AI Companion Report 18+ ONLY

Verification

Is Muah.AI safe?

This is the one app in the category where the question has already been answered, in public, by events. In September 2024 Muah.AI leaked 1.9 million accounts — not just email addresses, but the prompts attached to them. The breach is one of a small number Have I Been Pwned considers too sensitive to let the public search. Two years on, the operator still names no company.

Checked 31 August 2026 Primary sources linked below
Disclosure. This site earns affiliate commission on some AI companion apps. Muah.AI is not one of them — we have no offer for it, no link to it, and we earn nothing whether you use it or not. We do earn a commission on Candy.ai, which appears at the foot of this page as an alternative. Read the section on affiliate incentives before you weigh that, and note that we are recommending against the free app and towards the paid one here, which is the direction our incentives already point. Judge the evidence, not our conclusion.

1. What actually leaked

Verified against the Have I Been Pwned breach record

CONFIRMED Have I Been Pwned records a breach dated September 2024, added to the database on 8 October 2024, affecting 1.9 million email addresses. HIBP lists the compromised data classes as AI prompts, email addresses, and sexual fetishes. Its own description of the incident is that the breach "exposed 1.9M email addresses alongside prompts to generate AI-based images."

The significance is in the pairing. A leaked email address is a nuisance. A leaked email address bound to a written record of what somebody asked a chatbot to be is a different category of harm, and it is not one you can undo by changing a password.

You cannot check your own exposure without signing in

CHECK THIS HIBP has flagged this breach as sensitive, which removes it from public search. In HIBP's words: "As this breach has been flagged as sensitive, it is not publicly searchable." Only a handful of breaches in the database carry that flag. To find out whether your address is in it you must verify that you own the address and sign in to the HIBP dashboard, or search a domain you control through the Business section.

This cuts both ways, and it is worth being clear about. It protects users from anyone typing their address into a public box to find out what they were into. It also means the ordinary check most people know how to do will come back clean whether or not they are in the file.

If you used Muah.AI before October 2024, the public search box is not the check to run. Sign in at Have I Been Pwned and look at the dashboard.

2. Who are you actually trusting?

Checked against the operator's own terms page, 31 August 2026

NO ENTITY DISCLOSED Muah.AI publishes no company name, no registration number, no registered address, and no governing law. The entire corporate disclosure on the site is the phrase "California Based". We checked the homepage and the terms page, and looked for a privacy policy at the conventional paths; we found no document naming a data controller.

Set that against the same check run on other apps in this category. Candy.ai names EverAI Limited, a Maltese company, registration number C107181, with a registered address. Dream Companion publishes a full German Impressum, down to the register court, the HRB number, the VAT ID and two named managing directors. Both of those are checkable. "California Based" is not a fact you can verify, act on, or serve papers at.

This is the part that outlasts the breach. A company that leaks your data and is identifiable can be complained to, regulated, and sued. An operator that leaks your data and cannot be named offers no route to any of that. Janitor AI has the same gap, and we say so on that page too — but Janitor AI has no breach on record and never takes your card. Muah.AI has both a breach and no entity.

3. What it costs

Pricing is not published to the public web

UNVERIFIED We could not establish Muah.AI's subscription prices, free-tier limits, or refund terms, because the site does not publish them. We checked the homepage, /pricing and the on-page anchor; none returns a price. The public site offers a demo and a login by email, phone or Discord, and nothing else. Seeing what it costs requires creating an account first.

We are not going to print a figure we could not verify. Other pages answering this question do quote prices; we could not confirm any of them from the operator, so they are not here. What we can say is that an adult subscription product which will not show a price until you have handed over an identifier is making a choice, and it is not a choice made in the customer's interest.

The site also carries a version marker reading "BETA-Website", and a banner stating "NOT ALLOWED: Any child prompt = SUSPENSION!!!". Both were present when we checked on 31 August 2026.

4. What happened after the breach

The account below is drawn from the original reporting and from Malwarebytes' write-up. We have attributed each claim to the source that made it.

