Blog Building
What happens to what you say to a companion app
The more useful this kind of app is, the more it knows.
A companion app is useful in proportion to how much you tell it. That is the whole design, and it means the intimacy and the data sensitivity are not two separate topics. They are the same topic.
We build one, so this is not a neutral article. It is the article I would want somebody to read before choosing any of these, including ours.
Five questions worth asking
Every one of these is answerable from a privacy policy that is written honestly. If you cannot find the answer in a few minutes, that is itself the answer.
What is stored? The transcript, or the transcript plus audio, or a derived summary. There is a real difference between a product that keeps what you said and one that keeps a working memory of it.
For how long? A specific period is a good sign. Indefinitely, or no statement at all, usually means nobody decided, which is worse than deciding badly.
Who can read it? Can a support agent open your conversation to fix a bug. Sometimes the answer has to be yes, and the honest version says so and says under what conditions.
Is it used for training? The important part is whether you can decline without losing the product. An opt out buried behind a support request is not really an opt out.
Can you delete it? In one action, from inside the app, and does deleting the account delete the history. This is the question most policies handle worst.
What a bad answer looks like
The pattern I would push back on is a policy that describes data handling entirely in terms of what the company will not do. We will never sell your data is a common opening line and it is close to meaningless, because selling was never the main risk.
The main risks are ordinary. Data kept forever because no one wrote a retention rule. Transcripts used for model improvement with consent buried in an onboarding checkbox. A support tool that shows more than it needs to. None of those are selling and all of them are what actually happens.
Also worth noticing: a completely free product with no visible way of making money deserves more scrutiny, not less. Somebody is paying for the servers. It is fair to know how.
What we do
Conversations are yours. They exist to give the companion continuity, which is the point of a companion. They are not a dataset we mine.
You can delete them. From inside the app, in one action, without asking us. Deleting your account deletes the history with it.
No selling and no ad targeting. The business model is subscriptions, which is the boring answer and the reason there is no incentive to do anything else with what you say.
We do not need your identity. The product works without knowing your legal name, and asking for more than the function requires is a habit worth avoiding.
The current details are in the privacy policy, and if anything there is unclear it is a drafting failure on our side rather than a subtlety on yours.
The part that is not about policy
There is a separate question that no policy answers, and it is worth sitting with.
You will say things to a companion app that you have not said to anyone. That is genuinely useful, and it is also a reason to notice whether the app has become the only place those sentences go.
The test I would use: is anything you say at 3am ever getting said in daylight, to a person. If yes, the app is doing what it should, which is making the thought sayable. If no, the private channel has become a way of not having the conversation, and no privacy policy protects you from that.
That is the risk this industry does not talk about, and it is the one I would watch in myself.
Common questions
Is talking to an AI private?
It depends entirely on the product, which is why the question is worth asking before you get attached to one. Nothing about the format makes it private by default.
Should I use my real name?
You do not need to for a companion app to work. If a product requires more identity than its function needs, that is worth noticing.
What is the risk, realistically?
For most people it is not a dramatic breach. It is ordinary things: a support agent reading a conversation, transcripts used for training without a clear opt out, or data kept indefinitely because nobody wrote a deletion policy.
Can I delete my history?
You should be able to, and it should take one action rather than an email to support. If a policy is vague about deletion, treat that as an answer.