Privacy · 6 min read

AI girlfriend app chat logs: who can read them

Only one of the four things that can read your conversations is the character. Which of them a paid tier actually switches off, which one is not on a toggle at all, and the five minutes of policy reading that tells you which app suits you.

One chat bubble with four dashed paths leaving it, three muted and one bright, each arriving at a panel, and the lowest path carrying on past the edge of the frame

You are a few messages into a free tier, deciding whether to type something you would not say out loud at work. The app has already told you the character remembers. What it has not told you anywhere you would see it is how many other things can read what you send. AI girlfriend app chat logs are not a private line between you and a model: they pass several systems, at least one of which has a person at the end of it, and which of those you can switch off is a question about the price list as much as the privacy policy.

Four things that can read your AI girlfriend app chat logs

Only the first is the one you signed up for. The other three are ordinary infrastructure, present in some form at nearly every app in the category, and they are why "nobody sees this but you" is never quite the right model.

The model, in context. The part you are paying for. Your recent messages, plus whatever the app saved as memory, are sent with every turn. The model retains nothing between turns — continuity comes from the app re-sending the context, which is why memory is usually the thing behind the paywall.

Automated classifiers. Almost every app scores your messages for safety before or after generation, which is what produces a refusal or a redirect mid-conversation. Machine-read, not person-read, and the mechanism behind what people describe as the character getting odd about a subject.

Human reviewers. People read a sample of conversations: sometimes to check a flagged exchange was handled correctly, sometimes to rate response quality so the next model does better. A sample, not your whole history, normally stripped of the obvious identifiers. Still a person reading a conversation you had.

Service providers. Most companion apps do not host their own model, so your messages reach another company under contract, on terms set between two businesses rather than with you. An app built on someone else's model has a privacy policy and a second policy underneath it.

The pattern is written down — just rarely by the app you are comparing

None of this is a leak or a scandal, and you do not have to take it on trust. The clearest published version belongs to a general-purpose assistant rather than a companion app: Google's Gemini Apps privacy hub says human reviewers read a subset of conversations, tells you not to enter anything you would not want a reviewer to see, and notes that reviewed chats are kept up to three years and are not removed when you delete your activity.

A companion app runs the same mechanics; what differs is how plainly it writes them down, and that difference is the signal you are shopping for. It is being asked about from above, too: when the US Federal Trade Commission opened its inquiry into chatbots acting as companions, one thing it ordered companies to explain was how they use and share the personal information obtained through users' conversations. A regulator asking that of a whole category suggests the answers were not uniform.

What a privacy tier actually changes here

This is where the subject stops being abstract and becomes a line on a pricing page. Of the four readers above, a setting or a tier typically reaches exactly one.

Two dashed paths leaving one chat bubble: the upper one runs through an open switch to an empty outlined panel, the lower one runs unbroken and bright to a panel holding two filled bars
the training switch closes one path; review is not on a toggle

Training is usually switchable. The control is called improve the model, help us get better, or data sharing, and turning it off is the highest-value thing on the settings screen. On some apps it is free and buried; on others it is a paid feature, which our guide to which privacy settings cost money covers. On the mainstream assistants the same switch also drops those chats from the history the product uses, so what it costs you is continuity.

A temporary or incognito mode, where it exists, is stronger. It keeps the conversation out of the saved history and generally out of review, at the price of the character not remembering any of it. If you want one unrecorded conversation rather than a quieter account in general, it is the more useful of the two controls.

Safety review is generally not optional, and should not be. No paid tier sells an exemption from moderation, and one that advertised it would be saying something alarming about who else it declines to look at. That is the honest limit of what money buys: you can usually buy your way out of being training data, not out of being moderated.

A tier can take your conversations out of the next training run. It cannot take them out of the system that decides whether a conversation was allowed.

The copy your deletion request does not reach

One consequence of human review catches people out, and it is why this is worth five minutes before you pay rather than after. Once an excerpt is pulled for review or rating it tends to live outside your account: a separate store, its own retention clock, attached to the review record rather than to you. Google's hub puts a number on its version of that — up to three years, surviving the deletion of the activity it came from.

So the deletion button does less than the word implies, which is where our guide to what account deletion actually removes arrives from the other direction. The consequence is an ordering one: find the training and review switches on day one, because they only work prospectively. Nothing you turn off in month six reaches back into what has already been sampled.

Five minutes in the policy, before the card

You are comparing apps, not auditing one, so this is a search exercise rather than a reading one. Open each shortlisted app's privacy policy and search for five words.

  1. "human" or "reviewer". An app that says people may read a sample has told you the truth. A policy that never mentions it is either unusual or vague, and vague is the common case.
  2. "train" or "improve". Find out whether your conversations are used, then find the switch in the app rather than the sentence in the policy. The sentence is a promise; the toggle is a product.
  3. "service providers" or "processors". See whether the underlying model vendor is named or merely gestured at. Named is better: it means a second policy exists that you can go and read.
  4. "retention" or "retain". Specifically, whether reviewed or flagged material keeps a different clock from your account. A policy that distinguishes the two has thought about it.
  5. "anonymised" or "de-identified". Useful, not magic: a conversation stripped of your email can still read like you. A reduction in risk, not a removal of it.

Five minutes, three apps, and the one answering all five in plain sentences is usually the one to try first. The app we currently recommend has a free tier, so you can hold the policy and the settings screen against each other before any money moves. An app that answers none of the five has not failed a test it did not know about — these are the questions its own regulators are putting to it, and a company that will not answer them on its own website rarely answers them better in a support ticket.

Frequently asked questions

Can staff read my AI girlfriend app chat logs?

At most apps some people can read some conversations — typically a sample drawn for safety review or response rating, rather than browsing access to your history. The only reliable source for a given app is its privacy policy, and the useful signal is whether it says so explicitly or avoids the subject.

Does turning off training stop humans reading my conversations?

Partly. Opting out of training generally removes your conversations from the quality-rating pool, the larger of the two review streams. Safety moderation is separate and not usually switchable, so the switch narrows who can read your messages rather than closing it to nobody.

Are AI girlfriend app chat logs encrypted?

Almost certainly in transit and at rest, which protects them from outsiders and not from the app. End-to-end encryption, the kind where the company genuinely cannot read the contents, is incompatible with a model that processes your message on a server, so treat any claim of it in this category with care.

Disclosure. NaughtyEmber may earn a commission if you sign up through a Visit link on this page, at no cost to you. It does not change what we write. How we earn.

Related reading
Next
AI girlfriend app weekly plan: what the year costs →