“Private mode” sounds reassuring, but it is not a universal technical standard. In one service it might hide a conversation from a public profile; in another it might change local history, analytics or retention. The label alone does not tell you whether messages reach company servers, support staff, safety reviewers or model-improvement systems.

Before an AI companion becomes the place where you unpack a breakup, fantasy or family argument, map the data journey. You do not need to read every clause like a lawyer. You do need clear answers to a few ordinary questions.

Start with five kinds of data

  • Account data: email address, age confirmation, login provider and device identifiers.
  • Conversation data: messages, images, voice recordings and files you choose to share.
  • Generated data: replies, summaries, memories, labels or inferred preferences created from the conversation.
  • Usage data: timestamps, feature interactions, diagnostics and security logs.
  • Other people’s data: names, photos or private details that may appear in your prompts even though those people never consented.

A privacy page should explain how these categories are collected, used, shared, retained and deleted. Silence is not the same as protection.

What a useful private mode should clarify

The NIST Privacy Framework describes privacy as an enterprise risk-management issue. It is voluntary guidance rather than a law or product seal, but it provides a useful structure: understand data processing, govern it, control it, communicate it and protect it.

For a companion service, translate that structure into plain questions:

  1. Does private mode stop a chat from appearing in history, or does it also change server retention?
  2. Are prompts or replies used to develop or evaluate models? Is that setting opt-in, opt-out or unavailable?
  3. Can employees, contractors or automated safety systems review content, and under what conditions?
  4. Does deleting a chat remove the original, derived memories and stored attachments?
  5. How long can backups, fraud records or legal-compliance records remain?
  6. Can you export your conversations and account data before deletion?
  7. Will changing a privacy setting affect only future chats, or existing data too?

A privacy toggle should not be playing hide-and-seek in Settings. If the documentation and the interface give different answers, treat the more cautious interpretation as the working one.

Why promises matter

The US Federal Trade Commission has warned AI companies to honour privacy and confidentiality commitments wherever those commitments are made. Its 2024 guidance says that retaining or using consumer data for another purpose without clear notice and affirmative express consent can create legal risk. That guidance does not establish that any particular companion service has broken the law; it explains why vague or quietly changing terms deserve scrutiny.

An earlier FTC article about Alexa and Ring data cases illustrates separate voice-assistant and camera contexts, not AI companion apps. Its transferable lesson is narrower: deletion, retention and human access need real controls, especially where recordings or other sensitive data are involved.

Try a low-stakes deletion test

Create a short conversation that contains no intimate or identifying information. Check whether you can remove the chat, delete any saved memory, request an export and locate the account-deletion process. Record what the interface confirms. This does not prove that every backend copy vanished, but it reveals whether basic controls are understandable before the stakes rise.

Use a separate email alias when appropriate, choose a unique password, enable available account security, and avoid uploading identity documents or another person’s private content unless the feature genuinely requires it and the policy is clear. “The bot already knows me” is not a reason to give it your neighbour’s medical history.

Privacy is also a conversation boundary

A private-feeling chat can encourage disclosure faster than a conventional app. Decide in advance which topics stay offline, and pause when a prompt asks for unusually specific identity, financial, health or location details. Review the related guide to filters and consent, then use our review checklist to document what a service states without filling gaps with assumptions.

The safest definition of private mode is not “nobody can ever see this.” It is a documented set of controls you can find, understand and exercise. Until a service explains those controls, share only what you would be comfortable treating as retained data.

What we know / what remains uncertain

Known: This article distinguishes observed product behavior, published policy, and expert analysis.

Uncertain: AI products change quickly. Material updates are reflected in the modified date above.

Sources & method

EmberGF links primary sources where available, separates testing from opinion, and labels commercial relationships beside the relevant recommendation.