How to Read a Companion App's Privacy Policy
The privacy policy is the only statement an app makes about your conversations that it can be held to. The feature page is marketing, the store listing is a summary, and a reassuring sentence on a landing page commits nobody to anything. Policies in this category are usually short, and six clauses carry nearly all of the weight — which makes this a ten-minute job once you know which six to find.
The other half of reading one is knowing how to interpret silence, because a policy that does not mention something is not promising to abstain from it.
What a policy is, and what it is not
It is a commitment: a statement of practice the operator can be held to by regulators and, in some jurisdictions, by you. That is genuinely worth something, and it is why the specific wording matters more than the tone.
It is not a description of how the system is built, and it is not a guarantee about the future — nearly every policy reserves the right to change itself. It is also not the same document as the terms of service, which is where you will find what you may do with the app’s output and what the operator may do with your account.
And it is not a substitute for the ordinary observation that a policy is easy to write and impossible for you to audit. It tells you what an operator has committed to, not what an operator does.
The six clauses that carry the weight
Retention. Look for an actual period, not a phrase. “As long as necessary to provide the service” is a commitment to nothing in particular. A stated number of days or months, especially one that separately addresses logs and backups, is a real statement — and it is uncommon enough that finding one tells you something about the operator.
Use of conversations for improvement or training. The clause you most want to find and read closely. Establish whether it exists, whether there is a way to decline, whether declining applies to what you have already sent or only to what comes next, and whether declining costs you any part of the product. Absence of this clause is not an assurance.
Human review. Separate from training use and routinely overlooked. Quality review, moderation, abuse investigation, and debugging can all involve a person reading conversations. Policies that say so are being straightforward; the practice is normal and the surprise is what people object to.
Third parties and subprocessors. A policy that names its processors, or links to a list of them, is doing considerably better than one that refers to trusted partners and service providers. Model providers, speech services, analytics, and support tooling are the usual set, and each is a separate company holding a share of the material described in what a companion app operator actually holds.
Change of control. One or two sentences, usually near the end, saying what happens to your data if the company is bought, merged, or wound up. In a category of young companies this is the clause with the longest reach, and it is almost always permissive.
Jurisdiction and your rights. Where the operator is established determines which regime governs the policy and what rights you can actually exercise. A policy that spells out a deletion route, an export route, and an address to send a request to is far more usable than one that mentions rights in the abstract.
How to read silence
No retention period stated means retention is at the operator’s discretion, which in practice means indefinite.
No mention of backups means backups are outside whatever the deletion clause promises.
No training or improvement clause is not a commitment not to. It may mean the practice is covered by a general purposes clause elsewhere, which is worth looking for before concluding anything.
No processor list means you cannot know how many parties hold a copy.
No last-updated date means you cannot tell what you agreed to or whether it has changed since.
None of these is proof of bad behaviour. They are all reasons the policy cannot be used as reassurance, which is a different and more useful conclusion than treating vagueness as innocence.
What a deletion or export request actually reaches
The gap between the request and the result is where most of the disappointment in this area lives, so it is worth being precise.
A deletion request normally reaches the account record, the credentials, and the stored conversations in live systems. That is the substantive part and it matters.
It does not reliably reach backups still inside their cycle, aggregate figures already computed, moderation records held as a record of a decision, payment records the operator is obliged to keep, or copies with third-party processors whose own deletion timetables are separate.
An export request returns what the operator classes as your personal data, which is often the account record and a conversation archive in a machine-readable form. Whether the archive is complete or a summary varies, and finding out before you need it is worth the effort.
What you can verify is small: that your credentials stop working and that no further charges arrive. Everything else is a commitment being kept out of your sight. The separate question of what survives on your own phone regardless of any of this is covered in what account deletion leaves on your device.
Check the policy’s own history
Two minutes, and often the most informative part. Find the last-updated date. See whether the policy promises to notify you of material changes, and by what means. An app that reserves the right to amend its terms without notice has told you something clear, and it is not a technicality — the app itself can change substantially between releases, as described in what an app update can change without asking, and the policy governing it can change alongside.
If a previous version of the policy is still findable, comparing the two shows you the direction the operator has been moving in, which predicts more than the current wording does.
The honest limit
Reading a policy well cannot tell you whether it is being followed. There is no test you can run from a phone that distinguishes an operator honouring a retention period from one that is not, and this post cannot pretend otherwise.
What the exercise does do is separate operators who are willing to be specific from operators who are not. Specificity is a cost — it constrains the business and creates an obligation — so an operator who accepts it has told you something an unenforceable reassurance never could. On a decision where nothing else is verifiable, that is the signal worth using.