Picture one of these accounts six months in. It holds chats more candid than anything in your inbox, a folder of generated images, a saved card, and an email address that ties all of it back to you.
Then look at who is guarding it: usually a small company, a handful of engineers, and no regulator checking their work. Valuable contents, average locks. That mismatch is the entire problem.
Security gaps you should expect
Not every app has all of them, but they show up often enough that you should assume the worst until you check:
- No 2FA. Your password is the only lock, and anyone who gets into your email can get past it.
- No list of active sessions. There's no way to see which devices are signed in, or to kick out one that isn't yours.
- No sign-in alerts. A login from an unfamiliar phone or laptop happens without a peep.
- Weak account recovery. That hurts twice: getting back in is a slog when you're locked out, and an impostor can often sweet-talk a support agent into handing your account over.
- Sessions that never expire. An old tablet you abandoned may still be signed in half a year later.
When an app does give you 2FA and a session list, take note. Teams that build those usually got the rest right as well.
Four fixes that do the heavy lifting
1. A password manager and a password used nowhere else
Yes, it's basic. It's also most of the game. Nobody is likely to target this particular app. The real risk is credential stuffing: attackers take passwords spilled in some other site's breach and try them here.
A password manager costs you nothing and solves it. Any password you've recycled is one breach somewhere else away from belonging to a stranger.
2. An email address just for this
You get two wins. Nobody can find the account by searching your main identity, and if one of the two gets compromised, the other stays safe.
Pick a real inbox you'll still control next year, not a throwaway, because that's where a password reset will land. An alias service or a second mailbox with your current email provider both do the job.
Send your billing receipts to that address too, as explained in our guide to paying privately.
3. Switch on 2FA wherever you can
If the app has it, enable it, and choose an authenticator app over text messages. If the app doesn't have it, put 2FA on your email account instead. Email is how accounts get recovered, so locking it down protects every service that can send you a reset link.
When the app gives you no security tools at all, nothing else you can do is worth as much.
4. Sign out of devices you've stopped using
Borrowed and shared devices first. No session list in the app? Change your password: in most apps that's a blunt but effective way to kill every other session.
The biggest risk isn't a hacker
Let's say it straight, because in this category it's the one that actually hurts people: somebody picking up your phone or laptop while it's unlocked.
A strong password does nothing against that. The fix lives on the device: a separate browser profile, notification previews turned off, downloads kept out of folders that sync. We walk through it in our shared-device guide.
When an app gets breached
Breaches happen. Your response is the same every time:
- Change your password right away, plus every other place you used it.
- Keep an eye on that inbox for reset emails you didn't ask for.
- Look over the card on file and think about asking your bank for a new number.
- Decide if you're staying. A company that sends a clear notice with a real timeline is telling you something very different from one whose breach you learn about from reporters three months on.
Read the operator's actual statement. If it stays fuzzy on what was exposed, and above all on whether chats were part of it, that fuzziness is your answer.
A two-minute check before you pay
Poke around the settings before you enter a card. It reveals more about the engineering than any landing page will:
- Can you enable 2FA?
- Can you see your active sessions?
- Can you delete your account yourself, or do you have to email support?
This matters most for apps designed to build up years of history, like Nomi and Replika, for the simple reason that they end up holding the most about you. To see what that pile of data includes, read what your AI girlfriend app has on you. To get rid of it, see how to delete your account.

