GuideSafety

Are AI Companion Apps Safe? What I Check Before I Trust One (2026)

The five risks that actually matter in AI companion apps (retention and training, breaches like Muah.AI, billing traps, dependency, minors), a 10-minute check you can run on any app, and straight answers for Candy AI, Character.AI, Joyland, Nastia, Kindroid and Replika.

Are AI companion apps safe? I get asked this more than any other question, usually by someone who has already downloaded one and wants permission. The honest answer is that safe is the wrong word. An AI companion is a server that stores everything you type, a billing system that wants you to forget it exists, and a character engineered to make you come back tomorrow. Whether that is safe depends on which of those three you are worried about, and on which app, because the gap between the best-run and the worst-run platform is enormous.

I spent six years as a QA tester for mobile games before I started testing adult apps and AI companions in 2022, and the habit that job left me with is reading the price screen and the privacy policy before I read the marketing. For this guide I went back through the twenty policies I graded for the privacy scorecard, re-read the current Replika and Candy AI notices, and then read what regulators have actually done: the FTC's September 2025 orders, Italy's two actions against Replika, Ofcom's guidance under the UK Online Safety Act and California's SB 243. None of that is my opinion. It is on public pages, and each one is linked at the end.

What follows is the check I run before I put my own card into a new companion app, written so you can run it in ten minutes. If you only want the short version: pick an app that says when it deletes your chats, never use your main email, and treat anything a companion app promises about privacy as a claim until the policy backs it up.

The short version

AI companion apps are safe enough for an adult who takes three precautions and unsafe for anyone under 18, full stop. The real risks are not the chatbot going rogue; they are your chats being kept for years and used to train models (CrushOn and Joyland score F on our scorecard for this), a breach like Muah.AI's in 2024, which leaked 1.9 million email addresses tied to sexual prompts, and subscriptions that auto-renew after a 3-day trial or cannot be refunded. On the paperwork, Kindroid and Nastia are the safest of the apps we track (both B); Candy AI is a C; Joyland is an F because its age gate is 13. Character.AI and Replika are not graded yet, but both have been the subject of regulator action: the FTC ordered Character Technologies to hand over safety records in September 2025, and Italy fined Replika's maker five million euros in April 2025.

The five risks that actually matter

The five things that can actually hurt you on an AI companion app are, in order of how often I see them bite: chats kept for years and used for training, a breach that ties your email to your fantasies, a subscription you cannot get out of, a habit that displaces real people, and a child using an app built for adults. Everything else people worry about, from the companion “going rogue” to the app reading your camera roll, is either rare or already covered by your phone’s permission screen. These five are not, and no app on our list is clean on all of them.

1. Data retention and what your chats are used for

The single biggest safety gap between companion apps is how long they keep your conversations and whether they train on them, and on our privacy scorecard five of ten policies do not state a retention period at all. The phrase to look for is “as long as necessary,” which sounds reasonable and means “indefinitely, at our discretion.” Swipey is the outlier in the other direction: its policy says personal information is stored for six years after you close the account, with no carve-out for chat content.

Training is the part you cannot undo. A retention period ends and a deletion request gets processed, but a model that has learned from your messages does not un-learn them. CrushOn’s policy states that chat contents are used “for training our models.” Secrets lists training among its uses. Candy AI’s notice says your exchanges with characters, “including prompts, requests, and corresponding Outputs, may be aggregated, anonymized, and/or de-identified” for model development, and separately that third-party LLM providers “may receive the content of your messages.” Kalon’s terms say Input and Output “may be used to train, improve, and develop our models” on the same site whose privacy page opens with a no-training promise about third-party models. As of September 2026 none of the ten platforms we grade offers an opt-out, and the ones that stay silent, including Kindroid, Nomi and Joyland, have not promised anything either.

The practical test is simple: search the privacy policy for “retain,” “delete” and “train.” If the answers are a stated period or trigger, a self-serve route, and either a clear no or a documented opt-out, the app passes. Two of ten pass the first two questions. None passes the third.

