CompanionRank
Home / Blog / Privacy Checklist
Guide

AI Companion App Privacy Settings & Safety Checklist

Companion chats are personal by design, which makes data handling worth checking before you sign up. This checklist covers storage and deletion, age verification, permissions, where the privacy settings actually live and the 2026 app-store safety guidelines — with a two-minute verification for each.

Last verified: August 2026Author: CompanionRank Editorial TeamReading time: ~7 min
AI Companion App Privacy Settings & Safety Checklist 2026
TL;DR: Before committing to an AI companion app, check four things: how your chats are stored and whether you can delete them, whether conversations are used for training, how age verification works, and what device permissions the app requests. Each is verifiable in the privacy policy, the app store listing and your device settings — you don't have to take marketing copy on trust.

AI companion conversations tend to be more personal than a typical chatbot exchange, so the privacy questions matter more than usual. The good news is that most of what you need to know is checkable before you type a single message. Work through the checklist below and you'll have a realistic picture of how an app treats your data.

1. Data storage and deletion

Start with the most important question: can you get your data out, and can you get it removed?

How to verify

Search the privacy policy for the words "retention," "delete" and "backup." A trustworthy policy states a specific retention period and describes the deletion process. Vague language like "we may retain data as needed" without a timeframe is a signal to be cautious.

2. Training and data sharing

Many providers improve their models using real conversations. That's not automatically a problem, but you should know whether it's happening and whether you can opt out.

How to verify

Look in both the privacy policy and the in-app settings. Search the policy for "train," "third party" and "share." Then open the app's privacy or data settings and check for a training or personalization toggle, and note its default state.

3. Age verification and content controls

Age verification and content filters are two separate controls, and it's easy to confuse them. An age gate governs who can access the app or its mature content; a content filter governs what the app will generate. Both vary widely across the category and neither is standardized.

ControlWhat it doesWhat to check
Age gateRestricts access by ageSelf-declared birthdate vs. document-based check
Content filter / SFW toggleControls mature outputWhether it's on by default and how it's enforced
Adult labellingSignals mature contentClear 18+ labelling on relevant sections

Apps with mature content should make their 18+ status obvious and back it with some form of age gate. A stronger age check is generally a sign the provider takes compliance seriously.

4. App permissions

A text-based companion app needs surprisingly little access to your device. Each permission it requests should map to a feature you actually use.

How to verify

On iOS and Android you can review and revoke permissions in your device settings at any time. The app store listing's data-safety or privacy section also summarizes what the app collects — compare that against what the app asks for in practice.

5. Where the privacy settings actually live

Most of the controls above exist, but they are rarely on the first settings screen. Across the apps we have examined, they cluster in four predictable places — so if you cannot find a control, check these before concluding the app does not offer it.

What you want to changeWhere it usually sitsIf it is missing
Delete a single conversationLong-press or swipe the chat in the chat list, or a ⋯ menu inside the chatLook for "clear history" in account settings
Delete the account and all dataSettings → Account → Delete account (sometimes web-only, not in the app)Email the support address in the privacy policy — under GDPR/CCPA you can request erasure
Opt out of model trainingSettings → Privacy / Data controls → "improve the model" toggleAssume conversations may be used; the policy text is the authority
Mature-content filterSettings → Content / Safety, often behind age confirmationCheck whether it is off by default — that is the meaningful signal
Device permissionsYour OS settings, not the app: iOS Settings → app name; Android Settings → Apps → PermissionsRevoke anything that does not match a feature you use

Two practical notes. Account deletion is deliberately harder to find than conversation deletion, and is sometimes only available on the web version rather than in the app. And a filter toggle that lives behind a paid tier is a payment check, not an age check — worth knowing before you treat it as a safety feature.

6. Extra checks if you use mature modes (18+)

If you intend to use an app's adult or mature mode, the privacy stakes rise: the conversation log becomes more sensitive, and so does anything the app generates or stores alongside it. Four additional checks are worth the few minutes.

