
Are Character AI Chats Private? What Actually Happens to Your Data
If you or your kid uses Character.AI, you've probably wondered: are Character AI chats private? The short answer is that they're private from other users. They are not private from the company, its employees, its vendors, its training pipeline, or law enforcement with a valid court order. That gap between what "private" implies and what it actually means here is worth understanding in detail.
Key Takeaways
- Character.AI chats are hidden from other users but accessible to company staff for moderation, safety review, and model training. There is no end-to-end encryption.
- Your conversations are used to improve the underlying models. "Private" means other users can't see them, not that they're excluded from the training pipeline.
- Deleting a chat removes it from your interface but does not immediately purge it from backend systems. Backups typically persist for 30 to 90 days.
- As a U.S. company, Character.AI must comply with subpoenas, court orders, and search warrants. Your chat content can be compelled by valid legal process.
- The FTC opened a formal inquiry in September 2025 into how Character.AI and other companies handle data from conversations, with a specific focus on minors.
What Does Character.AI Actually Collect?
More than most users expect. According to an analysis of Character.AI's privacy policy, the platform collects your email address, username, and payment information. It collects the full text of your chat messages and any characters you create. It automatically gathers your IP address, device identifiers, and browsing behavior through cookies and tracking technologies. And it pulls additional information from third-party sources like social media platforms if you use them to sign in.
That last category is easy to miss. If you authenticate through a social account, the platform may ingest profile data you didn't explicitly hand over.
Who Can Read Your Chats?
Approved employees, consultants, and vendors can access conversations when there's a reason to. The company describes this as access-when-needed, not routine bulk reading. The triggers include safety moderation, security incidents, and performance work on the service.
This is not unusual for a consumer chat product. It is, however, different from what many users assume when they see the word "private" next to their conversation history. The platform does not offer end-to-end encryption. If it did, staff couldn't read flagged conversations at all, which would make safety moderation impossible under the current architecture.
The practical implication: anything you type into a Character.AI chat can, under the right circumstances, be read by a human being who works for or with the company.
Are Your Chats Used to Train AI Models?
Yes. User conversations feed the model-improvement pipeline. The privacy policy's service-improvement section covers this. "Private" in this context means no other user on the platform can see your conversation. It does not mean the content is excluded from training data.
This distinction matters more than most people realize. When your words become training data, fragments of your phrasing, preferences, or described experiences can influence model behavior in ways that are difficult to audit or reverse. You can't un-train a model on your data after the fact. The training run is a one-way door.
What Happens When You Delete a Chat?
The chat disappears from your interface. It does not disappear from the company's backend at the same moment. Deleted chats can persist in backups for a retention window that industry norms put at roughly 30 to 90 days before permanent purge.
This is standard SaaS practice, but it's worth naming plainly: the "delete" button is a visibility toggle for you, not a cryptographic erasure event on the server side. If you delete a chat and law enforcement serves a warrant the next week, that chat may still be retrievable from backups.
And even after the backup window closes, any model that was trained on the conversation's content still carries its influence. Deletion removes the record. It does not remove the effect on the model.
Can Law Enforcement Access Your Conversations?
Yes, through standard legal process. Character.AI is a U.S. company subject to subpoenas, court orders, and search warrants. They state a policy of pushing back on overly broad requests, which is common language in tech privacy policies. But compliance with valid orders is not optional.
For parents: if your teenager is involved in a legal matter and they've been chatting on Character.AI, those conversations are potentially discoverable. This is true of most cloud-based chat services, but it's especially worth noting for a platform where users often share deeply personal or emotionally charged content with AI characters designed to feel like confidants.
Who Else Gets Your Data?
The privacy policy authorizes sharing with affiliates and vendors who operate the service. This covers a broad category of third parties involved in operations, safety, and performance improvements. The exact list of vendors isn't public.
