Post this question anywhere online and two confident camps show up: "obviously they sell everything" and "that would be against the law." Neither is right, and the practical answer is in the gap.
"Selling" can mean three different things
Selling your chat content. Hand transcripts to an outside buyer for money and you invite legal trouble almost anywhere, plus a scandal the moment it surfaced. Companies flatly deny doing it, and nothing public shows a major companion app that has.
Sharing usage data with advertisers. Here's the common one. Ad and analytics code built into an app or site (a software development kit, or "SDK") tells outsiders what you did, at what time, and on which device. California's privacy statute treats handing personal information over for cross-context behavioral ads as "sharing," and trading it for something valuable can be a "sale." That leaves room for an app to truthfully say it never sold your chats while, legally, still selling you.
Passing data to service providers. Think of the host that runs the servers, the model vendor that writes the replies, and the processor that bills your card. The app can't run without them, and they don't count as a sale, yet each holds another copy of your data on its own systems.
A fourth route gets forgotten: a change of ownership. Almost every policy says the buyer gets your data if the company is sold. The companion app Soulmate was sold shortly before it closed down in 2023; see when your AI companion changes overnight.
The one systematic audit
The Mozilla Foundation studied 11 romantic AI chatbots in February 2024, Replika, Chai and EVA AI among them, for its Privacy Not Included buyer's guide. The group had roughly 100 million downloads on Google Play between them, and every one got Mozilla's privacy warning label.

What share of Mozilla's 11 reviewed apps fit each finding (February 2024). Source: Mozilla Foundation, Privacy Not Included.
Tracker counts were the eye-catcher. Across the apps, Mozilla recorded 2,663 trackers on average during the first minute, a figure inflated by one outlier: Romantic AI set off 24,354 within a single minute. EVA AI, second worst, triggered 955.
Keep two caveats in mind. It captured early 2024, and policies move. Several of today's leading apps also weren't included. So value the audit for what it says about how the whole category behaves by default, not for its verdicts on individual apps.
Decoding a privacy policy
Skip the full read. Search for a handful of phrases and read only the paragraph around each hit.
| Policy language | Usual translation | Should it worry you? |
|---|---|---|
| "We do not sell your personal information" | No sale in the strict sense; hunt for "share" on its own | Only if "share" shows up too |
| "Advertising partners," "targeted advertising" | Trackers assemble an ad profile out of your activity | Yes; opt out if you can |
| "Our affiliates" | Sibling companies under one parent, sometimes with dozens of apps | Depends on who owns it |
| "To improve our services," "train" | Your conversations could be used to train models | Yes; look for an opt-out |
| "Merger, acquisition or sale of assets" | New owners inherit your data in a sale | Standard, but keep it in mind |
| "Where we believe disclosure is necessary" | Data may go to authorities with no court order | Yes, unless something narrower is stated |
A footer link reading "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" tells you something on its own. California makes businesses that sell or share personal data post it, so finding one concedes that sharing happens, and hands you the switch to stop it.
Your five-minute audit
- Search the policy for sell, share, advertis, train and affiliate. Five searches, five paragraphs.
- Check the store labels. Apple's "Data Used to Track You" section and Google Play's "Data safety" section are filled out by the developer, so treat them as claims rather than audits. Even so, an app owning up to tracking there is unlikely to behave better in practice.
- Enable Global Privacy Control in your browser when you use the web version. Under California's rules, companies must honor that signal as a request to opt out of sale and sharing.
- Tap "Ask App Not to Track" on iPhone, and reset the advertising ID on Android.
- Notice any ads in the app. Where they exist, your attention and data help pay the bills; see how AI companion apps make money.
Your legal leverage, and its limits
Living in California, or in one of the many other states with a broad privacy law, lets you ask what was gathered, halt its sale or sharing, and demand deletion. GDPR in the EU and UK gives you that and more, and regulators wield it: in 2025 Italy fined Replika's operator 5 million euros, partly over a privacy policy that didn't explain what happened to users' data.
The recent state laws aimed at AI companions, which we cover in AI companion laws in the US, focus on disclosure and crisis response and barely touch data. One narrow exception stands out: Utah's law on mental-health chatbots forbids them from selling or sharing users' health information and from targeting ads based on what users type.
Bottom line
The typical companion app isn't selling your chats. Plenty let ad and analytics firms observe your behavior, though, and almost all keep the option to go further later. A careful app and a careless one look different in their policies and settings, and spotting it takes five minutes. Spend them before you type something you'd hate to see in a stranger's database, then use our four privacy checks for everything else.