7. What the 2026 rules require — and what they do not

Two regulatory changes now shape what companion apps must tell you, and both are frequently overstated. Knowing the actual scope keeps you from assuming a protection that does not exist.

Neither rule makes an app-store age rating meaningful. A July 2026 audit of 4,346 AI character and companion listings found about 60% carried a rating that classifies them as accessible to minors, and the two big stores frequently disagree about the same app — the reason we treat store ratings as a weak, self-declared signal rather than a scoring input. The numbers are in our write-up of the store-rating data.

8. The 2026 safety guidelines the app stores actually enforce

Ask what the “2026 AI companion safety guidelines” are and you get two different answers, because two different rule-makers are involved. Legislators set the layer described in section 7. The app stores set a second, separate layer — and that one is the layer you can verify from inside the app in about two minutes, because each requirement corresponds to a screen or a button that either exists or does not.

What the guideline requiresWho requires itHow you check it yourself
An age restriction mechanism based on verified or declared age, plus a way for users to identify software that exceeds the app’s age ratingApple, App Review Guidelines 4.7.5 (the section that covers chatbot apps)Sign up with an under-18 date of birth. If nothing changes, the mechanism is nominal
A method for filtering objectionable material, a mechanism to report content with timely responses, and the ability to block abusive usersApple, guidelines 4.7.1 and 1.2Open a chat and look for a report or flag control; check Settings for a content filter
In-app user reporting or flagging of offensive content, without needing to exit the appGoogle Play Developer Program Policy, in the version stated as effective 15 July 2026, for any app that generates content using AIIf reporting a bad reply means emailing support, the app is behind this requirement
Generative AI apps primarily intended to be sexually gratifying are not permitted, and the developer is responsible for output that breaches the Inappropriate Content policiesGoogle Play, AI-Generated Content policyCheck where the app is distributed: a web-only or direct-download build has not passed either store’s review
Published contact information so users can reach the developerApple, guideline 1.2Look for a real support address in the store listing and in the privacy policy

Two things follow. A missing in-chat report control is now a policy gap rather than a design preference, which makes it a fair signal about how the developer treats safety in general. And distribution channel matters more than it used to: an app that ships only as a web app or a direct download sits outside both stores’ review, so nothing above has been checked by anyone other than the developer. Where legislation applies as well, enforcement is separate again — Colorado’s chatbot law, for instance, routes complaints to the state attorney general rather than to a store, as we set out in our breakdown of HB 26-1263.

9. Data protection tips: the five-minute pass

If you have a few minutes before signing up, these are the checks with the best ratio of effort to information. Each returns a yes or a no, so you can run them on any app without knowing anything about it in advance.

  1. Search the privacy policy for three wordsretention, train, share. A policy that answers all three with a specific period or a named purpose is a different class of document from one that answers none.
  2. Find account deletion before you create the account. If you cannot locate it in the policy or in a trial account’s settings, assume it takes an email request — and that the app is aware this is inconvenient.
  3. Sign up with a dedicated email address. It costs nothing, keeps companion-app marketing out of your main inbox, and makes any later breach notice easy to attribute.
  4. Decline every optional permission on first launch. Grant them back only when a feature you use actually needs one. This is the only item here that improves your position rather than merely informing it.
  5. Check the training toggle’s default, not its existence. Off by default is the meaningful state; a toggle you have to hunt for and switch off yourself is a weaker commitment.
  6. Test the report control on a real reply. Under the store policies in section 8 it belongs inside the chat, and finding it also shows you what the developer says happens next.
  7. Note who processes payment before you subscribe. The app’s privacy policy does not govern the processor, and the statement descriptor is what anyone else looking at the bill would see.

None of this requires trusting a review, including ours. It is the same pass we run before an app enters a comparison, and its results are what we mean when we call an app’s data handling documented or unclear.

