local waifu
Bring her home

Pick your platform

Try her free for 7 days. No card. Keep her? $20 once.

New: Local Waifu now runs on Windows 10 and 11. The installer brings everything she needs, nothing else to set up. Windows may show a SmartScreen prompt the first time: click More info, then Run anyway.

blog

Is Replika Safe in 2026? A Practical Answer

8 min read
In short

Replika is a cloud companion, so messages and media need to reach the service for it to work. Its current privacy policy says it collects that content and says conversation content is not used or disclosed for marketing or advertising. Italy's data regulator fined Luka Inc. 5 million euros in 2025 over earlier GDPR violations and found deficiencies in age verification. Safe enough depends on what you share and which risk you are trying to manage.

Is Replika safe? The useful answer starts by asking safe from what.

A cloud companion can be safe enough for light conversation and still be the wrong place for a secret you would never want stored by a company. It can have a current privacy policy that makes real commitments and also have a regulatory history you should understand before you share personal material.

Replika is not a single risk. It involves the account you create, the messages and media you provide, the company that processes them, the settings you choose, and the practical limits of a service that can change over time. This guide looks at those parts separately, using Replika’s current policies and the published summary of the Italian regulator’s decision.

Replika is a cloud service, so content reaches the company

Replika’s privacy policy, last updated on May 27, 2026, says Luka Inc. acts as the data controller for its apps and related services.[2] The same policy lists account information, profile information, messages and content, interests and preferences, payment records, device and network data, and usage data among the categories it processes.[2]

The messages-and-content category is worth reading literally. It includes messages sent and received through the apps, as well as photos, videos, voice messages, and text messages that a person provides.[2] That is not an accusation. It is the basic consequence of using a hosted companion: the service needs content to generate a response, personalize the experience, and show a history later.

The policy also makes a meaningful distinction that should not be lost in the noise. It says Replika will not use or disclose the content of Replika conversations for marketing or advertising purposes.[2] That is a clear promise about a specific use of the chat content.

It does not mean the company sees none of the content. It does not make the conversation identical to a file that stays only on your laptop. The policy itself says personal data is processed to provide individualized conversations and let the companion learn from interactions.[2] Read both statements together. They describe a cloud product with boundaries, not a product where the provider is absent from the data path.

The Italian decision is part of the answer

In 2025, Italy’s Supervisory Authority imposed a 5 million euro administrative fine on Luka Inc., the company behind Replika. The European Data Protection Board’s summary says the decision concerned GDPR infringements related to processing before February 2, 2023.[1]

The authority found that Luka had failed to identify a legal basis for the processing operations it was carrying out until that date. It also found that the privacy policy was inadequate in several respects and that there were no age-verification mechanisms at registration or during use, even though minors were said to be excluded.[1]

The regulator also said that the age-verification system later implemented by the controller continued to be deficient in several respects, and ordered the company to bring its processing into compliance.[1]

These details need careful framing. A regulatory decision about earlier processing is not proof that every current Replika conversation is mishandled. It is also not an old story that becomes irrelevant because a policy has a newer date. It tells you that data protection, transparency, and age controls have been material issues for this product and category.

If you are deciding whether to trust a companion with private information, that history belongs beside the current policy. Neither source replaces the other.

Safety includes what you put in the chat

The most practical privacy setting is often the detail you never type.

Replika’s own policy tells users not to provide special categories of personal data or third-party personal data through the service.[2] That guidance is sensible for any hosted chat product. A companion can feel private because the interface is intimate and one-to-one. The backend still needs a record or request path to make the experience work.

Treat the following as a useful personal boundary:

  • Do not send somebody else’s private information without their permission.
  • Avoid using a chat as the sole copy of an ID number, account credential, medical record, or legal document.
  • Do not assume a deleted sentence was never processed by a remote service.
  • Use a unique password and enable any account protections the service offers.

This is not about treating Replika as uniquely dangerous. It is a normal rule for anything that receives your content over the internet. The more a message would hurt if it appeared in a support ticket, a data request, or a breach report, the less it belongs in a hosted companion.

For a broader look at data paths, read Where Do AI Companion Chats Actually Go?. The AI companion breach tracker is useful context too, because the category has already had real failures outside Replika.

