Users confide things to these apps they've told no one else. That's the product doing its job. It's also why you should spend ten minutes on how that text is handled before you send a first message, not after a headline.
Start with this
End-to-end encryption can't work here. To answer you, an app's servers have to read what you wrote. If an app advertises end-to-end encryption for chats, it's either dressing up ordinary transport encryption or talking about something other than the conversation.
That's no scandal. It's just how these apps are built. It does mean the questions worth asking concern retention and access, not cryptography.
Check 1: what else is collected
You know about the messages. Here's what you might not think about:
- Account identifiers, and whether you can sign up with an email other than your main one.
- Payment records. In this category they're the most sensitive metadata you create. A charge description on a card statement has exposed more people than any breach.
- Device and usage telemetry, such as when you open the app and how long you stay.
- Generated images, which sit on the company's servers whether or not you saved them.
Check 2: does it train a model
Search the privacy policy for "improve our services" or "train." Then look through the settings for an opt-out.
In practice there are three setups: no training on your content, training with an opt-out, and training with no control you can see. Any of them might be fine with you. Not knowing which one you're in is the problem.
Check 3: how long it's kept, and what deletion removes
Policies often blur two separate questions.
Retention is how long content is stored while your account is live. Deletion is what happens after you ask for it to go. An app may honor a request to wipe your conversations yet keep generated images, billing records and backups on a longer schedule. All of that can be perfectly legal and still not what you expected.
See deleting an AI companion account for specifics.
Check 4: your legal rights
Live in the EU, the UK, or a US state with a consumer privacy law? Then you can ask for a copy of your data and for its deletion, and the company has to respond within a set period. Our Dutch and French editions look at the same apps under GDPR.
The rights exist, so that's not the test. Look at whether the app gives you a button you can press yourself or makes you email an address and wait. The answer shows how the company sees its users.
Five free minutes of setup
Create a dedicated email address. See what shows up on your card statement before month two. Switch off training if there's a toggle. And decide now what you won't type into a service that has to store it: your employer's name, your address, anything about a third party who never agreed to appear in your chat log.
Replika and Nomi are the two apps in our ranking most likely to pile up years of this material rather than weeks, because both are built around continuity. That makes the five minutes worth more there, not less.

