When a Companion App Is Breached, What to Do First

A breach notice from a companion app is not the same as a breach notice from a shop. The record on the other side is the conversation itself, and no amount of credential hygiene retrieves it once it is out. So responding splits into two halves that want opposite speeds: a short security drill you should do immediately, and an exposure decision you should not rush.

Do the drill first. It is mechanical, it takes about the length of a coffee, and it is the part where speed genuinely changes the outcome.

The drill, in order

Change the credential, and change it everywhere you reused it. If the account used an email and password, that password is now assumed public — including at every other service where you typed the same one. Reuse is the mechanism by which a breach at a small app becomes a problem at your bank, and attackers automate exactly that replay. If the account used a platform identity instead, there is no password at the operator to leak, which is one of the reasons that choice is usually better; see what sign in with Google or Apple links together.

Sign out every other session. Many apps have a devices or sessions screen that ends every logged-in session except the one you are using. A stolen session token survives a password change unless you do this, which is the step most commonly skipped.

Turn on a second factor if the app offers one, and if it does not, treat the recovery email as the real credential. Whoever controls the inbox on file controls the account, breach or no breach. That inbox deserves the strong password and the second factor even when the companion app cannot accept one.

Check the billing channel, not the app. If the subscription was bought through a platform store, the operator never held your card details and the store’s own screens are unaffected. If a card was entered on the operator’s site, watch the statement and consider whether the card should be reissued. The distinction is worked through in who you actually bought the subscription from.

Keep the notice. Save the email, note the date you received it, and screenshot the operator’s public statement. If anything downstream needs to be raised with a payment provider, a store, or an authority, the dated notice is the document you will be asked for.

That is the whole security half. Everything past this point is judgement.

What actually leaked, as opposed to what the notice says

Breach notices are written by lawyers under time pressure and they describe categories, not contents. Two habits help when reading one.

Assume the conversation record is in scope unless the notice says otherwise, and be sceptical if it does. The message history is the product’s core asset; it is the thing the operator’s own systems must be able to read in order to reply to you. A notice that lists “names and email addresses” without mentioning message content has not necessarily ruled it out — it has described the fields the investigation had confirmed at the time of writing. First notices are routinely superseded.

Look for what else is stored alongside it. Not just messages: the profile and retained facts the app built about you, images you sent, the display name and email, the plan you are on, timestamps that reconstruct when you were awake and talking. An inventory of what an operator holds on its own servers is set out in what a companion app operator actually holds, and that inventory is the honest scope of a bad breach.

“Encrypted” in a breach notice is a claim that needs a follow-up question. Stored data can be encrypted in a way that protects it from a stolen disk and not at all from a compromised application, which is the more common intrusion. If the operator can show you your own history in the app, the operator can decrypt it, and so can anything that has taken over the operator’s systems.

The half you cannot undo

The uncomfortable truth is that the security drill protects your account and does nothing for the content. If a year of conversation is out, it is out. That leaves three real questions and none of them is technical.

Is there anything in the history that identifies a third party? Names, workplaces, a friend’s situation you described. This is the part people forget, and it is the part that involves someone who never consented to the app existing.

Is there anything in the history that could be used against you? Not because you did anything wrong, but because material taken out of context is the raw material of pressure. If the answer is yes, read if someone threatens to publish your conversations before anything arrives, not after.

Who, if anyone, would you rather hear it from you? There is no general answer. There is only the observation that a decision made calmly on day one is usually better than one made under pressure on day thirty.

What this teaches about the account you keep using

A breach is the moment the abstract question becomes concrete, so it is worth converting into a standing setting rather than a bad week.

Deleting your account now does not retrieve anything, and it may cost you the copy of your own history. If you want to leave, export first where an export exists, then delete — and be clear that deleting the app from your phone is a change to your phone, not an end to the account or the subscription.

A separate email address for accounts like this limits the blast radius of the next one, at the cost of one entry in a password manager.

What you choose to send remains the only control you fully own. Retention promises are commitments you cannot test; the volume and specificity of what you disclose is a decision you make every day and can change today. After a breach that asymmetry stops being theoretical, which is the one useful thing about it.