The short version: everything you type leaves your device, at least one company other than the service can read it, and 'delete' means different things at different services. All of that is knowable before you start — it is written in the privacy policy.
A companion is not running on your phone. When you send a message it travels to the service's server, which builds a bigger block of text — the character's description, a summary of what it remembers about you, and the recent conversation — and sends that block to a language model. The reply comes back the same way. So at minimum your words are handled by the service and by whoever runs the model, and the model sees more than your last message: it sees the memory too.
Different services keep different things, but the list is usually drawn from these:
| Item | Why it exists |
|---|---|
| Your setup answers | they define the character |
| A memory or profile | so it can refer back to what you said |
| Recent messages | so a reply follows the conversation |
| Counters and dates | to enforce a limit or a billing period |
| An account identifier | email, phone number, or a random id in your browser |
| Payment details | usually held by the payment processor, not the service |
| Analytics | device, rough location from your IP address, pages visited |
The two worth paying attention to are the memory and the account identifier. A memory is a written summary of you that outlives any single conversation. An identifier decides whether the record can be tied to a real person at all: a service that never asks for an email cannot hand one over.
Three groups, and a fourth in specific circumstances. The service's own staff, if their systems allow it — many allow support access, some allow review of flagged content. The model provider, which is a separate company unless the service runs its own model on its own hardware. Any subprocessor: hosting, error tracking, analytics, payments. And, on a lawful request, an authority — no encryption promise survives a valid court order over data the company itself can read.
The question is not whether a model was trained on the internet; it is whether your conversations are used to train it later. Policies say one of three things: never; only with your opt-in; or by default with an opt-out somewhere in the settings. The words to search for in the policy are 'train', 'improve our models' and 'human review'. If a policy is silent on this, treat that as an answer, not an omission.
There is a real difference between hiding a conversation in the interface and erasing the record. Ask two things: does deletion take effect immediately, and are there backups that still hold the data afterwards. A service can be entirely honest and still keep backups for a period; it just has to say so. Under GDPR you can ask for a copy of your data and for its erasure, and the service has to answer within a month — which is a right worth knowing, and slower than a delete button.
A service cannot know that a particular sentence was sensitive. It cannot tell your medical history from your holiday plans, and no filter reliably redacts what you volunteered. So the practical rule is not about the policy at all: passwords, financial details, other people's private information, health details, and anything that identifies you precisely are simply not worth typing into a chat window that is designed to remember.
Everything above applies to any service, including this one, so here are the same answers for the companion on this site, in the same terms.
What it is, and what it is not
Write to hello@toolkitlabs.org. It is a real inbox on this domain and the messages are read.