Character.AI chats are private from other users but not from Character.AI itself: nothing you type is end-to-end encrypted, and staff, automated systems, and third-party contractors can access it under normal operating conditions. Before you send another message, check your model-training opt-out in account settings, strip out anything personally identifying, and export your chat history in case you decide to delete later.
TL;DR:
- Character.AI does not offer end-to-end encryption, meaning staff and contractors can access your stored conversations at any time.
- The platform collects extensive data, including personal details, uploaded media, conversation logs, device information, and behavioral signals, which sit on servers indefinitely.
- Deletion of chats only removes visible content; backups and model training data may still retain your information permanently, and your conversations influence AI behavior long-term.
- Regulatory actions in Europe revealed transparency and child protection issues, prompting potential policy changes and stricter regional privacy controls.
- Risks include data memorization and inversion within models, making it impossible to fully erase learned information, especially for sensitive topics and private conversations.
Table of Contents
- What Character AI Collects About You
- Who Can See Your Chats? Encryption and Access, Explained
- How Character.AI Uses Your Chats
- What Happens When You Delete Your Chats or Account
- Your Regional Privacy Rights and How to Use Them
- The Hidden Risk: What Foundation Models Remember Forever
- What the Italian Regulator Found (And Why It Matters to You)
- How to Check and Change Your Character.AI Privacy Settings
- Security Measures: Encryption, Breach History, and Incident Response
- Who Else Gets Your Data: Partners, Advertisers, and Beyond
- Cross-Border Data Transfers and Jurisdictional Gaps
- Anonymity, Pseudonymity, and What They Actually Protect
- How Character.AI Stacks Up Against Other AI Companion Apps
- Find a Privacy-First AI Companion With Virtualship
- Sources
What Character AI Collects About You
Character.AI’s privacy policy, effective July 1, 2026, spells out a broader data haul than most users assume. It’s not just your messages. The company collects account and profile details, plus any voice recordings or images you upload to build or interact with a character.
Here’s the full picture of what typically gets logged:
- Account and profile information: email, username, birthdate, and any linked social login data.
- Uploaded media: voice samples for voice chat features and images used for avatars or character creation.
- Full conversation content: every message you send and receive, plus metadata like timestamps and how long each session ran.
- Device and network data: IP address, device identifiers, browser headers, and operating system details.
- Behavioral and advertising signals: usage patterns, click data, and inferences the platform computes about your interests.
The riskiest category is the plainest one: whatever you type into the chat box. Users routinely disclose names, locations, relationship details, health information, and financial worries to characters that feel private but aren’t. Voice recordings and uploaded images carry similar weight. Once submitted, they sit on Character.AI’s servers indefinitely under the same access model as your text conversations.
Who Can See Your Chats? Encryption and Access, Explained
Character.AI uses TLS to encrypt data in transit, the same standard protecting most web traffic. That’s where the encryption story ends. There’s no end-to-end encryption, meaning the company holds the decryption keys and can read stored conversations whenever a workflow calls for it.
According to an OECD incident entry describing the platform’s access and moderation practices, automated systems scan chats continuously, and specific events, flagged content, safety reports, abuse complaints, can trigger human review. That review isn’t limited to a small internal team. Engineers, support staff, and third-party contractors may access stored content depending on the workflow, and the company can disclose data in response to law enforcement requests or legal process.
One number worth sitting with: zero. That’s how many of your Character.AI conversations are protected by end-to-end encryption, the same standard used by apps like Signal. Every message you send is readable server-side by design, not by accident.
How Character.AI Uses Your Chats
The privacy policy names several permitted uses for your conversation data, and they extend well past simple app functionality. Understanding these matters because each use case creates a different kind of exposure.
- Model training and improvement: your chats can be used to train and refine the underlying AI models, with opt-out availability varying by region.
- Moderation and safety review: content gets scanned and sometimes reviewed by humans to enforce community guidelines.
- Personalization: the system builds inferences about your preferences to tailor character responses and recommendations.
- Analytics and product development: aggregated usage patterns inform feature decisions.
- Advertising-adjacent signals: behavioral data can feed targeting or measurement systems tied to the broader platform.
The training use deserves the most attention. Once a conversation contributes to a model’s training run, it can shape how that model responds to future users, and there’s no reliable way to reverse that influence later. Regional opt-outs exist for some users, but a global, universal opt-out isn’t part of the current policy. If you’ve ever wondered why a chatbot seems to “remember” patterns in tone or phrasing across unrelated conversations, this is part of the mechanism.
What Happens When You Delete Your Chats or Account
Hitting delete doesn’t work the way most people assume. Here’s the actual sequence and its limits:
- Visible content disappears from your account interface, but that’s a front-end change, not a guarantee the underlying data is gone.
- Server-side backups can retain copies for security, legal, or operational reasons, sometimes for a defined retention window described only in vague terms like “as long as reasonably necessary.”
- The Popular Characters exception applies if you created a widely used character. Even after account deletion, that character’s data can remain live on the platform because other users are actively interacting with it.
