Replika — privacy & data policy

Provider: Luka. PromptPrivacy score: 65/100. Last verified August 26, 2026.

What happens to your data?

Replika uses your account details, preferences, and chat messages to provide personalized AI conversations and maintain your account. Conversation inputs are sent to third-party AI models strictly to generate replies without allowing those providers to train on your data. Anonymized snippets are analyzed internally to maintain chatbot safety, and your chat content or media is never sold or shared with advertising partners.

Does it train on your data?

Luka collects and immediately anonymizes feedback and small portions of messages and content to train proprietary safety algorithms and enhance chatbot performance internally. These anonymized datasets are not used to train third-party AI models, and third-party AI language model providers are contractually prohibited from using user data to train their own systems.

Can you opt out?

Users can opt out of marketing communications via email unsubscribe links and manage or opt out of tracking cookies used for targeted advertising via the cookie policy settings. Users can also delete their account at any time. However, there is no standalone setting to opt out of internal anonymized safety training while continuing to use the service.

Data retention

Conversation messages, content, profile information, and preferences are retained for up to 60 days following the termination of your contract. Personal data processed for trend analysis is anonymized or deleted within 1 year. Financial records and account details are kept for up to 10 years for legal compliance. Third-party AI model providers process data transiently and delete it promptly after response generation, while AR face/head movement data is processed in real-time on-device and discarded immediately.

Encryption & security

Data in transit is encrypted using standard Secure Socket Layer (SSL) encryption. Stored data is hosted on secure servers protected by multi-layered controls such as firewalls, passwords, and role-based access controls. Specific at-rest encryption standards or third-party certifications (e.g., SOC 2, ISO 27001) are not specified.

Is it safe for work?

No. Replika is an AI companion designed for personal consumer use by individuals aged 18 and older. It lacks enterprise management capabilities, centralized administration controls, and corporate compliance frameworks suitable for processing sensitive business or proprietary data.

Source policy: https://replika.com/legal/privacy