ai companion privacy
AI Companion Privacy: One Name, Two Products — a Guide That Separates Them
The phrase AI companion attaches to two different things: a workplace meeting assistant that creates a record of what is said in a meeting, and a category of consumer companion chatbots studied for the privacy concerns that arise in intimate use. This guide separates the two, using institutional IT guidance for the workplace half and a preprint study on arXiv for the consumer half, then turns the cited material into a side-by-side table and a checklist you can run against a policy.
This article was researched with AI assistance and independently reviewed by multiple AI models before publication.
Key takeaways
- The name AI companion covers two different products: a workplace meeting assistant, which Georgetown's IT guidance describes as creating a record of what is said and done in a meeting, and consumer companion chatbots, which a preprint study on arXiv examines through 2,909 posts across 79 subreddits collected over one year.
- For Zoom AI Companion, Georgetown's guidance states participants get a pop-up banner when a host turns a feature on, that hosts control which features run, and that meeting summaries are accessible only to the host by default.
- UC Riverside's guidance states the meeting host must manually enable meeting summaries and that AI Companion summaries are automatically deleted after 30 days. That 30-day figure is the policy stated in UC Riverside's guidance; the cited material does not establish it as a Zoom product-wide default.
- Georgetown's guidance tells users not to use Zoom AI Companion features in clinical, telemedicine, healthcare, peer review, animal care, or public-record meetings except under an institutionally approved procedure.
- The arXiv study identifies four recurring privacy patterns in romantic AI use, the fourth labelled irreversibility, persistence, and user burden.
- That same preprint, citing Reuters and the European Data Protection Board, reports that Italy's data protection authority fined Replika over privacy violations including failures related to age verification. No primary regulator document is cited here, so the amount, date, and current status are unverified in this guide.
- Carahsoft's privacy policy is useful only as an example of drafting to watch for: it governs information Carahsoft itself collects as a reseller and distributor, states that collected data may be used for other purposes, and carries a last-updated date of 3/31/23.
AI Companion Privacy: One Name, Two Products — a Guide That Separates Them
The phrase AI companion names two different things. One is a workplace meeting assistant bolted into conferencing software. The other is a category of consumer companion chatbots built for conversation, roleplay, and emotional support. They create different records, sit under different controls, and fail in different ways, so this guide separates them: the workplace half first, the consumer half second, and one shared checklist at the end.
Scope, stated up front so you know which half serves you. The workplace half describes institutional deployment guidance from two university IT offices — not Zoom's own current terms, which this guide could not retrieve. The consumer half describes research-level privacy patterns reported by users — not the product policies of any named app.
Category one: the workplace meeting assistant
The clearest description of what a workplace AI companion does comes from a university IT office. Georgetown's University Information Services guidance on Zoom AI Companion states that the feature is similar to other Zoom features like meeting recording and live transcription in that it "creates a record of what is said and done in a meeting."
That sentence is the whole privacy model. The assistant is not an observer that forgets. It is a record-producing feature, and every downstream question — notification, access, retention, deletion — follows from the existence of that record.
Notification
Georgetown's guidance describes the notification mechanism directly: when a host turns on an AI Companion feature, participants are notified with a pop-up banner.
A banner is a notification model rather than a negotiation model — that reading is this guide's inference from the mechanism described, not a characterisation Georgetown makes. What the banner copy says, and what options a participant is offered alongside it, are not established by the cited material.
Who controls the output
Per the same Georgetown guidance, meeting hosts control which AI Companion features are used in their meetings and control the transcripts and summaries generated, with meeting summaries accessible only to the meeting host by default.
UC Riverside's School of Medicine IT guidance on Zoom AI Companion describes meeting summaries as a valuable feature and adds two operational details: the host must manually enable it, and AI Companion summaries are automatically deleted after 30 days under a stated retention policy.
That 30-day clock belongs to UC Riverside's guidance alone. Nothing cited here establishes 30 days as a Zoom product-wide default — it is the policy as stated in one institution's guidance, and it should be quoted that way rather than carried into any other deployment.
So the practical control surface described across those two documents is narrow and concentrated: one person decides whether the record exists, that person holds it by default, and under UC Riverside's stated policy it ages out on a fixed clock.
Where the guidance says not to use it
Institutional guidance is most useful where it draws hard lines. Georgetown's guidance advises caution in deciding whether to use Zoom AI Companion or other recording features in meetings where particularly sensitive, privileged, or confidential data may be discussed, and notes this includes PII or PHI related to research participants unless a specific exemption has been granted by the UISO as part of an approved protocol.
