Evergreen
AI Companion Privacy Questions to Ask
Before an intimate AI chat, check collection, training, human review, sharing, retention, deletion, export, account access, age rules, and the exact mode.
What Should You Ask Before Sharing Personal Information With an AI Companion?
Treat an AI companion conversation as data submitted to a service, not as a confidential human relationship. Before sharing health, sexual, financial, relationship, workplace, legal, identity, or location information, check what the exact product and mode collect, why the data are used, who can access them, how long they remain, and what deletion actually does.
The companion may sound private because it speaks to one person in an intimate voice. Interface intimacy is not a privacy guarantee.
Which service is receiving the conversation?
Start with the surface, account, and company.
The same model can appear in a standalone app, social platform, workplace account, API product, or third-party wrapper. Each route can have different terms, administrators, logs, retention, training choices, and sharing.
xAI's current privacy policy says it governs Grok in xAI's mobile app and website, while Grok used through X is governed by X's policies. It also warns that an employer-domain account may become linked to an enterprise subscription under the consumer terms. xAI privacy policy and xAI consumer terms
Do not stop after finding the company name. Confirm the app publisher, URL, login method, account type, and feature.
What information enters the system?
Conversation text is only the obvious part. A companion may process voice, video, images, uploaded files, contact or profile information, device data, location, usage history, feedback, purchases, and memory derived from previous chats.
Read the definitions of "input," "user content," "interaction," and "conversation history." Look for language about metadata and inferred interests. Check permissions at the operating-system level as well as the account settings.
Meta's current Privacy Policy includes interactions with Meta AI and related metadata among information it may process. That broad account context is different from a temporary privacy mode, a public Vibes post, or a direct message. Meta Privacy Policy
Is the conversation used to improve models or personalize products?
"Used to provide the service" and "used to improve the service" are different purposes.
Check whether conversations can be used for training, evaluation, safety review, personalization, advertising, recommendations, research, or development. Ask whether the choice is on by default, whether it applies to existing history, and whether opting out affects future use only.
The Federal Trade Commission's companion inquiry asks providers how they use or share personal information obtained through chats. The question appears in a regulatory study precisely because relational interfaces can encourage disclosure. The inquiry is not a finding that every provider follows the same practice. FTC companion inquiry
Can a person review the conversation?
A promise that a conversation is "not public" does not mean no human can ever access it.
Policies may permit review for safety, abuse investigation, support, quality, legal process, or model evaluation. Service providers may process data on the company's behalf. Account administrators or guardians may have access in some products.
Look for the people, purposes, and controls. If the answer is unclear, treat the conversation as reviewable.
What does private mode actually change?
Private, temporary, incognito, and history-off modes are product-specific.
xAI says its Private Chat mode keeps conversations out of history and deletes them from xAI systems within 30 days, subject to legal, compliance, and safety exceptions. The same policy says deleted conversations or accounts are generally removed within 30 days, subject to exceptions. xAI privacy policy
Meta announced Incognito Chat in May 2026 for WhatsApp and the Meta AI app. Meta says the mode processes messages in a private environment the company cannot read, does not save them, and makes them disappear by default. The announcement described a rollout over the following months. Verify that the mode is available and visibly active before relying on it. Meta Incognito Chat announcement
flowchart TD
A["Identify the exact app, account, and mode"] --> B["Read collection and purpose"]
B --> C["Check training, personalization, and human review"]
C --> D["Check retention, deletion, and export"]
D --> E["Inspect sharing, security, and age rules"]
E --> F{"Would disclosure still be acceptable if policy or access failed?"}
F -->|"Yes"| G["Share only what the task requires"]
F -->|"No"| H["Keep it out or use a more appropriate channel"]
How long does the data remain?
Retention may differ for active history, deleted history, safety logs, backups, legal holds, deidentified data, and trained models.
Find a specific period when one exists. Note exceptions. Ask whether deleting a chat removes memory derived from it. Ask whether account deletion covers linked surfaces and uploaded media.
If the policy says data remain while there is a legitimate business need, the practical answer is not a fixed number.
Can you export, correct, and delete?
Export reveals what the provider considers part of your record. Correction matters when memory or profile data are wrong. Deletion matters only when its scope and exceptions are understood.
Test the controls with unimportant data before trusting them with sensitive material. Save the policy version and date because the answer can change.
Who else can reach the account?
Privacy also fails through shared devices, weak passwords, reused credentials, notification previews, cloud backups, linked accounts, screenshots, and unauthorized third-party apps.
Use a unique password and available multifactor authentication. Review active sessions and connected services. Turn off lock-screen previews when the conversation is sensitive. Do not assume a companion can authenticate the person holding the device.
Use a disclosure ceiling
Decide in advance what the companion never needs.
Keep passwords, authentication codes, government identifiers, full payment details, confidential employer or client material, another person's private information, and precise information that could expose a vulnerable person out of the chat. Do not use a consumer companion as a substitute for a licensed professional, emergency service, or privileged legal relationship.
For everything else, disclose the minimum required for the task. Replace names with roles. Remove exact locations. Summarize a document instead of uploading it. Ask a hypothetical question when the identity is irrelevant.
The simple rule is this: if exposure, retention, human review, or a policy change would create serious harm, the information does not belong in an ordinary companion chat.
This page provides general privacy information, not legal, medical, or security advice. Policies and features were reviewed on July 27, 2026 and can change. AI assistance was used for research organization, drafting, and validation. Publication remains unauthorized.
Sources
Follow the evidence.
- apa.org: health advisory ai adolescent well beingapa.org
- pubmed.ncbi.nlm.nih.gov: 41870975pubmed.ncbi.nlm.nih.gov
- ftc.gov: GenerativeAI6(b)resolutionftc.gov
- ftc.gov: ftc launches inquiry ai chatbots acting companionsftc.gov
- x.ai: privacy policyx.ai
- about.fb.com: incognito chat whatsapp meta aiabout.fb.com
- NIST AI Risk Management Frameworknist.gov
- ftc.gov: ftc report shows rise sophisticated dark patterns designed trick trap consumersftc.gov
- docs.x.ai: faqdocs.x.ai
- x.ai: terms of servicex.ai
- ntia.gov: online health and safety for children and youthntia.gov
- apa.org: health advisory chatbots wellness appsapa.org
- facebook.com: policyfacebook.com
- about.fb.com: introducing vibes ai videosabout.fb.com
- spec.c2pa.org: charterspec.c2pa.org
- arxiv.org: 2509arxiv.org
- arxiv.org: 2503arxiv.org