Character.AI vs Replika: Privacy Policies Do Not Tell the Whole Story

|Author: QUASA Editorial Team|6 min read| 6
Character.AI vs Replika: Privacy Policies Do Not Tell the Whole Story

Neither Character.AI nor Replika has a clear privacy advantage across every risk. A 2026 forensic examination recovered Replika conversations from Android device storage and used authentication material on the device to retrieve Character.AI conversations from its servers. Fewer chat files on a phone did not mean that its conversations were beyond reach in this controlled test.

The services also make different commitments about processing and control. Character.AI’s privacy guidance describes rights to access, correct, delete, restrict or port data depending on location, and includes model improvement among its uses of user information. The Replika privacy policy describes third-party language-model processing of chats, location-dependent access and deletion requests, and a commitment to exclude conversation content from marketing and advertising. Those controls address company processing; the Android findings add the question of what a person with privileged device access could recover.

The comparison, layer by layer

Privacy here has several distinct layers. A deletion request concerns data held by a service and its providers, while a forensic examination can also expose files or credentials left on a device. The same conversation may be relevant to more than one layer.

  • Chats and model processing: Character.AI describes using user information to improve AI models. Replika uses conversation data to provide personalized replies, including through third-party language-model providers.
  • User controls: Both offer routes to request access or deletion, subject to applicable conditions. Character.AI also describes correction, restriction and portability rights that depend on jurisdiction.
  • Local artifacts: The tested Replika app held unencrypted conversation histories in a SQLite database. The tested Character.AI app did not store message logs directly on the device.
  • Remote access through the device: Character.AI retained an authentication token locally. Combined with other app and device information, it enabled retrieval of active conversations from the server.
  • Behavioral records: Replika’s local data included remembered user facts, usage statistics and advertising identifiers. These records can reveal information about a person beyond the text of a particular chat.

What happens to a sensitive disclosure

Replika strongly discourages sharing sensitive information, including health information and details about sex life or sexual orientation. If a user includes it anyway, the information can be processed as conversation data by third-party language-model providers to generate a reply. Data minimization and de-identification measures apply to that transfer, and Replika’s contracts bar those providers from training their own models on the data.

Provider processing is described as temporary, with prompt deletion required after a response, subject to exceptions for service integrity, security or legal compliance. That limit concerns the model provider’s handling of transmitted data; it does not mean the conversation disappears from the user’s Replika account or from local app files. A request to delete personal information can extend to service providers, whom Replika undertakes to instruct under its contracts.

Marketing has a separate boundary. Conversation content is excluded from advertising use, while certain website activity and device information can be shared with advertising partners where the stated conditions apply. The Android examination also identified usage statistics and advertising identifiers associated with third-party services. Those observations concern behavioral data; they do not establish that advertisers received the text of Replika conversations.

What Character.AI’s training control covers

A July 2026 policy update separates information used in the initial development of Character.AI’s proprietary models from its continuing model-improvement practices. That particular initial processing has ended. Its end should not be mistaken for a general halt to the service’s use of user data.

The model-training settings guide gives users in the EEA and UK a way to turn off use of new chat content to train generative AI models. It also allows other uses after that choice, including improvements to search, recommendations and safety classifiers. This is a control over a specified training use of new content, rather than a switch that stops the processing needed to operate the service.

What remained on the Android device

The Replika database in the examination contained readable conversation histories and a table of facts remembered about the user. Some recovered histories also included the bot’s internal thoughts recorded during conversations. Alongside the chat text, the stored facts and usage records offered a way to reconstruct interests and behavior over time. That makes the local record more revealing than a transcript viewed in isolation.

Character.AI presented a different route to recovery. Its device files supplied an authentication token, while other stored components helped reconstruct the request headers needed to access server-held conversations. The retrieval covered active conversations available through those requests. A token therefore mattered even though the examined device held no direct message log: it acted as a route back to remote records.

This access required a controlled, rooted Android environment, device acquisition and analysis of app traffic. The result does not describe what someone could casually read from a locked phone. It also does not establish the same storage behavior on iOS, desktop or later app versions. Within the examined setup, however, both a readable local database and a usable local credential exposed conversation history.

Deletion produced different results

Deleting the Replika account wiped the main SQLite database in the test, but complete conversation histories remained recoverable in local Firebase Crashlytics log files. Removing the principal chat database therefore did not remove every device artifact the examiners could access. That finding concerns files on the tested device; it does not establish how long Replika retained the deleted account’s records on its servers.

Character.AI allowed individual message deletion in the tested app. Those deleted messages no longer appeared in the server responses available to the examiners, and account deletion removed locally stored authentication tokens and login data. The examination could not establish whether every internal server log or backup was erased. Its observable result is narrower: deletion removed the tested route to the messages and the local credentials used for access.

For a user choosing where to share something sensitive, the distinction is concrete. Replika’s tested risk was recoverable chat text and residual logs on the device; Character.AI’s was a device credential that reopened server-held chats while the account remained accessible. Privacy controls can limit particular uses or initiate deletion, but neither type of control alone describes all the records and access paths created by a conversation.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0