The AI girlfriend who texts you first
AI Companion

Local vs Cloud Companion AI

Local AI companion privacy comes down to custody. A model running on hardware you own never sends the conversation anywhere, so no server holds it, no policy governs it, and no breach can expose it. A hosted service gives you a considerably better conversation and keeps your messages on its own machines. Capability against custody, and the trade is real in both directions.

Key Takeaways:

  • Running a model yourself changes exactly one thing for certain: the text never crosses the network. Everything else follows from that
  • Capability tracks model size, and the largest models need more memory than ordinary personal machines have, which is the gap you are paying for when you use a hosted service
  • Local describes where the model runs, not whether the app is silent. An app can run a model on your machine and still send crash reports, telemetry or a synced backup
  • A file on your own disk is unencrypted by default and readable by anyone who has your computer, so local custody is only as strong as the device
  • Mozilla’s 2024 review of romantic chatbot apps found the category performing poorly against basic privacy criteria (Mozilla Foundation, 2024)

Local AI Companion Privacy: What Actually Changes

One thing changes with certainty, and the rest is downstream of it. With the model on your machine, your message goes from the keyboard to a process a few inches away and comes back, and no copy is created anywhere you cannot reach. There is no retention window, no account, no deletion request to file, no employee access question, and nothing to hand over when a company is asked for records.

That is a genuinely large change, and it is smaller than people assume, because it is a statement about the model rather than about the software wrapped around it. A companion app running a local model can still report crashes, count sessions, sync a backup to a drive service, or check for updates with your username attached. Local is a fact about inference. Silence is a separate fact, and it needs checking.

Checking takes 5 minutes. Put the machine on airplane mode or pull the cable, then hold a full conversation. If it works, the model is genuinely running where you think it is. Then reconnect and watch whether the app immediately sends anything it had been queuing while it waited, which is the moment a quiet local setup and a chatty one look completely different.

What the Hosted Side Actually Buys

Quality, and pretending otherwise is how privacy advice loses the argument. Capability in these models scales with size, size is bounded by memory, and the biggest models are run on server hardware nobody buys for a desk. What that difference feels like in a conversation is a companion that holds a thread across a long exchange, catches a joke, and does not lose the plot when the topic turns.

Then there is everything built around the model. Voice, images, memory extraction that actually works, sync so the same conversation is on your phone at lunch and your laptop at night, and a team fixing it while you do something else. A local setup gives you a model. A companion is a model plus roughly a dozen features somebody else has already written.

Cost has a shape rather than a number. Hosted is a small amount forever, the subscription framing that the ai girlfriend memes never tire of; local is hardware you may already own, electricity, and your own evenings. The evenings are the part people underestimate.

Which is why the recommendation you will read on privacy forums fails so often in practice. It optimizes the wrong variable.

The Trade, Line by Line

What you are comparing Model on your own machine Hosted service
Where the conversation lives Your disk only Company servers, for a period set by their policy
Who can change the rules You The provider, at any time, usually by email notice
Capability ceiling Bounded by your machine’s memory Bounded by what the company will pay to run
Setup and upkeep An evening to start, occasional maintenance after None
Moving between devices You build it or you do without Built in
What a breach exposes Nothing of yours, unless the machine itself is taken Whatever the retention policy still holds
If the product shuts down Nothing happens. It keeps running The character and the history go with it
Continuity of the character Total. Nothing changes underneath you The model can be swapped and the character shifts

Two rows carry more weight than the rest. Shutdown risk is invisible until it fires, and companion apps close, get acquired, or reprice with 30 days of notice like any other consumer software. Continuity is the quieter one: on your own machine, the model you set up in March is the identical model in November, which is the single benefit of local nobody mentions and the one long-term users care about most.

Where the Privacy Argument Gets Overstated

The strongest objection to going local is not technical. A privacy setup you abandon after 9 days protects nothing, because the conversations that matter are the ones you actually have over a year, and they will be happening in the convenient app. Infrastructure you do not use is a preference, not a protection.

Two more corrections, since the local case gets oversold in the same three forum threads every time. Your conversation file sits on your disk in the clear unless you did something about it, so anyone with the machine, including whoever repairs it, can read the lot. And the security of the whole arrangement is now yours: unpatched system, shared login, no backup encryption, and the private setup is worse than a hosted one with a decent security team behind it.

On the hosted side, the case against is stronger than most people bother to check. Mozilla’s 2024 review of romantic chatbot apps found the category doing badly against basic privacy questions, with vague answers about what gets collected and where it goes (Mozilla Foundation, 2024). Vague is the operative word. Not proof of anything specific, and a poor foundation for the most personal text you will type this year.

So the honest summary is unglamorous. For most people the meaningful privacy control is not where the model runs, it is what goes into the box, and that control is available today at zero setup cost.

Choosing Without Kidding Yourself

Pick the local route if 3 things are true: the machine is already sitting there, you are willing to spend an evening on setup and an hour every month or two after, and you would rather have a plainer conversation you own outright than a better one you rent. Those conditions are not rare. They are also not most people, and they rule out setting the thing up for someone else, like an older relative who wants the companion but not the maintenance. The honest answer for most people is a hosted service used with some discipline.

The discipline is specific. Before you type anything you would mind seeing outside that window, find the retention and deletion section of the app’s policy, and answer one question: how long is the conversation kept after the account is deleted. Not whether they sell data, which every policy denies in the same sentence. How long they keep it, which is where the answers actually differ.

The per-message version takes 2 seconds and works better than any setting. Ask whether this particular thing would be survivable in a leak, and if it would not, that is the message to leave out. Nobody needs the full name of the person you are describing.

One boundary applies whichever side you land on. A conversation with a companion has no legal privilege of any kind, unlike one with a clinician or a lawyer, and running the model on your own hardware does not create protection that was never available. The custody question is about copies, not about status.

FAQ

Is a local AI companion actually private? The conversation is, as long as the model is genuinely running on your machine and the app is not sending anything else home. Test it with the network disconnected: if the chat still works, inference is local. The file it writes is a different question, since it usually sits unencrypted on your disk and is readable by anyone with access to the computer.

Can my computer run a companion model? Probably a smaller one, and the practical constraint is memory rather than processor speed. Quality tracks model size closely enough that the honest expectation is a noticeably plainer conversation than a hosted service gives you. Check the stated requirements published for the specific model rather than the claims on an app’s download page.

Does an offline AI companion mean the same thing as a local one? No, and the two get mixed up constantly. Local describes where the model runs, offline describes whether the app needs a network at all, and an app can be local and still contact a server for updates, licensing or analytics. The airplane-mode test is what separates the claim from the behavior.

Do I lose memory and persona by running a companion myself? Not necessarily, but you assemble them. Memory and persona are features of the software around the model rather than properties of the model, so a hosted product hands you a working memory system and a local setup makes it your problem to configure. This is the part that surprises people who expected the model alone to behave like the app they left.

The framing that gets people stuck treats this as a moral question, where one option is responsible and the other is careless. It is a custody question with a price attached, and the price is paid in conversation quality and evenings. What tips it for me is the row nobody talks about: on your own machine nothing changes underneath you, so the character you built in spring is still the same character in autumn, while a hosted one can shift the week a company swaps its model. Privacy is the reason people start looking at local. Continuity is the reason a few of them stay.

A hosted service such as Lona is the cloud half of this trade, a stronger conversation in return for messages that live on a server. That is why the control that matters is the per-message one: leave out anything you would not want surviving a leak.

Sources

  • Mozilla Foundation, *Privacy Not Included, review of romantic AI chatbots, 2024
LonaMeet LonaThe AI girlfriend who texts you first.Start talking →