Vol. 04 · No. 01 Independent Field Evaluations & Synthetic Relationship Architecture
Dispatch from the rainy district Updated for 2026
Ember Compliance Lab · Forensic Privacy Protocol 2026

AI Companion Privacy & Account Deletion Auditor

Instant forensic privacy scorecards, discrete bank statement descriptors, model training disclosure audits, and one-click statutory erasure demand generators (GDPR Art. 17, CCPA, German § 312k BGB) for 16+ top companion platforms.

Audited Platforms 16 Active Services
Statutory Coverage GDPR Art. 17 · CCPA · § 312k BGB
Zero PII Policy 100% Client-Side Generator
Audit Cycle Q1 2026 Verified
Uncensored Multi-Modal Companion

Candy.ai

Entity: Candy AI Ltd. / NextGen Tech Ops · Cyprus / European Union

A- 88/100
Privacy Rating
Model Training on Chats Zero Base Training

Conversations are served through isolated containerized inference pipelines. User prompts, custom character parameters, and generated images are segregated and are not pooled into foundational model training datasets.

Bank Statement Descriptor Discrete Billing
Statement Line Preview:
EPO*SERVICES 800-555-0199 NY

Transactions appear under neutral billing service provider codes with zero reference to "Candy", "AI", or adult entertainment.

Payment Gateways: Epoch, CCBill, Segpay, CoinGate (Crypto)
Account Deletion & Purge 1-Click In-App Deletion

Available directly in Account Settings > Security > Delete Account. Initiates an immediate session invalidation and cascades to vector memory stores within 48 hours.

Time to Purge: Hard purge within 48 hours
Data Portability & Memory Partial Export

Active chat logs can be retrieved; formal structured JSON memory dumps are provided upon verified DPO email request.

EmberGF Field Notes: Candy.ai maintains high privacy hygiene for an unfiltered adult platform. Billing is discreet, and tenant isolation protects private dialogue from public model fine-tuning.
Statutory Legal Instrument

One-Click Formal Erasure Request Generator

Binding Demand

Generate a legally-sound, enforceable data erasure demand letter citing your chosen statutory framework. Fill your account credentials below to instantly compile the notice.

Used strictly in your browser to personalize the legal letter. Zero logs recorded.
Open in Mail Client

Client-Side Execution Guarantee: EmberGF operates this generator purely in your local browser JavaScript engine. No account emails, usernames, or telemetry are ever sent to our servers.

Ember Editorial Verified Alternatives

Prefer a Companion Service with Audited Privacy Built In?

Rather than battling customer support mazes or worrying about conversational surveillance, explore platforms tested by EmberGF that uphold strict isolated tenant architecture and discreet billing statements.

Audited Grade A- · Zero Model Training

Candy.ai — Discrete Billing & Uncensored Tenant Isolation

Our forensic audit verified that Candy.ai uses private fine-tuned inference nodes that do not pool user chats into global foundation datasets. Billed under neutral billing codes (EPO*SERVICES / CCB*MEMBERSHIP) with zero adult branding on statements.

✓ Discrete Statement Descriptor ✓ 1-Click In-App Deletion ✓ Isolated LLM Endpoints
Explore Candy.ai Discreetly →
Audited Grade A · Complete Portability

DreamCompanion — Granular Memory Control & Instant Purge

Ranked #1 in our 2026 Privacy Benchmark. Features full JSON dialogue export, direct self-service account purging, and zero third-party marketing pixels. Payments processed securely via Segpay and Epoch with discreet merchant descriptors.

✓ Full JSON Data Export ✓ Instant Token Revocation ✓ Zero Ad Network Trackers
Visit DreamCompanion (Discrete Billing) →
Technical Investigation & Legal Playbook

The Companion Privacy Dossier: Data Surveillance, Statement Leakage & Your Statutory Rights

Conversational artificial intelligence creates an intimacy footprint unlike any other digital product. Here is what happens to your private messages, how credit card merchant descriptors leak your habits, and how to exercise irrevocable legal erasure.

