Request Your Data From an AI Companion App: A Step-by-Step Guide

Privacy & security

Live in California, another state with a privacy statute, the EU or the UK? Then an AI companion company must show you what it has on file and delete it on request. Almost nobody asks. It takes about ten minutes, and what comes back is often eye-opening.

We may earn a commission from links on this page. It never changes a rating.

Reading a privacy policy tells you what a company says it might do. A data request tells you what it really holds. Under GDPR this is called a "subject access request," and it is the most direct privacy audit an ordinary user can run.

Which law covers you

Summary of data rights by region: GDPR for the EU and EEA, UK GDPR for Britain, the CCPA in California, and privacy statutes in a growing number of other US states

Your address decides the law, not the company's headquarters.

  • California: the CCPA, as amended, lets you find out what is collected, delete it, correct it, and opt out of its sale or sharing.
  • Other US states: Virginia, Colorado, Connecticut, Texas and more have passed broad privacy laws with mostly similar rights. Some only bind companies above a certain size.
  • EU and EEA: GDPR covers access, correction, erasure, export, and objection to particular uses of your data.
  • UK: UK GDPR grants the same set of rights.

None of these fit? Send the request anyway. Many companies run every request through one process because that is easier than sorting people by location.

Choose what to ask for

Your goalWhat the company must give youBest moment
AccessA copy of your data and an explanation of its useThe first request, always
PortabilityThe data in a reusable fileYou are moving to a different app
ErasureYour data removedYou are leaving, or after a breach
Objection or opt-outAn end to uses like model training or ad sharingYou are staying but want limits
CorrectionErrors fixedA wrong birth date, wrong email, or duplicated accounts

A letter you can copy

Send it from the email tied to your account. Use the privacy contact listed in the company's policy (often privacy@ or dpo@) or its online privacy form.

Subject: Request for access to my personal data

Under Article 15 GDPR / the California Consumer Privacy Act (keep whichever applies), I ask for access to all personal data you keep about me. My account email is [address] and my username is [username].

Please include: every chat message, every image I uploaded or generated, voice recordings, any memories or profile notes your system built from my conversations, billing records, and device information. Also tell me why you process the data, which companies receive it (advertisers and AI model providers included), how long you retain it, and whether my data has helped train or tune any AI model.

Please answer within the legal time limit.

To request deletion instead, swap the opening paragraph for a demand that all personal data be erased, with written confirmation, covering backups and copies held by vendors that process data for the company.

Judging the response

A well-run company sends a downloadable package: chats, the list of "memories" it keeps about you, images, payment and sign-in history, and a plain-language account of who received what. Two parts deserve the closest look:

  • Inferred data. Summaries, personality profiles and "facts about you" the app worked out itself. This is often the most revealing section, and it shows how AI companion memory works for your own account.
  • Recipients. Model providers, analytics firms, ad networks. Put the list next to the company's policy, then read do AI girlfriend apps sell your data.

If the company stonewalls

  1. Follow up once the deadline has passed, citing the date of your first message.
  2. Go to the regulator. In California that means the California Privacy Protection Agency or the state Attorney General. In the EU it is your national data protection authority, and in the UK the ICO.
  3. Save everything. Regulators want copies of each message and its date.

Regulators do enforce here. In 2025 Italy's data protection authority fined the company behind Replika 5 million euros, partly because its privacy policy did not clearly explain how it used personal data.

Export before you erase

Might you want the character or chat history back someday? Then request access, or use the app's built-in export, before you ask for erasure. Deletion cannot be undone, and some apps purge their backups only after several weeks. The whole sequence is in deleting an AI companion account.

Worth doing even if you stay

A data request works as a small character test. A company that replies clearly and on schedule shows you how it handles everything else it holds. One that goes silent shows you something as well, and you find out before a breach instead of after.

Frequently asked questions

What is the deadline for a company to respond?

GDPR gives it one month, plus up to two more for complicated requests if it explains the delay. California allows 45 days and a single 45-day extension. Other state privacy laws run on similar clocks.

Can a company charge me for my data?

Not normally. Both GDPR and California law make ordinary requests free. A fee or a refusal is only allowed when a request is plainly baseless or abusive.

What if the company is based somewhere else entirely?

GDPR reaches any business offering services to people in the EU, and UK GDPR does the same for Britain. Going after a small foreign operator is harder, but your right stands and plenty of companies answer anyway to protect their access to the market.