Comparison › Blog › ai girlfriend privacy
AI Girlfriend Privacy 2026: What Data Do They Collect?

In short
An AI girlfriend app collects at minimum your conversations, generated images, your email address, your payment data, and technical browsing data; some also collect your voice and photos you upload. As of September 30, 2026, Secrets AI (Secret Labs Inc., United States) is the only app in our comparison that highlights chat encryption, Replika (Luka Inc.) was fined €5 million by Italy’s data protection authority, and Kupid AI’s terms mention a $3.99/month retention fee after cancellation. Use a pseudonym, a dedicated email, and a virtual card.
What data does an AI girlfriend collect?
An AI girlfriend collects five categories of data: the content of your conversations, generated or uploaded media, your account identity, your payment data, and technical data. That’s what the privacy policies of the apps in our comparison show, as reviewed on September 30, 2026.
- Conversations: every message you write is sent to the publisher’s servers to be processed by the language model. It’s stored so the character has “memory.” This is the most sensitive data: you share intimate preferences in it, sometimes details of your life.
- Media: generated images, voice messages, and videos are kept in your gallery, so on the servers. If you send a photo of yourself (some apps allow it for selfies or “calls”), it’s stored too.
- Account identity: email, username, sometimes date of birth for age verification. Few apps require an ID document as of September 30, 2026.
- Payment: handled by a third-party payment processor; the publisher normally doesn’t see your card number, but your name and the transaction descriptor show up on your bank statement.
- Technical data: IP address, device type, cookies, usage statistics, often shared with analytics tools.
The key point: no AI girlfriend can work without reading your conversations, since the model generates the replies. So the question isn’t “does it collect data” but “who has access, for how long, and can you delete it.”
Does advertised encryption really protect your chats?
The encryption some apps advertise protects your data from third parties, not from the publisher itself. Encrypting means making data unreadable without a key. There are three levels to tell apart.
Encryption in transit (HTTPS) protects traffic between your browser and the server; every app in our comparison uses it, it’s the web standard. Encryption at rest protects data stored on servers against a leak or a stolen drive; it’s a real plus, but the publisher holds the key. End-to-end encryption, where only your device can read the messages, is incompatible with an AI girlfriend: the model has to read your text to reply.
Secrets AI states on its public pages that conversations are encrypted and puts privacy at the center of its pitch; it’s the only app in our comparison to do so this explicitly. On the pages we reviewed, we found no detail on the exact level (at rest or not). Treat the claim as a credible commitment, not technical proof. Candy AI, OurDream AI, GirlfriendGPT, and Lovescape don’t say much on this point.
What does Replika’s Garante fine tell us?
Italy’s data protection authority, the Garante, fined Luka Inc., the publisher of Replika, €5 million for failures in how it processed personal data. It’s the only public penalty of its kind among the thirteen apps we track, as of September 30, 2026.
The decision notably concerns the lack of a clear legal basis for processing data and age verification deemed inadequate. It shows that European regulators are now looking at AI companions, and that even a player established since 2017, with apps in the stores and a multilingual interface, can be found at fault.
Should you avoid Replika because of it? Not necessarily: the app is still non-explicit, which limits how sensitive the chats are, and the penalty is meant precisely to force fixes. But it’s a reminder that “big name” doesn’t mean “data handled well.” Newer publishers, often based outside the European Union, simply haven’t been examined yet.
Where is your data hosted: Malta, Delaware, Bucharest?
Where the publisher is incorporated determines which law applies and how easy it is to seek recourse. Here’s what the legal notices state as of September 30, 2026.
| App | Publisher | Headquarters | Notable point |
|---|---|---|---|
| Candy AI | EverAI Limited | Santa Venera, Malta (EU) | Subject to GDPR by incorporation |
| Secrets AI | Secret Labs Inc. | Dover, Delaware (USA) | Encryption advertised |
| DreamGF | DreamAI SRL | Bucharest, Romania (EU) | Subject to GDPR |
| Nomi AI | Glimpse AI | United States | No known penalty |
| Replika | Luka Inc. | San Francisco (USA) | €5M fine (Garante) |
| Character.AI | Character Technologies | United States | Filtered content |
| Kupid AI | Kupid AI | Not stated on the pages reviewed | $3.99/month retention fee (terms) |
The GDPR, the EU’s data protection regulation, applies to any company targeting European users, wherever it’s based. In practice, though, exercising your right of access or erasure with a Maltese or Romanian company is easier than with a Delaware entity. In the US, there’s no single federal equivalent, so your rights depend on your state’s privacy law, if any. The publisher’s headquarters doesn’t tell you where the servers physically are, information that’s rarely published.