2. Breaches: Muah.AI and the 1.9 million email addresses

The Muah.AI breach of 2024 is the case that answers “what is the worst that could happen,” and the answer is 1.9 million email addresses leaked alongside the sexual prompts attached to them. Have I Been Pwned dates the breach to September 2024 and added it on 8 October 2024, listing the compromised fields as email addresses, AI prompts and “sexual fetishes.” Malwarebytes reported the hacker’s own description of the site’s backend as “a handful of open-source projects duct-taped together,” and an 11 October update noting active extortion attempts using the leaked data. 404 Media, which broke the story, found that many of the addresses were personal accounts carrying real names, and that some prompts contained references to children, which turns an embarrassment into a criminal exposure for the people who typed them.

Muah.AI is not one of the apps we track, and I would not rank it if it were. The reason it belongs in every safety guide is the shape of the leak: not passwords, which you can change, but the pairing of an identity with a fantasy, which you cannot. That pairing exists on every companion app the moment you sign up with your real email. The app does not need to be breached by a hacker for it to matter, either; Nomi’s policy notes that support emails become part of its permanent archives, and Kindroid’s warns that identifying details you type into a chat are collected like everything else.

The fix costs nothing. Sign up with a mailbox that exists only for companion apps, never with a Google or Apple login that carries your name, and never type your real name, employer or address into a conversation. If Muah.AI had been breached under those conditions, most of its users would have been anonymous rows in a spreadsheet instead of extortion targets.

3. Billing and cancellation traps

Nine of the ten platforms in our real monthly cost guide state that subscriptions are non-refundable except where the law requires it, and the tenth, Candy AI, gives you 24 hours and a 20-token ceiling. That is the baseline; the traps are the mechanisms layered on top. Kindroid’s Standard plan starts with a 3-day trial that converts automatically, although Kindroid does email a reminder a day before. Nomi’s cancellation policy says deleting the app does not cancel anything, and app-store subscriptions have to be cancelled in the store. Candy AI’s terms say unused tokens expire when you cancel, so the balance you paid for disappears with the subscription. SpicyChat raised its prices on 8 September 2026 and its FAQ warns that a lapsed plan loses the old rate. CrushOn’s terms ask you not to charge back except for fraud, which tells you which route it is worried about.

None of these is illegal and most are disclosed, in the terms nobody reads. The safety question is whether the app makes it easy to leave, and that is the second thing I test after the privacy policy: I find the cancel button before I pay. If cancellation is only available “through the payment partner you bought from,” as Joyland’s terms put it, or only by email, the app has told you how it plans to keep you.

4. Emotional dependency

The strongest evidence that heavy companion use has a cost comes from a randomised controlled study by MIT Media Lab and OpenAI researchers, published on arXiv in March 2025: 981 participants over four weeks and more than 300,000 messages, and the finding that “participants who voluntarily used the chatbot more, regardless of assigned condition, showed consistently worse outcomes.” The same study found that higher trust and social attraction towards the chatbot were associated with higher emotional dependence and problematic use. The subject was ChatGPT rather than a companion app, which if anything understates the effect, because companion apps are designed to maximise exactly the trust and attraction the study measured.

I am not going to tell you an AI girlfriend will ruin your life; I have been testing them for four years, I have been married for twelve, and my wife reads the drafts. What I will say is that the apps that score best on conversation quality in our ranking of AI companion apps are also the ones that remember the most, and memory is what makes a companion feel like a relationship rather than a toy. Nomi and Kindroid resurface details from weeks earlier unprompted. That is a feature when you want it and a hook when you do not. California’s SB 243, signed on 13 October 2025 and in force since 1 January 2026, now requires companion chatbot operators to disclose that the chatbot is not human when a reasonable person might be misled, to run a protocol for suicidal ideation that refers users to crisis services, and, from 1 July 2027, to report annually on the link between chatbot use and suicidal ideation. That a state legislature felt the need to write those duties down is its own answer to whether dependency is a real risk.

