Secrets.ai
The current April 2026 policy explicitly says raw voice-call audio is transcribed in real time and immediately deleted, while the text transcription is retained.
AI COMPANION PRIVACY · 2026
Adult and relationship-style AI can hold unusually personal conversations. This page compares current public evidence about deletion, retention, model-improvement use and voice-audio handling without turning a legal policy into a fake “privacy score.”
The most useful question is not “which app says privacy matters?” It is “what does the current policy actually say you can delete, what may be retained, and how conversation data may be used?”
The current April 2026 policy explicitly says raw voice-call audio is transcribed in real time and immediately deleted, while the text transcription is retained.
The current April 2026 policy says account deletion removes personal information in roughly 28 days, while information already in training or communications archives follows separate handling.
The July 2026 privacy notice explicitly describes de-identifying or anonymizing interactions for service improvement, model development and possible human review of de-identified/anonymized interactions.
The public privacy policy still shows a 2023 revision date. It documents withdrawal of consent, account deletion and erasure rights, but the older policy date is itself a reason to verify current practice before relying on a missing detail.
This is a policy comparison, not a legal grade, penetration test or guarantee of actual backend behavior.
| Platform | Policy date | Account / data deletion | Training / improvement disclosure | Retention signal | Voice-specific evidence |
|---|---|---|---|---|---|
| Secrets.ai | 10 Apr 2026 | PartialGeneral privacy/account controls documented; this table does not assert an unsupported universal deletion timeline. | UnknownNo training claim asserted here without clearer current policy language. | PartialChat/transcript handling documented; other retention depends on data type. | VerifiedRaw call audio deleted after real-time transcription; text retained. |
| Nomi | 27 Apr 2026 | VerifiedAccount deletion described as deleting personal information within roughly 28 days of confirmation. | PartialPolicy references a training archive and says deleted information there is no longer attributable to the user. | PartialMost personal information is not retained after account deletion, subject to stated archive/legal exceptions. | UnknownNo raw-call-audio retention claim asserted here. |
| Candy.ai | 30 Jul 2026 | VerifiedAccount-data deletion on request is described, subject to legal/contract exceptions. | VerifiedDe-identified/anonymized interactions may be used for model development, datasets and internal research; human review may occur on de-identified/anonymized interactions. | VerifiedAccount data can be retained after inactivity; debug logs are stated to auto-delete after 30 days. | UnknownNo precise live-call raw-audio retention statement verified here. |
| Kupid AI | 2 May 2023 | VerifiedWithdrawal of consent and right-to-erasure language describes account/personal-data deletion. | UnknownNo current explicit training/use statement verified from the public policy. | PartialRights and processing purposes are described, but policy freshness is materially weaker than the other rows. | UnknownNo specific voice-retention statement verified. |
Deleting one conversation, one memory, an account or a billing record can trigger different retention rules. Check the specific control you need.
A policy may describe de-identifying or anonymizing interactions for research or model development. That is different from saying the original conversation is never processed for improvement.
A voice product may discard raw audio but keep a transcript. For continuity and privacy, both layers matter.
An old policy can still be legally operative, but a stale revision date creates more uncertainty when the product has changed substantially since publication.
COMMERCIAL ROUTE · SEPARATE FROM PRIVACY FIT
Affiliate disclosure: LarkMetric may earn an affiliate commission from an eligible referral. Privacy evidence is evaluated separately from payout and route availability.
Checking whether the current supported referral route is available for your location…
A privacy policy describes what a provider publicly commits to or discloses. It does not prove what an app stores on-device, sends over the network or how users experience privacy boundaries in intimate use. Independent 2026 research helps define those separate layers.
Brigham, Qin and Kohno identified 489 AI companion apps and systematically walked through a stratified sample of 30, including risks around sensitive-data collection and sharing. LarkMetric uses this as context, not as a substitute for product-specific policy evidence.
Comeaux and co-authors examined six companion apps using device acquisition, network interception and file-system analysis, reporting local artifacts, undocumented APIs and third-party tracking. That is a different evidence layer from reading public policies.
Ma and co-authors interviewed 17 people about privacy in human-AI romantic relationships and found concerns including conversation exposure, anonymity and changing boundaries as intimacy deepened. Policy text alone cannot measure those lived effects.
The structured LarkMetric snapshot behind this page contains the checked policy dates, source URLs and DOCUMENTED / PARTIAL / UNKNOWN labels for the four products shown here. It contains no user data or conversation data.
LarkMetric uses public policy text as DOCUMENTED evidence. It does not claim that a policy proves actual security, encryption quality or every backend behavior.
Evidence checked 18 Sep 2026. This is informational product-policy research, not legal advice or a security certification.