Skip to content

Privacy and Consent

Privacy and Consent When Evaluating an AI Companion

By KindredMind Editorial Team

Published and updated September 14, 2026

When a family considers introducing an AI companion to a person with dementia, the conversation often focuses on features and feasibility. Equally critical—but frequently overlooked—are the practical and ethical questions of privacy, consent, and autonomy.

Dementia care technology is rapidly evolving, bringing new possibilities for connection alongside complex questions about data and decision-making. If you are exploring this technology, it is essential to understand how a product handles personal information and respects the rights of the person using it. You can learn more broadly about how to evaluate dementia care technology.

Understanding Consent and Capacity

A fundamental ethical standard must guide any discussion of technology and dementia: a diagnosis does not automatically establish incapacity. The ability to make decisions is specific to the person, the particular decision being made, and the moment in time. Many people living with dementia retain the capacity to understand and agree to how they spend their time and who they interact with.

When evaluating an AI companion, families must clearly distinguish between different types of agreement:

  • Account authorization: When a person is able to do so, they may authorize their own use. When someone is acting on their behalf, that person needs appropriate authority under applicable law and the service's terms. A family relationship or caregiving role does not automatically grant the legal authority to bind someone to terms of service or consent to data collection on their behalf.
  • Voice-owner consent: If the AI uses a familiar or cloned voice, the person whose voice is being replicated should provide appropriately documented consent. Read more about AI voice clones and dementia.
  • Willingness and assent: Regardless of who authorizes the account, the person interacting with the AI must be willing to do so. Their ongoing assent should be respected, and use should stop if they become distressed or express a desire not to participate.
  • Substitute decision-making: Where applicable, if a person no longer has the capacity to consent to data collection or terms of service, an appropriately authorized decision-maker must act according to applicable law and the person's known wishes and preferences.

Transparency and Deception

The question of whether to disclose that a companion is artificial is deeply nuanced. Transparency is contextual, depending on the person's ability to understand the technology and the potential for distress. However, deliberate deception is not—and should not be—a universal product policy. For a deeper discussion of ethics, read is AI ethical in dementia care?

Companies should not claim that emotional wellbeing broadly overrides the necessity for transparency. When introducing technology, families should seek approaches that prioritize respect and honesty, adapting to the person's reality without relying on systemic deception. Practical advice can be found in our guide on introducing technology to an older parent.

Practical Privacy Questions to Ask

Before creating an account, families should seek clear, plain-language answers to practical privacy questions. Do not assume that standard consumer privacy policies are sufficient for the sensitive context of dementia care.

What data is collected and why?

Understand exactly what information the AI companion records. Does it transcribe conversations, record audio, or collect behavioral data? You should verify whether the service limits data collection to what is needed to provide the service, and ask whether the data is used to profile the individual for unrelated commercial purposes.

Who has access to the data?

Determine who can view or listen to the interactions. Can family members monitor the conversations? Can company personnel access transcripts? Verify that any access is limited by role, appropriately authorized, and transparent to the user to the greatest extent possible.

Retention and deletion

Verify how long conversational data is kept. You should ask about the process for deleting data and closing the account, recognizing that complete deletion from active systems and secure backups may follow a defined timeline or be subject to specific legal retention requirements.

Vendors and subprocessors

Many AI services rely on third-party vendors (subprocessors) to power their technology, such as cloud hosting or transcription services. You should review their vendor terms to confirm whether these third parties are restricted from using sensitive personal data to train their own AI models.

Account control and stopping use

Determine who controls the account settings and how access or authority is reviewed over time. Administrative control by a family member should not imply that they can supersede the interacting person's autonomy. Understand the incident reporting routes, help channels, and the practical process for stopping use if the person with dementia no longer wishes to interact or if it is no longer appropriate for their care. You can review KindredMind's specific commitments in how we protect them.

Frequently Asked Questions

Does a dementia diagnosis mean a person cannot consent?

No. A dementia diagnosis does not automatically establish legal incapacity. Decision-making ability is specific to the person, the decision, and the time.

Who can authorize an AI companion account?

When able, a person may authorize their own use. Someone acting on their behalf needs appropriate authority under applicable law. A family relationship or caregiving role does not automatically grant the legal authority to bind someone to terms of service or consent to data collection on their behalf.

Is deliberate deception a standard practice for AI companions?

Transparency depends on context and the individual's understanding, but deliberate deception should not be a universal product policy. Emotional wellbeing claims do not broadly override the need for transparency.

What should families ask about data privacy?

Families should ask what data is collected, why it is needed, who has access, how long it is retained, whether vendors or subprocessors are used, and how to delete the account and associated data.