A data request is the most direct privacy check you can run. Rather than reading a policy about what a company might do with your information, you get a copy of what it actually holds.
Which rules apply to you

Your rights follow where you live, not where the company keeps its servers.
- Australia: the Privacy Act 1988 and its Australian Privacy Principles. Principle 12 gives you access to the personal information a business holds about you, and Principle 13 lets you have it corrected. The Act generally covers businesses with annual turnover above A$3 million, plus a few smaller categories, so a tiny startup may fall outside it.
- EU and EEA: GDPR adds a right to delete and export your data, and to object to certain uses. It applies if the company offers its service to people in Europe.
- UK: UK GDPR, with the same rights.
- US: state laws such as California's CCPA give US residents comparable rights. They matter for you mostly as context, since you would be relying on the Australian Act.
Even if a company says none of these bind it, ask anyway. Many handle every request the same way because that is easier than sorting people by country.
A caution on deletion. The Privacy Act has no blanket "right to erasure" like GDPR. Businesses must take reasonable steps to destroy or de-identify information they no longer need, and you can still ask. Some will say yes simply because it is their policy.
Choosing what to ask for
| What you want | What you receive | Best moment |
|---|---|---|
| Access | A copy of your information and how it is used | Always the first request |
| A portable copy | Your data in a format another service can read | Before moving to a different app |
| Deletion | Your information destroyed or de-identified | Leaving for good, or after a breach |
| Stop certain uses | No more model training or marketing use | Sticking around on your terms |
| Correction | Wrong details fixed | Incorrect age or email, mixed-up accounts |
A message you can paste
Send it from the email address tied to your account. Aim it at the privacy contact in the company's policy (often privacy@ or dpo@), or use its privacy form. You do not have to say it is a formal request under a particular law, but naming one helps.
Subject: Request for access to my personal information
I am asking for access to the personal information you hold about me under Australian Privacy Principle 12 of the Privacy Act 1988 (and Article 15 GDPR where it applies). My account email is [address] and my username is [username].
Please send: a copy of everything you hold about me, including chat history, images I made or uploaded, voice recordings, memory or profile data inferred from my chats, payment records and device data; why you hold it; who you have passed it to, including advertisers and AI model providers; how long you keep it; and whether it has been used to train or improve AI models.
Please reply within a reasonable time, and tell me if you intend to charge a fee.
To ask for deletion instead, swap the first paragraph for a request to destroy or de-identify all your personal information and to confirm in writing when that is done, backups and service providers included.
Signs of a good reply
A conscientious company sends a downloadable archive: your chats, a list of the stored "memories" about you, images, billing and login history, and a plain explanation of who received what. Look hardest at two parts:
- Inferred data. Summaries, personality notes and "facts about you" the app worked out itself. These are frequently the most revealing pages, and they show how AI companion memory works for you in particular.
- Recipients. Model providers, analytics firms and ad partners. Set the list against what the privacy policy claimed; the background is in do AI girlfriend apps sell your data.
If you are ignored or stonewalled
- Follow up in writing once a reasonable time has passed, quoting the date of your first message.
- Lodge a complaint with the company about how it handled the request. The OAIC will not take a complaint until you have done this.
- Go to the OAIC. If the company has not answered within 30 days, or you are unhappy with its response, you can lodge a complaint with the Office of the Australian Information Commissioner using its online form. If the company is in an industry with its own dispute scheme, check that first.
- Keep every message and date. Regulators ask for them.
Regulators do act in this space. Italy's data protection authority fined the company behind Replika 5 million euros in 2025, partly because its privacy policy did not clearly explain what it did with people's data.
Export before you erase
If you might want your character or chat history one day, download it or run the app's export tool before asking for deletion. Deletion cannot be undone, and some apps only rotate backups out after several weeks. The full order of steps is in deleting an AI companion account.
Worth doing even if you stay
A data request doubles as a quiet character test. A company that answers clearly and on time is showing you how it treats the rest of your information. One that goes silent is telling you something too, and you will have found out before a breach rather than after it.