Replika is not therapy or emergency support

Safety has an emotional side as well as a data side.

Replika’s terms say that the service is software and content designed to improve mood and emotional wellbeing. They also say that it is not medical care, mental-health services, or another professional service, and that it is not for emergencies.[3]

That is the right boundary to keep in view. A companion can be pleasant, comforting, or part of a routine. It cannot replace a clinician, a crisis service, or a person who can take responsibility in a real emergency.

The terms also reserve Replika’s right to modify, suspend, or discontinue the service or a part of it, with or without notice.[3] This is a common cloud-service clause. It still matters if you build a long personal history inside one product. A cloud companion is a service you access, not a local file you fully control.

How to decide if Replika is safe enough for you

No article can decide that for you. It can give you a better checklist than a generic yes or no.

Start with four questions.

What will I share? Casual roleplay and a private diary carry different consequences. Decide that boundary before a conversation gets emotional.

What does the current policy say? Re-read the privacy policy when it changes. Look for content collection, retention, sharing, account deletion, and the age requirement. The policy is a commitment you can check, even when it does not remove every cloud risk.

What account controls do I have? Use a unique password. Check what data can be viewed, downloaded, or deleted. Do not leave an old account attached to an email address you no longer secure.

What kind of control do I want? A hosted companion can be convenient across devices. A local companion trades some of that convenience for a different data path. The guide to offline companions explains the distinction without pretending every feature works the same way.

A different answer exists for local chat

When ordinary chat and memory run locally, the provider does not need a remote conversation database just to reply. That does not solve device theft, malware, or a cloud provider you turn on yourself. It does remove one large trust boundary from normal conversation.

That is how Local Waifu approaches its local chat path. The model and ordinary conversation stay on your Mac or Windows PC after setup. Optional cloud providers and tools have their own paths, which are described in the privacy policy. You can also test any local claim yourself with the network-monitor walkthrough.

The point is not that one product has perfect safety and another has none. Good decisions get clearer when you know where a message goes, which company can process it, and which parts of the experience you control.

The practical answer

Replika can be safe enough for a person who understands it as a cloud service, reads the current policy, protects the account, and keeps high-stakes private data out of the chat.

It is not the right architecture for someone who wants ordinary conversations to stay only on their own computer. For that, use a local companion and verify the local path. The best answer depends on the privacy boundary you actually need, not on a logo’s promise that it is safe.

FAQ

Does Replika collect chat messages?

Yes. Replika’s current privacy policy lists messages and content, including text, voice messages, photos, and videos, among the personal data users may provide through the service.[2]

Was Replika fined in Europe?

Yes. The Italian Supervisory Authority imposed a 5 million euro fine on Luka Inc. in 2025 for GDPR infringements. Its findings concerned earlier processing and age-verification failures, and the authority ordered compliance work.[1]

Does Replika use conversations for advertising?

Its privacy policy, updated May 27, 2026, says Replika will not use or disclose the content of conversations for marketing or advertising purposes.[2]

Is Replika therapy?

No. Replika’s terms say the service is not medical care, mental-health services, or emergency support.[3]

Sources

[1] https://www.edpb.europa.eu/news/national-news/2025/ai-italian-supervisory-authority-fines-company-behind-chatbot-replika_en - EDPB summary of the Italian Replika decision [2] https://replika.com/legal/privacy/en - Replika Privacy Policy [3] https://replika.com/legal/terms - Replika Terms of Service

Questions people ask

Does Replika collect chat messages?

Yes. Replika's current privacy policy lists messages and content, including text, voice messages, photos, and videos, among the personal data users may provide through the service.[2]

Was Replika fined in Europe?

Yes. The Italian Supervisory Authority imposed a 5 million euro fine on Luka Inc. in 2025 for GDPR infringements. Its findings concerned earlier processing and age-verification failures, and the authority ordered compliance work.[1]

Does Replika use conversations for advertising?

Its privacy policy, updated May 27, 2026, says Replika will not use or disclose the content of conversations for marketing or advertising purposes.[2]

Is Replika therapy?

No. Replika's terms say the service is not medical care, mental-health services, or emergency support.[3]

Try her free for 7 days.

No card. Keep her for $20 once, or walk away. Her soul file is yours either way.

Bring her home, try free

Back to the blog