrushOn.AI
- “We may use User Content from character chats to train AI models.” No opt-out is described (AI training: 0).
- The policy lists sub-processors such as “tech support entities and operator of the AI basic model” but does not limit their access to chat content to named purposes (chat access: 1).
- The policy says third-party ad SDKs in the mobile app “may be able to identify you across sites, devices, and over time.” The opt-outs described are browser cookie settings, Google's tools and a Nevada sale opt-out request (sale and ads: 1).
- The policy text names no legal entity and says “We operate in the United States.” The Terms of Use name TECHIEPIE LTD, a company registered in Cyprus (operator: 2). The policy says accounts are closed by emailing support and does not say that this deletes chat content (deletion and retention: 1), and the policy does not address sensitive data (sensitive data: 0).
Sweetdream.ai
- “All data is encrypted in transit and at rest using industry-standard encryption protocols. Your conversations are protected with end-to-end encryption.” (security: 2) The same policy says chats are “stored to provide personalized experiences and improve our AI models”. We did not verify these claims.
- “Chat data may be used to train and improve our AI models, always in an anonymized and aggregated manner that cannot identify you personally.” No opt-out from training is described (AI training: 0).
- The policy says users can “delete individual conversations or your entire chat history” and that “Inactive accounts and associated data are automatically deleted after 2 years of inactivity” (deletion and retention: 2).
- The privacy policy states no minimum age and does not say whether personal data is sold or shared for advertising (age checks: 0, sale and ads: 0). The separate Terms of Service require users to be 18, but the policy does not refer to them; if they counted, the age score would be 1. The operator is named only in the page footer.
Our full review: Sweetdream.ai review
What you can do
The grades point to a few practical habits. Our guides go into each one in detail.
- Assume your chats may be used to improve the AI. 14 of 15 policies either describe no training-specific opt-out or do not address training at all. Leave out details you would not want stored or reviewed; our guide on limiting what an AI knows about you shows how.
- Keep health and sexual details general. 6 of 15 policies do not address sensitive data at all, and only 2 (Candy.ai and Replika) scored full marks on it. Our AI companion privacy guide covers what to keep out of your chats.
- Use the opt-outs that exist. Where a policy offers an opt-out from ad sharing, through a Your Privacy Choices link, cookie settings or a request, use it. On Character.AI, the model-training opt-out is described in its Regional Privacy Disclosures. Our guide to GDPR and CCPA rights explains the rights behind these options.
- Check the deletion route and retention period before you start. Only 7 of 15 policies give a concrete retention rule, and some say they keep certain data for years after an account is closed or deleted. See how encryption and data deletion work in AI girlfriend apps.
- Treat encryption claims as claims. Seven policies name specific security measures, but none of them has been independently verified here. Our explainer on what end-to-end encryption claims really mean helps you read them.
Methodology and right of reply
This scorecard is a desk review of public documents. On September 19, 2026 we read each app's privacy policy and, where the policy refers to them, its terms of service, cookie notice or other policies. The grades draw only on those documents; no product testing, traffic analysis or system audit went into them.
Grading ran in two passes. In the first, each criterion was scored against the rubric and tied to a quote or, where a topic is not addressed, to a search of the documents. In the second, an adversarial re-grading pass checked every score and quote against the documents and tried to overturn it. That pass changed four scores, all downward, so that apps with the same level of detail are scored the same way: Character.AI's age score (2 to 1, because no verification method is described), Chai's chat-access score (2 to 1, because its access clause names no purposes), and the sensitive-data scores of OurDream.ai and SecretDesires (2 to 1, because their only limit is a California-only reference to the CCPA). The last change moved OurDream.ai from a B to a C. The pass also corrected the wording of one finding, Kindroid's age check, without changing its score. Where a call was close, the notes above say so.
Apps we could not grade
None in this edition. Every app we set out to review had a public privacy policy we could read on September 19, 2026, so all 15 were graded.
Right of reply and updates
We re-grade every app quarterly. If you represent one of these companies and believe a grade misreads your documents, or your policy has changed, contact us through our About page with the passage you want us to look at, and we will re-review it. If a re-review changes a score, we will update this page and its CSV and note the change. This scorecard describes what companies' documents say. It is not legal advice and not an assessment of whether any company complies with the law.
How to cite this page
Suggested citation:
AI Girlfriend World (2026). AI Companion Privacy Scorecard 2026: 15 Apps Graded. https://aigirlfriendworld.com/ai-companion-privacy-scorecard
HTML link:
<a href="https://aigirlfriendworld.com/ai-companion-privacy-scorecard">AI Companion Privacy Scorecard 2026</a> (AI Girlfriend World)License: the scorecard data is licensed under CC BY 4.0. You are free to reuse it with a link back to this page. Quoted policy text belongs to the respective companies.
Download the scorecard (CSV): one row per app with operator, country, grade, total score, the eight criterion scores (columns score_operator to score_security, in rubric order), privacy policy URL, policy date and review date.
More research from AI Girlfriend World
- AI companion statistics: the numbers behind AI companion apps and their users.
- AI companion laws tracker: laws and regulations that apply to AI companion apps.
- AI companion history timeline: how AI companions developed over time.