Is Secrets AI Safe? (2026 Review)
Minor caveats, but generally fine.
The short answer
Secrets AI is mostly safe as of April 2026. No public breach history, payment processing looks standard, and the company hasn’t had any reported incidents in its roughly two years of operation. The specific wrinkle with Secrets versus a text-only companion app: generated video is stored server-side, and video is a more sensitive data category than text or even static images. If Secrets were ever compromised, the exposure would include video prompts and outputs. The basic hygiene advice applies with slightly more weight than usual.
What data does Secrets AI collect?
Signup requires an email. Phone number is optional. During use, Secrets stores your full chat history, character customizations, generated images, generated videos, and payment metadata. Alias emails from SimpleLogin, Apple Hide My Email, or Firefox Relay work in the signup flow. There’s no strict verification loop that blocks them.
The platform also collects standard web telemetry: IP, browser fingerprint, session duration, referrer. This is typical SaaS behavior and not unique to AI companion products.
There’s no identity verification, no KYC, no ID upload. The data they hold on you is essentially: email, payment descriptor, chat content, and whatever media you’ve generated. The media bucket is the thing that distinguishes Secrets from text-only competitors.
Who owns the company?
Secrets AI launched in 2024. The site names the operator as Secret Labs Inc., Dover, Delaware. A Delaware address is common for startups and says little about where the team or servers are, and a US company is not bound by GDPR the way Candy.ai’s operator (EverAI Limited, Cyprus) is. Named leadership and ownership details are still hard to find from the outside.
If you want deletion rights you can enforce, ask support how they handle them before you subscribe.
Has Secrets AI had a breach or incident?
No. As of April 2026, there’s no public breach, no HaveIBeenPwned entry, no credential dump traced to Secrets AI, and no regulatory action. That’s a clean record, though “no public incident” isn’t the same as “definitely never breached.” Not every incident gets disclosed, and early-stage companies sometimes lack the process maturity to detect breaches quickly.
The cautionary tale in this category is Muah.ai, which had a major breach in October 2024. That incident leaked generated image prompts tied to user emails. See our Muah breach writeup for the full details. It’s the reference case for why server-side storage at AI companion platforms is a meaningful risk category.
Payment safety
Secrets uses a mainstream payment processor. Your card details don’t touch Secrets’ own infrastructure directly; the processor handles the PAN, CVV, and 3DS flow. This is standard SaaS payment architecture and is about as safe as online card payments get.
The charge descriptor on your bank statement is discreet but not fully generic. If you share statements with anyone who might Google unfamiliar line items, pay with a virtual card from Revolut or Privacy.com so the descriptor is tied to a throwaway card rather than your main account.
Content on your device vs on their servers
This is where Secrets’ privacy calculus differs meaningfully from text-only AI companion apps.
Everything is server-side. Chats, custom characters, generated images, and, critically, generated videos. The Secrets homepage now claims end-to-end encryption. That is the vendor’s own claim: there is no published audit, and I can’t check it from outside. Until someone does, plan as if the server can read your content. Video is a more sensitive category than text for a few reasons: the data itself is larger, the content is more identifiable if leaked, and the association between a specific prompt and a specific output is harder to obfuscate after the fact.
Candy.ai stores generated images server-side, which is already a step beyond text-only storage. Secrets stores generated video on top of that. If you’re thinking about your threat model, imagine a breach dump that includes video files linked to email addresses. That’s the exposure profile here.
You can delete content from the UI. Whether that’s a hard delete or a soft delete isn’t publicly documented, and whether the files are purged from backups and CDN caches immediately is also not specified. Assume “eventually” rather than “instantly.”
Can anyone see what you’ve done?
Your account is password-protected. There are no public profiles, no social feed, no friends list. Secrets is a private 1-to-1 experience by design, same as the rest of the category. Nobody stumbles onto your content.
The real risk is a future breach. If Secrets were ever compromised, the leak would likely tie your email address to your chat prompts, your generated images, and your generated videos. That’s a bigger footprint than a text-only app. This is why the alias-email and virtual-card advice matters more here than it does for a chat-only product.
How to minimize your exposure
- Use a dedicated email alias (SimpleLogin, Apple Hide My Email, Firefox Relay). Signing up with your main Gmail is a bad idea
- Pay with a virtual card (Revolut, Privacy.com) so the merchant descriptor is linked to a throwaway
- Use a strong unique password: credential stuffing is the most likely downstream attack if the platform ever leaks
- Never upload photos of yourself or anyone you know, even to test features
- Think carefully before uploading reference images for video generation. Video generation often uses reference inputs, and once a reference image is in their pipeline, it’s one more piece of your data sitting on their servers. If the reference identifies a real person, the exposure stakes are meaningfully higher.
Is Secrets AI safer than similar apps?
Secrets is roughly comparable to Candy.ai and other reputable 2023-2024 launches on the core safety axes: no breach history, mainstream payment, password-protected accounts, no social surface. Where it’s a shade more sensitive is the video storage: that’s a novel data category in this space, and the calculus is slightly different from text-and-image apps.
All of them are notably safer than Muah.ai, which has a breach on its record. If you’re choosing between Secrets, Candy, and a known-breached product, the first two are the obvious picks.
Our verdict
Secrets AI is mostly safe. Clean breach record, standard payment stack, no identity verification requirements, and a product that behaves like a legitimate commercial operation. The caveat is the server-side video storage. It’s a more sensitive data category than text or images alone, and the basic hygiene advice (alias email, virtual card, careful choices about reference photos) applies with more weight here.
If you’re comfortable with server-side storage of media you generate, Secrets is a reasonable pick. If you’re not, no commercial AI companion product will meet that bar, and a locally-hosted open-source model is your only real option.
Affiliate link. We may earn a commission if you subscribe. How we make money.