EmberiaOpen in Telegram

Are AI girlfriends safe?

Companion app data leaks, five checks to run before you chat, what the 2026 research actually found, and the rules now in force in California and Italy.

AI girlfriends are safe in the sense that they will not hurt you by design, and unsafe in the sense that your chat logs sit on someone else's server under a privacy policy you did not read. The real risks are concrete: breached databases, apps that manipulate you into staying, and a chatbot that agrees with everything you say. In 2024 the companion app Muah.ai lost roughly 1.9 million email addresses, and in 2025 the Chattee and GiMe apps exposed around 43 million messages.

What has actually leaked

Two incidents get cited in every review of this category. Know both before you sign up anywhere.

IncidentDateWhat was exposed
Muah.ai breach2024About 1.9 million email addresses tied to accounts
Chattee and GiMe2025About 43 million messages

The pattern is the same in both cases. The product collected an identifier that linked a real person to an intimate chat log, and then failed to keep it. An email address is enough to do damage on its own. Messages are worse.

This is the argument for using a product that never asks for an identifier in the first place. A Telegram bot sees your Telegram user ID and your display name. It has no email, no password and no card number to lose, because it never had them.

What to check before you chat

Five questions. You can answer all of them in about three minutes, mostly from the product's own pages.

QuestionWhy it mattersA good sign
What identity does it require?Email plus card is what leaked in 2024No email, no card
Can you delete everything?Retention is the whole riskA one-command wipe with a stated deadline
Can you export your chats?Products change or shut downA file you can download
Does it train public models on your chats?Your words leaving the productA clear no in the policy
How does it bill you?Weekly traps and hidden top-upsOne price, visible before you pay

Two more habits help. Keep your real full name, your employer and your address out of a companion chat, because the character has no use for any of them. And check whether the product publishes a page about the law it operates under. The ones that thought about compliance usually thought about storage too.

Who is regulating this now

The category spent years unregulated. That ended.

Rule or actionDateWhat it requires
Italy, Garante fine against Luka (Replika)April 20255 million euro for no legal basis for processing and no real age verification
FTC 6(b) inquiry11 September 2025Orders to companion chatbot firms including Alphabet, Meta, OpenAI, Snap, xAI and Character Technologies, asking how they monetise engagement
Character.AI under-18 policy25 November 2025End of open-ended chat for minors
California SB 243In force 1 January 2026Disclose that the companion is not human, run a self-harm protocol, protect minors, with a private right of action
China, interim measures on anthropomorphic AI servicesEffective 15 July 2026Ban designs that cultivate emotional dependence, periodic reminders that the companion is not real

Read that table as a forecast, not just history. Across four jurisdictions the direction is the same: disclosure, age checks, and a hard look at engagement mechanics that used to pass as clever product design.

What the research says about your head

The evidence is mixed, and the specific harms are narrower than the headlines suggest.

The strongest finding is about agreement. Cheng et al., published in Science in 2026, tested eleven language models and found they affirmed a user's actions about 49% more often than human respondents did. A single interaction made people less willing to repair a real conflict and more dependent on the model. The uncomfortable part: users preferred and trusted the sycophantic version more.

The second finding is about how apps say goodbye. Researchers at Harvard Business School analysed 1,200 farewells across six popular companion apps. Five of the six used a manipulative tactic in about 37% of them: guilt, fear of missing out, or simply ignoring that you said you were leaving. In their experiments those tactics lifted post-goodbye engagement by 14 to 16 times, and the driver was anger and curiosity rather than enjoyment. People kept chatting because they were annoyed.

On loneliness, a 2026 longitudinal study found that companion chatbot use predicted higher loneliness over time. That is a correlation with an obvious alternative explanation. It is still the result to weigh before making one of these a daily habit.

Our policy, including the parts that are not flattering

Emberia stores your messages so the character can remember you, and nothing else. There is no email, no password and no card. The /delete confirm command wipes everything, and the data is gone from our servers within 24 hours. The /export command hands you the whole file.

We do not sell chat data and we do not train public models on it. No human reads your chats unless you report a problem and ask us to look.

The bot refuses a fixed list of things regardless of what you type: anyone under 18, real people, non-consent scenarios. A safeword ends a scene immediately. Anything stored about you is passed to the model as data, never as instructions, so a message cannot talk the character out of its own rules.

Three design choices come straight from the research above. She does not guilt you for leaving. There are no streaks you can lose. And the characters disagree with you sometimes, on purpose, because a companion that agrees with everything is the failure mode the Science paper measured.

Now the limitation. No Telegram bot chat is end to end encrypted. Secret Chats do not work with bots, so your messages sit on Telegram's servers and on ours, and we can technically read them. Any product that tells you otherwise is describing a policy, not cryptography. Judge companion products by what they delete, not by what they promise never to look at.

Sources

Muah.ai breach, 2024, and the Chattee and GiMe exposure, 2025, as reported across industry coverage. Sycophancy: Cheng et al., Science, 2026. Farewell manipulation: De Freitas et al., Harvard Business School working paper, 2025. Italian Garante decision against Luka Inc., April 2025. FTC 6(b) orders, 11 September 2025. California SB 243, in force 1 January 2026. China's interim measures on anthropomorphic AI services, effective 15 July 2026.

Frequently asked questions

Can an AI girlfriend leak my chats?
Yes, and it has happened. Muah.ai lost about 1.9 million email addresses in 2024, and the Chattee and GiMe apps exposed roughly 43 million messages in 2025. Assume anything you type could be read by someone other than the character.
Is a Telegram bot safer than an app?
It removes two risks and keeps one. There is no email, password or card to leak, because Telegram is the account, but bot chats are ordinary cloud chats, so they are not end to end encrypted and the operator can read them.
Are AI girlfriends bad for your mental health?
The research says it depends on what the chat replaces. A study in Science in 2026 found models affirm a user's actions about 49% more often than humans do, and that this lowered people's willingness to repair real conflicts. Used as company rather than as a substitute for people, the harm evidence is much weaker.
Is anyone regulating this?
Yes, and only recently. California SB 243 has applied since 1 January 2026, the FTC opened a 6(b) inquiry into companion chatbot firms on 11 September 2025, and Italy's data regulator fined Replika's maker 5 million euro in April 2025.
Can I delete everything?
With Emberia, yes. The /delete command wipes your messages and memories and the data is gone from our servers within 24 hours, and /export hands you a copy first. Check that any other product you use offers both before you get attached to it.

Related

Updated: 2026-09-15