Reading a privacy policy tells you what a company says it might do. A data request tells you what it really holds. Under GDPR this is called a "subject access request," and it is the most direct privacy audit an ordinary user can run.
Which law covers you

Your address decides the law, not the company's headquarters.
- California: the CCPA, as amended, lets you find out what is collected, delete it, correct it, and opt out of its sale or sharing.
- Other US states: Virginia, Colorado, Connecticut, Texas and more have passed broad privacy laws with mostly similar rights. Some only bind companies above a certain size.
- EU and EEA: GDPR covers access, correction, erasure, export, and objection to particular uses of your data.
- UK: UK GDPR grants the same set of rights.
None of these fit? Send the request anyway. Many companies run every request through one process because that is easier than sorting people by location.
Choose what to ask for
| Your goal | What the company must give you | Best moment |
|---|---|---|
| Access | A copy of your data and an explanation of its use | The first request, always |
| Portability | The data in a reusable file | You are moving to a different app |
| Erasure | Your data removed | You are leaving, or after a breach |
| Objection or opt-out | An end to uses like model training or ad sharing | You are staying but want limits |
| Correction | Errors fixed | A wrong birth date, wrong email, or duplicated accounts |
A letter you can copy
Send it from the email tied to your account. Use the privacy contact listed in the company's policy (often privacy@ or dpo@) or its online privacy form.
Subject: Request for access to my personal data
Under Article 15 GDPR / the California Consumer Privacy Act (keep whichever applies), I ask for access to all personal data you keep about me. My account email is [address] and my username is [username].
Please include: every chat message, every image I uploaded or generated, voice recordings, any memories or profile notes your system built from my conversations, billing records, and device information. Also tell me why you process the data, which companies receive it (advertisers and AI model providers included), how long you retain it, and whether my data has helped train or tune any AI model.
Please answer within the legal time limit.
To request deletion instead, swap the opening paragraph for a demand that all personal data be erased, with written confirmation, covering backups and copies held by vendors that process data for the company.
Judging the response
A well-run company sends a downloadable package: chats, the list of "memories" it keeps about you, images, payment and sign-in history, and a plain-language account of who received what. Two parts deserve the closest look:
- Inferred data. Summaries, personality profiles and "facts about you" the app worked out itself. This is often the most revealing section, and it shows how AI companion memory works for your own account.
- Recipients. Model providers, analytics firms, ad networks. Put the list next to the company's policy, then read do AI girlfriend apps sell your data.
If the company stonewalls
- Follow up once the deadline has passed, citing the date of your first message.
- Go to the regulator. In California that means the California Privacy Protection Agency or the state Attorney General. In the EU it is your national data protection authority, and in the UK the ICO.
- Save everything. Regulators want copies of each message and its date.
Regulators do enforce here. In 2025 Italy's data protection authority fined the company behind Replika 5 million euros, partly because its privacy policy did not clearly explain how it used personal data.
Export before you erase
Might you want the character or chat history back someday? Then request access, or use the app's built-in export, before you ask for erasure. Deletion cannot be undone, and some apps purge their backups only after several weeks. The whole sequence is in deleting an AI companion account.
Worth doing even if you stay
A data request works as a small character test. A company that replies clearly and on schedule shows you how it handles everything else it holds. One that goes silent shows you something as well, and you find out before a breach instead of after.