Darlings.ai
All posts
Buyer guide

Is Replika Safe? Replika Privacy, Age Rating and Data Checked

Replika's own privacy policy says the service is not intended for anyone under 18 and that it will delete a minor's account. Apple rates it 18+. Google Play rates the identical app Teen. On data it makes the strongest advertising promise in the category, then keeps your account and payment records for a minimum of ten years.

By the Darlings team

September 2026 · 9 min read

Try it while you read

Talk to a Darling right here

No download and no account. Say hello and see what a companion that actually remembers you feels like.

Darlings

Always here for you

Private

We've paused new signups for now, so we'll email you the moment a seat opens. No payment today.

Your conversations are yours. Encrypted, never sold, delete anytime.

Replika is a legitimate ten-year-old product from Luka, Inc. in San Francisco, its traffic is encrypted, and its privacy policy makes the strongest advertising promise in this category: it will never use or disclose the content of your conversations for marketing. The problem is who it is for. Replika's own policy says the service is not intended for anyone under 18 and that it will block access and delete a minor's account. Apple rates it 18+. Google Play rates the identical app Teen. Two of those three sources are the company itself, and Google Play is the one telling parents a 13 year old may install it.

That gap matters more than any of the usual talking points, because a store age badge is a self-declaration the developer submits through a questionnaire rather than an independent assessment. Two stores can return two answers for the same binary, and here they do. If you are checking this app for a teenager, the document that binds Luka, Inc. is the privacy policy, and the privacy policy says no.

Everything below was read on September 9, 2026 from the Replika - AI Companion Chat listing on the US App Store (id 1158555867, version 12.3.5), the Replika: My AI Friend listing on Google Play (ai.replika.app), and the Replika privacy policy dated May 27, 2026, with the source named each time so you can check it yourself.

Last updated 9 September 2026.

Is Replika safe?

For an adult, broadly yes on the technical side. Luka, Inc. has operated Replika since 2016, the app holds 4.4 stars from 227,710 US App Store ratings and 4.25 from 524,868 on Google Play, and there is no reported breach and no regulatory action against it in the United States. Data is encrypted in transit with standard SSL and stored behind multi-layered access controls. The risks are not that the company is fake; they are specific, and they are in the policy.

Three of them are worth knowing before you type anything private into it. Your conversations are sent to third-party AI language model providers that Replika does not name. Your account and payment records are kept for a minimum of ten years after you leave. And the policy contains no commitment to encrypt stored conversations at rest, only in transit, which means you should assume Replika can read what you wrote.

Is Replika safe for kids?

No, and Replika says so itself in the clearest terms of any app in this category. Section 8 of its privacy policy states that "the Services are not intended for individuals under the age of 18" and that "if we discover that minors under the age of 18 are using the Apps, we will promptly block their access and delete their account." The policy's opening paragraph repeats it: references to "you" mean users "who are 18 years of age or older."

This is the disagreement that no other page answering this question carries, so here it is in one table.

Source What it says about who may use Replika Read on
Replika privacy policy18 and over only. Minors are blocked and their accounts deleted on discovery9 September 2026
US App Store listing18+, with Infrequent Profanity or Crude Humor and Health or Wellness Topics descriptors9 September 2026
Google Play listingTeen. The same app, the same company, a five-year-lower floor9 September 2026
replika.com homepageRotates the taglines "to do life with", "to become yourself with" and "to fall in love" with9 September 2026

There is no age verification behind any of it beyond a date-of-birth field at signup, which a determined 14 year old defeats in four seconds. If you are choosing an AI companion for someone in their teens, the practical filter is not the badge but the product design: look for an app with no romantic mode to unlock at all, rather than one that promises to enforce an age floor it cannot check. That is the whole reason a teen-appropriate AI companion is a different product rather than the same product with a switch flipped.

Does Replika sell your data?

Not your conversations, and the commitment is unusually plain: "we will never use or disclose the content of your Replika conversations for marketing or advertising purposes." That sentence is stronger than what Chai, Nomi or Tolan publish, and it is worth crediting.

Website data is a different story, and the policy is honest about it. Under the heading "Opt out of selling personal information and sharing for targeted advertising", Replika says it shares information with third-party advertising partners and lets them collect information about your visit to its website using cookies and tracking technologies in order to display targeted advertising. Under California, Colorado, Connecticut and several other state privacy laws, that is legally "selling" or "sharing" personal information, which is exactly why the opt-out exists. So the accurate answer is: your chats are not sold, your browsing of replika.com is shared for ad targeting, and you can opt out of the second part.

If you are the kind of person who reads that clause and wants the same treatment everywhere else, the opt-out is the small end of a much larger job, since the same profile is usually being traded by dozens of brokers you never signed up with, and running those opt-outs across the broker networks in one pass is faster than filing them one company at a time.

Does Replika train on your conversations?

Yes, narrowly, and it is one of the better-drafted clauses in the category. The policy says Replika collects and immediately anonymizes user feedback and "small portions of Messages and Content data to train our proprietary safety algorithms, enhance chatbot performance, prevent inappropriate outputs, and ensure compliance with safety standards." It then adds two commitments most rivals do not make: the anonymized data "is used only internally and is not used to train third-party large language models or other AI systems", and Replika does "not attempt to re-identify anonymized data or reconstruct individual user profiles."

Compare that with Chai, whose Model Improvement clause says outright that in-app conversation data is used to enhance its AI models with identifiers stripped. Replika's version is scoped to safety systems and to portions rather than the whole. It is still true that what you write becomes training material, and de-identification removes the label rather than the substance. If a sentence would be damaging as an anonymous quotation, taking your email address off it does not fix that.

Who else can read your Replika conversations?