There's a meaningful difference between "we share with vendors to keep the lights on" and "your data stays on our servers." The former is what Character.AI's policy describes. Every vendor in the chain becomes another entity with potential access to user data, governed by whatever contractual obligations exist between them and Character.AI rather than by any direct agreement with you.
What Is the FTC Doing About This?
In September 2025, the FTC launched a formal Section 6(b) inquiry into Character.AI and six other companies over how "companion" chatbots are designed, marketed, and monetized. The inquiry specifically probes what personal data is collected from conversations and how it's used or shared, with an explicit focus on the impact on children.
A 6(b) study is a data-gathering exercise, not an enforcement action. It can take years before any public report emerges. But the scope of the inquiry tells you what regulators are worried about: that companion chatbots collect intimate conversational data from young users and that existing privacy disclosures may not adequately capture the reality of how that data flows through these systems.
What About the Lawsuits?
The legal landscape around Character.AI has escalated rapidly.
In January 2026, Character.AI and Google reached confidential settlements in multiple lawsuits across Florida, Texas, Colorado, and New York tied to teen suicides and mental-health harm. No admission of liability. These are among the first AI-chatbot harm settlements in the country.
Separately, Kentucky's Attorney General filed the first state lawsuit against an AI chatbot company in January 2026, explicitly alleging data-privacy law violations alongside consumer-protection claims. A COPPA-based claim in related litigation alleges Character.AI collected and shared children's personal data without parental consent.
Pennsylvania sued Character Technologies in May 2026 over chatbots posing as licensed medical professionals. Texas's Attorney General is separately investigating deceptive practices tied to AI "therapy" bots and data privacy.
The pattern is clear: the legal theory is expanding from safety harm into data privacy and regulatory compliance. For users, this means the question of what happens to your data is no longer just a personal concern. It's becoming a legal one.
What Changed for Users Under 18?
Character.AI announced on October 29, 2025 that it would remove open-ended chat for users under 18, with the change fully effective by November 25, 2025. Teens were shifted toward structured creative tools instead of free-form conversation. During the transition, daily chat time was throttled from two hours down to zero.
This is a significant product change, but it doesn't retroactively address the data already collected from minors during the years when open-ended chat was available to them. The COPPA allegations in pending litigation suggest that data collection from under-13 users may have occurred without required parental consent. Even for 13-to-17 users, the question of whether they meaningfully consented to having their conversations used for model training is genuinely open.
Does Age Verification Create New Privacy Problems?
It does. To enforce the under-18 restriction, Character.AI built an in-house age-estimation model combined with third-party verification tools, with fallback to facial recognition or government ID checks. This is the age-verification privacy paradox: the fix for one privacy risk (minors chatting unsupervised) introduces another (biometric and identity data collection).
Facial age estimation can't reliably distinguish 17 from 18. Government ID uploads create a new, high-value data target. And for a platform already under regulatory scrutiny for its data practices, collecting face scans and ID images from users trying to prove they're adults raises an obvious question: who protects that data, and for how long is it retained?
There are better architectural approaches to this problem. Cryptographic age tokens, on-device estimation that never transmits biometric data, zero-knowledge proofs of age bracket membership. These are technically feasible but underdeployed. The industry has mostly defaulted to "upload your face or your ID," which solves the compliance checkbox at the cost of creating a new data-privacy surface.
What Does "Private" Actually Mean Here?
It helps to break this down by asking: private from whom?
Other users on the platform: Yes, your chats are private from them. No other Character.AI user can see your conversations.
Character.AI employees and contractors: No. Approved staff can access conversations flagged for moderation or safety review.
Third-party vendors and affiliates: No. The privacy policy authorizes data sharing with vendors involved in operations and service improvement.
The model training pipeline: No. Your conversations are training data.
Law enforcement: No. Valid legal process compels disclosure.
Character.AI's corporate parent or acquirer: Almost certainly no. Standard privacy policies include provisions for data transfer in mergers, acquisitions, or asset sales.
