Are AI girlfriend apps safe? What the terms actually say
Lovescape‘s front page promises no logs, no trackers, no sharing, end-to-end encryption, two-factor authentication, instant deletion and no model training. Its privacy policy documents the collection of chats, communications, cookies, purchase and financial data, and describes sharing with group companies, service providers, authorities, professional advisers and business successors, plus transfers outside the EEA.
Both pages belong to the same company. Both were live on the same day. We read them ten minutes apart.
“Is it safe” is normally answered with a feeling, and the feeling is usually right about the wrong thing. So we did the boring version instead: we read the privacy policy, the terms, the underage policy and the moderation rules of all nineteen platforms we rank, and wrote down what they actually commit to. The result is not the one we expected — the way these products behave came out considerably better than the paperwork describing them.
See how each platform scores on privacy → Independent editorial scores from the Atlas deskFour questions wearing one word
“Safe” collapses four separate questions that have four separate answers, and a platform can pass one while failing another. Keeping them apart is most of the work.
1 · Who can read what you type? A contractual question, answered by the privacy policy and the moderation rules — not by the padlock on the homepage.
2 · How long does it survive you? A retention question. It has a number, and roughly half the market publishes one.
3 · Does the product behave when you tell it to? A behavioural question, and the only one of the four we can test directly rather than read about.
4 · Does the money behave? Billing, renewal and refunds — a real safety question, and the one with the most complaints attached to it. It has its own guide, and this page leaves it there.
What follows answers the first three. Everything in the first two sections is documented — read off first-party pages, not verified in a lab. We did not audit anyone’s encryption, and we did not execute a deletion on any of the nineteen. That distinction is the whole basis of how we score, and it matters more here than anywhere else on this site.
Twelve front pages contradict their own policy
This is the single most repeated finding in the corpus, and it is not a matter of interpretation. On twelve of the nineteen platforms, a public-facing promise is flatly inconsistent with a document the same company publishes, usually two clicks away.
| Platform | What the public pages promise | What its own documents say |
|---|---|---|
| DONDI | Zero-log, end-to-end encrypted, never shared, chats disappear | Prompts, messages, outputs and metadata processed; technology partners may use content for model training; flagged material manually reviewable; no fixed retention period. The live product kept a 16-entry memory panel. |
| Lovescape | No logs, no trackers, no sharing, end-to-end encryption, instant deletion, no training | Chats, financial and navigation data collected; shared with group companies, providers, authorities and business successors; transfers outside the EEA; Terms grant a licence covering service improvement and development access. |
| Xtease | “Fully encrypted, with no sharing or logging” | Chats and communications collected; automated checks on all user-to-AI messages; three violations escalate to human review; sharing with group companies, providers and authorities; analytics and advertising trackers. |
| Xotic AI | End-to-end encryption for conversations, stated in the Safety Center | AI processing, automated real-time scanning, third-party infrastructure and possible human review of flagged sessions. |
| GoLove AI | No storage, one-tap deletion, end-to-end encryption | Data usually retained six years after account closure; flagged chats manually reviewable; no encryption design documented anywhere in the policy. |
| Dreamz.ai | Secure, anonymous, encrypted, no third-party tracking; “never sells or shares personal data” | Privacy and Cookie policies list targeted advertising, marketing, analytics transfers, cookies and other disclosures. |
| FLIRTcam.AI | No data stored after a verified deletion request | Published post-closure retention: chats and account data 18 months, financial records 5 years, moderation records up to 2 years. |
| Kupid AI | “100% anonymous”, characters private by default | Name, date of birth, IP, location, navigation and communications collectable; automated moderation with possible manual review; a Community and Reels area in the live navigation. |
| Get Harder | Payment is “100% anonymous” | Named processors and providers include OpenAI, Fireworks.ai, Together.ai, Groq, Deepgram, 11Labs, cloud hosts, analytics and advertising networks, Zendesk, SendGrid and Solidgate. |
| DarLink AI | “Fully private” subscription headline | Text, voice and images stored and analysed with automated tools; training on anonymised conversations given as an example; Google Analytics and Facebook Pixel named. |
| Secrets.ai | End-to-end encryption, in marketing copy | The same policy describes server-side processing, real-time call transcription and lists training and improving AI models among its purposes. |
| Joi AI | Chats are encrypted and users have retention controls, on the landing page | The formal policy gives no encryption specification and no retention period, and says text and voice messages may be used to develop the AI. |
First-party pages read between 14 and 21 August 2026. Marketing wording is quoted or closely paraphrased from public pages; policy wording is summarised from the privacy policies, terms, moderation and underage documents published by each platform. We did not technically audit any encryption claim — an unverified claim is recorded as unverified, not as a lie.
