Is It Safe to Tell an AI Companion Personal Things?
Short answer: sharing low-risk context with an AI companion can be a reasonable choice after you inspect the policy and settings. It is not risk-free. No app in this guide should be treated as completely private or secure, and a warm conversation can make it easy to forget that your words are still data processed by a company and its providers.
Disclosure: we make Nola, one of the products discussed below. This is a neutral decision guide built from dated, first-party policy and help-page statements. Privacy policies are company statements, not guarantees. We compare what each company publishes, not what an independent security audit might prove.
Start with the consequence, not the feeling
The useful question is not simply, "Is this personal?" A story about feeling overlooked at work is personal, but it can often be told without names, employer details, or an exact location. A password reset code is not emotionally meaningful, yet exposing it can cause immediate harm.
Before typing, ask: what would happen if this exact text reached the wrong person? If the answer includes financial loss, account takeover, physical danger, legal exposure, or harm to someone else, keep it out. If the risk comes mainly from identification, remove names and precise details. An AI companion usually needs the shape of the situation, not a complete dossier.
What data an AI companion conversation can involve
A privacy decision has several layers. Treating "the chat" as one object hides the important differences.
- Account data: email address, login provider, subscription status, and billing records.
- Conversation content: the text, voice input, images, or files you send, plus generated replies.
- Memory data: saved facts, summaries, preferences, journals, or other context used in later conversations.
- Technical data: device, browser, IP address, logs, diagnostics, and security signals.
- Usage and marketing data: visits, installs, purchases, campaign attribution, and interactions with product features.
- Provider copies: text or context processed by cloud, AI, analytics, payment, support, or security providers.
Deleting one layer may not delete the others. A chat can disappear from history while a saved memory remains. An account deletion can still leave legally required billing records. A temporary mode can avoid history and training while preserving a short safety copy. Read each promise at the level it describes.
AI companion privacy policies compared
Scroll the table sideways to see all policy fields →
| App | Training statement or control | Deletion and retention evidence | Concrete control or advantage | Important limit |
|---|---|---|---|---|
| Nola | Does not use personal conversations to train generative AI models | Users may request access, correction, deletion, or a copy, subject to legal and technical limits | Clear no-sale and training language | Trusted AI infrastructure providers may process relevant text; limited authorized human access can occur for stated purposes |
| Nomi | Not clearly resolved in the reviewed policy | Full account deletion is offered; policy says about 28 days after confirmation, subject to exceptions | Same history supports continuity across text and voice interactions | Individual messages cannot be deleted |
| Pi | Account setting to opt out of model training | Individual-message deletion; deleted inputs generally retained no more than 15 days, with exceptions; outputs may be retained indefinitely for limited stated purposes | Visible, editable cross-chat memories and an emotion-inference opt-out | Policy permits longer retention in listed cases |
| Kindroid | Not clearly resolved in the reviewed policy | Chats and generated media retained until a specific AI or the account is deleted | States encryption at rest and in transit, plus a documented five-system memory design | Automated scans review recent context; an appeal can authorize human decryption of the flagged context; messages cannot be individually deleted |
| Replika | Third-party AI providers are contractually barred from training on minimized or de-identified response data; limited anonymized internal improvement use is described | Account deletion removes chat history; some messages and preferences may be retained up to 60 days after the relationship ends | Conversation content is stated not to be used for marketing or advertising | Full conversation history cannot be deleted without deleting the account |
| ChatGPT | Personal users can turn off model improvement for new conversations | Temporary Chat can keep chats out of history and training, with an up-to-30-day safety copy | A well-documented Temporary Chat mode and separate memory controls | Deleting a chat alone may not remove a saved memory |
| Claude | Consumer users can opt out of model improvement; Incognito chats are not used to improve Claude | Ordinary deleted chats leave history immediately and backend storage within 30 days; longer training, feedback, and safety categories are documented | Incognito mode plus editable topic and project memories | Deleting a conversation may not remove its separate memory entry |
| Character.AI | Generative-model training opt-out documented for EEA and UK users | No complete current retention or deletion schedule was captured in the reviewed sources | Two-way Character Calls and a no-sale statement | No supported global training opt-out or claim that conversations are completely private |
Policy checks are dated September 1, 2026. Blank or unresolved fields are not evidence of either good or bad practice. They mean the reviewed first-party material did not answer the question clearly.
How to read training language
Look for a sentence that answers three points: whether conversation content is used to train generative models, whether the default differs by plan or region, and whether the control affects old data or only new conversations.
ChatGPT says personal users can switch off "Improve the model for everyone," after which new conversations are not used for training. Claude says users can turn off model improvement, while data already in a training run or trained model is not pulled back. Character.AI documents an opt-out for EEA and UK users, not a global control. Nomi and Kindroid did not clearly resolve generative-model training of private chat content in the reviewed material. That uncertainty belongs in the decision, not under a confident guess.
Nola does not use personal conversations to train generative AI models. Nola also states that it does not sell conversations or personal information. Relevant text may still be processed by trusted AI infrastructure providers to produce replies.
Deletion is a sequence, not one button
Check four separate actions: deleting an individual message, deleting a whole conversation, clearing memory, and deleting the account. Nomi and Kindroid say individual messages cannot be deleted. Replika lets users manage Memory entries, but its help material says deleting all conversation history requires account deletion. Pi permits immediate removal of individual messages from conversation history.
For general assistants, memory needs a second pass. ChatGPT says fully removing a remembered fact can require deleting both the saved memory and the chat where it appeared. Claude says a related memory entry may remain when its conversation is deleted, though users can delete memories separately. This is why "I deleted the chat" is not always the end of the data trail.
