RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 160 retrospective records ↗
Love With Machines

The archive / Privacy & data

Privacy & data / Companion note · Entry note · prepared 16 September 2026

Replika names three legal bases for processing EU users' data

Replika's privacy policy assigns contract, legitimate interest or consent as the legal basis for different data uses and names its GDPR representatives.

replika.comprimary record

Replika Privacy Policy

Document
undated document
Event
no single event
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The design

Replika's Privacy Policy, retrieved 16 September 2026 and stated on its face to have been last updated 27 May 2026, includes a section on how the company processes personal data that assigns a named legal basis under EU law to each category of processing. Core account and conversational functions are described as 'necessary to perform our contractual obligations with you.' Fraud prevention, security monitoring and corporate operations are instead grounded in 'legitimate interests, adequately balanced with your rights and interests.' Processing sensitive personal information a user volunteers in conversation is treated as consent-based: continuing to provide such information after a notice is described as constituting the user's 'explicit consent.'

What the evidence says

This legal-basis structure is Replika's own characterization of its processing, not a regulator's finding; no EU data protection authority's assessment of these specific claims is referenced in the document. The same policy states that Luka, Inc. has appointed the European Data Protection Office as its Article 27 GDPR representative in the EU, and heyData GmbH as its Article 37 Data Protection Officer, giving named contact points rather than only a general email address. A companion help-center article, 'GDPR Compliance and Right to Erasure', states that Replika 'fully complies' with GDPR and commits to confirming an erasure request 'within one month,' a specific figure the general privacy policy does not itself state.

What it asks of people

An EU user who wants to rely on this section is asked to identify which of several bases applies to the data they are concerned about, since the policy assigns different bases, and therefore different rights, to different purposes; a right to object applies most cleanly to legitimate-interest processing and less directly to contract-based processing. The erasure procedure asks the user to submit a request through a support form, verify their identity with a screenshot or receipt, and wait up to a month for confirmation.

Privacy and safeguards

The Cookie Policy states that legal bases for cookie- and tracking-technology processing are addressed there rather than in the main policy, splitting the GDPR disclosure across two documents. The privacy policy also describes cross-border transfer safeguards, stating that transfers out of the European Economic Area rely on the European Commission's Standard Contractual Clauses and unspecified 'supplementary measures' referencing the Schrems II ruling, without itemizing what those measures are.

  • Which legal basis would govern a specific disputed use, and does the policy make that assignment clear enough to contest?
  • Has any EU regulator reviewed these specific legal-basis claims, as opposed to Replika's practices generally?
  • What would the unspecified supplementary measures for international transfers need to include to satisfy Schrems II?

The document gives EU users named contacts and stated timelines that a purely US-facing privacy policy would not need to include, but the legal-basis claims remain the company's own legal characterization until a regulator or court examines them directly.

Sources & reading trail

Replika Privacy Policy ↗

Assigns contract performance, legitimate interest, or consent as the legal basis for different categories of processing, and names EDPO as EU representative and heyData GmbH as Data Protection Officer under GDPR Articles 27 and 37.

Source published: Not established · Retrieved: 16 September 2026

GDPR Compliance & Right to Erasure ↗

States Replika fully complies with GDPR and commits to confirming an erasure request within one month, via a specific support-form procedure.

Source published: Not established · Retrieved: 16 September 2026

Replika Cookie Policy ↗

States legal bases for cookie-related processing separately from the main privacy policy's legal-basis table.

Source published: Not established · Retrieved: 16 September 2026

Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.