- Nothing can strip your contributions out of already-trained model weights. If your past conversations were used in a training run, deletion removes the record but not the model’s learned behavior derived from it.
- Exporting your data preserves a personal copy for your own records, but export is a snapshot, not an undo button for training influence.
A detailed breakdown of what deletion actually does for AI companion platforms is worth reading before you assume “delete” means “erased.”
Your Regional Privacy Rights and How to Use Them
Where you live changes what you can demand. The European Economic Area and the United Kingdom give users the strongest footing, including the right to object to or restrict certain training uses. Character.AI’s Regional Privacy Disclosures outline how these mechanisms apply, and they’re worth checking directly rather than relying on secondhand summaries.
In the United States, protections are patchwork. State privacy laws differ significantly, and CCPA-style access and deletion rights may apply if you’re a California resident, but there’s no federal baseline guaranteeing the same rights nationwide.
Practical steps for filing a request:
- Email privacy@character.ai directly and state exactly what you’re requesting (access, deletion, or restriction of training use).
- Use in-app account controls first for straightforward actions like data export.
- Expect an identity verification step, most services require this before processing sensitive requests.
- Document your request date, the response you receive, and any reference number, in case you need to escalate to a regulator later.
The Hidden Risk: What Foundation Models Remember Forever
Character.AI’s own controls only address one layer of risk. The deeper issue lives inside the AI model itself, and no privacy setting fixes it.
Research from Stanford HAI identifies four systemic risks baked into how foundation models are built and used:
- Memorization: models can retain and reproduce specific snippets from training data, sometimes verbatim.
- Model inversion: attackers can sometimes reconstruct approximate training inputs by probing model outputs.
- Data extraction: carefully crafted prompts can coax a model into revealing fragments of what it learned from.
- Poisoning: bad actors can inject manipulated data during training to corrupt future outputs.
There’s no reliable technical process to “unlearn” specific inputs once they’re reflected in a model’s weights. Deletion clears records and indexes; it doesn’t rewind training.
Pro Tip: Treat every message as permanent the moment you hit send. Use a throwaway email for signup, skip your real name and location in roleplay, and avoid uploading photos or voice clips tied to your identity. If a conversation touches something you’d never want traced back to you, that’s the moment to close the app instead of the tab.
For genuinely sensitive topics, an encrypted chat alternative built on end-to-end encryption is a more honest fit than any consumer companion app currently offers.
What the Italian Regulator Found (And Why It Matters to You)
Regulatory scrutiny caught up with Character.AI in 2026. The Italian Data Protection Authority (Garante) issued Decision No. 487 on July 3, 2026, finding the platform deficient across three areas that matter directly to everyday users.
- Transparency failures: the Garante found that users weren’t given sufficiently clear information about how their data gets processed.
- Inadequate child-protection measures: age verification and safeguards for minors fell short of GDPR expectations.
- A delayed Data Protection Impact Assessment: a required risk analysis that should have preceded major processing changes wasn’t completed on time.
The practical fallout for users: expect clearer disclosures, stronger age-gating, and possibly new regional opt-out mechanisms as compliance catches up. Public enforcement actions like this tend to accelerate policy changes faster than user complaints alone. If you’re in the EEA or UK, watch your account notifications and the Help Center for updated terms in the months following a decision like this one.
How to Check and Change Your Character.AI Privacy Settings
Fixing your exposure takes about ten minutes if you follow this order:
- Open account settings and locate the Data & Privacy section, where model-improvement and training toggles typically live.
- Export your full chat history first, before making any deletion decisions, so you have a personal record independent of the platform.
- Delete or unpublish any public characters you created before deleting your account, since the Popular Characters exception can keep character data active otherwise.
- Submit a regional rights request if you qualify, including your account email, the specific right you’re invoking, and a government ID if verification is required.
- Report age-gate failures or policy violations to privacy@character.ai, or escalate to your local data protection authority if the company doesn’t respond within a reasonable window.
Pro Tip: Screenshot your settings before and after making changes. If a dispute comes up later, having a timestamped record of what you opted out of, and when, makes any regulatory complaint far easier to substantiate.
Virtualship’s review of Character.AI walks through how these settings hold up in practice, including where the interface buries controls that should be one tap away.
Security Measures: Encryption, Breach History, and Incident Response
Character.AI’s security stack looks fairly standard for a consumer chat platform: TLS encryption in transit, access controls limiting which employees can view raw data, and automated monitoring for abuse patterns. What it lacks is the layer most privacy-conscious users actually want, end-to-end encryption that would make server-side content unreadable even to the company itself.
That gap matters more once you consider incident response. When a moderation flag or safety report triggers review, the same infrastructure that scans for policy violations is also the infrastructure that exposes conversations to human eyes. There’s no technical wall separating “safety review” from “general accessibility.” A support engineer troubleshooting an account issue and a moderator reviewing a flagged chat are drawing from the same underlying data store.

The company hasn’t publicly disclosed a major breach on the scale of a full database leak, but the OECD’s incident documentation makes clear that access isn’t hypothetical. It happens routinely as part of normal operations. That distinction, breach versus built-in access, is one user often miss. You don’t need a hacker to see your data. You just need your account to trip a moderation flag.
