Getting Your Data Back From an AI Companion App: A Practical Walkthrough

Privacy & staying safe

Australian law lets you ask any company covered by the Privacy Act what personal information it holds about you. Hardly anyone does it with a companion app. It takes about ten minutes, and what comes back is often eye-opening.

We may earn a commission from links on this page. It never changes a rating.

A data request is the most direct privacy check you can run. Rather than reading a policy about what a company might do with your information, you get a copy of what it actually holds.

Which rules apply to you

Summary of data rights by region: the Privacy Act 1988 in Australia, GDPR in the EU and EEA, UK GDPR in the UK, and state privacy laws in the US

Your rights follow where you live, not where the company keeps its servers.

  • Australia: the Privacy Act 1988 and its Australian Privacy Principles. Principle 12 gives you access to the personal information a business holds about you, and Principle 13 lets you have it corrected. The Act generally covers businesses with annual turnover above A$3 million, plus a few smaller categories, so a tiny startup may fall outside it.
  • EU and EEA: GDPR adds a right to delete and export your data, and to object to certain uses. It applies if the company offers its service to people in Europe.
  • UK: UK GDPR, with the same rights.
  • US: state laws such as California's CCPA give US residents comparable rights. They matter for you mostly as context, since you would be relying on the Australian Act.

Even if a company says none of these bind it, ask anyway. Many handle every request the same way because that is easier than sorting people by country.

A caution on deletion. The Privacy Act has no blanket "right to erasure" like GDPR. Businesses must take reasonable steps to destroy or de-identify information they no longer need, and you can still ask. Some will say yes simply because it is their policy.

Choosing what to ask for

What you wantWhat you receiveBest moment
AccessA copy of your information and how it is usedAlways the first request
A portable copyYour data in a format another service can readBefore moving to a different app
DeletionYour information destroyed or de-identifiedLeaving for good, or after a breach
Stop certain usesNo more model training or marketing useSticking around on your terms
CorrectionWrong details fixedIncorrect age or email, mixed-up accounts

A message you can paste

Send it from the email address tied to your account. Aim it at the privacy contact in the company's policy (often privacy@ or dpo@), or use its privacy form. You do not have to say it is a formal request under a particular law, but naming one helps.

Subject: Request for access to my personal information

I am asking for access to the personal information you hold about me under Australian Privacy Principle 12 of the Privacy Act 1988 (and Article 15 GDPR where it applies). My account email is [address] and my username is [username].

Please send: a copy of everything you hold about me, including chat history, images I made or uploaded, voice recordings, memory or profile data inferred from my chats, payment records and device data; why you hold it; who you have passed it to, including advertisers and AI model providers; how long you keep it; and whether it has been used to train or improve AI models.

Please reply within a reasonable time, and tell me if you intend to charge a fee.

To ask for deletion instead, swap the first paragraph for a request to destroy or de-identify all your personal information and to confirm in writing when that is done, backups and service providers included.

Signs of a good reply

A conscientious company sends a downloadable archive: your chats, a list of the stored "memories" about you, images, billing and login history, and a plain explanation of who received what. Look hardest at two parts:

  • Inferred data. Summaries, personality notes and "facts about you" the app worked out itself. These are frequently the most revealing pages, and they show how AI companion memory works for you in particular.
  • Recipients. Model providers, analytics firms and ad partners. Set the list against what the privacy policy claimed; the background is in do AI girlfriend apps sell your data.

If you are ignored or stonewalled

  1. Follow up in writing once a reasonable time has passed, quoting the date of your first message.
  2. Lodge a complaint with the company about how it handled the request. The OAIC will not take a complaint until you have done this.
  3. Go to the OAIC. If the company has not answered within 30 days, or you are unhappy with its response, you can lodge a complaint with the Office of the Australian Information Commissioner using its online form. If the company is in an industry with its own dispute scheme, check that first.
  4. Keep every message and date. Regulators ask for them.

Regulators do act in this space. Italy's data protection authority fined the company behind Replika 5 million euros in 2025, partly because its privacy policy did not clearly explain what it did with people's data.

Export before you erase

If you might want your character or chat history one day, download it or run the app's export tool before asking for deletion. Deletion cannot be undone, and some apps only rotate backups out after several weeks. The full order of steps is in deleting an AI companion account.

Worth doing even if you stay

A data request doubles as a quiet character test. A company that answers clearly and on time is showing you how it treats the rest of your information. One that goes silent is telling you something too, and you will have found out before a breach rather than after it.

Frequently asked questions

How soon does the company have to reply?

The Privacy Act says a business must respond within a reasonable period. The OAIC treats 30 days as the outer limit you should expect. Under the EU and UK GDPR the deadline is a firm one month, stretchable by two if the request is complicated and you are told why.

Can they charge me for it?

A business can charge for access in Australia, but the fee must not be excessive. It can only cover things like staff time to find and copy your information and postage. Most apps simply do not charge, so ask for the archive first and question any fee.

What if the company is based overseas?

The Privacy Act can reach overseas businesses that carry on business in Australia, and GDPR follows companies that serve people in Europe. Chasing a small offshore operator is harder in practice, but the right still exists and plenty of companies answer anyway to protect their market.