It goes further for certain settings, instructing users not to use Zoom AI Companion features in clinical, telemedicine, or healthcare settings such as patient encounters, in peer review meetings, in animal care meetings, or in meetings entered into public records, except under an institutionally approved procedure.
That list transfers well beyond Georgetown as a way of framing the decision: the question is not whether the tool is secure, but whether this conversation belongs in a durable, summarizable record at all.
What this guide could not check on the vendor side
The two documents above describe deployment practice at two institutions. They are not Zoom's terms. Attempts to retrieve Zoom's current AI data-handling and retention documentation for this guide returned a session-timeout page rather than the article content, so no current vendor rule on retention or data handling is cited here.
What could be captured from Zoom's own material is thin and general. Zoom's support material on AI features leads with capability, describing real-time features intended to help users improve productivity. Zoom's privacy statement describes the personal data collected and processed to provide products and services offered directly by Zoom — a first-party scope, which is a prompt to ask separately about anyone else in the chain. And Zoom's AI whitepaper states that it describes AI features across the platform but does not guarantee that any feature described is currently available, since access can depend on subscription plan, license assignment, administrator settings, regional availability, product configuration, technical compatibility, credit availability, and usage limits.
That last point matters more than it looks: if availability varies by administrator setting and plan, then a description of the feature elsewhere is not a description of your deployment.
Category two: the consumer companion app
Before anything else in this half: no product-level collection, access, or retention terms for any named consumer companion app appear in the material cited here. What the research cited below describes is user-reported concern patterns across the lifecycle of use, plus market context and one enforcement report at second hand. If you came for a per-app comparison of what each product collects and keeps, this half does not deliver that, and no source used here would support it.
A preprint study published on arXiv tracing users' privacy concerns across the lifecycle of companion AI use analyzed 2,909 posts from 79 subreddits collected over one year and identified four recurring patterns: disproportionate entry requirements, intensified sensitivity in intimate use, interpretive uncertainty and perceived surveillance, and irreversibility, persistence, and user burden.
Those four labels work better as a privacy checklist for this category than any feature comparison, because each names a failure mode rather than a missing setting. The paper's authors argue the findings highlight the need for privacy and safety governance in romantic AI that is staged across the lifecycle of use, supports meaningful reversibility, and accounts for the emotional vulnerability of intimate human-AI interaction.
The paper also situates the market. It notes that platforms such as Replika and other companion-AI apps are increasingly marketed as sources of virtual courtship, emotional support, and roleplay, while critics have raised concerns about dependence, isolation, and the adequacy of platform safeguards. Citing Surfshark, it reports that character.ai had around 20 million monthly active users as of February 2026 — a figure carried here at second hand, not checked against a primary source. Those platform references sit alongside the Reddit analysis rather than defining its scope; the study describes its corpus as posts drawn from 79 subreddits, not as an examination of two named products.
On the state of privacy practice, the paper points to Mozilla's Privacy Not Included articles, which it summarizes as arguing that romantic AI chatbots perform poorly on core privacy expectations including data collection, user control, and transparency around data use. The same paper, citing Reuters and the European Data Protection Board, reports that Italy's data protection authority fined Replika over privacy violations including failures related to age verification. That report reaches this guide one level removed: no primary regulator document is cited here, and the fine amount, its date, and its current status are unverified.
One independent account, labeled as such
A publicly available independent write-up, the AI Companion Privacy Guide 2026 published under the byline Alex on March 13, 2026, states as its headline conclusion that most AI companion apps have terrible privacy practices. The author reports reading 15 privacy policies and exercising data export and deletion across 12 platforms, concluding that only two or three handle user data responsibly. The post also describes finding, on page 11 of one policy inside a paragraph about service improvement, a single sentence reserving the right to share anonymized conversation data with unnamed third-party partners for research and commercial purposes.
Treat that as one author's published account rather than an audited result — the counts and the unnamed platform cannot be corroborated from the other material cited here. Its useful contribution is the shape of the finding: the consequential clause sat deep inside a policy, under an innocuous heading.
Side by side: what the cited sources actually establish
Rows are filled only from the sources cited in this guide. Where the cited material is silent, the cell says so rather than guessing.
| What to check | Workplace meeting assistant (per institutional IT guidance) | Consumer companion apps (per the cited research) |
|---|---|---|
| Record created | Yes — Georgetown's guidance describes AI Companion as creating a record of what is said and done in a meeting | Not in evidence at product level; the arXiv study reports user concerns about irreversibility and persistence |
| Notification | Participants notified with a pop-up banner when a host enables a feature (Georgetown) | Not in evidence |
| Default access | Meeting summaries accessible only to the meeting host by default (Georgetown) | Not in evidence |
| Stated retention | Summaries automatically deleted after 30 days per UC Riverside's guidance; not established as a product-wide default | Not in evidence |
| Secondary-use language | Not in evidence in the cited institutional guidance | Not in evidence at product level; the arXiv paper summarizes Mozilla's articles as finding poor transparency around data use |
| Policy date | Not in evidence | Not in evidence |
The empty cells are the point. For the consumer half, the questions a searcher most wants answered — what is collected, who can see it, how long it is kept — are not answered by any source available here, and a page that filled them in would be inventing them.
