AI COMPANION PRIVACY · 2026

Privacy is not one promise.
Check the controls and the policy.

Adult and relationship-style AI can hold unusually personal conversations. This page compares current public evidence about deletion, retention, model-improvement use and voice-audio handling without turning a legal policy into a fake “privacy score.”

Evidence checked: 18 Sep 2026Primary policies firstPolicy freshness shownUNKNOWN stays UNKNOWN

Fast privacy map

The most useful question is not “which app says privacy matters?” It is “what does the current policy actually say you can delete, what may be retained, and how conversation data may be used?”

AUDIO HANDLING

Secrets.ai

The current April 2026 policy explicitly says raw voice-call audio is transcribed in real time and immediately deleted, while the text transcription is retained.

Policy freshness10 Apr 2026Raw call audioImmediately deletedTranscriptRetained
ACCOUNT DELETION

Nomi

The current April 2026 policy says account deletion removes personal information in roughly 28 days, while information already in training or communications archives follows separate handling.

Policy freshness27 Apr 2026Account deletion~28 days after confirmationTraining archiveMay persist de-attributed
MODEL DEVELOPMENT DISCLOSURE

Candy.ai

The July 2026 privacy notice explicitly describes de-identifying or anonymizing interactions for service improvement, model development and possible human review of de-identified/anonymized interactions.

Policy freshness30 Jul 2026Model developmentExplicitly describedDebug logs30-day deletion stated
POLICY FRESHNESS WARNING

Kupid AI

The public privacy policy still shows a 2023 revision date. It documents withdrawal of consent, account deletion and erasure rights, but the older policy date is itself a reason to verify current practice before relying on a missing detail.

Policy freshness2 May 2023Consent withdrawalAccount/data deletion describedTraining detailUNKNOWN from current policy text

Evidence matrix

This is a policy comparison, not a legal grade, penetration test or guarantee of actual backend behavior.

PlatformPolicy dateAccount / data deletionTraining / improvement disclosureRetention signalVoice-specific evidence
Secrets.ai10 Apr 2026PartialGeneral privacy/account controls documented; this table does not assert an unsupported universal deletion timeline.UnknownNo training claim asserted here without clearer current policy language.PartialChat/transcript handling documented; other retention depends on data type.VerifiedRaw call audio deleted after real-time transcription; text retained.
Nomi27 Apr 2026VerifiedAccount deletion described as deleting personal information within roughly 28 days of confirmation.PartialPolicy references a training archive and says deleted information there is no longer attributable to the user.PartialMost personal information is not retained after account deletion, subject to stated archive/legal exceptions.UnknownNo raw-call-audio retention claim asserted here.
Candy.ai30 Jul 2026VerifiedAccount-data deletion on request is described, subject to legal/contract exceptions.VerifiedDe-identified/anonymized interactions may be used for model development, datasets and internal research; human review may occur on de-identified/anonymized interactions.VerifiedAccount data can be retained after inactivity; debug logs are stated to auto-delete after 30 days.UnknownNo precise live-call raw-audio retention statement verified here.
Kupid AI2 May 2023VerifiedWithdrawal of consent and right-to-erasure language describes account/personal-data deletion.UnknownNo current explicit training/use statement verified from the public policy.PartialRights and processing purposes are described, but policy freshness is materially weaker than the other rows.UnknownNo specific voice-retention statement verified.

Four checks before you share something personal

1. Account deletion is not chat deletion

Deleting one conversation, one memory, an account or a billing record can trigger different retention rules. Check the specific control you need.

2. “Anonymized” is a separate claim

A policy may describe de-identifying or anonymizing interactions for research or model development. That is different from saying the original conversation is never processed for improvement.

3. Audio and transcripts can diverge

A voice product may discard raw audio but keep a transcript. For continuity and privacy, both layers matter.

4. Policy freshness matters

An old policy can still be legally operative, but a stale revision date creates more uncertainty when the product has changed substantially since publication.

COMMERCIAL ROUTE · SEPARATE FROM PRIVACY FIT

Referral payout does not change the policy evidence.

Affiliate disclosure: LarkMetric may earn an affiliate commission from an eligible referral. Privacy evidence is evaluated separately from payout and route availability.

Checking whether the current supported referral route is available for your location…

Related evidence

Policy evidence is one layer

A privacy policy describes what a provider publicly commits to or discloses. It does not prove what an app stores on-device, sends over the network or how users experience privacy boundaries in intimate use. Independent 2026 research helps define those separate layers.

App-level ecosystem risks

Brigham, Qin and Kohno identified 489 AI companion apps and systematically walked through a stratified sample of 30, including risks around sensitive-data collection and sharing. LarkMetric uses this as context, not as a substitute for product-specific policy evidence.

Brigham et al. - 2026 preprint

Forensic and network behavior

Comeaux and co-authors examined six companion apps using device acquisition, network interception and file-system analysis, reporting local artifacts, undocumented APIs and third-party tracking. That is a different evidence layer from reading public policies.

Comeaux et al. - DFRWS EU 2026

User privacy boundaries

Ma and co-authors interviewed 17 people about privacy in human-AI romantic relationships and found concerns including conversation exposure, anonymity and changing boundaries as intimacy deepened. Policy text alone cannot measure those lived effects.

Ma et al. - CHI 2026

Reusable policy snapshot

The structured LarkMetric snapshot behind this page contains the checked policy dates, source URLs and DOCUMENTED / PARTIAL / UNKNOWN labels for the four products shown here. It contains no user data or conversation data.

Download the JSON evidence snapshot

Primary sources

LarkMetric uses public policy text as DOCUMENTED evidence. It does not claim that a policy proves actual security, encryption quality or every backend behavior.

Evidence checked 18 Sep 2026. This is informational product-policy research, not legal advice or a security certification.