AI Companion Apps, Audited From the Store Listings
AI companion apps compared using App Store metadata and Google Play data safety panels, including the app that declares your precise location for advertising.

Every AI companion app has two descriptions of itself, and only one of them was written by a marketing team.
The short answer, before the detail. The most useful comparison you can run on AI companion apps takes about four minutes and never touches a review site, because both app stores force these companies to disclose things their homepages skip. Google Play's Data Safety panel says whether the app shares your data with other companies. Apple's listing says which category the app filed under, how many languages it ships, when it was last updated, and how many people have rated it. Read those two panels across nine apps, as I did this morning, and the category sorts itself into groups that no star rating would have produced. One popular app declares your precise location as shared for advertising. Another tells Google it collects no user data while declaring on the same screen that it shares your device ID with advertisers.
Every figure below was read off apps.apple.com and play.google.com on 28 July 2026.
The Metadata Nobody Reads
Marketing pages for these products are close to interchangeable. Store listings are not, because Apple and Google require specific fields and the developer has to fill them in.
| App | Seller of record | App Store category | Age rating | Languages | Ratings | Last version |
|---|---|---|---|---|---|---|
| Replika | Luka, Inc. | Health & Fitness | 18+ | 5 | 228K, 4.4 stars | 3 days ago |
| Character.AI | Character Technologies, Inc. | Entertainment | 18+ | 28 | 550K, 4.3 stars | 6 days ago |
| Kindroid | Beautifully Incorporated | Entertainment | 18+ | 1 | 7.3K, 4.8 stars | 26 May |
| Nomi | AI GLIMPSE INC | Lifestyle | 18+ | 1 | 2.6K, 4.6 stars | 31 March |
| Aiko | Irfan SENER | Entertainment | 16+ | 1 | 586, 4.7 stars | 19 March 2024 |
Star ratings are the least interesting column there and they're the only one anybody quotes.
Look at the last one instead. Aiko's most recent version is 1.6, shipped 19 March 2024, which means the app currently ranking in App Store results for anime companion searches has gone more than two years without an update. It also still requires only iOS 12.4, a release from 2018. Compare that with Replika, updated three days before I looked, or Character.AI six days before. Neither of those is proof of quality. Both are proof that somebody is still employed to work on the thing.
Aiko is also rated 16+, while every other app in that table is 18+. Its own descriptors include mature or suggestive themes and unrestricted web access. I'd read that as a rating that hasn't been revisited since it was set, which is the same story the version date tells.
Replika Is Filed Under Health and Fitness
This one made me stop and re-read the page.
Character.AI, Kindroid and Aiko all sit in Entertainment. Nomi sits in Lifestyle. Replika, the oldest and largest of the dedicated companion products, sits in Health & Fitness, with age-rating descriptors that name health or wellness topics alongside infrequent profanity.
Category choice is a distribution decision rather than a legal one, so I don't want to over-read it. Health & Fitness is a less crowded chart than Entertainment and ranking well there is easier. But it also positions a chatbot next to sleep trackers and step counters, and I think that's worth knowing before you decide how much emotional weight to hand the thing. The company is not, on paper, selling you a game.
Nomi's Apple listing is 7.3 MB. Replika's is 434 MB. That's a factor of roughly sixty between two products doing broadly the same job, and the explanation is almost certainly architectural rather than functional, since Nomi's Android package identifier ends in .twa, which is how Google labels an app that's really a wrapped website. That last bit is my inference from the package name, not something Nomi states.
Google's Data Safety Panel Is the Better Document
Apple's privacy label gets quoted occasionally. Google's Data Safety panel almost never does, and it's the more legible of the two, because it separates collected from shared and attaches a stated purpose to each row.
I pulled it for nine companion apps.
| Play listing | Shares data with third parties | Message content declared as collected | Advertising named as a purpose |
|---|---|---|---|
| Character AI: Chat, Talk, Text | None declared | Other user-generated content | No |
| Nomi: AI Companion with a Soul | None declared | Other in-app messages | No |
| Kindroid: Your Personal AI | None declared | Other in-app messages | No |
| Replika: My AI Friend | Device IDs, app interactions | Not declared | Yes, on device IDs |
| Anima: AI Friend Virtual Chat | User IDs, device IDs, app interactions, crash logs | Not declared | No |
| Anima: My Virtual AI Boyfriend | Same as above | Not declared | No |
| iGirl: AI Girlfriend | Same as above | Not declared | No |
| HiWaifu: AI Friend & Waifu Hub | Device IDs, app interactions, installed apps, precise location | Not declared | Yes, on four separate rows |
| Luna: AI Girlfriend Chat | Crash logs, diagnostics, device IDs, app interactions | Developer says none collected | Yes, on device IDs |
Three of the nine declare no sharing at all. That group is Character.AI, Nomi and Kindroid, and it's also the group that admits to collecting message content, which I find quietly reassuring rather than the opposite. An app that tells Google it holds your in-app messages is an app that has thought about what the panel is for.
Two of the nine, Anima: My Virtual AI Boyfriend and iGirl: AI Girlfriend, list the same developer, LABANE CORP. Limited, and file identical declarations. Same company, two genders, one codebase, presumably. Nobody discloses that anywhere in the marketing and I don't think it's a scandal, but if you were planning to compare the boyfriend product against the girlfriend product on privacy grounds, there's nothing to compare.
The App That Wants Your Precise Location
HiWaifu's panel is the outlier and it isn't close.
