Are AI girlfriend apps safe? Privacy, payments and age checks explained
AI girlfriend apps are safe to use if you treat every message as something a company keeps: the real risks are what happens to your chats and how your card is billed, not your phone being hacked. Mozilla found that 10 of the 11 romantic chatbots it reviewed failed its minimum security standards, and most refund policies across the 31 apps we track offer little or nothing once you have used a plan.
What the privacy research found
The most detailed independent look at this category is Mozilla's *Privacy Not Included review of 11 romantic AI chatbots, published in February 2024. Every one of them earned Mozilla's warning label, which the researchers said put romantic chatbots on par with the worst categories of products they had ever reviewed for privacy. The main findings:
- 10 of the 11 apps could not be confirmed to meet Mozilla's Minimum Security Standards.
- 73% published no information on how they manage security vulnerabilities, and 64% gave no clear information about encryption.
- 45% allowed weak passwords, including the single character "1".
- 90% may share or sell personal data, for example for targeted advertising, or did not say enough to rule it out.
- 54% did not give every user the right to delete their personal data.
- The apps averaged 2,663 trackers per minute of use, pushed up by one app that fired 24,354 in a single minute.
The review covered apps such as Replika, Chai, Romantic AI, EVA AI and CrushOn.AI rather than every app we rank, and policies change. The pattern still holds: companion apps collect intimate information by design, and many say little about how they protect it.
Breaches do happen. In September 2024 the AI girlfriend site Muah.AI was breached, and Have I Been Pwned lists 1.9 million email addresses exposed along with the prompts users had written.
Who runs AI girlfriend apps, and where they are registered
A named company with a registered address is the most useful trust signal an app can give. It tells you which country's consumer and privacy laws apply, who to send a refund or deletion request to, and who is accountable if something goes wrong. Every one of the 31 apps we track has a named operating company in our data, taken from each app's own terms, footer or legal pages. They are spread across 11 countries:
| Country | Apps | Which apps |
|---|---|---|
| United States | 11 | Secrets AI, OurDream, Nomi AI, Infatuated AI, Kindroid, TryNectar AI, Dondi.ai, HeyGF, Replika, Muah AI and Roger |
| Cyprus | 8 | Lovescape, Kupid AI, Joi, GoLove AI, CrushOn AI, Spicier, Swipey AI and Anima |
| Romania | 3 | FantasyGF, DreamGF and DreamBF.ai |
| Malta | 2 | Candy AI and LusyChat |
| Canada | 1 | GirlfriendGPT |
| Germany | 1 | My Dream Companion |
| Italy | 1 | AI Peeps |
| Netherlands | 1 | Selira AI |
| Spain | 1 | My Lovely AI |
| Switzerland | 1 | DarLink AI |
| United Kingdom | 1 | SweetDream AI |
Some companies run more than one app: Warmtech Ltd (Lovescape and Spicier) and DreamAI SRL (DreamGF and DreamBF.ai). Candy AI's own terms, for example, name EverAI Limited, registered in Malta under company number C107181. A name alone does not make an app trustworthy, but it does tell you where to send a complaint and which country's regulator to contact.
Trust is 10% of every score in our methodology. It covers whether the company is named, where it is registered and how clear the billing and refund terms are.
What happens to your chats, pictures and voice
Everything you type, every picture you generate and every call you make is processed on the company's servers. Depending on the privacy policy, it may be stored indefinitely, read by moderators, used to train the model or shared with service providers. Mozilla found that most of the companies it reviewed say they can share information with government or law enforcement without a court order, and that one privacy policy allowed the collection of sexual health information.
A few habits cut the risk a lot:
- Use a separate email address and a strong, unique password.
- Do not share your full name, address, employer, or photos of yourself or other real people.
- Turn off location, contacts and photo-library access in your phone's settings unless a feature needs them.
- Opt out of having your chats used for AI training if the app offers it.
- Ask the company to delete your data when you stop using the app.
Mozilla's own summary of the safest habit is blunt: do not say anything to an AI companion that you would not want your cousin or colleagues to read.
Payments, renewals and refunds
For most people the bigger risk is the bill. Three patterns catch users out.
Yearly plans are charged up front
The low monthly prices you see are usually yearly plans paid in one go. Infatuated AI's cheapest plan works out at $6.99 a month, but it is a 12-month plan billed $83.88 up front. Plans renew automatically unless you cancel.
Refund windows are short or missing
Candy AI's terms allow a refund request within 24 hours of paying, refused if you have used more than 20 tokens, with a 14-day withdrawal right for EU and UK residents (Candy AI terms, section 10.4). Nomi's policy says all payments are nonrefundable apart from case-by-case exceptions, and Swipey AI's terms call all purchases final and non-refundable. Assume you will not get money back.
Tokens go fast
Pictures, videos and calls use tokens or credits. Top-up packs are an easy way to spend more than the subscription in a single month.
Paying through Apple or Google puts cancellation and refund requests in one familiar place, while paying on the website means dealing with the app directly. Our step-by-step guide on how to cancel an AI girlfriend subscription covers both.