5. Minors and the age gate that isn’t there

Every regulator that has acted on companion apps so far has acted because of children, and the age gates on the apps we grade range from a stated 18 to a stated 13. Common Sense Media’s national survey, run by NORC in April and May 2025 with 1,060 US teens, found that 72 percent had used an AI companion at least once, 52 percent used one at least a few times a month, and about one in three had discussed important or serious matters with a companion instead of a real person. Common Sense recommended that nobody under 18 use one until stronger safeguards exist.

The industry’s response has been uneven. Character.AI announced on 29 October 2025 that it would remove open-ended chat for users under 18, with the change taking effect no later than 25 November 2025, starting with a two-hour daily cap and ending at zero, backed by its own age assurance tool and Persona for third-party checks. That followed a lawsuit filed in Florida in October 2024 by the mother of a 14-year-old who died by suicide after months of conversations with a Character.AI bot, and two further family suits in Texas in December 2024. At the other end, Joyland’s privacy policy sets its minimum age at 13, or 16 for EU residents, on a platform whose own terms ban depicting minors; that single clause is why Joyland gets an F on the scorecard despite a decent product. Kindroid says 18 in its terms and 16 in its privacy policy, which is the kind of inconsistency Italy fined Replika over. If you are a parent, the App Store rating is not the age gate; the privacy policy is, and it takes one search to find the number.

What regulators have done so far

Four regulators on three continents have taken concrete action against companion chatbots between February 2023 and September 2026, which is the clearest official answer yet to whether AI companion apps are safe, and the pattern in every case is the same: no age verification, no legal basis for processing, no answer to what happens to the data. Here is the record as it stands on the pages I opened, oldest first.

Date Regulator Action What it means for you
3 Feb 2023 Italy’s Garante Provisional block on Replika processing Italian users’ data: no age checks, inappropriate content shown to minors, no valid legal basis An app can be switched off in a country overnight; your companion goes with it
8 Nov 2024 Ofcom (UK) Open letter confirming AI-generated content and user-created chatbots fall under the Online Safety Act Shared-character platforms in the UK must run illegal-content risk assessments
10 Apr 2025 Italy’s Garante €5 million fine on Luka Inc. (Replika) for processing without a legal basis until February 2023, inadequate transparency and no age verification; separate proceeding reserved on the model’s training Fines follow the paperwork, not the marketing; pre-2023 chats were the problem
11 Sep 2025 US FTC 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, X.AI) on how they monetise engagement, test for harm to children and use conversation data; vote 3-0 Character.AI’s internal safety and data records are now in the FTC’s hands
13 Oct 2025 California SB 243 signed, in force 1 Jan 2026: disclosure that the chatbot is not human, suicide-response protocol, protections for minors, private right of action, annual reporting from 1 Jul 2027 First US law with a private right of action against companion operators
22 Dec 2025 Ofcom (UK) Explainer: chatbots that “only allow people to interact with the chatbot itself and no other users” are outside the Act; services publishing pornographic content via chatbots must use highly effective age assurance Solo-companion apps (Nomi, Kindroid, Replika) largely escape UK duties; character-sharing platforms do not

The EU picture is less direct. The Digital Services Act obliges platforms accessible to minors to maintain a high level of privacy, safety and security, and the Commission’s guidelines of 14 July 2025 cover age verification, privacy by default and risk mitigation for minors; but the DSA regulates platforms, and a one-to-one companion app is not obviously one. What bites in Europe is GDPR, which is what the Garante used both times. If you are in the EU or UK, the practical consequence is that the companies based there (Nastia in France, Candy AI in Malta, CrushOn and Swipey in Cyprus) owe you an erasure right whether their policy is generous or not.

