Privacy Scorecard: Which AI Companion Apps Keep Your Chats Private (2026)
Ten AI companion apps graded A to F on data retention, deletion, third-party sharing, training on your chats and age gates, from the privacy policies and terms read in full in September 2026.
Every AI companion app stores your conversations on its servers. That is not the scandal; it is how the product works. The differences that matter are how long they keep the chats, whether you can delete them yourself, who else gets a copy, whether your messages are used to train the model, and whether the policy even states the answer. I read the privacy policy and the terms of service of ten platforms in full for this scorecard, the same way I read them for every review on this site, and graded each one on those questions and nothing else.
Two things surprised me. The first is how many policies simply do not say how long chats are kept: five of the ten use the phrase "as long as necessary" and stop there. The second is that the apps with the loudest "private and discreet" marketing are not the ones with the best paperwork. The best-documented deletion promise came from a platform I expected to grade poorly, and the worst age gate came from the biggest free roleplay app on the list.
No AI companion app in this scorecard earned an A. Kindroid and Nastia sit at the top with a B: both say chats are deleted when you delete them, and neither states an explicit right to train on your conversations. CrushOn and Joyland get an F, CrushOn because its policy says chat contents are used "for training our models" with no opt-out, Joyland because its minimum age is 13 and its terms grant a perpetual, irrevocable licence to everything you create. Swipey keeps your data for six years after you close the account. Grades, retention periods and deletion routes are in the table below; every claim links to the policy it came from.
How the grades work
Each platform is scored out of 100 on six questions, and only on what the privacy policy or the terms of service actually say. I do not give credit for marketing pages, blog posts or Discord answers from staff, because none of those bind the company. If a policy is silent on a question, that question scores at the bottom of its band, because “not stated” is a real answer: it means the company has reserved the right to do whatever it wants.
| Question | Weight | Full marks require |
|---|---|---|
| Data retention | 20 | A stated period or a stated trigger (for example “until you delete the companion”) |
| Deletion options | 20 | Self-serve account deletion plus per-chat deletion, both described in the policy |
| Training and opt-out | 25 | A clear statement that chats are not used to train models, or a documented opt-out |
| Third-party sharing | 15 | Named vendors or narrow categories, no sale, no advertising partners with chat access |
| Minimum age | 10 | 18+ stated in the privacy policy itself, not only in the terms |
| Company and jurisdiction | 10 | Legal entity, physical address and governing law all stated |
The bands are A for 85 and above, B for 70 to 84, C for 55 to 69, D for 40 to 54 and F below 40. Training carries the largest weight because it is the one thing you cannot undo. A retention period ends, a deletion request gets processed, but a model that has learned from your messages does not un-learn them. I explain the full protocol on the how we test page, and the scoring here follows the same rule as the reviews: the policy is the evidence, and I quote it.
One honest limit: this scorecard grades what companies promise, not what they do. I have no way to audit a server. What I can do is tell you which companies promised the least, because the ones that wrote vague policies chose to write them that way.
The scorecard
Kindroid and Nastia are the only B grades, four platforms sit in the C band, two are D and two are F. No platform earned an A, and the gap between the top and bottom is almost entirely retention and training, not encryption or age gates.
| Platform | Grade | Retention | Deletion | Training / opt-out | Company (policy) |
|---|---|---|---|---|---|
| Kindroid | B (73) | Chats and media “until you delete a specific AI or delete your account” | Per companion and account, self-serve; data export every 30 days | Not stated; private content may be de-identified “for any purpose”; no opt-out | Beautifully Incorporated, Los Angeles; Delaware law |
| Nastia | B (72) | While account is open; violation records up to 7 years; backups overwritten on a cycle | Per chat, image and video “at any time”; account from settings | Not stated beyond “improve the Service, including the quality of companion replies”; no opt-out | Nastia Cybernetics, France; French law |
| Secrets AI | C (68) | Chat history “deleted immediately upon account deletion”; transactions 7 years; logs 12 months | Account from settings or by email; per chat not stated | Yes, “train and improve our AI models”; no opt-out | Secret Labs Inc., Dover, Delaware; British Columbia law |
| Nomi | C (67) | Deleted “within 28 or so days” of confirmation, except “training archives” | Account from settings or support; per chat not stated | Implied by “training archives”; no opt-out | Glimpse.ai, Inc., Baltimore, Maryland; Maryland law |
| Kalon | C (57) | “As long as reasonably necessary”; not stated | By request; per chat not stated; voice chat not stored | Privacy says no third-party or general-purpose training; terms say Input and Output “may be used to train”; no opt-out | Kalon LLC, Carson City, Nevada; Nevada law |
