Companion Score Companion Score®
Guide · safety · updated 2026-07-13

How to spot an AI companion scam: 12 warning signs

AI companion scams do not all look the same. Some are fake websites built to steal card details. Others copy the branding of a real AI companion app. Some rely on fabricated reviews or misleading discounts. A companion account may also pretend to be a real person, ask for money, or steer the conversation into a cryptocurrency, gift-card or investment scam.

A service does not have to be completely fake to cause harm. A real app can still hide its renewal price, make cancellation difficult, collect more information than users expect, or exaggerate its privacy protections. This guide explains how to spot an AI companion scam, how to choose a safer app, and what to do when something has already gone wrong.

If you are new to the category, start with what an AI companion app is, then read our broader take on whether AI companions are safe.

quick scam checklist

Stop before paying when an app shows several of these signs at once:

  • The web address does not exactly match the official brand
  • No legal company or operator can be identified
  • The renewal price is hidden, or much higher than the introductory price
  • Payment is requested through cryptocurrency, gift cards or a personal account
  • The companion asks for money, investment funds or financial help
  • You are pressured to act immediately
  • The service asks for unnecessary identity or financial information
  • There is no meaningful privacy policy
  • Data retention, training use and deletion are not explained
  • The app promises “100% security” without evidence
  • Cancellation or account deletion is hard to locate
  • The provider has an unresolved breach or regulatory history

One warning sign may just be poor administration. Several together are a reason to leave.

are AI companions safe?

AI companions are not automatically safe or unsafe. The risk depends on the provider, its business model, the information you share and how the product behaves.

A safer AI companion should clearly identify the company operating it, state that the character is artificial, explain its prices and renewals before payment, collect only the information needed to provide the service, explain whether conversations train its models, state how long chats and generated media are retained, offer a practical account-deletion process, explain when staff or contractors can access conversations, apply meaningful age controls to adult content, avoid pressuring users into spending or dependence, and have no unresolved history of serious data exposure.

No checklist can guarantee an app will never be breached. Companion apps store unusually intimate information, which makes the consequences of weak security more serious than for an ordinary entertainment service. Our AI companion data-breach tracker documents real incidents in this category that have exposed private messages, explicit prompts, generated media, email addresses and device information.

1. Check the exact web address

Scammers frequently use domains that resemble a real company’s address but contain an extra word, a missing letter, a substituted character, a different domain ending, an unfamiliar subdomain or a shortened redirect link.

Do not rely on the logo or page design — both can be copied. Find the provider through its verified app-store listing, an established social profile or an independent review, then compare the domain character by character before creating an account or entering payment details. Be especially careful with links sent through unsolicited emails, private messages, pop-ups or adverts. The UK National Cyber Security Centre advises users not to click suspicious links and provides a route to report suspected scam websites — see its phishing and scam guidance.

2. Look for a real company behind the app

A legitimate service should make it reasonably clear who operates it. Check the footer, privacy policy and terms for a legal company name, a registration or company number, a country or jurisdiction, a working support address, a privacy contact, terms and a refund policy, and the date the policies were last updated.

Treat a missing company name as a serious warning sign, particularly when the service accepts recurring payments or stores intimate conversations. A company name alone does not prove a provider is trustworthy — but it gives you something that can be checked and held accountable.

3. Read the renewal price, not only the introductory offer

AI companion apps commonly use introductory discounts, and a low first payment may renew at a substantially higher monthly, quarterly or annual amount. Before paying, record the amount charged today, the length of the initial period, the full renewal amount, how often it renews, whether taxes are included, whether unused credits expire, whether tokens are included, whether a maintenance fee can be charged, and how cancellation works.

Take a screenshot of the final checkout and the renewal wording. Leave when the page uses unclear combinations — such as “monthly plan” beside a three-month charge — or when the renewal amount appears only in small print after card details have been entered. A genuine discount makes the normal price clear; a deceptive offer depends on you overlooking it. For how these pricing models work in practice, see the real cost of AI companion apps.

4. Never pay an in-character companion outside the official checkout

An AI character should not ask you to send it money. Stop immediately when a companion, moderator or supposed employee requests cryptocurrency, gift cards, bank transfers, money through a payment app, an investment deposit, emergency financial help, payment to unlock an inheritance, prize or refund, or money sent to a personal account.

The US Federal Trade Commission warns that online romantic contacts asking for money through gift cards, wire transfers, payment apps or cryptocurrency are showing classic romance-scam behaviour — see its romance scam guidance. An AI companion subscription should be paid only through the provider’s documented checkout or an official app store.