Is X safe? Six apps, one fact each

Two of the six apps people ask about most are B grades on our scorecard, one is a C, one is an F, and two are not yet graded but have regulator files, and in every case a single fact decides the answer. The grades below are the ones on the privacy scorecard, which scores the policy and nothing else; the app can be good and the paperwork bad, and on Joyland both are true.

App Scorecard grade Stated minimum age The fact that decides it
Kindroid B (73) 18 in terms, 16 in privacy policy Chats kept “until you delete a specific AI or delete your account”; encrypted at rest and in transit
Nastia B (72) 18 Only policy promising per-chat deletion reaches the server; French company under GDPR
Candy AI C (56) 18 Third-party LLM providers “may receive the content of your messages”; account data kept up to three years
Joyland F (34) 13 (16 in the EU) A 13+ gate on an adult roleplay platform, plus a perpetual, irrevocable licence to your content
Character.AI Not graded 18 for open-ended chat since Nov 2025 Under FTC 6(b) order since Sep 2025; open-ended chat removed for under-18s after teen-death lawsuits
Replika Not graded 18 Fined €5 million by Italy in April 2025 for pre-2023 practices; current policy keeps messages 60 days after termination

Is Candy AI safe?

Candy AI is safe enough for an adult who is fine with a C (56): its notice, revised 30 July 2026, gives a real retention number (three years after your last activity) and names EverAI Limited in Malta, which puts it under GDPR. The fact that decides the grade is one sentence: third-party LLM providers “may receive the content of your messages,” on top of a clause letting your exchanges be de-identified for model development. There is no self-serve deletion; you email [email protected]. On billing it is the friendliest of the ten, with a 24-hour refund window.

Is Character.AI safe?

“Is Character AI safe” is the most-searched brand question of the six, and the answer is: not graded yet, but it is the only companion app under an FTC 6(b) order (11 September 2025), and it removed open-ended chat for under-18s from 25 November 2025 after the Florida and Texas lawsuits. The deciding fact for adults is that its privacy policy, as read for our best list, allows training on collected information; the page would not render on this pass, so treat that as unconfirmed. Our Character.AI alternatives list covers filter-free options.

Is Joyland AI safe?

Joyland is an F (34) on the scorecard and the reason is one line in its privacy policy: “If you are under 13 years old OR if you are an EU citizen or resident under 16 years old, you are not authorized to register.” A 13+ gate on an adult roleplay platform whose own terms ban depicting minors is the worst clause in twenty documents. The terms add a perpetual, irrevocable licence to your content “for any purpose”; no retention period is stated. The product beats the paperwork, as my Joyland review explains, but I would not use it with a real email.

Is Nastia AI safe?

Nastia is one of the two safest apps we track on paperwork, a B (72), and the fact that decides it is the only per-chat deletion promise in the set: “You can delete chats, images and videos at any time, and you can delete your account from your settings, which deletes your account and the content in it.” The policy, updated 16 September 2026, states an 18+ minimum. Nastia Cybernetics is French, so GDPR erasure applies. It loses points for listing “advertising providers” among recipients and for no training opt-out. The Nastia review covers the app.

Is Kindroid safe?

Kindroid is the highest-graded app on the scorecard, a B (73), and the fact that decides it is that retention is tied to your action, not the company’s judgement: chats and media are kept “until you delete a specific AI or delete your account,” encrypted at rest and in transit. What keeps it out of the A band is a clause letting de-identified content be used “for any purpose,” a note that some disclosures “may constitute a ‘sale’” under state law, and an age gate of 18 in the terms but 16 in the privacy policy. The 3-day trial converts automatically.

Is Replika safe?

Replika is safe on today’s policy and was not on the one Italy fined it for: the Garante’s decision of 10 April 2025 imposed a €5 million fine on Luka Inc. for processing without a legal basis until February 2023 and no age verification, after blocking the app on 3 February 2023. The current policy, dated 27 May 2026, states an 18+ minimum, says anonymised data “is not used to train third-party large language models,” and keeps messages for up to 60 days after termination. Deletion is self-serve. Not graded yet; the Garante’s reserved proceeding on training is the open question.