Reading the policy: a checklist built from these sources
1. Find the sentence that says a record is created. Georgetown's guidance names record creation explicitly. If a policy never says plainly what persists, that gap is the first thing to chase down.
2. Check who is notified, and how. A pop-up banner, as Georgetown describes for Zoom AI Companion, is a notification model. Know whether everyone in the conversation is told, or only the person who enabled the feature.
3. Check who holds the output by default. Host-only access by default, per Georgetown's guidance, is a meaningfully different posture from shared-by-default.
4. Look for a stated retention period, and check whose policy it is. UC Riverside's guidance states AI Companion summaries are automatically deleted after 30 days. A number you can quote beats a paragraph about appropriate periods — but attribute it to the document that states it rather than assuming it applies everywhere.
5. Check whether deletion is meaningful. The arXiv study's fourth pattern is labelled irreversibility, persistence, and user burden. The label suggests reading a delete control sceptically — whether it undoes what was shared, or only removes it from view — though the cited extract names the pattern without elaborating on that distinction.
6. Read the secondary-use clause for elastic drafting. As an example of the drafting to watch for, Carahsoft's privacy policy states that while the information collected enables it to offer better service, "we may use the data for other purposes." That policy governs information Carahsoft itself collects in its role as a master government aggregator, value-added reseller, and distributor serving public sector customers and other resellers; nothing cited here establishes Carahsoft as a recipient or processor of AI Companion transcripts, summaries, or any companion-app conversation content. The clause is useful purely as a pattern — an open-ended purpose sentence is the kind of language worth resolving before you turn a feature on, not after.
7. Check the date on the document you are reading. The same Carahsoft policy carries a last-updated stamp of 3/31/23. Whatever a policy says, its date tells you how long ago someone last thought about it.
8. Check whether the feature you read about is the feature you get. Zoom's AI whitepaper states it does not guarantee that any described feature is currently available, and that access can depend on plan, license assignment, administrator settings, and regional availability. Confirm behaviour in your own deployment rather than from a general description.
Why the two halves do not share a playbook
The meeting-assistant controls — host enablement, participant banners, host-only summaries, and the 30-day deletion clock stated in UC Riverside's guidance — are described in the context of an institutional deployment with rules set around it. The consumer companion concerns in the arXiv study — entry requirements, intimacy, perceived surveillance, irreversibility — are framed around the individual user's experience across the lifecycle of use.
These are different layers of the same broad question, not competing answers to one question. The failure mode is carrying enterprise reasoning across: assuming that because one deployment publishes a retention number, a consumer app you install on your phone has a comparable arrangement. Nothing cited here supports that assumption.
What this guide does not settle
Zoom's own current AI data-handling and retention documentation could not be retrieved for this guide; support fetches returned a session-timeout page. The institutional guidance used above therefore describes deployment practice at those institutions and is not a substitute for the vendor's current terms.
The Italy enforcement report reaches this guide through the arXiv preprint citing Reuters and the European Data Protection Board, with no primary regulator document consulted, and the character.ai user figure is reported at second hand from Surfshark without an independent check.
Legal and professional-ethics discussion of AI meeting assistants — the question of what a regulated professional may put into an automated summary — was considered for this guide but could not be brought into scope with a usable source, so this guide does not address it.
And for the consumer half, the per-app product terms are simply absent from the material here. Where you need a determination for a regulated context — legal privilege, healthcare, research protocols — the pattern in Georgetown's guidance is the instructive one: those decisions were routed through an institutional approval process, not resolved by reading a feature page.
Sources
- Security and Privacy for Zoom AI Companion — Georgetown University Information Services
- Guidance on the Use of Zoom AI Companion — UC Riverside School of Medicine IT
- How Zoom AI features handle your data — Zoom Support
- Zoom Support session-timeout page
- Zoom Privacy Statement
- Zoom AI Whitepaper
- Carahsoft Privacy Policy
- Tracing Users' Privacy Concerns Across the Lifecycle of Companion AI Use — arXiv
- AI Companion Privacy Guide 2026 — aicompanionguides.com