What are Kupid AI’s post-cancellation retention fees?
Kupid AI’s terms of service mention a data retention fee of $3.99/month after cancellation, a mechanism we haven’t seen at any other app in our comparison. In practice, if you stop your subscription but want to keep your character, gallery, and history, the platform can bill you that amount every month.
It isn’t a scam in itself, since it’s written in the terms, but it’s exactly the kind of clause nobody reads before subscribing at “$3.44/week.” The right question to ask: what happens if you don’t pay the fee? Is the data deleted, and how quickly? The terms we reviewed don’t make that clear, so ask support before paying.
More broadly, check what happens to your account when you cancel at each app: immediate deletion, retention by default, or the option to export. Our article on canceling Candy AI covers the issue of non-refundable tokens.
What should you check before subscribing to an AI girlfriend?
Ten minutes of checking before entering a card saves you from most nasty surprises. Here’s the list we apply to every app.
- Find the legal notice: company name, address, country. If you can’t find it in two clicks, walk away.
- Read the “data retained” section of the privacy policy: how long conversations are kept, sharing with subcontractors, use for training models.
- Look for the right to deletion: a “delete my account” button in settings beats an email you have to send to support.
- Spot hidden fees in the terms: retention (Kupid AI), non-refundable tokens (Candy AI), auto-renewal.
- Note the billing descriptor: some publishers bill under a neutral name, others under the app’s name, which will appear on your statement.
- Check authentication: a unique password, and two-factor authentication if it’s offered.
If an app fails two of these points, the price doesn’t make up for it. Our guide to choosing an AI girlfriend builds this checklist into its six criteria.
How can you use an AI girlfriend anonymously?
You can’t be fully anonymous, but you can shrink what ties you to your account to almost nothing. Three steps cover the essentials.
- A dedicated email, created for this purpose, without your name in it. Most apps require nothing else to open an account.
- A pseudonym in conversations: the character doesn’t need your real first name, your city, or your employer to be believable. What you write is stored; write as if someone could read it one day.
- A virtual or single-use card, offered by many online banks. It limits unexpected charges and hides your main card.
Avoid sending identifiable photos of yourself, even if the app offers it to personalize the experience. And on a shared device, use a private browsing window: since Candy AI, Secrets AI, and most competitors are web-only, your browser history is the first place your use shows up.
The full comparison lists the publisher, the country, and billing red flags for each app.
FAQ — ai girlfriend privacy
Are my AI girlfriend conversations read by humans?
Privacy policies generally allow possible access for moderation, support, or service improvement. The language model necessarily reads them. Assume your chats aren’t private in the strict sense.
Which AI girlfriend respects privacy best?
None is beyond reproach. Secrets AI is the only one to highlight chat encryption; Candy AI and DreamGF are based in the European Union, so easier to contact under the GDPR. Replika is the only one publicly penalized.
Why was Replika fined?
Italy’s Garante fined Luka Inc. €5 million for failures in processing personal data, notably the lack of a clear legal basis and inadequate age verification.
Can you delete your data after canceling?
The GDPR gives you a right to erasure with any publisher targeting Europe; outside the EU, it depends on local law. In practice, look for an account deletion button in settings; otherwise, write to support. Kupid AI mentions a $3.99/month retention fee if you want to keep your data without a subscription.
Is billing discreet on my bank statement?
It depends on the publisher and the payment processor. The descriptor may show the app’s name or a neutral name. A dedicated virtual card is the safest way to stay in control.
Sources consulted
Helpful comparisons
Read next
This article compares verifiable facts (advertised features, displayed prices, terms) collected from official sites on the date shown. It is not based on timed tests. The “Try it” buttons are affiliate links. Adults only.