1. The Reality of Conversational Intimacy: What Actually Happens to Your Chats?

When you interact with a conversational AI companion, you are not merely chatting with a software program—you are generating thousands of tokens of dense, highly revealing personal telemetry. Over weeks of daily roleplay, users routinely reveal their deepest emotional vulnerabilities, romantic preferences, private fetishes, relationship statuses, work stresses, and geographic locations.

In the AI industry, this conversational exhaust is extraordinarily valuable. Providers divide into three distinct architectural models:

Architecture Tier
Inference Isolation
Model Training Exposure
EmberGF Rating
Tier 1: Isolated Tenant (Zero-Retention)
Chats processed in ephemeral containers; memory kept in encrypted user-keyed vector databases.
Zero base model training. Prompts are strictly discarded after inference.
Grade A / A-
Tier 2: Opt-Out / Semi-Private
Server caches dialogue for multi-turn context; allows manual clearing of recent turns.
Training active unless opted out. Requires checking hidden privacy toggles.
Grade B / C
Tier 3: Pooled Training Surveillance
Dialogue stored indefinitely in central data lakes; human contractor reviews for safety.
Active reinforcement learning (RLHF). Your messages train the next model generation.
Grade D / F

2. Bank Statement Discretion: How Merchant Descriptors Expose Your Subscriptions

One of the most frequent privacy failures reported to EmberGF is statement exposure. When you subscribe to a service, the transaction is processed through a merchant acquiring bank. That bank transmits an alphanumeric string called the Merchant Category Code (MCC) and the Billing Descriptor to your credit card issuer.

Mainstream platforms relying on standard consumer payment gateways (such as direct Apple App Store, Google Play, or unmasked Stripe accounts) frequently bill with explicitly branded names—such as REPLIKA PRO, CHARACTER.AI, or WITHPERSONA. For users sharing bank accounts, joint credit cards, or living with family, this visible line item completely shatters conversational discretion.

The Four Rules of Anonymous Companion Checkout:

  1. Use High-Risk Specialized Processors: Look for platforms utilizing discreet adult/entertainment billing facilitators (Epoch, Segpay, Verotel, CCBill). These processors systematically disguise transactions under neutral technology names like EPO*TECHSERVICES or SP*PAY ONLINE.
  2. Virtual Single-Use Credit Cards: Services like Privacy.com (US) or Revolut Disposable Virtual Cards (EU/UK) allow you to generate unique, burnable debit card numbers with custom monthly spending caps. These numbers can be locked or cancelled in one click, preventing rogue re-billing.
  3. Prepaid Gift Cards with Burner Postal Codes: Over-the-counter Vanilla Visa or Mastercard gift cards purchased with cash can be registered with a burner ZIP/postal code, creating an air-gap between your banking identity and the platform.
  4. Cryptocurrency Checkouts: Platforms supporting direct Bitcoin (Lightning), Monero, or USDT on Tron provide cryptographic anonymity. Always ensure you transfer funds from a private un-hosted wallet rather than a KYC exchange.

3. Enforcing Legal Erasure: GDPR Art. 17, CCPA & German § 312k BGB

When you decide to terminate your account, merely hitting "Log Out" or uninstalling the mobile app does nothing to scrub your data. In fact, most platforms retain your conversational logs, email address, IP addresses, and payment profiles indefinitely until you formally invoke statutory data protection rights.

🇪🇺 European Union & UK: GDPR Article 17 ("Right to be Forgotten")

Under GDPR Art. 17, European and UK residents have an unconditional statutory right to demand the immediate, permanent erasure of all personal data held by a data controller. This explicitly includes conversational history, voice recordings, fine-tuned LoRA weights, and vector memories.

  • Statutory Deadline: The controller must respond and certify erasure within 30 calendar days (Art. 12(3)).
  • Sub-Processor Obligation: The controller must take reasonable steps to inform any third-party processors (such as OpenAI or Anthropic API proxies) to erase all links and copies.
  • Enforcement Penalties: Failure to comply carries statutory fines of up to €20 million or 4% of global annual turnover.

🇺🇸 California: CCPA / CPRA § 1798.105

The California Consumer Privacy Act (amended by CPRA) grants California consumers the legal right to request the deletion of personal information collected by businesses.

