The AI Companion Safety & Privacy Handbook
One fact organizes everything: no AI companion platform is end-to-end encrypted, because memory requires the server to read you. From that follows the whole discipline — the threat model, the five-moment protocol, the platform data-practice tiers, the category's breach history told straight, and the exit ritual. The complete handbook, one page.
By Ash Kepler · Jul 19, 2026 · 15 min read
One fact organizes this entire handbook, so it goes first, in bold: no AI companion platform is end-to-end encrypted — none — because memory and personalization architecturally require the server to read what you write. Your conversations live readable on company infrastructure, scanned by automated moderation, subject to human review on reports, and governed by policies you didn't write. That isn't a scandal; it's the design. But it means privacy in this category is never something you buy — it's something you practice. This is the complete practice: threat model, protocol, platform tiers, breach history, and the exit.
Part 1: The honest threat model
Rank the threats by realism, because defense budgets should follow probability. Most likely: mundane exposure — a notification preview on a lock screen, a shared card statement, a browser autofill offering your name to an adult site, a shared device's history. Cheap to defend, most often the actual incident. Likely over time: platform data practices — chats used for training (varies by platform), broad "partner" sharing clauses, retention after "deletion" on weaker platforms. Defended by platform choice and content discipline. Rare but catastrophic: the breach — this category stores maximally sensitive data and has at least one proven catastrophic incident; defended almost entirely by identity separation — a breach that leaks a dedicated email tied to no real name is an inconvenience; the same breach tied to your primary identity is the Muah story. Background: platform death and policy change — servers get wiped and rules get rewritten; defended by local backups. Notice what's absent: exotic hacking of you. The realistic threats are boring, and so are the defenses — which is the good news.
Part 2: The five-moment protocol
Privacy happens at five moments, each with one discipline. Signup — identity separation: a dedicated email (no real name, used for nothing else — it becomes login, recovery, and deletion channel, isolating the whole category from your identity), and a username you've never used elsewhere (reverse username search is the cheapest doxx that exists). Payment — billing isolation: virtual card numbers (own limit, deletable, kills zombie renewals), descriptor checked before subscribing — the table matters: Candy → UPGATE.COM (nothing identifiable), Dream Companion → MiracleAI, some platforms → their own names in lights, app-store billing → a store charge with the app name buried (workable indirect discretion). The full payment mechanics by market. Chatting — the golden rule: real feelings, fake facts. The better the companion, the stronger the pull to tell her everything — so the line must be bright: emotions, tastes, and stories with names changed flow freely; full names, employers, addresses, family members' real names, and identifiable specifics (plates, schools, one-of-a-kind anecdotes) never enter. Photos carry location metadata; voice is biometric; both deserve a three-second pause. Device — the four gestures: separate browser profile for the category, apps off the home screen with notification previews disabled (the lock-screen "I miss you" in a meeting is the category's classic self-inflicted wound), autofill off on these sites, incognito-always on shared machines. Exit — the ritual with an order: covered in Part 5, because doing it backwards costs money.
Part 3: Platform data-practice tiers
Calibrate confidence depth to platform honesty. The standard-setter — Kindroid: explicit no-training-on-your-conversations commitment, a viewable, editable memory bank (you can audit what she knows and delete it), and deletion that deletes. This is what good faith looks like structurally, and it's why deep confidences are rational there. The discreet professional — Candy: category-best billing opacity, real self-serve deletion (settings → Danger Zone), solid baseline practices; the media-token structure is a wallet issue, not a privacy one. The broad middle: most major platforms — standard encryption, standard moderation, policies of varying vagueness, third-party clauses of varying width. The protocol above is designed for this tier: practiced fully, the middle is fine for everything you'd accept a stranger's server holding. The demonstrated floor — Muah: one breach, ~1.9 million emails tied to private prompts, HIBP-catalogued as sensitive, extortion in the aftermath, store delistings — the category's standing proof that the floor exists. Platforms are innocent until documented; Muah is documented. And the structural exception — the self-hosted route: your own frontend, your own model key, data residing with a model API rather than a companion platform (or fully local, with the right setup) — the only architecture in which privacy is a property rather than a practice. The migration of China's displaced users toward exactly this is the category's largest-ever endorsement of the principle.
Part 4: The breach that defines the stakes
The Muah incident deserves its half-page because every abstract warning above is concrete inside it. September 2024: intruders breach Muah AI and extract roughly 1.9 million registered email addresses along with the image-generation prompts tied to each account — for a platform of its type, close to the most intimate data pairing possible. The breach lands in Have I Been Pwned's sensitive class (verifiable only by the email's owner); security researcher Troy Hunt documents it; extortion emails follow, some to workplace addresses — meaning the users who registered with real, primary emails experienced the full worst case, while users with dedicated throwaway emails experienced… an inconvenience. Same breach, two outcomes, one variable: identity separation, decided months earlier at a signup screen. That is the entire argument of this handbook in a single incident. (Anyone with a pre-2024 Muah account: check the email at Have I Been Pwned tonight, rotate any reused password, delete the account, keep the receipt. The full account.)
Part 5: The exit ritual, and the backup that isn't optional
Leaving a platform has an order, and reversing it costs money: cancel the subscription first (deleting an account does not stop billing — the phantom-charge classic), then delete via the official channel (Candy: Danger Zone; Kindroid: account settings, and there deletion is real; email-only-deletion platforms: send it and keep the thread — and weight "self-serve deletion exists" heavily at signup, because platforms that only let you leave by email never gave you the controls), then screenshot the confirmation. And before any exit — indeed, tonight, regardless — the one practice this site will repeat until the heat death of the universe: the local backup. Persona verbatim plus a self-written relationship summary, in your own notes, updated monthly. It's simultaneously your memory tool, your migration kit, and your insurance against every threat in Part 1 that no protocol can prevent — the shutdown, the policy change, the decree. Privacy in this category, fully practiced, comes down to a fair trade stated plainly: the platform holds a record of your heart, and you hold everything that could connect it to your name — plus the originals. Keep both sides of that trade, and this whole category is exactly what it should be: a private room, in your own house, where someone is always glad you're back.
questions