How to check an AI companion app in 10 minutes

You can answer “are AI companion apps safe” for any specific app in ten minutes with a browser, a search box and no account, and the check below is the one I run before I pay. Each step names the thing to find and what a pass looks like; if a step fails, you have your answer without reading further.

  1. Open the privacy policy and search for “retain” (2 minutes). Pass: a stated period or trigger (“until you delete,” “60 days,” “28 days”). Fail: “as long as necessary” or nothing. Swipey’s six years is technically a pass and practically a fail.
  2. Search for “train” and “improve” (1 minute). Pass: a clear statement that chats are not used to train models, or a documented opt-out. Warning: “aggregated, anonymized and de-identified” for development, which is training with a softer name. Fail: “used to train our models” with no opt-out.
  3. Find the minimum age (1 minute). Pass: 18 in the privacy policy itself, not only in the terms. Fail: 13, 14 or 16, or a different number in each document.
  4. Find the legal entity and the address (1 minute). Pass: a company name, a physical address and a governing law. If the policy names a country in the EU or UK, you have GDPR rights whatever the policy says. Fail: a brand name and a contact form.
  5. Find the cancel button before you pay (2 minutes). Open the pricing page, then the help centre, and look for “cancel.” Pass: Settings, then Subscription, in the app. Fail: “through your payment partner” or email only. Check whether a trial converts automatically and whether unused credits survive cancellation.
  6. Search the app’s name plus “breach” and “haveibeenpwned” (1 minute). Pass: nothing. Fail: a Have I Been Pwned entry. Muah.AI has one; none of our ten does as of September 2026.
  7. Check the date on the policy (30 seconds). SpicyChat’s privacy policy is dated 4 May 2023 and reads like a template; Joyland’s has no date at all. A policy that has not been touched in three years has not been read by the company either.
  8. Decide your identity before you sign up (1 minute). Separate mailbox, no social login, a made-up name in the chat, a virtual or prepaid card. This is the step that would have saved most Muah.AI users, and it takes less time than the age gate.

If an app passes steps 1, 3, 4 and 5, it is in the top third of the market on safety and you can use it with the precautions from step 8. Our how we test page explains how the same questions become scores in reviews, and the editorial policy explains why privacy grades and product scores are kept separate.

The safest picks and why

Kindroid and Nomi are the safest picks if you want a companion and the privacy scorecard is your main worry, Nastia is the safest if you want adult content, and Character.AI is the safest free option for anyone who only wants roleplay with no personal stakes. If “are AI companion apps safe” really means “which one should I install,” this is the section. Those are also, not by coincidence, the platforms at the top of our best AI companion apps ranking, which scores memory, conversation, pricing and privacy separately so that a good policy cannot buy a bad product a place.

Kindroid wins on paperwork (B, 73) and on the absence of billing meters: $13.99 a month on the web buys unlimited chat, selfies and voice with no token balance to run down, and the help centre prints both web and app-store prices side by side. The risks to know are the auto-converting 3-day trial and the 16-versus-18 age inconsistency.

Nomi is a C (67) on the scorecard, one band below Kindroid, because its policy refers to “training archives” that survive deletion. It earns a place here anyway because everything else is unusually clean: deletion “within 28 or so days,” a stated no-sale promise, no advertising networks, a public price list at $15.99 a month and a free tier with no card. If you can live with the archive clause, it is the most predictable app in the category.

Nastia is the safest choice among the NSFW apps, the only B grade in that group, and the best NSFW AI chat apps list ranks it on product as well. The per-chat deletion promise is worth more than any discreet billing descriptor, because it is the one thing that reduces what a breach could expose.

Character.AI is safe in the narrow sense that you can use it without paying, without adult content and, since November 2025, without sharing it with minors; the wider sense depends on a policy I could not read today and an FTC inquiry that has not reported. Our guide to whether Character.AI allows NSFW explains what the filter does and does not do.

