Privacy guides

Is It Safe to Tell an AI Companion Personal Things?

12 min read · September 1, 2026 · Facts verified September 1, 2026

Short answer: sharing low-risk context with an AI companion can be a reasonable choice after you inspect the policy and settings. It is not risk-free. No app in this guide should be treated as completely private or secure, and a warm conversation can make it easy to forget that your words are still data processed by a company and its providers.

Disclosure: we make Nola, one of the products discussed below. This is a neutral decision guide built from dated, first-party policy and help-page statements. Privacy policies are company statements, not guarantees. We compare what each company publishes, not what an independent security audit might prove.

Start with the consequence, not the feeling

The useful question is not simply, "Is this personal?" A story about feeling overlooked at work is personal, but it can often be told without names, employer details, or an exact location. A password reset code is not emotionally meaningful, yet exposing it can cause immediate harm.

Before typing, ask: what would happen if this exact text reached the wrong person? If the answer includes financial loss, account takeover, physical danger, legal exposure, or harm to someone else, keep it out. If the risk comes mainly from identification, remove names and precise details. An AI companion usually needs the shape of the situation, not a complete dossier.

What data an AI companion conversation can involve

A privacy decision has several layers. Treating "the chat" as one object hides the important differences.

Deleting one layer may not delete the others. A chat can disappear from history while a saved memory remains. An account deletion can still leave legally required billing records. A temporary mode can avoid history and training while preserving a short safety copy. Read each promise at the level it describes.

AI companion privacy policies compared

Scroll the table sideways to see all policy fields →

AppTraining statement or controlDeletion and retention evidenceConcrete control or advantageImportant limit
NolaDoes not use personal conversations to train generative AI modelsUsers may request access, correction, deletion, or a copy, subject to legal and technical limitsClear no-sale and training languageTrusted AI infrastructure providers may process relevant text; limited authorized human access can occur for stated purposes
NomiNot clearly resolved in the reviewed policyFull account deletion is offered; policy says about 28 days after confirmation, subject to exceptionsSame history supports continuity across text and voice interactionsIndividual messages cannot be deleted
PiAccount setting to opt out of model trainingIndividual-message deletion; deleted inputs generally retained no more than 15 days, with exceptions; outputs may be retained indefinitely for limited stated purposesVisible, editable cross-chat memories and an emotion-inference opt-outPolicy permits longer retention in listed cases
KindroidNot clearly resolved in the reviewed policyChats and generated media retained until a specific AI or the account is deletedStates encryption at rest and in transit, plus a documented five-system memory designAutomated scans review recent context; an appeal can authorize human decryption of the flagged context; messages cannot be individually deleted
ReplikaThird-party AI providers are contractually barred from training on minimized or de-identified response data; limited anonymized internal improvement use is describedAccount deletion removes chat history; some messages and preferences may be retained up to 60 days after the relationship endsConversation content is stated not to be used for marketing or advertisingFull conversation history cannot be deleted without deleting the account
ChatGPTPersonal users can turn off model improvement for new conversationsTemporary Chat can keep chats out of history and training, with an up-to-30-day safety copyA well-documented Temporary Chat mode and separate memory controlsDeleting a chat alone may not remove a saved memory
ClaudeConsumer users can opt out of model improvement; Incognito chats are not used to improve ClaudeOrdinary deleted chats leave history immediately and backend storage within 30 days; longer training, feedback, and safety categories are documentedIncognito mode plus editable topic and project memoriesDeleting a conversation may not remove its separate memory entry
Character.AIGenerative-model training opt-out documented for EEA and UK usersNo complete current retention or deletion schedule was captured in the reviewed sourcesTwo-way Character Calls and a no-sale statementNo supported global training opt-out or claim that conversations are completely private

Policy checks are dated September 1, 2026. Blank or unresolved fields are not evidence of either good or bad practice. They mean the reviewed first-party material did not answer the question clearly.

How to read training language

Look for a sentence that answers three points: whether conversation content is used to train generative models, whether the default differs by plan or region, and whether the control affects old data or only new conversations.

ChatGPT says personal users can switch off "Improve the model for everyone," after which new conversations are not used for training. Claude says users can turn off model improvement, while data already in a training run or trained model is not pulled back. Character.AI documents an opt-out for EEA and UK users, not a global control. Nomi and Kindroid did not clearly resolve generative-model training of private chat content in the reviewed material. That uncertainty belongs in the decision, not under a confident guess.

Nola does not use personal conversations to train generative AI models. Nola also states that it does not sell conversations or personal information. Relevant text may still be processed by trusted AI infrastructure providers to produce replies.

Deletion is a sequence, not one button

Check four separate actions: deleting an individual message, deleting a whole conversation, clearing memory, and deleting the account. Nomi and Kindroid say individual messages cannot be deleted. Replika lets users manage Memory entries, but its help material says deleting all conversation history requires account deletion. Pi permits immediate removal of individual messages from conversation history.

For general assistants, memory needs a second pass. ChatGPT says fully removing a remembered fact can require deleting both the saved memory and the chat where it appeared. Claude says a related memory entry may remain when its conversation is deleted, though users can delete memories separately. This is why "I deleted the chat" is not always the end of the data trail.

