Source-first safety checklist

How to Compare AI Companion Privacy Policies

A privacy notice is most useful when you convert it into answerable questions. A reassuring adjective is less informative than a sentence naming a data category, purpose, recipient, retention rule, or control. This guide does not award scores or assert compliance. It teaches a source-first comparison that keeps uncertainty visible and checks the live policy again before account creation, upload, or payment.

Check the live source before acting. Policies, prices, credit rules, feature limits, labels, and account screens can change. Recheck the provider's current terms, privacy notice, checkout, help pages, and account interface. This site does not claim to have tested paid accounts and does not promise security, compliance, deletion results, fixed costs, or medical outcomes. Page updated 2026-07-26.

Fast evidence screen

What to verify before continuing
AreaUseful current evidenceReason to pause
Scope and controllerThe notice identifies service, company, region, and covered usersIt is unclear which product or entity the notice covers
Data and purposeCategories are connected to stated usesBroad purposes are listed without data examples
Sharing and processorsRecipient types and reasons are explainedThe notice says trusted parties without useful detail
Retention and controlRules, criteria, or examples connect to request routesForever and immediately are implied without operational detail

Confirm scope and date

Question: Does this notice cover the exact service, account type, and region you are considering?

Action: Record title, effective date, accessed date, company name, and product scope before reading individual promises. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: The live notice and any region-specific supplement linked from it. Keep the access date and enough context to understand the wording later.

Worked example: A parent-company policy may cover several products with separate supplements.

Pause when: No entity, service scope, effective date, or contact route can be identified. A pause is a useful result when proceeding would require an assumption.

Map data to purpose

Question: Which profile, conversation, upload, billing, technical, and support categories are named, and why?

Action: Create one row per category and copy the stated purpose beside it. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: Short accurate excerpts with section links, not paraphrases that strengthen the claim. Keep the access date and enough context to understand the wording later.

Worked example: Conversation content and payment metadata may appear in different sections with different purposes.

Pause when: The notice uses open-ended language without examples or boundaries you can understand. A pause is a useful result when proceeding would require an assumption.

Trace sharing language

Question: Which recipient categories receive which data for what reason?

Action: Separate service providers, business partners, legal disclosures, corporate changes, and public sharing. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: The recipient category, purpose, and any linked vendor or regional information. Keep the access date and enough context to understand the wording later.

Worked example: A provider hosting infrastructure differs from content intentionally shared publicly; keep the categories distinct.

Pause when: The notice uses vague partner language and support will not clarify material sharing. A pause is a useful result when proceeding would require an assumption.

Read retention as criteria

Question: Does the notice give periods, events, or criteria for each important category?

Action: Record exact language and mark unknown where no usable duration or criterion appears. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: The retention section plus deletion and account-closure explanations. Keep the access date and enough context to understand the wording later.

Worked example: Billing records and conversation content may follow different stated rules; do not apply one sentence to both.

Pause when: A summary promises immediate removal while detailed terms describe unexplained exceptions. A pause is a useful result when proceeding would require an assumption.

Verify controls in the interface

Question: Can you find the settings, export, deletion, communication, and contact routes described?

Action: Open the current account or help screens before relying on policy wording, without purchasing merely to test. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: A dated control-path record and unresolved questions sent to official support. Keep the access date and enough context to understand the wording later.

Worked example: A notice may name a request right while the actual route is a form or support address.

Pause when: The control is inaccessible, the route is broken, or support contradicts the policy. A pause is a useful result when proceeding would require an assumption.

Copyable checklist

Complete each line from the provider's current interface or published documents. A blank or unclear answer should remain visible in your notes.

Worked situations

Policy A is shorter than Policy B

Length is not a quality score. Compare whether each answers the same worksheet questions with specific, current language. A shorter notice can be clearer; a longer one can still leave key categories or controls vague.

Record what the current source shows, keep personal details out of the worksheet, and mark unresolved questions rather than filling them with an assumption.

Summary and detailed notice conflict

Treat the detailed current notice, interface, and provider clarification as separate evidence. Record the conflict rather than choosing the friendlier statement. Ask official support which language controls and preserve the answer.

Record what the current source shows, keep personal details out of the worksheet, and mark unresolved questions rather than filling them with an assumption.

How to record a reliable answer

Use a dated worksheet with four columns: the question, the current source, the exact answer, and what remains unknown. Prefer a live detailed policy or account control over a promotional summary. Preserve enough surrounding wording to avoid changing the meaning, but cover names, addresses, payment values, conversation text, and other personal details. A screenshot records one interface at one moment; it is not proof that the same rule applies later, in another region, or to another account.

When two sources disagree, do not choose the answer you prefer. Record the conflict and ask the provider through a contact route reached from its current account, terms, or privacy page. Keep the case number and exact response. If the answer affects payment, an upload, account access, or sensitive disclosure, wait until the conflict is resolved or choose not to proceed. Unknown is a valid worksheet result.

A calm stop rule

Pause when a required term is missing, the final confirmation differs from the earlier page, a request moves outside the documented account route, or support asks for secrets that normal support should not need. Do not send passwords, one-time codes, full payment credentials, recovery secrets, or unrelated private conversation content. Do not install unknown software or grant remote control. Return through a known official address and verify the account state independently.

Related safety checklists

Frequently asked questions

Can this checklist tell me which policy is safest?

No. It helps you compare disclosed practices and uncertainty. Your decision depends on the data you plan to share, the controls you need, and answers from current official sources.

Does a privacy notice prove the interface follows it?

A notice is one source. Check the current account, upload, billing, notification, export, and deletion controls that matter to you and record any mismatch.

Should I rely on a policy summary?

Use summaries for navigation only. Read the linked detailed notice and any regional or product supplement before relying on a claim.

How often should I compare again?

Recheck before a new sensitive use, upload, payment, or major account change, and whenever the provider announces a policy update. Keep dates so old evidence is not mistaken for current.