Picture the contents of an account six months in: chats franker than anything in your inbox, generated images, a saved card, and the email address that ties everything back to your everyday life.
Now consider the operator: usually a small outfit with a few engineers, answerable to nobody outside. Sensitive data guarded by ordinary defences is the whole problem in one sentence.
Gaps you should expect
These are not present everywhere, but they are common enough to assume until you have confirmed otherwise:
- No second login factor. Whoever controls your inbox, or guesses your password, is in.
- No device list. There is no screen showing where you are logged in, and no way to end a login that looks unfamiliar.
- No sign-in notifications. A login from a new phone raises no alert.
- Weak recovery, a weakness in both directions: you struggle to get back in, while an impostor can talk a support agent into it.
- Sessions that never expire, so an old tablet may still be signed in half a year later.
Finding 2FA and a device list in an app is a good sign. It usually means the people behind it considered the rest as well.
Four steps worth your time
1. One password, used nowhere else
It sounds basic, and it decides most outcomes. The likely attack is rarely aimed at the app itself. It is credential stuffing: passwords spilled in some unrelated breach get tried on every service.
A password manager removes the effort. Any password you reuse is one other company's breach away from being public.
2. An email address just for this
A separate address does double duty. Strangers cannot connect the account to who you are elsewhere, and a compromise of one mailbox stays out of the other.
Use a genuine inbox you expect to keep, not a disposable one; a reset link may need to reach you a year from now. A forwarding alias or an extra mailbox at your current provider will do.
Have receipts land in that same inbox too, following the advice in payment privacy.
3. Switch on 2FA when you can
An authenticator app beats SMS codes. If the companion app lacks 2FA, put it on the email account instead: resets travel by email, so securing the mailbox covers every service that can send you a link.
With an app that offers no protection of its own, this is your strongest remaining option.
4. Sign out of anything you have finished with
Do this first on shared or borrowed devices. Where no session list exists, a new password is a crude but usually effective way to end every other login.
A danger no setting can fix
It is worth stating directly, since it does the most real damage in this category: someone else using your unlocked phone or laptop.
Password rules do nothing against it. What helps is work on the device itself, such as a dedicated browser profile, hidden notification previews and downloads kept outside synced folders. The details are in using an AI companion on a shared device.
When an app gets breached
Breaches happen, and the response barely changes:
- Change the password right away, along with every other place you used it.
- Keep an eye on the mailbox for reset emails you did not ask for.
- Review the card and think about replacing it.
- Decide if you want to stay. A company that publishes a clear notice and a real timeline is sending a different message than one whose breach journalists report months later.
Read what the operator actually says. If it will not state whether conversations were affected, that silence tells you something. In Canada, organizations covered by PIPEDA must report breaches that pose a real risk of significant harm to the Office of the Privacy Commissioner and notify the people affected, though a small overseas app may not follow that rule.
A quick test before subscribing
Spend two minutes in the settings and you will learn more about how an operator works than its sales page will say:
- Is 2FA offered?
- Can you view your logged-in devices?
- Is deletion a button, or a request to a support inbox?
The stakes rise with apps built to keep years of history, for example Nomi and Replika, simply because they end up storing the most about you. Here is what such an app knows, and this is how to remove it.