Temporary and incognito chats have limits

ChatGPT Temporary Chats do not appear in history, do not create new memories, and are not used for model improvement while they remain temporary. OpenAI says a safety copy may remain for up to 30 days, and a personalized temporary chat can reference existing memory. Data sent through a third-party action follows that recipient's policy.

Claude says Incognito chats do not enter chat history or memory and are not used to improve Claude. Ordinary consumer deletion is described as immediate from history and within 30 days from backend storage. Separate rules apply to safety-flagged content, opted-in training data, feedback, legal duties, and organization-managed accounts. "Temporary" means a narrower data path, not invisibility.

What not to tell an AI companion

Keep credentials and high-consequence identifiers out of every conversational app:

For emotionally sensitive stories, minimize rather than silence yourself. "A manager at work" may be enough instead of a name and company. "A family member has a health issue" may be enough instead of a full record. You can describe a conflict accurately while changing irrelevant details. If an exact fact matters later, store it somewhere designed for that risk level.

The 10-point privacy checklist

  1. Training: Is consumer chat used for generative-model training by default, by opt-in, or not at all?
  2. Chat deletion: Can you delete one message and a whole conversation?
  3. Account deletion: What disappears, what remains, and on what schedule?
  4. Retention: Are ordinary, deleted, safety-flagged, feedback, and billing records treated differently?
  5. Encryption: Does the company make a specific at-rest or in-transit claim? Do not translate that into end-to-end encryption.
  6. Advertising: Is conversation content used for ads? What analytics or attribution data is collected?
  7. Memory: Can you view, correct, pause, or clear what the app remembers?
  8. Temporary mode: Does it avoid history, memory, and training, and is a safety copy retained?
  9. Human and provider access: Who can process or review content, for what reason, and under what controls?
  10. Boundaries: Does the service clearly explain age, ordinary safety, and human-help limits?

Use the checklist with a low-stakes sample before a deeply personal conversation. Our broader AI companion buyer's guide adds purpose, memory, tools, and pricing. For continuity specifically, see AI companions with memory. For cost, use the free and affordable options guide.

Where Nola fits

Nola is built for open-ended emotional conversation, relevant continuity across conversations, pattern noticing, and moving from words into a grounding, breathing, reflection, or sleep tool when useful. Her privacy position is unusually direct about training and sale, while also naming real limits: trusted providers process relevant context, authorized human access can occur for support, debugging, safety, security, abuse review, legal obligations, or a user-requested investigation, and chats are not watched in real time by therapists or staff.

That does not make Nola completely private or secure. It makes the stated trade-off easier to evaluate. If you want relationship-style roleplay, Replika's avatars, roleplay options, and voice features may fit better. If you want general research and work features, ChatGPT or Claude cover a broader job. If your priority is a configurable, multi-layer memory system, Kindroid documents more memory components. Nola is our recommendation when the job is emotional continuity plus useful in-app tools, with privacy boundaries stated in plain language.

Read the full Nola privacy policy and safety page before deciding. You can also compare category fit in our AI companion apps guide and see focused trade-offs in Nola vs Replika and Nola vs ChatGPT.

Methodology and source ledger

We reviewed current first-party privacy policies, terms, pricing pages, and help documentation captured on September 1, 2026. We recorded only explicit claims about consumer products, kept regional controls regional, separated chat deletion from memory and account deletion, and marked unanswered questions as unresolved. We did not run security tests, inspect company systems, rank privacy, or treat marketing language as proof.

FAQ: AI companion privacy

Is it safe to tell an AI companion personal things?

It can be reasonable to share low-risk personal context after checking the policy and controls, but no AI companion is completely private or secure. Avoid secrets that could cause serious harm if exposed, use the least identifying detail you need, and review training, memory, deletion, retention, provider access, and temporary-chat settings first.

Do AI companion apps train on private conversations?

Policies differ. Some companies say conversations are excluded from generative-model training, some provide an opt-out, and some do not clearly resolve the question. Check the current policy and settings for the exact consumer product you use. A vague statement about improving the service is not a clear answer about generative-model training.

Does deleting a chat delete an AI companion's memory?

Not always. Chat history, saved memory, summaries, and account records can be separate systems. ChatGPT and Claude both document cases where deleting a conversation does not by itself remove a related saved memory. Check each memory area and deletion control separately.

What should I never share with an AI companion?

Do not share passwords, authentication codes, private keys, full payment-card or bank details, government ID numbers, or another person's confidential information. Avoid exact addresses, detailed schedules, and identifiable workplace or medical records when a less specific description will do.

Are privacy policies proof that an AI companion is safe?

No. Privacy policies are company statements, not guarantees. They explain stated practices and legal commitments, but they do not prove that a service is completely private, secure, error-free, or immune from unauthorized access. Use policy language as one part of a practical risk decision.

Sources checked September 1, 2026

First-party sources used: Nola's privacy policy; Nomi privacy and account deletion; Pi privacy and memory controls; Kindroid legal, moderation, and FAQ; Replika privacy and account deletion; OpenAI's training control, Temporary Chat FAQ, and memory FAQ; Anthropic's privacy policy, retention guide, and memory guide; and Character.AI's privacy summary and training settings.

Talk personally without pretending privacy is absolute.

Nola offers warm conversation, relevant continuity, useful tools, and direct privacy boundaries. Free to start.

Get Nola free