Age checks and the law in 2026
Every app we track is for adults only. How hard they check varies, and regulators are closing in:
- Italy: the data protection authority fined Replika's developer Luka Inc. 5 million euros in April 2025, partly because it had no age verification despite saying minors were excluded.
- United Kingdom: Ofcom has said that sites and apps with generative AI tools that can produce pornographic material are regulated under the Online Safety Act and must use highly effective age assurance. It has been investigating adult sites without age checks since new rules came into force on 25 July 2025.
- California: SB 243, signed into law in October 2025, requires companion chatbots to disclose that they are AI, show minors a reminder every three hours, keep suicide and self-harm protocols, and block sexually explicit content for minors. Users can sue for at least $1,000 per violation.
- US federal: in September 2025 the FTC ordered seven companies, including Character Technologies, Meta, OpenAI and xAI, to explain how their companion chatbots protect children and teens.
The pressure exists because teens use these apps. Common Sense Media found that 72% of US teens have used AI companions at least once, and it recommends that no one under 18 use them. Expect more apps to ask for ID or a face check before unlocking 18+ content. Secrets AI already treats age and consent verification as a core part of its platform.
Emotional safety: dependence, spending and well-being
Safety is not only about data. AI companions are designed to be pleasant and available at any hour, which is exactly what can make them hard to put down. A four-week MIT Media Lab study of 981 people found that participants who voluntarily used a chatbot more had consistently worse outcomes, including more loneliness, more emotional dependence and less time with real people.
Mozilla also noted that apps marketed as good for your mood or mental health disclaimed any therapeutic benefit in their terms. An AI companion is not a therapist, however supportive it sounds.
Warning signs worth taking seriously:
- Spending more than you planned on tokens or upgrades.
- Skipping plans with friends to keep chatting.
- Feeling anxious when you cannot open the app.
- Hiding it from a partner.
If any of these apply, set time limits, turn off notifications or take a break. If you are struggling, talk to someone you trust, or in the US call or text 988 to reach the Suicide and Crisis Lifeline.
A safety checklist before you pay
- Check who runs the app and where the company is registered, in the terms of service or the footer.
- Read the refund and cancellation section of the terms before paying, not after.
- Pay month to month for the first month, even though yearly is cheaper per month.
- Use a card you can freeze, or pay through the App Store or Google Play so cancellation is in one place.
- Set a calendar reminder three days before the renewal date.
- Sign up with an email you use only for this, and a unique password.
- Keep identifying details and photos of real people out of the chat.
- Find the data deletion option in settings, and use it when you leave.
The reviewed apps with the highest trust scores right now are Nomi AI (8.4 out of 10, run by Glimpse.ai, Inc.), Secrets AI (7.6 out of 10, run by Secret Labs Inc.) and Candy AI (7.2 out of 10, run by EverAI Limited). If you want the uncensored side of the category, our list of NSFW AI girlfriend apps applies the same trust score.
Frequently asked questions
Are AI girlfriend apps safe to use?
They are safe enough for adults who share nothing identifying and keep spending under control. The main risks are how chats are stored and shared, plans that renew automatically, and strict refund rules. Check who runs the app and read its refund terms before you pay.
Do AI girlfriend apps sell your data?
Some can. Mozilla's 2024 review of 11 romantic AI chatbots found that 90% may share or sell personal data, for example for targeted ads, or did not say enough to rule it out. Read the privacy policy of the app you choose and opt out of sale or sharing where your local law allows.
Are AI girlfriend chats private?
Not in the way a message to a friend is. Chats are stored on the company's servers and may be reviewed by moderators, used to improve the AI or disclosed to authorities. Assume anything you type could one day be read by someone else.
Can I delete my data from an AI girlfriend app?
Often, but not always. Mozilla found that about half of the romantic chatbots it reviewed did not give every user the right to delete their personal data. Look for a delete-account option in settings; if there is none, email the company and cite laws such as California's CCPA or the GDPR.
Do AI girlfriend apps check your age?
All of them say they are for adults, but checks range from a tick box to ID or face-based verification. Rules are tightening: the UK requires highly effective age assurance for services that can generate pornographic material, and California's SB 243 adds protections for minors using companion chatbots.
Is it safe to use my card on an AI girlfriend app?
Card payments go through payment processors, so the card itself is at no more risk than any online purchase. The bigger risk is automatic renewal combined with strict refund rules. Pay monthly at first, set a renewal reminder and consider paying through the App Store or Google Play.
How can I tell if an AI girlfriend app is legit?
Look for a named company with a registered address in the terms, a clear price before you pay, a written refund and cancellation policy, and a way to delete your account. Apps that hide all of these are harder to hold to account if something goes wrong.
Keep reading
- How to cancel a subscriptionCancel on the web, App Store or Google Play, get refunds, delete data.
- What is an AI girlfriend?How AI girlfriend apps work, what they can do and what they cost.
- NSFW AI girlfriendApps that allow 18+ chat and media, and how age checks work.
- All reviewsEvery AI girlfriend app we review, with its score and price.
- How we rankHow AI Girlfriends Guide scores AI girlfriend apps: six weighted categories, sources we use, how often we re-check prices and why paying apps get no advantage.