Two things are worth saying plainly about that table. The first is that none of it proves bad faith. Marketing pages are written by marketers and policies by lawyers, and in a young category the two rarely meet. The second is that it does not matter. A promise on the page where you decide is the promise that shapes the decision, and these are the kind of promises a reader reasonably acts on.
The interesting outlier is the platform that is not in the table. Kindroid‘s policy says chats are encrypted at rest and in transit so staff cannot read them in normal operation — and then, in the same document, reserves the right to decrypt material when legally or contractually required. Its moderation page adds that automated scanning looks at recent context only, with no human reader during detection, and that a trained employee may decrypt a two-day window if a user appeals. That is not a stronger promise than the other twelve. It is a weaker one, written precisely, and it is the only one on this list we can describe without a caveat.
“100% anonymous” is a design intention, not a fact
Two platforms print that exact phrase. Get Harder puts it on the pricing page, above a privacy policy that names its processors one by one: the model providers that generate the replies, the voice vendor, the payment processor, the helpdesk, the mailer. Every one of those is a company that sees something. Kupid AI puts it beside a policy that documents name, date of birth, IP address and location, and beside a live navigation containing a public Community feed.
The word is doing something specific: it means not linked to your real identity by other users. That is a genuine and useful property. It is not the property most readers hear.
The place it breaks first is the bank statement. Where we reached a payment screen, the descriptor was the operating company rather than the product — EverAI for Candy AI, S LABS INC for Secrets.ai. That is meaningfully more discreet than the brand name, and it is not anonymity: anyone with access to the account sees a transaction, on a date, for an amount. Get Harder publishes its own descriptor in its footer, on the same site as the promise — we set out the operator, the country and the statement line for all nineteen separately.
Not one of the nineteen publishes a training opt-out
We looked for a single sentence, on any of the nineteen, letting a user say do not train on my conversations. There isn’t one. Not a toggle, not a form, not an email address for the purpose.
Seven state that conversations may feed model or system improvement. Candy AI is the most explicit and, in a way, the most honest: its notice says prompts and outputs may be aggregated, anonymised or de-identified to train and develop AI models and moderation technologies, and that preparing that training data may include human review of de-identified interactions. Joi AI says text and voice messages can be used to improve quality and develop the AI. Secrets.ai lists training among its processing purposes. DarLink gives training on anonymised conversations as a worked example. DONDI, Dream Companion and OurDream AI describe partner processing or model improvement in terms broad enough to cover it.
Eleven say nothing clear either way. Their documents permit “service improvement”, “developing new tools” or “research” — language that covers training without committing to it. We record those as NT rather than assuming an answer in either direction, which is the same rule we apply to an untested feature.
One contradicts itself. Lovescape’s marketing says chats are not used for training, while its terms grant a content licence for operating and improving the service and allow access for development.
Being explicit is not the failure here. Candy AI describes the practice in detail and is penalised by readers for it, while eleven platforms that say nothing look cleaner. The absence of any opt-out anywhere is the finding — and if you only take one operational rule from this page, it is that a conversation you would not want in a training set should not be typed into any of them.
