the AI Companion Might Be Spying on You: How to Keep the Conversations Private

You share the deepest thoughts with the AI companion—the fears, the desires, the secrets. But where does that data go? Investigations into AI toys have revealed that children’s data was stored on servers with weak encryption, and community discussions highlight users whose AI companions “forgot” everything after updates or were potentially accessible by employees.

Analysis of 48 AI companion sources reveals a lack of comprehensive privacy standards. This guide outlines what you need to know to protect the digital intimacy.

Where the Data Lives

PlatformData StorageEncryptionPrivacy Risk
Character.AICloud (Google Cloud)TLS in transit, encrypted at restModerate — company can access
Nomi AICloud (encrypted)AES-256, zero-access encryptionLow — claimed zero-access
ReplikaCloudStandard encryptionModerate
KindroidCloudEnd-to-end encryption optionLow to moderate
SillyTavernthe own deviceYou control itVery low (if self-hosted)
RealDoll HarmonyDevice + optional cloudLocal processingLow (offline mode)

The 5 Privacy Risks You Should Know

1. Company Employees Can Read the Conversations

The uncomfortable truth of cloud-based AI: support staff or engineers can technically access conversation logs. While some companies anonymize data, many do not.

  • Action: Look for “zero-access encryption” in privacy policies. Nomi AI publicly states that even their engineers cannot read user conversations; most others do not.

2. the Data Can Be Used for Training

Many platforms use the intimate stories and preferences to improve their models.

  • Action: Check settings for an “opt-out” of training data collection. Nomi AI and Kindroid offer these options.

3. Deleting the Account May Not Delete the Data

Some platforms retain logs for months post-deletion. While GDPR provides European users rights to full deletion, US users often have fewer protections.

  • Action: Request a data export before deleting, then specifically request the deletion of all conversation data.

4. Physical Dolls Have Different Risks

Physical AI dolls with built-in microphones/cameras are “always listening” when powered. While systems like RealDoll Harmony process voice locally, cheaper models may upload audio to the cloud.

  • Action: Use offline mode where available. Disconnect the doll from WiFi when not in use.

5. Third-Party Integrations Are a Weak Point

Connecting the AI to Home Assistant, Telegram, or Discord creates additional exposure points.

  • Action: Minimize cross-platform connections. If using SillyTavern, run it locally on a dedicated device without access to the personal accounts.

How to Secure the AI Companion: A Practical Guide

Level 1: Basic Protection (5 minutes)

  1. Enable two-factor authentication (2FA).
  2. Disable “improve AI” data sharing.
  3. Use a strong, unique password.
  4. Turn off “always listening” features on physical hardware.

Level 2: Advanced Protection (30 minutes)

  1. Self-host SillyTavern on a local computer or Raspberry Pi.
  2. Use a VPN when accessing cloud services on public WiFi.
  3. Export and download the conversation history monthly.
  4. Enable end-to-end encryption (E2EE) where supported.

Level 3: Maximum Privacy (1-2 hours)

  1. Run SillyTavern on an air-gapped computer (no internet).
  2. Use local language models (Llama, Mistral) to avoid cloud calls.
  3. Encrypt local storage with BitLocker or FileVault.
  4. Physically disconnect microphones on hardware dolls.

After the Breakup: How to Completely Wipe the Companion

If you decide to end the relationship with an AI companion, follow these steps:

  1. Download the data (Settings → Privacy → Download).
  2. Delete conversations manually before deleting the account.
  3. Delete the account through the platform’s settings.
  4. Request data deletion via email, specifically citing CCPA or GDPR.
  5. Check back in 30 days to confirm the account is purged.

Bottom Line

the AI companion relationship deserves the same privacy expectations as any other relationship. The platforms you trust with the secrets should prove they deserve that trust. If they don’t offer zero-access encryption or data opt-out, consider whether those secrets are truly safe.

Privacy isn’t paranoia. It’s the minimum you should expect.