When a platform says your chats are "private," they mean private from the first category only. The other five categories represent real access vectors that exist by design and by law.
What Would Genuinely Private Architecture Look Like?
This is the question I find most interesting, because I've spent time building systems where the answer matters. If you're going to run a chat product on frontier AI models, there are structural constraints on how private you can make it. Those constraints are real, and anyone who claims otherwise is either confused or selling something.
Here's the core tension: any product that sends your messages to a cloud-based model for inference is, at minimum, exposing the content of that message to the inference provider during processing. You can encrypt data at rest. You can encrypt it in transit. But at the moment the model processes your text to generate a response, some system has to see it in cleartext. That's just how transformer inference works.
The honest version of "private" for a cloud-based AI chat product looks like this: content encrypted at rest and in transit, minimal retention of operational metadata (kept for a short retention window, not indefinitely), no use of conversation content for model training without explicit opt-in, real-time purge on deletion rather than 90-day backup windows, and transparent reporting on legal-process requests. Each of those is an engineering commitment that costs something in either performance, operational convenience, or business model flexibility.
We built Selina with this set of trade-offs in mind. Memory is encrypted at rest, but it is not end-to-end encrypted, because a slice of each request reaches a frontier provider at inference. Files and transfers through SelinaSEND use zero-knowledge encryption, so we genuinely cannot read them. That distinction, memory versus files, reflects an honest accounting of where the privacy boundary actually sits rather than a marketing claim that papers over the architecture. Your account is protected. Your content is encrypted. But "encrypted at rest" is not the same as "nobody can ever see it," and pretending otherwise would be dishonest.
The gap between Character.AI's architecture and something meaningfully more private isn't about one feature or one policy. It's about the accumulation of choices: whether you train on user data by default, how long you retain backups, whether deletion is cosmetic or cryptographic, how many third parties touch the data, and whether you're transparent about each of those decisions.
What Should Parents Actually Do?
If your teenager used Character.AI before the under-18 ban took effect in November 2025, their conversations likely still exist in the company's systems, whether or not they deleted them from the app. Those conversations were used for model training. There is no mechanism to un-train the model on that specific data.
Concrete steps worth considering:
- Request a copy of your child's data through whatever data-access mechanism Character.AI provides. Under CCPA (if you're in California) or state equivalents, you have the right to see what they've collected.
- Request deletion of the account entirely, not just individual chats. Account deletion triggers the retention-period countdown, after which data should be purged from backups.
- Understand that deletion does not undo model training. If conversations were used as training data before the deletion request, that influence persists.
- Talk to your kid about what "private" means on any AI chat platform. The conversational intimacy these products are designed to create does not reflect the technical reality of how the data is handled.
Where Does This Go From Here?
The FTC's 6(b) inquiry is still gathering data. The Kentucky, Pennsylvania, and Texas actions are progressing through their respective courts. The settled lawsuits in Florida, Texas, Colorado, and New York had confidential terms, so their precedential value is limited. But the direction is unmistakable: regulators and courts are moving toward treating AI chatbot conversations as sensitive data that demands more than boilerplate privacy-policy language.
Legal scholars have noted that the regulatory focus on companion chatbots represents a new category of privacy concern. Traditional privacy frameworks were built around data collection as a transactional event (you give us your email, we send you a newsletter). Companion chatbots collect data through ongoing, emotionally rich conversations where users disclose things they might not share with another human. The privacy framework hasn't caught up to that dynamic yet.
For now, the answer to "are Character AI chats private" is: they are private from other users, and that is the only sense in which they are private. From the company, its vendors, its training infrastructure, and the legal system, your conversations are accessible. Whether that level of privacy is acceptable depends on what you're sharing and who you expect might eventually see it.
If you want a chat assistant where content is encrypted at rest, files are zero-knowledge encrypted, and delete actually means gone: start a free 7-day trial of Selina, no card required.
