
Most "is this app trustworthy" advice is vague. This is a ten-point checklist of specific, checkable questions covering data survival, export, verifiable local processing, breach history, pricing transparency, real deletion, legal compliance, the filter-versus-privacy distinction, and real memory versus a big context window. Score any app honestly against all ten before trusting it with months of real conversation.
Most advice on choosing an AI companion app amounts to “read the reviews” and “check if it feels trustworthy.” Neither is a real test. Here are ten specific, checkable questions instead, the kind you can actually run against a real app rather than a vibe.
1. Does your data survive the company closing?
The short version: if the company shuts down, does your relationship history disappear with it, or does it live somewhere you actually control?
A cloud-hosted companion’s memory of you lives on someone else’s server. If that company folds, gets acquired and shut down, or simply decides to sunset the product, months or years of conversation history can vanish with no warning and no recourse. A locally stored history survives on your own disk regardless of what happens to the company that made the app. This is the single most consequential item on this list, because it’s the one failure mode you cannot fix retroactively once it happens.
Think about what that actually means in practice. Someone who spent eight months building a relationship with a companion, sharing real things, working through a difficult period, having it be part of their routine, has no way to get any of that back once a company-hosted service disappears. Not a delayed inconvenience. Gone, permanently, the same way any account tied to a defunct company is gone. Whether that risk matters to you depends entirely on how much weight you put on the relationship continuing, but it’s worth deciding that consciously rather than discovering it the hard way.
2. Can you export your history whenever you want?
The short version: a real export function, not a support ticket you have to file and wait on, is the actual test.
Being able to leave with your own data is a basic form of respect a product can extend to you or withhold. Check for an actual, self-service export feature, not a policy that technically allows a request but routes it through a support queue with no stated timeline.
3. Is “runs locally” verifiable, or just a slogan?
The short version: don’t take the phrase on faith. A network monitor will show you the real behavior in about ten minutes.
“Runs locally” and “on-device AI” describe where the model processes, not necessarily the app’s entire network behavior. I’ve written a full walkthrough of how to check this yourself with a network monitor that asks permission before any connection fires, and a companion piece breaking down what the phrase actually promises versus what it implies. This is the item almost nobody actually checks, and it’s the one most likely to be technically true while implying something broader that isn’t.
4. Does the privacy policy name real companies, or hide behind vague language?
The short version: “we may share data with trusted partners” tells you nothing. A policy that names specific third parties by name is the one worth trusting.
A privacy policy specific enough to name the actual companies data goes to, and under what conditions, is a policy you can independently verify claim by claim. One that stays permanently vague gives you nothing to check against reality, which tends to be vague on purpose rather than by oversight.
5. Has the company had a breach, and did they disclose it honestly?
The short version: past incidents are the most honest signal available, because they describe what actually happened rather than what a policy promises.
This category has a real, documented breach history. I keep a running, sourced tracker of the actual incidents, which company, how many records, and where it was reported. A breach in the past isn’t automatically disqualifying, companies do improve, but how honestly and quickly it was disclosed tells you a great deal about how the next one will be handled.
6. Is the price clear before you commit, or does it reveal itself gradually?
The short version: a subscription that only shows its real monthly cost after you’ve already started using the app is designed to make you not notice.
Token-based pricing, usage tiers that only become clear with real use, and “starting at” prices that don’t reflect what an active user actually pays are common enough in this category to be worth checking specifically. A one-time price or a clearly stated flat subscription is easy to evaluate honestly before you commit anything.
7. Can you actually delete your data, not just deactivate your account?
The short version: “deactivate” and “delete” are different verbs, and a lot of products only offer the first one while implying the second.
Deactivation typically means your account stops being usable while your data stays on the company’s servers indefinitely. Real deletion means the data is actually gone. Check which one the app’s settings actually offer, and read the account-closure language closely, because the two get conflated in copy far more often than the underlying behavior actually matches. A genuinely local app sidesteps this question in an interesting way: deletion is just removing files from your own disk, something you can verify by looking rather than something you have to trust a company to actually carry out on servers you’ll never see.
8. Does it meet real legal requirements, or ignore them?
The short version: companion chatbot law is no longer hypothetical. Check whether the app actually discloses its AI nature and has a real crisis-referral mechanism.
Laws like California’s SB 243 and New York’s GBL Article 47 now specifically require AI disclosure and crisis-referral protocols for companion chatbots. I’ve written a plain-English breakdown of what SB 243 actually requires, including what compliance looks like in practice versus in a privacy policy nobody reads. An app with users in either state that shows no sign of either requirement is either exempt for a specific reason or behind on a real legal obligation, and it’s worth knowing which.
9. Does “no filter” mean private, or are those two separate questions?
The short version: removing content restrictions and protecting your privacy are architecturally unrelated. An app can do one without the other.
An app that markets itself as unfiltered has told you nothing about whether your messages are still routed through a server where they can be read, logged, or exposed in a breach. I’ve written the honest breakdown of why these are separate axes, and it’s worth checking both independently rather than assuming one implies the other.
10. Does it actually remember you, or does it just have a big context window?
The short version: a huge context window and real persistent memory are not the same feature, and the difference shows up the moment a new session starts with no memory of the last one.
A context window resets. Real memory writes facts to durable storage, retrieves them by meaning, and weights them by importance, surviving the app closing entirely. I’ve written the full technical difference and the honest, direct answer to whether an AI can really remember you, including where even a good memory system’s limits actually are. If an app’s pitch for “she remembers you” turns out to mean “the current conversation is long,” that’s the tell.
Scoring it honestly
There’s no certified passing score here, and treating this as a strict pass/fail misses the point. What matters is which specific items an app fails and why. A failure on export, breach disclosure, or real deletion protects you even after you’ve stopped using the product, and those are the three I’d weigh heaviest if you’re choosing between otherwise similar options. A failure on price transparency or filter clarity is more of an annoyance than a lasting risk. Run the actual checks, especially point 3, since it’s the one a network monitor answers in minutes rather than one you have to take on faith, and decide with real information instead of a feeling.
If you want to see how one product answers all ten honestly, it’s free to try, and the privacy policy is written specifically enough to check against everything above.
Questions people ask
How many of the 10 points does an app need to pass to be trustworthy?
There's no magic threshold, but treat any app failing more than two or three as a real warning sign, especially failures on data export, breach disclosure, or real deletion. Those three protect you even after you've stopped using the app, which is exactly when you have the least power to fix a bad decision.
Can a cloud-based AI companion pass this checklist?
Some of it, yes. Export, clear pricing, and real deletion are architecture-independent. Points 3, 5, and 10, verifiable local processing, no server-side breach exposure, and real persistent memory without a context-window sleight of hand, are structurally easier for a local app to satisfy, because the properties they're checking for follow directly from where the data lives.
Isn't this checklist just describing your own product?
It describes properties, not a specific app, and several of the ten (export, pricing clarity, real deletion) apply equally well to any well-run product regardless of architecture. Apply it to whatever you're using or considering, mine included, and judge honestly rather than taking the framework's existence as an argument in itself.
What's the single most overlooked item on this list?
Point 3, whether 'runs locally' is verifiable or just a slogan. Almost nobody actually checks it, and it's the one claim most likely to be technically true in a narrow sense while implying something broader that isn't.
Try her free for 7 days.
No card. Keep her for $20 once, or walk away. Her soul file is yours either way.
Bring her home, try free