Turning the checklist into a decision

You don't need every answer to be perfect; you need them to be clear and reasonable for what the app does. An app that documents retention, offers real deletion, explains training use, gates age appropriately and requests only relevant permissions has earned a baseline of trust. One that's vague on all four deserves more caution — regardless of how good the conversation feels. Privacy is one of the five criteria we weigh in How to Choose an AI Companion App, and where we can confirm these details for a specific app, we note them in our reviews and rankings.

This checklist is general guidance, not legal advice, and the specifics differ by app and by region — always defer to the app's own current privacy policy and your local regulations.

Frequently asked questions

Can I delete my AI companion chat history?

Many apps let you delete individual conversations and your whole account, but not all delete data immediately or from backups. Check the privacy policy for how deletion is handled and whether a retention period applies after you request removal.

Are my conversations used to train the AI?

Some apps use conversation data to improve their models, sometimes with an opt-out and sometimes not. Look for a clear statement in the privacy policy, and check the settings for a training or data-sharing toggle before assuming your chats stay private.

What app permissions should an AI companion app need?

A text-based companion app generally needs very little — notifications at most. Requests for contacts, location, microphone or photo library access should match a feature you actually use, such as voice replies; if a permission has no obvious purpose, that is worth questioning.

Where are the privacy settings in an AI companion app?

They are usually split across four places: conversation deletion in the chat list or a chat's ⋯ menu, account deletion under Settings → Account (sometimes web-only), training opt-out under Settings → Privacy or Data controls, and the mature-content filter under Settings → Content or Safety. Device permissions are not in the app at all — they live in your iOS or Android settings.

Is an AI companion app safe for adults to use?

The main risks for an adult user are data risks rather than content risks: how long conversations are retained, whether they are used for training, whether deletion is real, and what a mature tier stores alongside the chat. Check the age gate, whether mature content is off by default, where generated images are stored, and which payment processor handles a paid tier — its handling of your data is not covered by the app's own policy.

What do the 2026 rules require from AI companion apps?

Two things, with narrower scope than often assumed. The EU AI Act's Article 50, applicable since 2 August 2026, is a disclosure rule: apps must make clear you are talking to an AI and mark generated content as machine-readable, with penalties up to €15 million or 3% of worldwide turnover. California's SB 243, operative since 1 January 2026, is the prescriptive one for companion chatbots — disclosure, break reminders for known minors, self-harm protocols and measures to keep explicit material from minors. Neither requires age verification across the board, and neither makes a store age rating a reliable safety signal.

Does an app-store age rating tell me whether an app is safe?

No. Ratings are largely self-declared by developers, they change after launch, and the two major stores frequently disagree about the same app. A July 2026 audit of 4,346 companion and character-app listings found roughly 60% carried a rating that classifies them as accessible to minors. The in-app age gate and the content-filter default are far more informative, and you can check both yourself in a couple of minutes.

What are the AI companion app safety guidelines for 2026?

There is no single official guideline — two layers apply at once. Legislation sets one: the EU AI Act’s Article 50 requires AI disclosure and machine-readable marking of generated output, while California’s SB 243 adds break reminders for users known to be minors and self-harm protocols for companion chatbots. The app stores set the other, and that is the layer you can verify yourself — Apple’s guideline 4.7.5 requires an age restriction mechanism based on verified or declared age, and Google Play’s Developer Program Policy, in the version stated as effective 15 July 2026, requires in-app reporting of offensive content in any app that generates content using AI.

What data protection steps should I take before signing up to an AI companion app?

Search the privacy policy for the words retention, train and share; locate account deletion before you create an account; sign up with a dedicated email address; decline every optional permission on first launch and grant them back only for features you use; check whether the training opt-out is off by default rather than merely present; and note which company processes payment before you subscribe to a paid tier. Each check returns a yes or a no, and none of them requires trusting the app’s marketing copy.