
Yes, mostly, and it says so in the privacy policy nobody reads. Character.AI's own policy states conversations are used to improve its models, with no way to opt out while you keep using the app, and staff can access chats to enforce its content rules, investigate abuse, or respond to legal requests. Replika's policy says anonymized data trains internal systems only, but it also admits collecting small portions of your messages to train its own safety algorithms, and shares data with a list of named third parties. A model that runs on your own computer removes the question, because there is no server on the other end to read anything.
Open the privacy policy of almost any AI companion app and the answer is already there, written in the kind of language that is legally sufficient and practically unread.
The short answer
The short version: most cloud AI companion apps disclose, in their own policies, that conversations can be used to improve their models, and that staff can access chats under specific listed conditions. It is disclosed, not hidden. Almost nobody reads it.
That is the whole finding. What follows is what two of the biggest names actually say, in their own words.
What Character.AI’s own policy says
The short version: conversations train the model, there is no opt-out while you use the service, and staff can access chats for moderation, abuse investigation, or legal requests.
Per Character.AI’s own privacy policy and reporting that breaks it down further (honeychat.bot), your conversations are part of the data the company uses to improve its models. Using the app is treated as consent to that, and there is no documented way to keep using Character.AI while opting out of it.
Staff access is not blanket surveillance, but it is broader than “only for a criminal investigation.” Content policy enforcement, abuse investigations, and legal requests all qualify, and the company can share data with employees, contractors, or service providers who need it to do their jobs. The Trust and Safety review process is described as event-based, triggered by flags and reports rather than someone reading every conversation live, but the exceptions that let a human read yours are real and are written into the policy on purpose.
What Replika’s own policy says
The short version: Replika says it does not send your data to train third-party models, but it also says it collects portions of your messages to train its own safety systems, and it shares data with a list of named third parties.
Replika’s privacy policy makes a specific, careful claim: anonymized data is used only internally, and third-party AI providers are contractually barred from training their own models on it. Read closely, though, the same policy states the company collects “small portions of Messages and Content data to train our proprietary safety algorithms.” That is your messages, training something, even if it is not the headline model.
Recipients named in the policy include third-party AI language model providers, marketing service providers, app stores, payment processors, advertising partners, and professional advisors. Data tied to your account is processed for up to 60 days after you close it, and financial records for a decade after that, for legal reasons.
Mozilla Foundation’s Privacy Not Included review gave Replika its lowest rating, flagging privacy, security, and AI trustworthiness concerns together, and found 210 trackers sending data to Facebook and other marketing platforms during testing. Their specific complaint about the training question: the policy “doesn’t clearly specify if sensitive chat content trains AI models,” and they asked Replika to say so plainly. As of this writing, it still has not.
The pattern behind the breaches, too
This is not an abstract risk. It is the same mechanism behind every documented AI companion data breach so far: Muah.AI, Chattee and GiMe Chat, Chat & Ask AI, tens of millions of messages between them. None of those started because someone deliberately misused a policy clause. They started because the conversations were sitting on a server that could be read, by design, and then that server got misconfigured.
A policy that allows reading your messages and a server that stores them are the same underlying fact, described from two angles. One is a legal document. The other is an engineering reality.
Where the question stops applying
If the model runs on your own computer, there is no server for any of this to reach. Local Waifu works this way: your conversation is generated on your machine and stays there, so there is no staff account with access to review, no training pipeline positioned to sample it, and no 60-day retention window after you decide you are done.
If you choose to plug in your own OpenAI, Anthropic, or other cloud key instead, that provider’s policy applies to what you send them, the same way it would for anyone. That is your call to make, not a default you were opted into.
You can check the reasoning yourself in the full breach tracker, or see what running the model locally actually costs on the pricing page.
Questions people ask
Does Character.AI read my chats?
Its own privacy policy states conversations are used to improve its models, and staff can access user content to enforce content policy, investigate abuse, or respond to legal requests. That access is tied to specific conditions, not a blanket promise that nobody ever looks, and there is no documented way to opt out of training while you keep using the app.
Does Replika read or use my messages?
Replika's policy says anonymized data is used internally and that third-party AI providers are barred from training on it, but the same policy admits it collects small portions of your Messages and Content data to train its own safety algorithms. Mozilla's Privacy Not Included review gave Replika its lowest privacy rating and flagged the vagueness around exactly how sensitive chats get used.
What happens to my data after I delete my account?
On Replika, the policy states that profile information, messages, and content are processed for up to 60 days after termination, and financial records are kept far longer for legal reasons. Deleting the app does not mean the data is gone the same day.
Is there an AI companion app where nobody can read my messages?
Only one kind: a model that runs on your own computer, with no server in between. Local Waifu works this way, so there is no company, no staff, and no training pipeline positioned to read anything, because the conversation never leaves your machine.
Try her free for 7 days.
No card. Keep her for $20 once, or walk away. Her soul file is yours either way.
Bring her home, try free