Companion Score Companion Score®
Report · Privacy · 2026-06-04

AI Companion Privacy Risk Index

These apps invite unusually intimate disclosure. This index compares what 16 of them actually say about your data — breaches, training-use, encryption, data sale, deletion and where they're based — each flag sourced to the provider's own policy or a documented report.

5.5Avg privacy / 10
1Confirmed breach
2Train on chats, no opt-out
3Contested training-use
2No encryption
App Privacy BreachTrains on chatsEncryptionSells dataDeletionJurisdiction Sources
6.3 None on recordYes — no opt-outNot statedNot soldNot statedSwitzerland
View
  • The policy says conversation data may be used to train its AI on an anonymised basis, with no opt-out described.
  • The policy states data is not sold to third parties.
  • Operated by FameLink SA, registered in Switzerland.
Full DarLink AI review →
6.0 None on recordNot disclosedNoneNot statedEU/legal rightsMalta (EU)
View
  • The policy is not explicit on whether conversations are used to train models.
  • There is no end-to-end encryption, so the company can in principle access chat logs.
  • Operated by EverAI Limited (Malta); the policy gives EU deletion rights.
Full Candy.ai review →
6.0 None on recordNot disclosedClaimed onlyNot statedNot statedNot confirmed
View
  • The official site claims end-to-end encryption ('not even us' can read chats), but this is self-reported and unverified.
  • No public policy text was found setting out retention, training-use or deletion.
Full OurDream review →
6.0 None on recordNot disclosedNot statedNot statedEU/legal rightsEstonia (EU)
View
  • Operated by Xotic Tech OU (Tallinn, Estonia), so EU data rights apply by law; the official policy lists deletion rights.
  • There is no clear statement on training-use; retention is described only as "as long as necessary".
Full Xotic.ai review →
5.8 None on recordNot disclosedNot statedNot statedClaimed onlyNot confirmed
View
  • The official privacy policy claims GDPR rights and a deletion process.
  • The policy states a six-year data-retention period after account closure.
  • Training-use is not clearly addressed.
Full Girlfriend GPT review →
5.8 None on recordNot disclosedClaimed onlyNot statedNot statedNot confirmed
View
  • The provider claims end-to-end encryption, discreet billing, limited retention and no data sharing; these are self-reported and unverified.
Full JustSext review →
5.8 None on recordNot disclosedNot statedNot statedNot statedCyprus
View
  • The Terms grant a broad, transferable, sub-licensable licence over user content, which is consistent with training-use.
  • No dedicated privacy policy could be retrieved, so retention and deletion specifics are unconfirmed. The operator is associated with a Cyprus-registered payment entity.
Full Kupid AI review →
5.8 None on recordContestedNot statedNot soldSelf-serviceNot confirmed
View
  • The policy says data is used to train and improve its AI with no opt-out found; a competitor analysis argues the "100% private" marketing does not match the retention documentation.
  • The official policy states personal data is not sold, with self-service permanent deletion.
Full Secrets.ai review →
Swipey
5.8 None on recordNot disclosedNot statedNot statedClaimed onlyNot confirmed
View
  • Swipey claims one-click, permanent deletion.
  • Training-use and the operating company are not clearly documented, and no official privacy policy text was confirmed.
Full Swipey review →
5.5 None on recordContestedNot statedNot soldEU/legal rightsNot confirmed
View
  • The homepage promotes a "zero-log" policy (conversations processed and never stored), while the privacy policy says messages and AI outputs are collected and may be used to train its AI.
  • The policy states data is not sold and offers a right to erasure.
Full Dondi.ai review →
5.5 None on recordNot disclosedClaimed onlyNot statedNot statedNot confirmed
View
  • DreamGF claims to encrypt conversations and not to share chats with third parties, but reviewers note the specifics are not set out clearly in the policy.
Full DreamGF review →
Joi
5.5 None on recordYes — no opt-outNoneNot soldNot statedNew York (US)
View
  • The official privacy policy states text and voice messages are used to improve and develop its AI, with no opt-out.
  • No end-to-end encryption; the company says it does not sell personal data.
  • Operated by Lanoto Solutions Inc. (New York), previously branded EVA AI.
Full Joi review →
5.5 None on recordContestedNot statedNot soldEU/legal rightsCyprus (EU)
View
  • The privacy page's own metadata marks AI-training as allowed, while the body does not explain how chat data is used.
  • The policy says personal data is not sold.
  • Operated by a Cyprus-registered company (Warmetch Ltd), so EU data rights apply.
Full Lovescape review →
5.3 None on recordNot disclosedNot statedNot statedClaimed onlySlovakia (EU)
View
  • FlirtCam AI states GDPR compliance, discreet billing and account deletion, but there is no independent privacy assessment.
  • The public materials do not address whether content is used for training. Operated by DevPro s.r.o. (Nitra).
Full FlirtCam AI review →
5.0 None on recordNot disclosedNot statedNot statedNot statedIreland (EU)
View
  • Operated by VisionAI Labs Limited (Dublin, Ireland).
  • Whether prompts or images are used for training, and the image-retention period — the policy is silent in the sources checked.
Full Promptchan review →
2.5 Confirmed 2026Not disclosedNot statedNot statedNot statedNot confirmed
View
  • A confirmed April 2026 data breach (documented by Have I Been Pwned and Help Net Security, ~106,000 users) exposed email addresses, explicit prompts and links to generated images, contradicting the site's 'never share your data' claim.
Full MyLovely AI review →
How to read this

Research-assessed from each provider's public policy, marketing and documented reports as of 2026-06-04 — not a security audit and not legal advice. Crucially, "Not disclosed" / "Not stated" means we found no public statement, not that a practice is absent. "Contested" marks a genuine contradiction (for example, "zero-log" marketing alongside a policy that discloses training-use), not a confirmed practice. "Claimed" means the provider asserts it but we found no independent verification. Every flag is sourced — open "View" on any row, then read the full review. Flags can change as providers update their policies; tell us at info@companionscore.com if one is out of date.

Cite this index

Companion Score, AI Companion Privacy Risk Index 2026, companionscore.com/privacy-risk-index. Free to cite and link with attribution. Journalists and researchers: info@companionscore.com for the underlying data.