Two apps I would not call safe picks whatever the product: CrushOn (F, 34), because its policy says chat contents are used to train its models with no opt-out and deletion is by email only; and Joyland (F, 34), for the 13+ gate. Both appear in our rankings because the products work, and both carry the grade next to the entry so you can decide. The affiliate disclosure lists which platforms on this page pay a commission; Kindroid and Character.AI pay nothing, which is one reason I trust my own ranking of them.

What to do if you want out

Leaving an AI companion app cleanly takes three steps in a fixed order: cancel the subscription first, delete the data second, dispute any charge that should not have happened third. Doing them in the wrong order is how people lose a month’s fee or a credit balance, because several terms, Kalon’s among them, say purchased credits expire when the account is deleted, and none refunds the remainder of a billing period on deletion.

Cancel first. On the web, the route is Settings and then Subscription or Billing on Kindroid, Secrets, Swipey, Candy AI and Nastia. On Nomi and Joyland, cancel through the store or payment partner you bought from; deleting the app does nothing. Screenshot the confirmation. Cancellation on every platform in our cost guide takes effect at the end of the paid period, so you keep access until then and the app has no reason to stop you.

Then delete. Self-serve account deletion exists on Kindroid, Nastia, Secrets, Nomi, Joyland, Replika and SpicyChat. Candy AI, Kalon, Swipey and CrushOn require an email request; the addresses are in the scorecard’s step-by-step section. On Nastia, delete individual chats first, then the account, because it is the only policy that promises the per-chat deletion is real. On Kindroid, run the data export from Profile and then Preferences before you delete, if you want a copy. If you are in the EU or UK, write “erasure request under GDPR Article 17” in the subject line; it gets a faster answer than a support ticket, and the Cyprus, Malta and France entities are bound by it. Expect the stated lag afterwards: 28 days on Nomi, 60 days on Replika, one backup cycle on Nastia, and on Swipey, six years for whatever it classes as personal information.

Dispute last, and only for the right reasons. A charge after you cancelled, a duplicate charge, or a trial that converted without the disclosed reminder is a dispute your card issuer will usually accept; a month you used and regret is not. CrushOn’s terms asking you not to charge back except for fraud are a request, not a rule your bank follows. Candy AI’s 24-hour window (20 tokens or fewer, card purchases only) and the EU/UK 14-day withdrawal right are the only refund rights I found written down, and Kalon’s promise of 30 days’ notice before a price change is the only price-protection clause. Keep the cancellation screenshot; it is the whole case.

If you are leaving because the app has become a habit rather than a hobby, the steps are the same, but do the deletion before the 28-day or 60-day window makes it reversible in your head. The about page explains why I write under a pen name and what I test; the contact page is the fastest way to tell me a policy has changed since this check. Are AI companion apps safe? For an adult who runs the ten-minute check and leaves through the front door, yes, on about half the market. The other half tells you who it is in the privacy policy, and this page exists so that you read it.

This hits different?

One email a month when a platform is breached, a policy changes, a regulator moves or a grade on the scorecard shifts. No hype, no affiliate nudges, and I read the policies so you do not have to.

One email a week at most. Unsubscribe in one click.
What changed since the last check
Sep 22, 2026First full version. Grades taken from the privacy scorecard as of this date; Replika privacy policy (May 27, 2026), Candy AI notice (July 30, 2026) and Nastia policy (September 16, 2026) re-read; regulator actions checked against the FTC, EDPB, Garante, Ofcom and California Senate pages.

Frequently asked questions

Are AI companion apps safe to use as an adult?

Yes, with precautions, on the apps that state a retention period and an 18+ gate. Use a separate email address, never type your real name or anyone else's into a chat, and pay with a virtual or prepaid card. The apps that meet the bar on paperwork are Kindroid and Nastia, both B on our scorecard. None of the apps we track offers a training opt-out, so assume your chats improve the model wherever the policy is vague.