It declares sharing device or other IDs for analytics, advertising or marketing, personalisation and account management. It declares sharing app interactions for advertising or marketing and personalisation. It declares sharing your list of installed apps for analytics and advertising. And it declares sharing precise location for advertising or marketing.
Precise location. On a chat app.
Then, in the collected column, it lists sexual orientation, used for app functionality, personalisation and account management. That's a special category of personal data under European law and it sits there in the panel next to the email address field, which nobody reading a waifu app listing is likely to notice.
I want to be careful about what that does and doesn't prove. A Data Safety declaration is the developer's own statement and Google doesn't independently audit it. Declaring something isn't the same as abusing it, plenty of ad SDKs pull location by default, and the honest reading is that this looks like a mobile app monetised through advertising rather than something sinister. It's still four advertising rows on a product built around intimate conversation, and none of the three larger apps needed any of them.
One App, Two Stores, Two Different Answers
Character.AI's disclosures don't match each other, and I've been turning this over since I noticed it.
On Google Play, the app declares no data shared with third parties. Full stop, that exact phrasing.
On the App Store, the same product's privacy label lists location, contact info, identifiers and usage data under Data Used to Track You, which Apple defines as linking your activity with third-party data for advertising or sharing with data brokers. Its listing also carries an Advertising content descriptor.
Both statements are probably technically defensible, because Apple and Google define their terms differently and "tracking" in Apple's framework is not the same as "sharing" in Google's. I'm not accusing anyone of lying to a store. What I'd take from it is narrower and more useful, which is that a single privacy panel from a single store is not enough to characterise an app, and if you only ever read the Apple one you'd have a materially worse impression of Character.AI than if you only ever read the Google one. Read both. They take a minute each.
The wider pricing and policy picture for this product sits in the main AI girlfriend app guide, and the reasons people leave it are covered in the alternatives comparison.
What Staleness Actually Costs You
An abandoned companion app is a different risk from an abandoned utility.
If a torch app stops being updated, it keeps working until an OS release breaks it. If a companion app stops being updated, the conversations are usually server-side, the server bill is still running, and the day somebody decides it isn't worth paying, your history goes with it. Nobody in this category publishes an export function prominently and several don't have one.
So version dates are a solvency signal, roughly. Not a perfect one. A well-built app can go three months without a release and be perfectly healthy, and a churning release schedule can just mean the team keeps breaking things.
But a listing last touched in March 2024, still targeting an iOS version from 2018, with 586 ratings, published under an individual's name rather than a company, tells you something about how much attention the product is getting. I wouldn't start a long story in it. I'd also apply the same test before paying for an annual plan anywhere, since the annual plan is a bet on the company outliving the subscription.
Reading a Listing in Four Minutes
Here's the sequence I'd use, and none of it requires installing anything.
Open the Google Play listing and scroll to Data Safety, then hit "See details". Look only at the shared column first. If precise location, installed apps, or anything tagged advertising or marketing appears there, you've learned the business model. Then check whether message content is declared as collected, and note that an app declaring nothing about messages is not necessarily one that holds nothing.
Second, open the Apple listing and read four fields that people skip. The category, which tells you how the company positions itself. The seller of record, because an individual's name means no entity to send a data request to. The language count, since one language often means a small team or a wrapper. And the last version date.
Third, compare the two privacy panels against each other. Where they disagree, the disagreement is the finding.
Fourth, and this is the only slow part, open the privacy policy and read the retention section. Four minutes, tops, and it's the only part of the terms describing something you can't undo.
None of that tells you whether the writing is any good. It tells you what kind of company you're handing a diary to, which is a separate question and, I'd argue, the one that survives longer.
Questions That Come Up
Are AI companion apps safe to use? Depends what you mean by safe. On the data question, the three biggest products declare no third-party sharing on Google Play while several of the smaller ones declare quite a lot, so the answer varies more within the category than between the category and, say, social apps. Read the panel for the specific app rather than trusting a category-level verdict.
Which AI companion apps are free? Most have a free mode and the limits are usually unpublished. The exceptions and the ways free tiers are actually constrained get worked through in what free companion tiers hold back and in the broader free companion options.
Do any of them work offline? A couple of desktop products run models locally, which changes the whole privacy question because there's nothing on a server to disclose. It's more setup and a weaker model.
Why are they all rated 18+ now? Because the rules changed in 2025 and the companies moved. Aiko's 16+ rating is the exception in my sample, and I'd read it as an old rating rather than a considered one.
What about the roleplay-first platforms? They're a related but distinct group with different economics, covered in roleplay chatbot platforms and in what makes one usable over a long story.
Is Replika still the default choice? It's the oldest, the most rated, and the most actively maintained of the ones I checked, and it also carries the most documented regulatory history. Both of those are covered in the Replika breakdown.
Where I'd Start
I'd sort the field by disclosure before I sorted it by anything else.
Three apps in my sample told Google they share nothing with third parties and told Google they hold message content. That combination reads to me like a company that filled the form in properly rather than one that has nothing to hide, and it's a low bar, but it's a bar and about half the field doesn't clear it.
Then I'd check the version date and the seller name, because those two fields together predict whether the product will still exist in eighteen months better than any review will.
Then, and only then, I'd care about the demo. The conversation quality across the funded products has largely converged, as far as I can tell from what they publish, and it's the stuff around the conversation that still varies wildly. The pricing side of that comparison is where the differences show up hardest.


