Do AI Girlfriend Apps Sell Your Data?

Privacy & security

Usually not how you'd picture it. No one is auctioning chat logs by the gigabyte. The risk is subtler: ad trackers, fine print about partners and affiliates, and policies that hold onto rights the app might never exercise yet never surrenders.

We may earn a commission from links on this page. It never changes a rating.

Post this question anywhere online and two confident camps show up: "obviously they sell everything" and "that would be against the law." Neither is right, and the practical answer is in the gap.

"Selling" can mean three different things

Selling your chat content. Hand transcripts to an outside buyer for money and you invite legal trouble almost anywhere, plus a scandal the moment it surfaced. Companies flatly deny doing it, and nothing public shows a major companion app that has.

Sharing usage data with advertisers. Here's the common one. Ad and analytics code built into an app or site (a software development kit, or "SDK") tells outsiders what you did, at what time, and on which device. California's privacy statute treats handing personal information over for cross-context behavioral ads as "sharing," and trading it for something valuable can be a "sale." That leaves room for an app to truthfully say it never sold your chats while, legally, still selling you.

Passing data to service providers. Think of the host that runs the servers, the model vendor that writes the replies, and the processor that bills your card. The app can't run without them, and they don't count as a sale, yet each holds another copy of your data on its own systems.

A fourth route gets forgotten: a change of ownership. Almost every policy says the buyer gets your data if the company is sold. The companion app Soulmate was sold shortly before it closed down in 2023; see when your AI companion changes overnight.

The one systematic audit

The Mozilla Foundation studied 11 romantic AI chatbots in February 2024, Replika, Chai and EVA AI among them, for its Privacy Not Included buyer's guide. The group had roughly 100 million downloads on Google Play between them, and every one got Mozilla's privacy warning label.

Horizontal bars showing how many of the 11 romance chatbots Mozilla reviewed in 2024 fell short: data sharing or sale (10), security (10), flaw handling (73%), encryption (64%), data deletion (54%), password strength (about 45%)

What share of Mozilla's 11 reviewed apps fit each finding (February 2024). Source: Mozilla Foundation, Privacy Not Included.

Tracker counts were the eye-catcher. Across the apps, Mozilla recorded 2,663 trackers on average during the first minute, a figure inflated by one outlier: Romantic AI set off 24,354 within a single minute. EVA AI, second worst, triggered 955.

Keep two caveats in mind. It captured early 2024, and policies move. Several of today's leading apps also weren't included. So value the audit for what it says about how the whole category behaves by default, not for its verdicts on individual apps.

Decoding a privacy policy

Skip the full read. Search for a handful of phrases and read only the paragraph around each hit.

Policy languageUsual translationShould it worry you?
"We do not sell your personal information"No sale in the strict sense; hunt for "share" on its ownOnly if "share" shows up too
"Advertising partners," "targeted advertising"Trackers assemble an ad profile out of your activityYes; opt out if you can
"Our affiliates"Sibling companies under one parent, sometimes with dozens of appsDepends on who owns it
"To improve our services," "train"Your conversations could be used to train modelsYes; look for an opt-out
"Merger, acquisition or sale of assets"New owners inherit your data in a saleStandard, but keep it in mind
"Where we believe disclosure is necessary"Data may go to authorities with no court orderYes, unless something narrower is stated

A footer link reading "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" tells you something on its own. California makes businesses that sell or share personal data post it, so finding one concedes that sharing happens, and hands you the switch to stop it.

Your five-minute audit

  1. Search the policy for sell, share, advertis, train and affiliate. Five searches, five paragraphs.
  2. Check the store labels. Apple's "Data Used to Track You" section and Google Play's "Data safety" section are filled out by the developer, so treat them as claims rather than audits. Even so, an app owning up to tracking there is unlikely to behave better in practice.
  3. Enable Global Privacy Control in your browser when you use the web version. Under California's rules, companies must honor that signal as a request to opt out of sale and sharing.
  4. Tap "Ask App Not to Track" on iPhone, and reset the advertising ID on Android.
  5. Notice any ads in the app. Where they exist, your attention and data help pay the bills; see how AI companion apps make money.

Living in California, or in one of the many other states with a broad privacy law, lets you ask what was gathered, halt its sale or sharing, and demand deletion. GDPR in the EU and UK gives you that and more, and regulators wield it: in 2025 Italy fined Replika's operator 5 million euros, partly over a privacy policy that didn't explain what happened to users' data.

The recent state laws aimed at AI companions, which we cover in AI companion laws in the US, focus on disclosure and crisis response and barely touch data. One narrow exception stands out: Utah's law on mental-health chatbots forbids them from selling or sharing users' health information and from targeting ads based on what users type.

Bottom line

The typical companion app isn't selling your chats. Plenty let ad and analytics firms observe your behavior, though, and almost all keep the option to go further later. A careful app and a careless one look different in their policies and settings, and spotting it takes five minutes. Spend them before you type something you'd hate to see in a stranger's database, then use our four privacy checks for everything else.

Frequently asked questions

Is Replika selling my data?

Replika says it has never sold what its users tell it and has never supported advertising. Mozilla's 2024 review faulted it for sharing behavioral data and permitting weak passwords. Both can hold at once, since feeding usage data to analytics or marketing partners is a different act from selling conversations. Check the current policy instead of trusting either headline.

Can I block an app from sharing my data?

Some of it. Use the "Do Not Sell or Share" link when the app has one, switch on Global Privacy Control in your browser, say no to tracking requests on your phone, and disable model training if a toggle exists. Deleting your account stops future collection, though it doesn't always claw back what was already shared.

Are paid apps safer than free ones?

Not by default, though the motives are healthier. A business paid by subscribers has less reason to stuff its app with ad trackers than one paid by advertisers. Only the policy, never the price, settles it.