Temporary and incognito chats have limits
ChatGPT Temporary Chats do not appear in history, do not create new memories, and are not used for model improvement while they remain temporary. OpenAI says a safety copy may remain for up to 30 days, and a personalized temporary chat can reference existing memory. Data sent through a third-party action follows that recipient's policy.
Claude says Incognito chats do not enter chat history or memory and are not used to improve Claude. Ordinary consumer deletion is described as immediate from history and within 30 days from backend storage. Separate rules apply to safety-flagged content, opted-in training data, feedback, legal duties, and organization-managed accounts. "Temporary" means a narrower data path, not invisibility.
What not to tell an AI companion
Keep credentials and high-consequence identifiers out of every conversational app:
- passwords, one-time codes, recovery phrases, API keys, or private encryption keys;
- full card, bank, tax, passport, national ID, or insurance numbers;
- an exact home address, live location, door code, or predictable schedule;
- confidential employer, client, legal, or unreleased business information;
- another person's messages, records, photos, or identifying details without permission.
For emotionally sensitive stories, minimize rather than silence yourself. "A manager at work" may be enough instead of a name and company. "A family member has a health issue" may be enough instead of a full record. You can describe a conflict accurately while changing irrelevant details. If an exact fact matters later, store it somewhere designed for that risk level.
The 10-point privacy checklist
- Training: Is consumer chat used for generative-model training by default, by opt-in, or not at all?
- Chat deletion: Can you delete one message and a whole conversation?
- Account deletion: What disappears, what remains, and on what schedule?
- Retention: Are ordinary, deleted, safety-flagged, feedback, and billing records treated differently?
- Encryption: Does the company make a specific at-rest or in-transit claim? Do not translate that into end-to-end encryption.
- Advertising: Is conversation content used for ads? What analytics or attribution data is collected?
- Memory: Can you view, correct, pause, or clear what the app remembers?
- Temporary mode: Does it avoid history, memory, and training, and is a safety copy retained?
- Human and provider access: Who can process or review content, for what reason, and under what controls?
- Boundaries: Does the service clearly explain age, ordinary safety, and human-help limits?
Use the checklist with a low-stakes sample before a deeply personal conversation. Our broader AI companion buyer's guide adds purpose, memory, tools, and pricing. For continuity specifically, see AI companions with memory. For cost, use the free and affordable options guide.
Where Nola fits
Nola is built for open-ended emotional conversation, relevant continuity across conversations, pattern noticing, and moving from words into a grounding, breathing, reflection, or sleep tool when useful. Her privacy position is unusually direct about training and sale, while also naming real limits: trusted providers process relevant context, authorized human access can occur for support, debugging, safety, security, abuse review, legal obligations, or a user-requested investigation, and chats are not watched in real time by therapists or staff.
That does not make Nola completely private or secure. It makes the stated trade-off easier to evaluate. If you want relationship-style roleplay, Replika's avatars, roleplay options, and voice features may fit better. If you want general research and work features, ChatGPT or Claude cover a broader job. If your priority is a configurable, multi-layer memory system, Kindroid documents more memory components. Nola is our recommendation when the job is emotional continuity plus useful in-app tools, with privacy boundaries stated in plain language.
Read the full Nola privacy policy and safety page before deciding. You can also compare category fit in our AI companion apps guide and see focused trade-offs in Nola vs Replika and Nola vs ChatGPT.
Methodology and source ledger
We reviewed current first-party privacy policies, terms, pricing pages, and help documentation captured on September 1, 2026. We recorded only explicit claims about consumer products, kept regional controls regional, separated chat deletion from memory and account deletion, and marked unanswered questions as unresolved. We did not run security tests, inspect company systems, rank privacy, or treat marketing language as proof.
FAQ: AI companion privacy
Is it safe to tell an AI companion personal things?
It can be reasonable to share low-risk personal context after checking the policy and controls, but no AI companion is completely private or secure. Avoid secrets that could cause serious harm if exposed, use the least identifying detail you need, and review training, memory, deletion, retention, provider access, and temporary-chat settings first.
Do AI companion apps train on private conversations?
Policies differ. Some companies say conversations are excluded from generative-model training, some provide an opt-out, and some do not clearly resolve the question. Check the current policy and settings for the exact consumer product you use. A vague statement about improving the service is not a clear answer about generative-model training.
Does deleting a chat delete an AI companion's memory?
Not always. Chat history, saved memory, summaries, and account records can be separate systems. ChatGPT and Claude both document cases where deleting a conversation does not by itself remove a related saved memory. Check each memory area and deletion control separately.
What should I never share with an AI companion?
Do not share passwords, authentication codes, private keys, full payment-card or bank details, government ID numbers, or another person's confidential information. Avoid exact addresses, detailed schedules, and identifiable workplace or medical records when a less specific description will do.
Are privacy policies proof that an AI companion is safe?
No. Privacy policies are company statements, not guarantees. They explain stated practices and legal commitments, but they do not prove that a service is completely private, secure, error-free, or immune from unauthorized access. Use policy language as one part of a practical risk decision.
Sources checked September 1, 2026
First-party sources used: Nola's privacy policy; Nomi privacy and account deletion; Pi privacy and memory controls; Kindroid legal, moderation, and FAQ; Replika privacy and account deletion; OpenAI's training control, Temporary Chat FAQ, and memory FAQ; Anthropic's privacy policy, retention guide, and memory guide; and Character.AI's privacy summary and training settings.
Talk personally without pretending privacy is absolute.
Nola offers warm conversation, relevant continuity, useful tools, and direct privacy boundaries. Free to start.
Get Nola free