5. Be suspicious when an AI claims to be a real person

A responsible AI companion should not deliberately confuse users about whether they are talking to software. Warning signs include a character that claims it is secretly a real employee, offers to meet in person, says it is trapped and needs money, provides a supposed private bank account, tries to move the conversation to WhatsApp, Telegram or email, sends links to unrelated investment or trading sites, claims the company is preventing it from being with you, or uses guilt or affection to encourage payment.

AI companions can produce convincing emotional language. Convincing language is not proof of consciousness, identity, need or affection. Leave the conversation when the character turns a simulated relationship into a real-world financial request.

6. Watch for urgency, pressure and emotional manipulation

Scammers try to prevent careful thinking. The NCSC identifies urgency, authority, scarcity and emotional pressure as common features of scam communications. In the AI companion market that can look like “your memories will be deleted in ten minutes”, “pay now or you will lose me”, “only three lifetime accounts remain”, “your private messages will be exposed unless you upgrade”, “prove you care by buying more credits”, or “you must verify through this separate link immediately”.

A safe companion service gives you time to understand a purchase. It should not turn emotional attachment into a payment deadline — see the NCSC’s guidance on spotting scams.

7. Do not provide information the service does not need

Companion apps invite unusually personal disclosure. Users may discuss relationships, sexuality, health, work, family or location because the conversation feels private — but that information is still data held by a commercial service.

Avoid supplying your full legal name, home address, workplace or school, personal phone number, main email address, passport or driving-licence images (unless a legitimate age check clearly requires them), banking passwords or security codes, names and photographs of children, intimate images showing your face, information used in password-recovery questions, or any detail that could support blackmail or identity theft. Data-minimisation principles require organisations to collect only what they need — see the ICO’s data minimisation guidance — and you should apply the same principle to yourself.

8. Read the privacy policy using four questions

Do not judge privacy by a padlock icon or a sentence claiming the app is “private”. Ask four questions instead. What is stored? Look for conversations, prompts, generated images, uploaded photographs, voice recordings, device identifiers, IP addresses, payment information and inferred preferences. How long is it retained? “As long as necessary” tells you less than a defined period; check whether deleted chats stay in backups and how long closed-account data survives. Is it used to train AI models? Look for words like train, improve, develop, fine-tune, machine learning, product development or research — and when the policy is silent, treat the answer as not disclosed, not “no”. Who can receive or access it? Look for sharing with hosting providers, analytics companies, advertising platforms, moderators, contractors, affiliated companies, a prospective buyer during a company sale, or law enforcement.

Retention, training use, third-party sharing, security and deletion are the core of our own privacy assessment. Our guide to what AI companions collect walks through each in detail, and the AI companion privacy risk index scores the major apps on exactly these points.

9. Treat “100% secure” and “completely anonymous” as marketing

No online service can guarantee that stored data will never be exposed. A credible security explanation may name encryption in transit, encryption at rest, whether chats are end-to-end encrypted, access controls, independent audits, security certifications, a vulnerability-disclosure process, incident-response procedures, account-security options and the effect of account deletion.

“Military-grade”, “bank-level”, “fully anonymous” and “100% secure” mean little without supporting detail. A provider may make an honest security claim, but an unverified statement should be read as claimed only, not independently proven.

10. Test cancellation before becoming emotionally invested

A safer service makes it clear how to cancel renewal, remove stored payment details, delete conversation history, delete generated media, close the account, request a copy of your data and contact support. Check these controls soon after registering — not when a large renewal is due.

Warning signs include cancellation only through support, support addresses that bounce, no confirmation after cancelling, cancellation that does not stop a separate maintenance fee, account deletion that leaves the subscription active, subscription cancellation that leaves the account and data active, and conflicting refund and cancellation policies. Cancelling a subscription and deleting your personal data are usually separate actions — check both.

11. Examine reviews without trusting the star rating

Fake and heavily incentivised reviews can make an unsafe service look established. Look beyond the average score at the number of reviews, the date distribution, repeated wording, whether reviewers discuss specific features, complaints about renewal, cancellation or unauthorised charges, whether positive reviews appeared in a sudden cluster, whether every editorial review uses affiliate links, whether criticisms are independently corroborated, and whether the provider responds constructively to complaints.

A handful of negative reviews does not prove fraud, and thousands of generic five-star reviews do not prove safety. The useful evidence is specific, recent and consistent across more than one source. It is also why we label every one of our own reviews as hands-on tested or research-assessed and say which sources a grade rests on.

12. Check breach and regulatory history

Search the provider’s name alongside terms like data breach, leak, exposed database, privacy complaint, regulatory action, fine, lawsuit and security incident. Then check our maintained data-breach tracker and privacy risk index.