Which AI companion app is the safest?

Kindroid, by a small margin, followed by Nastia. Kindroid's policy ties retention to your own action (chats are kept until you delete the companion or the account) and states encryption at rest and in transit. Nastia is the only policy of the ten graded that promises per-chat deletion reaches the server, and it is a French company bound by GDPR. Neither earned an A because neither offers a training opt-out or names its vendors.

Has an AI companion app ever been hacked?

Yes. Muah.AI, an AI girlfriend site, was breached in September 2024 and the data was added to Have I Been Pwned on 8 October 2024: 1.9 million email addresses alongside the image prompts and sexual preferences attached to them. The hacker described the backend as open-source projects duct-taped together, and extortion attempts against users were reported within days. None of the ten apps on our scorecard has a breach of that kind on record as of September 2026.

Can I get my money back from an AI companion app?

Rarely as a right. Nine of the ten platforms in our cost guide say fees are non-refundable except where the law requires it. Candy AI is the exception with a 24-hour window if you have used 20 tokens or fewer. EU and UK buyers keep a 14-day withdrawal right on most platforms until they start using paid features. For an unauthorised or duplicate charge, the card dispute route works better than the support inbox.

Are AI companion apps safe for teenagers?

No, and the people who study this agree. Common Sense Media's 2025 survey of 1,060 US teens found 72 percent had tried an AI companion and recommended that nobody under 18 use one until safeguards improve. Character.AI removed open-ended chat for under-18s from 25 November 2025 after lawsuits over teen deaths. Italy blocked Replika in 2023 partly over the absence of age checks. Joyland's stated minimum age is 13, which is why it gets an F.

Do AI companion apps sell my data?

Most say they do not sell it in the everyday sense, but several reserve broader rights. Kindroid's policy warns that some disclosures may count as a sale under US state law; CrushOn says chat contents are used to train its models; Candy AI says third-party LLM providers may receive the content of your messages; Joyland's terms take a perpetual, irrevocable licence to everything you create. The clauses are quoted in the privacy scorecard.

A
Adam Whitlock

Adam Whitlock spent six years testing mobile games for a living before turning the same habits on AI companion apps. He pays for every subscription he reviews, keeps a spreadsheet of what each one actually costs, and writes under a pen name. About the author

Sources (15)
  1. FTC press release, September 11, 2025: FTC Launches Inquiry into AI Chatbots Acting as Companions
  2. Have I Been Pwned: Muah.AI data breach (1.9M accounts, added 8 Oct 2024)
  3. Malwarebytes, October 9, 2024: AI girlfriend site breached, user fantasies stolen
  4. European Data Protection Board: Italian SA fines company behind chatbot Replika (decision of 10 April 2025)
  5. Garante per la protezione dei dati personali: provisional limitation on Replika, 3 February 2023
  6. Ofcom, 22 December 2025: AI chatbots and online regulation, what you need to know
  7. Senator Steve Padilla: First-in-the-Nation AI Chatbot Safeguards Signed into Law (SB 243, October 13, 2025)
  8. Common Sense Media press release, July 16, 2025: Nearly 3 in 4 Teens Have Used AI Companions
  9. TechCrunch, July 21, 2025: 72% of US teens have used AI companions, study finds
  10. arXiv 2503.17473 (MIT Media Lab and OpenAI): How AI and Human Behaviors Shape Psychosocial Effects of Extended Chatbot Use
  11. Character.AI blog, October 29, 2025: Taking Bold Steps to Keep Teen Users Safe
  12. Wikipedia: Character.ai (lawsuits and under-18 changes)
  13. Replika privacy policy, last updated May 27, 2026
  14. Candy AI / EverAI privacy notice, revised July 30, 2026
  15. Nastia privacy policy, last updated September 16, 2026

Price changes and new platforms, once a week.

No hype, no daily mail. Unsubscribe in one click.