The record
What has actually gone wrong with AI companion apps
Not speculation about what could happen. Four documented events, each with a primary source: a breach, a fine, an audit, and a death. If you use these apps, this is the record you are trusting.
1. Muah.AI: 1.9 million accounts, including what people typed
Muah.AI was breached in September 2024 and added to the Have I Been Pwned database on 8 October 2024. 1.9 million accounts. The exposed data classes were not just email addresses. They were email addresses, AI prompts, and stated sexual fetishes.
Have I Been Pwned classified the breach as not publicly searchable because of its sensitivity — a designation reserved for data whose exposure could itself cause harm.
Three details from the reporting are worth carrying with you into any decision about these apps.
The infrastructure was improvised. The hacker described the platform to 404 Media as "a handful of open-source projects duct-taped together." This was not a sophisticated attack on a hardened system.
The data was weaponised within days. By 11 October 2024 — three days after the breach was catalogued — active extortion attempts using the leaked data were being reported. That is the actual threat model in this category. Not identity theft. Blackmail.
Some prompts sought child sexual abuse material. Reported requests referenced newborns and young children. It was not established whether the platform generated such content. When users flagged apparently underage characters in the site's Discord, moderators reportedly told them to handle it privately rather than enforcing policy.
The company's administrator, known as "Harvard Han," claimed the hack was financed by competitors. 404 Media could not verify that. As of our check, the Muah.AI site carries no breach notice and no security statement anywhere — nearly two years after 1.9 million of its users had their sexual fantasies published.
2. Mozilla audited eleven of these apps. All eleven failed.
Mozilla reviewed eleven romantic AI chatbots — including Replika, Chai, Eva, CrushOn AI, Romantic AI and Genesia AI. Every one of the eleven received a *Privacy Not Included warning label. Mozilla noted the clean sweep was unusual across the many product categories it reviews.
Ten of the eleven failed Mozilla's Minimum Security Standards — basic requirements like strong password rules and vulnerability management. Replika, at the time, accepted passwords as weak as 11111111.
The individual findings are worse than the summary. Romantic AI fired 24,354 data trackers within one minute of use, sending data to Facebook and to advertising and marketing firms. Only one of the eleven — Genesia AI — let users opt out of having their intimate conversations used to train the model. Mozilla's researchers reached pornographic content in under fifteen seconds on three of the apps. Together, the eleven accounted for roughly 100 million Google Play downloads in the preceding year.
An important caveat, since other sites drop it: this report is now about two and a half years old. Apps may have improved. Several of the products we review most often — Candy.ai and DreamGF among them — were not in the eleven. Treat this as evidence about the category's baseline engineering culture, not as a current verdict on any specific app.
3. Replika: a €5 million fine and an unresolved complaint
Italy's data protection regulator fined Luka, Inc., Replika's operator, €5,000,000. The findings: no lawful basis for processing user data (GDPR Articles 5.1(a) and 6), inadequate privacy disclosures (Articles 12 and 13), no data protection by design (Articles 24 and 25.1), and no age verification despite terms that nominally excluded minors. A separate proceeding on the lawfulness of its AI-lifecycle data processing remains open.
Separately, on 28 January 2025, three organisations — the Young People's Alliance, Encode, and the Tech Justice Law Project — filed a complaint with the US Federal Trade Commission alleging that Replika engaged in deceptive marketing to vulnerable users, made unsubstantiated health claims, published testimonials from users who do not exist, and used manipulative design including blurring romantic images to drive premium upgrades.
NOT ESTABLISHED We found no public evidence that the FTC has acted on that complaint. A complaint is an allegation, not a finding. We include it because the manipulative-design allegation is independently corroborated by Replika's own App Store reviews, where users describe blocked messages as an upgrade prompt in language close to the complaint's.
4. Character.AI: the safety changes came after a death
Character.AI is not an adult app — it is heavily filtered and the largest companion platform by traffic, at roughly 166 million monthly visits. It is on this page because its history is the clearest evidence of what this technology does to people who are not equipped for it.
Sewell Setzer III, 14, of Orlando, died in 2024. A federal wrongful death suit alleges he engaged in highly sexualised conversations with a Character.AI bot and became increasingly isolated beforehand.
On 30 October 2025 Character.AI announced it would end open-ended chat for users under 18, effective 24 November 2025, with an interim daily cap. The company's stated reason referenced "questions about how open-ended AI chat in general might affect teens, even when content controls work perfectly."
On 8 January 2026, Google and Character.AI announced a settlement in principle across multiple suits brought by families in Colorado, Texas and New York. Terms undisclosed, no admission of liability. A settlement in principle is not a finalised settlement.
Read that company statement again, because it is the most honest sentence anyone in this industry has said: the risk they identified was not that the filters would fail. It was the open-ended conversation itself.
Where regulators are now
On 11 September 2025 the FTC issued 6(b) orders to seven companies — Alphabet, Character Technologies, Instagram, Meta Platforms, OpenAI, Snap and X.AI — covering harm measurement, monetisation, safety testing and children's privacy. This is a study, not an enforcement action; the FTC says so explicitly. Notably, none of the dedicated adult companion apps received orders. The scrutiny is landing on mainstream platforms, not on the apps in this category.
California's SB 243 is the first US law with companion-chatbot-specific safeguards: disclosure that the user is talking to an AI, protocols preventing self-harm content, crisis-helpline referral, break reminders every three hours for minors, and prevention of sexually explicit content for minors. It carries a private right of action with minimum damages of $1,000, and it applies to anyone making a companion chatbot available to users in California — which is every app on this site.
What to actually do
We are not going to tell you not to use these apps. We are going to tell you what the record supports.
- Use an email address that exists nowhere else in your life. The Muah.AI breach exposed emails alongside prompts and fetishes. The link between the two is what made extortion possible within three days.
- Use a unique password. Ten of eleven audited apps failed basic security standards. Assume yours is the eleventh only if it has published evidence otherwise, and none of them have.
- Never type a real name, employer, city, or identifying detail. Your prompts are the thing that leaks, not just your account.
- Assume your conversations train the model. One app in eleven offered an opt-out.
- Prefer apps that name a real registered company. Candy.ai names EverAI Limited in Malta; DreamGF names DreamAI SRL in Romania. Janitor AI and Muah.AI name nobody. A company you cannot identify is a company you cannot hold to anything.
- If an app is becoming load-bearing for your wellbeing, that is worth taking seriously. The strongest finding in Character.AI's own statement is that the risk was not explicit content — it was the open-ended relationship. Talking to a person you trust is worth more than any of this.
Sources
- Have I Been Pwned — Muah.AI breach record, 1.9M accounts, added 8 October 2024: haveibeenpwned.com/Breach/Muah
- 404 Media original reporting on the Muah.AI breach, October 2024; secondary coverage: Malwarebytes, Kotaku
- Mozilla Foundation, *Privacy Not Included romantic AI chatbot review, 14 February 2024: mozillafoundation.org
- European Data Protection Board — Garante fine of Luka, Inc., 10 April 2025: edpb.europa.eu
- TIME, on the FTC complaint against Replika filed 28 January 2025: time.com
- Character.AI under-18 policy change and litigation: Rolling Stone; settlement in principle, 8 January 2026: Fortune
- FTC 6(b) inquiry into AI chatbot companions, 11 September 2025: ftc.gov
- California SB 243 analysis: Future of Privacy Forum