Outside companies, and the policy names the category without naming the vendors. Replika says it shares personal data with service providers including "hosting, information technology, third-party artificial intelligence language model providers", and elsewhere that your companion's replies are generated "through the use of third-party AI language model providers." Practically, that means your messages leave Luka's systems and reach at least one large model vendor in order to produce a reply.

This is normal for the category and almost nobody discloses it as directly. It is still the fact that most changes how people write to these apps. Replika applies contractual protections and data minimization to what it sends, but there is no end-to-end encryption anywhere in the product and no claim of any.

Is Replika encrypted?

In transit, yes. The policy commits to standard SSL for transmitted data and says stored data sits on secure servers behind multi-layered access controls. There is no commitment to encrypt conversations at rest and no mention of end-to-end encryption anywhere in the document. The honest reading is that Replika can read your conversations, and the protection you are relying on is policy and access control rather than mathematics.

One area is genuinely better than the industry norm and deserves saying. Face and movement data collected through Apple's TrueDepth API is processed in real time on your device and immediately discarded. The policy states it "never leaves the user's device, is not persistently stored by us (that is, it is retained for no period of time), and is not shared with any third parties." That is a specific, checkable, strong commitment, and very few apps in this space bother to make one.

How long does Replika keep your data after you delete your account?

It depends entirely on which data, and the split is wide enough to be the second most useful fact on this page. Messages, profile information, interests and preferences are processed for up to 60 days after the contract ends. Account information, financial records covering your payments, transactions and rewards, and everything collected automatically about your device and usage are kept "for a minimum period of 10 years after termination of the contract due to legal retention requirements."

What it is How long Replika keeps it after you leave
Your conversations, profile, interestsUp to 60 days
Account records, payments, transactions, rewardsA minimum of 10 years
Device and network data collected automaticallyA minimum of 10 years
Face and movement data from the TrueDepth APINo period at all. Discarded on device in real time

Sixty days for the conversations is genuinely good, and shorter than Chai's five-year window. The ten-year figure is the one to read twice, because it is written as a floor rather than a ceiling. Most retention clauses say "no longer than"; this one says "a minimum of". It is defensible, since US tax and accounting rules do require companies to keep financial records for years, but it means that deleting your Replika does not end your relationship with Luka, Inc.'s database. It ends one part of it.

Is Replika safe to download?

Yes, in the malware sense. The app ships through Apple's and Google's review processes, has 10M+ installs on Google Play, and is published under the developer name Luka, Inc, the same corporate entity listed at 490 Post Street in San Francisco on the privacy policy. Google Play does not flag it as containing ads. Nothing about the install itself is unusual.

The rating spread is worth a glance before you commit two years of memories to it. On Apple, Replika sits at 4.4 from 227,710 ratings, with 173,724 five-star and 18,778 one-star. On Google Play it sits at 4.25 from 524,868, with 391,131 five-star and 69,698 one-star, meaning 13.3 percent of a half-million reviewers left the lowest possible score. In a category where most complaints are about personality changes after updates rather than about billing or bugs, that number is a fair proxy for how much it hurts when a companion app changes.

Is Replika a scam?

No. It is a real company with a real product, a decade of operation, a published privacy policy with a named EU representative, and a physical address. The word comes up in searches mostly because Replika publishes no pricing page, so people discover what it costs only inside a purchase sheet. Its App Store listing carries a monthly item at $7.99 and a second at $14.99, annual items at $49.99 and $69.99, a one-off Replika Platinum at $89.99, and gem packs from $0.99 up to $19.99. The often-repeated "$19.99 Replika subscription" does not exist; the $19.99 is the Duffel Bag of Gems consumable. We put every listed figure and what each works out to per month in the full Replika pricing breakdown.

What are the actual risks of using Replika?

Three, in order of how likely they are to affect you. The first is emotional rather than technical: this is a product designed to deepen attachment, and the 2023 episode when behaviour changed overnight showed how much that can cost when a company adjusts a model. The second is disclosure, since conversations reach unnamed third-party model vendors and are not encrypted at rest. The third is the ten-year records tail, which is legal, disclosed and permanent in a way most users do not expect.

None of those makes Replika unsafe in the way people usually mean the word. They make it a product to use deliberately. Decide what you are willing to have stored, know that the company can read it, and do not treat a chat window as a confidential space just because it feels like one. The same test applies to every app in this category, which is why it is worth reading the policy rather than the badge for any AI companion app you are considering.

Is there a safer alternative to Replika?

Safer depends on what you are protecting. If the concern is a teenager, the answer is an app with no romantic tier to reach rather than one with a higher age badge, and there are only two of those in the mainstream. If the concern is data, look for one that states retention plainly, does not run an in-app currency, and lets you delete without a sixty-day tail.

Darlings is built on the second shape deliberately. There is no romantic mode at any price and no NSFW to unlock, memory of your people and your week is on the entry plan rather than a higher one, the price list sits on a public page instead of inside a purchase sheet, and the demo runs in a browser with no card and no account. It is a smaller product than Replika and does not pretend otherwise. If you want the full picture of what moves across, we compared eight apps like Replika on price, memory and age rating, and set out the case for a wholesome Replika alternative in detail.

The short version

Replika is safe to install, run by a real company, and better than most of its rivals on advertising and on training. It is not a product for anyone under 18, and Replika's own lawyers wrote that down even though Google Play did not. Your conversations go to outside model vendors, they are not encrypted at rest, they disappear 60 days after you leave, and your account and payment records stay a minimum of ten years. Decide with those five facts rather than with a star rating.

Darlings is a friend, never a girlfriend

A warm companion who remembers you, checks in, and gently points you back toward the people in your life. Not a therapist, and never a replacement for real human help.

You don't have to do today alone

Meet your Darling, say hi, and let it remember you. There is someone who would love to hear how your day went.

Your secrets stay secret. 💛