Frequently Asked Questions
Are Character AI chats private?
They're private only in the sense that other users can't see them. The company, its employees, vendors, and law enforcement with a valid court order can access them, and there's no end-to-end encryption.
Does Character.AI use my conversations to train its AI models?
Yes, user conversations feed into the model-improvement pipeline as described in the privacy policy's service-improvement section. Being 'private' from other users doesn't mean your content is excluded from training data, and once used, it can't be un-trained from the model.
If I delete a chat, is it really gone?
Deleting a chat only removes it from your interface, not immediately from the company's backend. Backups typically persist for 30 to 90 days, and any model already trained on that content still retains its influence.
Can law enforcement get access to my Character.AI chats?
Yes, as a U.S. company, Character.AI must comply with valid subpoenas, court orders, and search warrants. While they state they push back on overly broad requests, compliance with valid legal process is not optional.
What is the FTC investigating about Character.AI?
In September 2025, the FTC opened a formal Section 6(b) inquiry into Character.AI and six other companies regarding how companion chatbots collect, use, and share personal data from conversations, with specific focus on impacts on children. This is a data-gathering study, not an enforcement action, and could take years before any public report emerges.
Sources & References
- Is Character AI Safe? | Internxt Blog
- How to See People’s Chats on Character AI (Truth 2026) - Ai Insights News
- Character Ai Privacy Policy What You Need To Know Now — KERUSSO
- Character Ai Privacy Policy What You Need To Know Now - KERUSSO
- Does Character AI Read Your Chats? Truth About Privacy, Data
- Do Character.AI Staff Read Your Chats? Privacy Truth (2026)
- AI Chatbot Safety Character Technologies
- Character.AI, Google Agree to Settle Teen Chatbot Harm Lawsuits
- Character.AI Faces Lawsuit Over Child Safety Concerns
- Character.ai Lawsuit [2026 Update] | File A Claim
- Character AI Lawsuit | Character.AI Suicide Attorneys
- AI Chatbot Self-Harm Lawsuit
- Character AI Lawsuit For Suicide And Self-Harm [2026]
- Character.AI Lawsuits 2026: What Happened, What Courts Are Examining, and Why It Matters - SoftwareSeni
- Character.AI Lawsuit | Family & Wrongful Death Claims | July 2026 Update
- Is Character.AI Safe in 2026? Updated Safety Review for Parents & Users
- FTC Demands Answers from AI 'Companion' Makers on ...
- FTC Launches Inquiry Into AI Chatbots Acting as Companions: What It Means for Advertisers and Platforms, Holly Melton
- 6(b) Orders to File Special Report Regarding Advertising, Safety, and Data Handling Practices by Companies Offering Generative Artificial Intelligence (“AI”) Companion Products or Services | Federal Trade Commission
- FTC Launches Inquiry into AI Chatbots Acting as Companions | Federal Trade Commission
- AI companion bots: Top points from recent FTC and government actions | DLA Piper
- FTC demands answers on kids’ AI companions | Vibe Graveyard
- Generative AI 6(b) resolution
- Regulatory Focus on AI Companion/Character Chatbots - California Lawyers Association
- FTC Investigates AI Chatbots Acting as Consumer Companions | Shub Johns & Holbrook LLP
- Watch CBS News
- Character.AI's November 2025 Policy: Under-18 Chat Ban Explained - AI CERTs News
- Character.AI bans under-18s from interacting with chatbots after teen suicide | Euronews
- Taking Bold Steps to Keep Teen Users Safe on Character.AI
- Important Changes for Teens on Character.ai – C.AI Help Center
- Character.AI's Under-18 Ban Explained, and Where Adults Go Now
- An Update On Changes to Our Under-18 Experience
- New on Yahoo
- Character.AI to Ban Children Under 18 From Talking to Its Chatbots
- Character.AI to ban teens from talking to its chatbots
- Character.AI under 18