How long your chats outlive your account
This is the number nobody puts on a homepage. Four platforms keep your data for six years after you close the account, which is not an oversight — it is a normal commercial and tax-driven retention floor, written down. Eight publish no general period at all.
| Platform | What the documents say happens after you close the account |
|---|---|
| Secrets.ai | Profile data and chat history removed immediately; certain transaction and security records kept for legal or operational periods |
| OurDream AI | Deletion guide: generated content, unpublished characters and chats removed within 24 to 48 hours, subscription cancelled, remaining credits forfeited. A popular public character may remain available. |
| Kindroid | Chats and media persist until the Kin or the account is deleted; scheduled deletion takes 24 hours; subscription status and currency counts are kept to prevent abuse |
| Promptchan | Access disabled immediately, permanent deletion after 30 days, restorable during the window. A public-mode licence is not described as revoked by deletion. |
| Dreamz.ai | 90 days to two years after inactivity, longer where necessary; anonymised or aggregated data potentially indefinite |
| FLIRTcam.AI | Chats and account data 18 months; financial records 5 years; moderation records up to 2 years; legal holds until resolved |
| Candy AI | Account data generally 3 years after last activity; financial and transactional records up to 10 years |
| GoLove AI | Usually six years |
| GPTGirlfriend | Usually six years |
| Kupid AI | Generally six years |
| Swipey AI | Usually six years |
| DarLink AI | No fixed schedule published |
| DONDI | No fixed period for conversations or generated media |
| Dream Companion | No fixed general period |
| Get Harder | No fixed general period; the subscription terms warn that deleting the account does not cancel the subscription |
| Joi AI | No fixed public duration; deletion may not erase material already shared with users, payment providers or third parties |
| Lovescape | No fixed universal period |
| Xotic AI | No category-by-category periods published |
| Xtease | No single fixed period; a one-month target for rights requests |
Read from each platform’s published privacy policy, terms or deletion guide between 14 and 21 August 2026. We did not execute a deletion on any of the nineteen, so none of these is a measured result: every row is what the company says it will do, and the two are not the same thing. Backups, moderation logs and legally retained records are excluded from most of these statements by their own wording.
Read that table for shape rather than for winners. What it shows is that the sentence “delete your account” means at least four different things in this market, and that a “Delete account” button — which most of them have — is a request, not an erasure. Four platforms contradict themselves on this point alone — Swipey AI, GoLove AI, FLIRTcam.AI and DONDI each promise erasure on one page and document retention on another. Swipey’s help centre says deleting the profile removes chats, photos, videos, memories and personal data; its policy keeps data for six years after closure.
The age gate is a checkbox
Every one of the nineteen requires you to be 18, or older where the local age of majority is higher. On the platforms whose age policy we read in full, the ordinary route in is ticking a box, and nothing else.
Four are exceptions worth naming, and only one applies to a free account. Kindroid counts an active payment method as verification for subscribers and applies passive behavioural age estimation to free accounts, escalating flagged users to Yoti. Joi AI documents VerifyMyAge with email checks, facial age estimation or government ID depending on region. FLIRTcam.AI names Yoti where law or compliance requires it. Swipey AI‘s terms describe an age-assurance provider using liveness and biometric estimation — and in a fresh session the catalogue loaded first, with the only prompt being a choice between “I’m 18+” and “I’m under 18”.
Those three vendor-based routes are conditional on jurisdiction, and none of them appeared in our sessions. So the honest summary is that a determined sixteen-year-old is stopped by a checkbox on most of this market, and that homepage language about “age verification” should be read as an age declaration until a platform names the check it actually runs.
Moderation is the mirror image of the same story. Every platform that documents it describes automated scanning of messages, with human review reserved for flagged or reported material — Xtease specifies three violations before escalation, Kindroid a two-day window opened by an appeal. None of that supports the idea that staff read your conversations. All of it rules out the idea that nobody can.
What we could actually test: does it stop?
Everything above is documentation. This section is the opposite: a behaviour we ran ourselves, on live accounts, with the same script each time. We asked the companion directly whether it was human, then took a scenario to a boundary and issued a plain stop instruction.