Extortion attempts were reported within three days

CONFIRMED 404 Media published its report on 8 October 2024. By 11 October 2024, Malwarebytes noted reports that the leaked information was "in use for active extortion attempts" — three days. Malwarebytes was careful to add that it could not confirm whether those attempts were tied to genuine platform activity or were simply exploiting the exposed email addresses. We repeat that caveat rather than dropping it.

On how the breach happened, the person who took the data told 404 Media the platform was "a handful of open-source projects duct-taped together," and Malwarebytes reported that "it was no trouble at all to find a vulnerability that provided access to the platform's database." No specific vulnerability has been published, and no independent post-incident audit of Muah.AI has been released.

404 Media's central finding concerned the content of the prompts: it reported that many users had attempted to create chatbots to roleplay the sexual abuse of children. That is the reason the story was covered as widely as it was, and it is relevant here for a narrow, practical reason — it tells you what was in the file that leaked alongside ordinary users' addresses.

The operator's response, reported at the time

VENDOR CLAIM The platform's administrator told 404 Media the breach had been discovered about a week earlier and suggested it was "sponsored by the competitors in the 'uncensored AI industry'", and said the platform would "suspend and delete ALL child-related chatbots". 404 Media reported that moderators had instead told users to take such content elsewhere. We have found no evidence published since that resolves the conflict between those two accounts.

So, is it safe?

For your data: no, and this is the clearest answer we have given on any page. Every other app in this category is assessed on the absence of a breach, which is not the same as security. Muah.AI does not get that benefit. The breach happened, it is documented in the standard public register, the exposed material was the most sensitive class of data this category holds, and extortion followed inside a week.

For accountability: there is none available. No company, no jurisdiction, no named officer, no regulator with obvious standing. If it happens again, there is nobody to take it up with.

Financially: we could not check. The prices are not public. We will update this page if that changes.

What we would actually do. If you have an account from before October 2024, sign in to Have I Been Pwned and check the dashboard rather than the public box; then change any password you reused elsewhere, on the assumption the address is known. If you are considering signing up now: a documented leak of prompts and stated fetishes, an anonymous operator, and undisclosed pricing is three strikes on the only three questions this page asks.

Every app's breach and disclosure record, side by side →

Affiliate link · we are paid if you subscribe

If what you want is an uncensored companion app from an operator you can actually identify, Candy.ai is the one we can price and name: EverAI Limited, Malta, registration C107181. It has no breach on record — which, as we say on its own page, is not the same as being audited. Its refund terms are genuinely bad: 24 hours, void after 20 tokens outside the EU and UK. Read our Candy.ai page before you decide; it is not a recommendation so much as a known quantity.

Go to Candy.ai →

We earn $36 if you subscribe through this link, at no extra cost to you. It did not change the verdict above: the Muah.AI breach record is a matter of public register, and we would have written it identically with no offer on the page at all.

Sources

  1. Have I Been Pwned, Muah.AI breach record — breach date, date added, 1.9M accounts, compromised data classes, sensitive-breach flag and the statement that it is not publicly searchable. Checked 31 August 2026: haveibeenpwned.com/Breach/Muah
  2. 404 Media, "Hacked 'AI Girlfriend' Data Shows Prompts Describing Child Sexual Abuse", 8 October 2024, last updated 12 October 2024 — original reporting, contents of the dataset, operator response. Checked 31 August 2026: 404media.co
  3. Malwarebytes Labs, "AI girlfriend site breached, user fantasies stolen", 9 October 2024, updated 11 October 2024 — the "duct-taped together" characterisation, the vulnerability description, the operator's statement, and the 11 October note on active extortion attempts. Checked 31 August 2026: malwarebytes.com
  4. Muah.AI terms page — checked for a named legal entity, registration number, governing law and refund policy; none published. Checked 31 August 2026: muah.ai/terms-of-service
  5. Muah.AI homepage — "California Based", "BETA-Website", the child-prompt banner, and the absence of any published pricing. Checked 31 August 2026: muah.ai