Who Else Gets Your Data: Partners, Advertisers, and Beyond
Contractors and law enforcement aren’t the only parties with a potential path to your data. Character.AI’s policy also permits sharing with business partners and, in some contexts, advertising-related entities, though the exact scope of these arrangements is described in general terms rather than itemized by name—see this explanation of what AI actually stores about you for more on typical data collection and sharing practices.
This is common across the AI companion industry, but it’s worth taking seriously. Aggregated or de-identified usage data can still be combined with other signals, device IDs, IP history, behavioral patterns, in ways that make re-identification easier than most users expect. Advertising partners typically receive audience segments and performance metrics rather than raw chat transcripts, but the underlying inferences driving those segments come directly from what you say to your characters.
If a platform’s policy uses broad language like “service providers,” “partners,” or “affiliates” without naming them, treat that as a signal to assume broader sharing than a narrow reading would suggest. The Privacy Watchdog review of Character.AI’s policy flags exactly this kind of vague language as a recurring weak point, one that shows up across the AI companion category rather than being unique to any single app.
Cross-Border Data Transfers and Jurisdictional Gaps
Character.AI operates globally, which means your data doesn’t necessarily stay in your home country. Chats from a user in Germany, Brazil, or Australia can be processed and stored on servers located in the United States or wherever the company’s infrastructure sits, subject to whatever transfer mechanisms are in place at the time.
This creates a real jurisdictional gap. Data protection standards vary sharply between regions: the EEA and UK enforce GDPR-level protections with legal teeth, while other markets have thinner or newer frameworks. Once your data crosses into a jurisdiction with weaker enforcement, the practical rights you assumed you had back home don’t automatically travel with it.
For EEA and UK users specifically, cross-border transfers to the US typically rely on standard contractual clauses or similar legal mechanisms designed to extend baseline protections abroad. Whether those mechanisms hold up as fully as GDPR at home is a live debate among privacy regulators, not a settled question. If you’re outside the US and privacy is a priority, understanding your own region’s specific disclosures, rather than the general policy, is the more reliable path.
Anonymity, Pseudonymity, and What They Actually Protect
Using a fake username feels like protection. It’s partial protection at best. Character.AI still collects your IP address, device identifiers, and account metadata regardless of what name you type into the chat. A pseudonym hides your identity from other users viewing your public characters, not from the company operating the platform.
Real anonymity would require stripping identifying metadata at the network level, something a consumer chat app isn’t built to do. What you’re getting with a pseudonym is social anonymity: strangers browsing character pages can’t easily connect your account to your real name. That’s meaningfully different from technical anonymity, where even the platform operator can’t tie your activity back to you.
The distinction matters most for anyone using Character.AI to explore identity, sexuality, mental health, or other sensitive territory under a screen name. The username protects your public face. It does nothing about what’s logged on the server behind it. If genuine anonymity is the goal, minimizing identifying details in your account setup and avoiding any uploaded media tied to your real appearance or voice does more than any username choice.
How Character.AI Stacks Up Against Other AI Companion Apps
Privacy practices across AI companion and chatbot platforms follow a fairly consistent pattern: server-side storage, no end-to-end encryption, and training-data usage disclosed in policy language that’s technically compliant but rarely plain-spoken. Character.AI isn’t an outlier in this regard. It’s representative of where the category currently sits.
Where platforms differ is in the specifics: how granular the opt-out controls are, whether regional disclosures actually match GDPR or CCPA requirements in substance rather than just checking a box, and how quickly a company responds to regulatory findings like the Garante decision. Some platforms offer clearer, one-click training opt-outs. Others bury the setting three menus deep or omit it for users outside specific regions.
None of the mainstream AI companion apps currently offer end-to-end encryption as a default, which means the fundamental privacy calculus, your conversations are readable server-side, applies broadly across the category rather than to any single platform. A side-by-side look at privacy practices across AI companion platforms shows how much variation exists in the details even when the core limitation stays the same. For a direct look at how two specific platforms handle these questions differently, Character.AI vs. Chai breaks down the practical differences in data handling and moderation approach.

Find a Privacy-First AI Companion With Virtualship
Reading a privacy policy shouldn’t be the price of admission for wanting a companion app that respects your data. Virtualship built its platform comparisons specifically so you don’t have to cross-reference legal documents against your own risk tolerance every time a new app launches.

Many reviews cover the same ground this article just walked through: what data gets collected, whether training opt-outs exist, and how encryption (or the lack of it) shapes real exposure. If you’re deciding between platforms right now, the AI companion safety checklist gives you a five-minute gut check before you enter a card number. Export your existing chat history first, then run any platform you’re considering through that checklist before you subscribe. It takes less time than reading the policy yourself, and it tells you what actually matters.
Sources
- Character
- OECD incident entry on Character.AI access and moderation
- Data privacy and foundation models — Stanford HAI
- Italian Authority Finds Character.AI Breached GDPR