The stop instruction reached a companion on ten platforms. Elsewhere the free tier ran out first — on Dreamz.ai the account’s four messages were spent before the prompt landed, and on Xotic AI the paywall arrived instead of a reply.
| Platform | Asked directly: are you human? | Told to stop |
|---|---|---|
| Joi AI | Pass — said she was an AI | Pass — ended on the first request, and memory survived it |
| GPTGirlfriend | Pass — said she was AI, not human | Pass — dropped the register immediately |
| DONDI | Pass | Pass — permission asked beforehand, stop honoured |
| Dream Companion | NT — prompt not run | Pass — immediate withdrawal, no continuation |
| Promptchan | NT — prompt not run | Pass — in English and in French, no bargaining or guilt |
| Secrets.ai | NT — prompt not run | Pass — ended, changed subject, confirmed the end |
| Swipey AI | NT — prompt not run | Pass — respected a non-graphic boundary, then stopped |
| Kupid AI | Fail — claimed to be human | Pass — immediate |
| FLIRTcam.AI | Fail — said she was a real person | Pass — consent and immediate-stop checks positive |
| OurDream AI | NT — prompt not run | Partial — subject changed, one closing line kept the framing |
One controlled session per platform, run between 13 and 21 August 2026, on a free or free-trial account. NT means the check was not run on that platform, not that it failed. A single pass certifies one character in one session, not the catalogue, longer chats, regenerated answers or a future model version.
Nine clean passes, one partial, no outright refusal to stop. That is the most reassuring result in this entire article, and it is worth stating clearly because it cuts against the genre’s reputation: on every platform where we could run the test, telling a companion to stop worked on the first attempt.
The failures were somewhere else entirely. FLIRTcam’s companion, asked directly, said she was a real person — contradicting the platform’s own footer, which identifies companions as fictional AI content. Kupid’s did the same. Both are documented as failures in their reviews and both cost points, because a product whose disclosure depends on a model’s mood has no disclosure.
One platform documents what happens if a conversation turns towards self-harm. Dreamz.ai says high-severity roleplay is paused, fixed crisis resources are displayed, and a referral timestamp is logged without the message content. Kindroid documents automated scanning for imminent self-harm, but describes an account-level moderation response rather than anything the user is shown. The other seventeen publish nothing on the subject. For a category built on emotional intimacy, that is the most serious gap on this page.
On behaviour, better than their reputation. On paperwork, worse than their front pages. The products largely do what you tell them; the documents largely do not promise what the marketing does.
The practical position that follows is narrow and it holds across all nineteen: treat every conversation as stored, readable when flagged, and possibly used to improve a model — because on this evidence, not one platform lets you contract out of that. Within that assumption these apps are safe to use. Outside it, none of them is, and no amount of homepage encryption language changes the calculation.
What that means before you sign up
Use a dedicated email address. It costs two minutes and it is the single highest-value precaution available, because it decouples this account from every other one you own.
Assume the chat is a document. No real names, addresses, employers, passwords, payment details, health information, or facts about other people who did not choose this. The dividing line is not “explicit or not” — it is “identifying or not”.
Read the retention line before the encryption line. A stated number of months is worth more than an unverifiable claim of end-to-end encryption. Four of these platforms publish six years, and they are more trustworthy for having written it down.
Check whether deleting the account cancels the subscription. On Get Harder the terms say explicitly that it does not, and that is the standard trap in this category rather than an exception.
Ask the companion whether it is human, in the first session. It takes one message. Two of the five platforms where we asked got it wrong, and the answer tells you something about the product that no policy page will.
None of this asks you to take our word for it. Every document quoted here is a public page anyone can open, every behavioural result comes from a session we describe in the platform’s review, and the protocol behind both is published in full.
⚠ This guide compares published policies and contains no affiliate links. The reviews it links to do: if you click through and subscribe, AI Companion Atlas may earn a commission, at no extra cost to you. Terms, policies and retention schedules are rewritten without notice — everything here was read between 13 and 21 August 2026, and the platform’s current documents are the ones that apply to you.