What a Companion App Operator Actually Holds

The concerns worth having about a companion app are not vague. They are about a short list of specific things that exist on someone else’s servers: the conversations themselves, the identifiers that tie them to you, the payment relationship, the diagnostics that travel alongside, records created when something was flagged, and copies held by the outside companies the operator relies on. What makes this different from ordinary app privacy is not the technology. It is that the content is unusually revealing and that its lifespan is set by policy rather than by whether you still use the app.

Everything below is on the operator’s side of the line. The exposures on your own phone are a separate subject with different answers, and they start with reading your phone’s privacy dashboard.

The inventory, roughly in order of how long it outlives you

The conversations. The substance of the thing, stored so it can be shown back to you and, on most apps, so the app can behave consistently across sessions. This is the operator’s most valuable asset and the reason the rest of the list exists.

Account identifiers. An email address, or an identity supplied by a platform sign-in, plus whatever device and installation identifiers the app generates. These are the join keys — the reason conversations are attributable at all — and they are also what a second account fails to share, as described in what sign-in with Google or Apple links together.

The billing relationship. Whoever took your money holds a record with your real name attached, and that party is frequently not the app’s operator. Establishing which is the subject of who you actually bought the subscription from, and it changes who holds what.

Diagnostics and usage telemetry. Session lengths, feature use, error reports. Ordinary and mostly dull, with one sharp edge: crash reports can carry fragments of whatever was on screen or in memory when the crash happened.

Moderation records. When content is flagged, the flag and the material behind it are usually kept as a record of a decision, and often kept apart from ordinary conversation storage and for longer. This is under-discussed and it is a genuine asymmetry: the parts of your history most likely to be retained longest are the parts something objected to.

Support correspondence. A message to support puts whatever you quoted into a ticketing system that is a separate product, run by a separate company, outside the app’s own privacy story entirely.

Backups and logs. Both exist, both are normal engineering, and both commonly run on retention clocks unrelated to the ones that govern your account.

Copies with outside processors. Model providers, speech services, image services, analytics vendors, payment processors, the support desk. This is the part where “what the operator holds” stops being a complete question, because some of the material is not being held by the operator at all.

Why retention outlives your use

Three ordinary reasons, none of them sinister and all of them worth expecting.

Deleting an account record is not the same as deleting everything derived from it. Aggregate figures, statistics, and material already incorporated into something else generally survive by design, and a policy will usually say so if you read it.

Backups exist so that data can be recovered, which means recent data is recoverable for as long as the backup cycle keeps it, regardless of what happened to the live record. A policy that is silent about backups is not covering them.

And where there is a legal obligation to keep something — a payment record, a moderation decision, material subject to a request from an authority — that obligation outranks a deletion request. This is the same in every industry.

What changes hands when the company does

This is the part most worth thinking about in advance, because it is the one nobody expects and it applies to the whole inventory at once.

Companies in this category are young, numerous, and frequently acquired or closed. When one is acquired, the data is part of what is bought; the acquirer’s practices then govern it, and the policy you agreed to can be replaced with a different one. When one shuts down, an orderly deletion is the courteous outcome rather than the automatic one, and assets including user data are sometimes sold as part of the wind-down.

The clause that governs this is a change-of-control provision, it is in most privacy policies, and it is short. How to find it and what else to look for is covered in how to read a companion app’s privacy policy.

The two things genuinely in your control

How much identity is attached. An account created with a dedicated email address, no platform sign-in, no contact permissions, and a billing route that does not add your name is meaningfully less attributable than the default path. None of that hides you from the operator; it reduces how easily the material joins to the rest of your life.

How much you attach to it. Not in the sense of censoring yourself, but in the sense of knowing that a feature which remembers is a feature which stores. The relationship between the two is set out in what memory means when a companion app claims it.

Those two decisions are made at signup and are awkward to revise later, which is the argument for making them deliberately.

The honest way to hold this

Not as a prediction that something bad will happen, and not as a reason to avoid the category. Simply as an assumption: a store of these conversations exists, it is attributable, it will outlast your interest in the app, and it may end up under different management. Everything sensible follows from taking that as the baseline rather than hoping otherwise.

What cannot be done is verification. You cannot audit an operator’s storage, enumerate its processors, or confirm that a deletion happened. What is visible from outside is the policy, the jurisdiction, and the billing trail — and preferring an app that is specific about all three is the whole of the available diligence.