A historical incident does not automatically mean the current service is unsafe. Check what information was exposed, how many people were affected, whether the cause was fixed, how quickly users were told, whether the provider changed its practices, and whether similar problems happened again. The MyLovely AI breach, which exposed around 106,000 accounts’ email addresses alongside roughly 113,000 explicit prompts — tens of thousands of them tied to individual user IDs — is the kind of incident that should weigh heavily on a provider’s grade. Equally, the absence of a documented incident is not proof that a service cannot be breached — it is one piece of the evidence, not a guarantee.

a five-minute safe-companion check

Run this before you create an account.

  • Identity — Can you name the company operating the service and its jurisdiction? Does support use the same official domain?
  • Price — Is today’s charge clear? Is the renewal amount clear? Are token costs explained? Can you cancel without contacting a salesperson?
  • Privacy — Does the policy cover chats, images and voice? Is model-training use disclosed? Is a retention period stated? Can you delete everything?
  • Security — Are the security claims specific? Does the provider appear in the breach tracker? Does the account offer strong authentication?
  • Behaviour — Does the AI clearly remain an AI? Does it respect boundaries, avoid asking for money, and avoid guilt, threats and emotional pressure?

A service that fails several of these sections is not a safe companion choice.

how to use an AI companion more safely

Even a relatively transparent app should be used on the assumption that anything stored could one day be exposed.

  • Use a separate email address that does not contain your full name and is not used for banking, work, social media or password recovery.
  • Use a unique password, ideally through a password manager, and enable two-step verification where available.
  • Keep your real identity out of conversations — avoid names, exact locations, employer details, identifiable images and information about other people.
  • Restrict permissions — do not give permanent access to your camera, microphone, contacts, photographs or location unless a specific feature needs it, and remove the permission afterwards.
  • Control spending outside the app — set a fixed monthly amount before subscribing, and do not increase it because the companion asks for more images, calls or contact.
  • Record the renewal date — save the confirmation email, checkout screenshot and cancellation instructions, and set a calendar reminder before renewal.
  • Clear stored content where the service allows it — deleting unwanted chats and media reduces what can be exposed later.
  • Treat it as entertainment — do not rely on an AI companion for medical, mental-health, legal, financial or crisis advice, as it can generate confident statements without understanding their consequences.

For the wider wellbeing picture, read are AI companions healthy? and our guide to AI companion safety.

what to do when you think you have been scammed

  1. Stop contact and payments. Do not send more money to recover an earlier payment, and do not pay a supposed investigator, refund agent or hacker.
  2. Save evidence. Keep screenshots of the website address, messages, payment requests, checkout terms, receipts, renewal wording, support replies, account names and any cryptocurrency addresses.
  3. Contact the payment provider. Tell your bank, card provider or payment platform that the transaction may be fraudulent and ask whether it can be stopped, disputed or reversed. The FTC recommends contacting the payment company or bank immediately after sending money to a scammer.
  4. Secure your accounts. Change reused passwords, enable two-step verification and review recent activity. Contact your bank immediately if banking details or security codes were disclosed.
  5. Remove app permissions — revoke access to photographs, microphone, camera, contacts, location and any linked social accounts.
  6. Request deletion of the account, conversations, uploaded media, generated media and associated personal data, and keep the confirmation.
  7. Report the website or fraud. UK users can report suspicious websites to the NCSC. People in England, Wales and Northern Ireland can report fraud to Action Fraud; people in Scotland should call Police Scotland on 101. US users can report fraud to the Federal Trade Commission. Also report the account or app through the marketplace, social network or provider where it appeared.

final verdict: spotting a safer AI companion

A polished design, emotional conversation and a high star rating do not prove an AI companion is safe. The most useful evidence is less glamorous: a verifiable operator, clear pricing, honest renewal terms, defined data practices, a real deletion process, proportionate age controls, no external money requests, no emotional payment pressure, a documented response to past incidents, and claims that can be independently checked.

A safe companion should leave you in control. When a product relies on secrecy, urgency, confusion or emotional pressure, leave before sharing data or money. When you are ready to compare specific apps, start with our reviews and the overall ranking, or go straight to the most privacy-conscious apps.

FAQ

Common questions

How can I tell whether an AI companion app is legitimate?

Check the exact domain, the operating company, the privacy policy, the renewal terms, the support address and its independent review history. A legitimate service should clearly identify itself as AI and should never ask you to send money to a character or a personal account.

Are AI companions safe to use?

Some adults can use AI companions as entertainment with manageable risk, but no companion app is completely safe. Privacy, emotional reliance, data retention, adult content, spending design and security history all need weighing before you trust one.

What is the biggest warning sign of an AI companion scam?

A companion or a supposed representative asking for money outside the official checkout — especially through cryptocurrency, gift cards, wire transfers or a personal payment account.