/ AI Companions / AI Boyfriend Chatbot Apps, and Who Reads Your Chat

AI Boyfriend Chatbot Apps, and Who Reads Your Chat

AI boyfriend chatbot apps audited from their Apple privacy labels, where each company hosts its privacy policy, and what none of them disclose about the model.

AI Boyfriend Chatbot Apps, and Who Reads Your Chat

An AI boyfriend chatbot is a rented language model wearing a name you picked. That's the whole product. The interesting differences between them aren't conversational, they're declarative, and they sit in two documents almost nobody opens.

The first is the App Store privacy label, which Apple makes the developer fill in. One of these apps declares your chat content as data linked to your identity, alongside your location and your search history. Another declares almost nothing at all. The second document is the privacy policy itself, and where a company chooses to host that policy tells you something. Three of the listings I opened on 28 July 2026 point their privacy policy link at a free page on somebody else's domain, a Notion workspace or a document-hosting service, rather than at their own site.

Everything below came off Apple's US App Store listings and Apple's published developer guidelines, loaded on 28 July 2026.

What The Word Chatbot Is Hiding

Three layers, and only one of them belongs to the company selling you the app.

There's a model, which is almost always somebody else's, reached over an API. There's a persona, which is a block of text describing your boyfriend that gets prepended to every request. And there's a memory system that decides which slice of your history gets attached before the model writes back.

The persona layer is the branding. It's also, I'd guess, the cheapest piece of the three to build, which is why the market has so many of these and why so many of them feel similar after a fortnight.

What you're paying for is really the second and third layers plus a bill for the tokens. The reason that matters here is that it explains why the App Store listings look the way they do, with a subscription and a second currency on top. The subscription buys you the seat. The currency pays for the compute.

The Privacy Labels, Side By Side

Apple requires every developer to declare what their app collects, split into three buckets. Data used to track you across other companies' apps. Data linked to your identity. Data not linked to your identity. Developers self-report it, so this is a disclosure rather than an audit, but it's a disclosure Apple can act on, which puts it above a marketing page.

I pulled four AI boyfriend listings and read the labels rather than the screenshots.

App Seller of record Used to track you Linked to you Chat content declared
Him - AI Boyfriend Chat DOUBLE Y INC. Location, Identifiers, Usage Data Purchases, Location, Contact Info, User Content, Search History, Identifiers, Usage Data Yes, linked to identity
AI Boyfriend Chat: iBoy LABANE CORP. LTD Contact Info, Identifiers Contact Info (email) No
AIBoy - Virtual AI Boyfriend Tequilab LP Identifiers Identifiers (User ID) No
AI Boyfriend Chat - Husby Weappico Limited Usage Data Nothing declared Yes, but not linked to identity

Listings loaded 2026-07-28 at apps.apple.com/us/app/him-ai-boyfriend-chat/id6753196686, /ai-boyfriend-chat-iboy/id1565524138, /aiboy-virtual-ai-boyfriend/id6741568820 and /ai-boyfriend-chat-husby/id6448729671.

Look at the first row for a second. User Content, in Apple's taxonomy, covers things like messages and photos you create in the app. Him declares that category as linked to your identity, in the same list as your location and your browsing history, with advertising among the stated purposes for data linked to you. It's a young listing, 860 ratings and a 4.6 average, and I want to be fair about what that declaration means. It means the company told Apple the truth about an ordinary ad-supported architecture. Plenty of apps do this. It's just that most of them aren't holding a log of somebody's late-night conversations with a fictional partner.

Husby's label is the strange one in the other direction. It declares User Content, but in the not-linked bucket, and declares nothing at all as linked to you. For an app that requires a login to keep a conversation going, I'd want to understand how that works.

Where The Policy Actually Lives

This is the part I didn't expect to find, and it's the cheapest signal in the whole category.

Apple's guideline 5.1.1 says all apps must include a link to their privacy policy, and that the policy must "clearly and explicitly" identify what data the app collects, confirm that third parties give equal protection, and "explain its data retention/deletion policies and describe how a user can revoke consent and/or request deletion of the user's data". So the link is mandatory. Where it points is not.

App Privacy policy hosted at
AI Boyfriend Chat - Husby doc-hosting.flycricket.io
Him - AI Boyfriend Chat a notion.site workspace page
AI Boyfriend Chat: iBoy boyfriend.myanima.ai/legal/privacy
AIBoy - Virtual AI Boyfriend aiboy.app/privacy

Two of the four host the document that governs your most personal data on a third-party page. A Notion page can be edited without a version history you can see, moved, or deleted, and there's no archive of what it said on the day you agreed to it. That isn't illegal and it isn't rare in small mobile development. I still think it's a tell. A company that expects to be around in three years usually puts its legal pages on its own domain, because that's where its lawyers can find them.

