AI Companion Privacy Checklist: Photos, Chats and Data
Before uploading a photo or intimate chat, assume it is sensitive data that may be copied, processed or retained. Check consent, permissions, retention and deletion first.
Are photos and intimate chats personal data?
Yes. They can identify a person, reveal sensitive preferences or expose another person's information even when a username is hidden.
The ICO AI rights guidance is a useful framework: ask what is collected, why it is needed, who receives it, how long it is kept and how you can exercise rights. A privacy policy is more useful when you map it to the exact feature you plan to use.
| Before upload | Question |
|---|---|
| Consent | Does every identifiable person agree? |
| Purpose | Is the upload necessary? |
| Retention | How long are files and prompts kept? |
| Sharing | Who processes or moderates them? |
| Deletion | Can you remove the source and output? |
What should you compare next?
Once the answer is clear, use the relevant product reviews to compare fit, memory, media, privacy, price and cancellation terms before visiting a provider.
What should you remove from a photo before uploading?
Remove faces, location metadata, documents, badges, backgrounds and any other detail that identifies a real person unless it is necessary and consented.
Crop or use a synthetic reference instead of a personal photo. Do not upload a partner's or child's image to make a companion more realistic. Check whether the service creates public links or reusable character assets.
- EXIF location and device metadata
- Names, addresses, school or workplace details
- Other people in the frame
- Tattoo, license plate and document details
Do AI companion apps keep chats after deletion?
Possibly, depending on the provider's retention, backup, safety and legal obligations; deletion should be verified rather than assumed.
Compare the policies of Nomi AI, Kindroid, Replika and Character.AI directly. Their products and disclosures differ, and a general claim about the whole category is not reliable. The provider's current policy controls the answer.
- Look for chat, image, audio and backup retention.
- Check whether training or improvement uses your content.
- Find the deletion request path before sign-up.
What if you already uploaded something sensitive?
Delete the content from the service and your devices, rotate compromised credentials and request erasure if the upload could identify you or someone else.
If the content involves another person, tell them and follow the provider's reporting or deletion process. Preserve only the evidence needed for a report. Do not upload more personal information to ask for support.
Which privacy controls should you compare?
Prioritize readable policies, minimal data collection, visible memory controls, account deletion and a clear support contact.
Read the Nomi AI and Kindroid reviews as comparison pages, not privacy certifications. Re-check the official policy when a feature, plan or region changes. Privacy is a process you can audit, not a permanent badge.
Sources and review note
These primary sources support the workflow or risk framing. Product features, prices and regional availability should still be checked on the official provider page before payment.
Start with an internal review so you can check fit, limits and privacy notes before an affiliate visit.