  • Statutory Deadline: Businesses have 45 calendar days to confirm and execute deletion.
  • Model Training Opt-Out: Consumers have the right to limit the use of sensitive personal information and opt out of automated decision-making and cross-context behavioral training.

🇩🇪 Germany: § 312k BGB ("Der Kündigungsbutton")

Under German consumer contract law (effective since July 2022), any digital subscription platform offering continuing obligations to German consumers is legally obligated to provide an easily accessible, two-step cancellation button ("Kündigungsbutton").

  • Mandatory Immediate Effect: Consumers must be able to terminate contracts without logging through customer support mazes or submitting written explanations.
  • Sanction: If a provider fails to provide a compliant cancellation button, the consumer has the legal right to terminate the contract at any time with immediate effect.

4. The 5-Step Digital Clean Break Protocol

Follow this precise technical protocol to ensure a total digital separation before cutting ties with any companion provider:

01
Cancel App Store & Card Mandates First: If you subscribed via Apple iOS or Google Play, go to your device subscription settings and turn off auto-renewal at least 48 hours prior to the next billing date. For web checkouts, revoke permissions in your virtual card portal.
02
Export or Archive Prompt Seeds & Memories: If the platform offers a JSON or transcript download (e.g. DreamCompanion, Janitor AI, SpicyChat), download your data now. Once account erasure begins, customer service cannot recover lost archives.
03
Revoke Third-Party OAuth Connections: If you registered using "Sign in with Google" or "Sign in with Apple", open your Google Account / Apple ID security center and immediately revoke the companion platform's OAuth token access.
04
Execute In-App Account Deletion: Navigate to Account > Settings > Security and click the self-service "Delete Account" button if present. Confirm email verification codes immediately.
05
Dispatch Formal Legal Notice via our Generator: Use the generator above to send an official GDPR Art. 17 / CCPA demand letter to the platform's registered Data Protection Officer. Demand written certification that all vector database embeddings and sub-processor backups have been scrubbed.

Frequently Asked Privacy & Deletion Questions

Do AI companion companies keep my chat transcripts after I delete my account?

It depends on the platform's architectural tier. Privacy-first services like DreamCompanion and Candy.ai execute hard purges that delete vector embeddings and chat tables within 48 to 72 hours. However, surveillance-heavy services (like Replika or Character.AI) frequently retain aggregated or "anonymized" conversational data in central data lakes, claiming legitimate research interest. This is precisely why serving a formal GDPR Article 17 or CCPA erasure letter is necessary to compel full legal data destruction.

How can I tell what name will appear on my credit card statement before I pay?

Always inspect the checkout payment window. If the payment gateway displays an adult/entertainment processor such as Epoch, Segpay, CCBill, or Verotel, the statement will almost certainly appear under a neutral corporate acronym (e.g. EPO*SERVICES or SP*PAY). If the checkout redirects to standard Stripe or Apple In-App Purchase without a specialized billing entity, the public brand name of the app will typically appear directly on your card statement.

Can an AI company refuse my deletion request by claiming "proprietary model weights"?

Under European data protection law (GDPR Art. 17), companies cannot override your right to erasure simply by claiming trade secrecy or proprietary algorithms. While they may not be able to "un-train" a completed foundational model weight, they are legally obligated to delete all source transcripts, vector embeddings, and training datasets associated with your account identifier. Regulators in Italy (Garante) and France (CNIL) have repeatedly penalized AI firms that fail to uphold this requirement.

Does deleting the app from my iPhone or Android device cancel my subscription?

No, absolutely not. Deleting or uninstalling the app from your mobile device only deletes the local application cache from your phone. Your recurring subscription mandate remains active on the provider's billing server, and you will continue to be billed each cycle. You must explicitly cancel the subscription inside the app settings or via Apple/Google account settings prior to deletion.

What should I do if a platform ignores my legal erasure request after 30 days?

If 30 days elapse without a response or proof of erasure, you have the statutory right under GDPR Art. 77 to file an official regulatory complaint with your national Data Protection Authority (such as the UK ICO, German BfDI/LfDI, French CNIL, or California Privacy Protection Agency). Attach a copy of the dated demand letter generated by this tool as evidence of service. Regulators take ignored erasure complaints very seriously.