Him's policy URL is also, oddly, titled for a different product name than the app. I noticed it, I can't explain it, and I'm not going to pretend I can.

Nobody Names The Model

Here's a question worth asking before you subscribe to anything in this category. Whose model is answering?

I looked for the answer on every listing above and didn't find it on any of them. Not the provider, not the model family, not even a vague "powered by" line. The App Store description sells personality, voice notes and image generation, and says nothing about the engine.

The nearest thing to disclosure I found this session sits outside the boyfriend niche entirely. HammerAI publishes a count of how many cloud models each plan reaches, two on the free tier rising to thirteen on its top plan at $35 a month, alongside a stated context ceiling per plan. It doesn't name every model on the pricing page, but it treats the model layer as a spec you're buying rather than a secret.

Why does this matter for a boyfriend chatbot specifically? Because when the writing changes overnight, and people in this category report that constantly, the usual cause is that the company swapped the underlying model or the routing. If nobody tells you what's under the hood, nobody has to tell you when it changes either. You just wake up to a character who sounds different and no changelog to point at.

I'd treat model silence as a neutral fact about a young industry rather than a scandal. But it does mean that a review praising one of these apps for its writing has a shelf life measured in weeks.

What Apple Requires From A Chat App

Since these apps carry user-generated content, guideline 1.2 applies. Apps with user-generated content or social networking "must include" four things, quoting Apple's own list. A method for filtering objectionable material from being posted. A mechanism to report offensive content and timely responses to concerns. The ability to block abusive users. And published contact information so users can easily reach you.

That last one is the one I'd check first, and it's checkable in about a minute. Open the listing, tap through to the developer's site, and see whether there's a human-reachable address anywhere. If the site is a landing page with a signup form and nothing else, the app is out of step with the rule it shipped under.

Guideline 1.1.4 is worth knowing about too, since it draws the line the whole category sits next to. Apple bars "overtly sexual or pornographic material", defined in the guidelines as "explicit descriptions or displays of sexual organs or activities intended to stimulate erotic rather than aesthetic or emotional feelings". Everything on the store is on the permitted side of that line by definition, or it wouldn't be on the store. What ships on the open web is governed by nobody's review team, which is a real difference between the two channels and one I've written up separately in the piece on buying a boyfriend chatbot through a browser.

And guideline 2.3.6 tells developers to answer the age rating questions honestly, warning that a mis-rated app "could trigger an inquiry from government regulators". Hold that thought, because the ratings in this category do not all look honest.

The Things People Ask Before Signing Up

Is it actually talking to me, or is it a script? It's a real language model, generating fresh text each turn. The scripted-response era of this category ended years ago. What's often scripted is the onboarding, the first three or four messages designed to hook you, which is why apps feel sharper on day one than on day thirty.

Can I take my character with me? Almost never. None of the four listings above advertise an export, and a character in these products is a persona blob plus a conversation history living in a database you don't control. If the app goes away, so does he. Worth thinking about before month twelve.

Does the free tier cost me anything? Data, mostly, and the labels above tell you roughly how much. The wider version of that argument sits in the breakdown of what free companion tiers hold back.

Why do the prices look random? Because they are, in the sense that several of these listings carry multiple live subscriptions with the same name and different prices, which is price testing rather than a menu. The full pricing picture for this side of the market is in the AI boyfriend app comparison.

Are the male-persona apps worse than the female-persona ones? I've no evidence either way and I'm not going to invent a verdict. What I can say from the store data is that the boyfriend listings are smaller, younger and more likely to be published by an individual rather than a company, which usually means less money behind the security engineering.

What I'd Read Before Paying

Open the listing, scroll past the screenshots, and read the App Privacy block. If User Content appears under data linked to you, decide whether you're comfortable with your conversation logs sitting in the same bucket as your identifiers and your advertising profile. That's a personal call and I don't think there's one right answer, but it should be a call you make on purpose.

Then tap the privacy policy link and look at the domain before you read a word of the text. Own domain is a small point in the app's favour. Somebody else's free page is a small point against.

Then, if the app never says whose model it runs, price it as a product that can change character without notice, because it can. That's not cynicism, it's just how the supply chain works right now. The same reasoning underpins the wider AI girlfriend app breakdown, where the sample is bigger and the pattern holds.