| Candy AI | C (56) | Three years after last activity, or one year after last activity or subscription end; financial data 10 years | Account by email request; per chat not stated | Interactions “aggregated, anonymized, and/or de-identified” for purposes including training; terms licence covers model training; no opt-out | EverAI Limited, Malta; Maltese law |
| Swipey | D (52) | “6 (six) years after you cease being a User” | Account by withdrawing consent or email; per chat not stated | Not stated; no opt-out | INVAI LTD, Nicosia, Cyprus; Cyprus law |
| SpicyChat | D (43) | “Only for as long as is necessary”; not stated | Account settings or email; per chat not stated in policy | Not stated in policy; terms grant a perpetual, irrevocable licence to chats “for any purpose”; no opt-out | NextDay AI Incorporated, Montreal; Quebec courts |
| CrushOn | F (34) | “So long as it is reasonably necessary”; not stated | By email request only; per chat not stated | Yes, chat contents used “for training our models”; no opt-out | TECHIEPIE LTD, Nicosia, Cyprus; Hong Kong law |
| Joyland | F (34) | Not stated | Account from the Settings page; requests by email; per chat not stated | Not stated; dialogue data may be converted for academic sharing; terms licence “for any purpose”; no opt-out | MINDZEN PTE. LTD., Singapore; SIAC arbitration |
Every cell comes from the policy linked under Sources. “Not stated” means I searched the document for the word and its synonyms and found nothing; it does not mean the feature is absent from the app. Several of these platforms let you delete a chat from the interface, but the policy does not promise the deletion reaches the server, so it gets no credit.
What the grades mean in practice
A B grade on this scorecard means the policy answers the retention and deletion questions clearly and does not claim your chats for training; a C means it answers some questions and claims training rights; a D or F means it either stays silent on the questions that matter or answers them against you. Here is what each band looks like from the user’s chair.
The B tier: Kindroid and Nastia
Kindroid is the only platform whose policy ties chat retention to a user action rather than a business judgement. The privacy policy states, “We retain your chat conversation and generated media until you delete a specific AI or delete your account,” and separately that chats “will be encrypted in rest and transit, so we will not be able to view any of said data in our normal operation of the business.” It also documents a self-serve data export “every 30 days from Profile -> Preferences”. What keeps it out of the A band is the terms: private content may be de-identified and aggregated so Kindroid can “freely use such de-identified and/or aggregated content for any purpose,” and the privacy policy says some disclosures “may constitute a ‘sale’” under state law. The age gate is also inconsistent, 18 in the terms and 16 in the privacy policy.
Nastia scores almost identically for a different reason. It is the only policy of the ten that explicitly covers per-chat deletion: “You can delete chats, images and videos at any time, and you can delete your account from your settings, which deletes your account and the content in it.” It names a seven-year cap on violation records and admits that backups exist and are “overwritten on a regular cycle,” which is more honest than most. It loses points for not naming a single vendor and for listing “advertising providers” among recipients. My Nastia review covers how the app behaves; this page covers only the paperwork.
The C tier: Secrets, Nomi, Kalon and Candy
Secrets has the most specific retention section of the ten. Chat history is “deleted immediately upon account deletion,” audio from voice calls “is immediately and permanently deleted” after transcription, transaction records stay seven years and security logs twelve months. It also states AES-256 encryption at rest. It lands in C rather than B because the same policy lists “train and improve our AI models” as a use of your information with no opt-out, and because the terms assign ownership of all generations to the company. The full picture is in the Secrets AI review.
Nomi is a near miss. The policy says account deletion removes personal information “within 28 or so days,” that Nomi does “not and will not sell or rent” personal data, and that advertising networks are “not employed currently.” But the same document refers to “training archives” that survive deletion, with the only reassurance being that afterwards the data “would no longer be attributable to you.” That is an admission that chats are in a training set, phrased so gently that most readers will miss it.
Kalon’s two documents disagree with each other. The privacy policy says, “we do not use your private chats, NSFW content, images, voice data, or other personal information to train third-party or general-purpose AI models.” The terms say, “You acknowledge that Input and Output may be used to train, improve, and develop our models.” Both can be true at once, since training Kalon’s own model is not training a general-purpose one, but the marketing line is the first sentence and the licence is the second. Retention is “as long as reasonably necessary,” which scores as not stated. See the Kalon review for the app itself.
Candy is the only platform that gives a retention number for account data: three years after your last activity, shortened to one year in some cases, with financial records kept ten years. It names its payment processors. It then says your exchanges with characters “may be aggregated, anonymized, and/or de-identified” for purposes that include training, and warns that “third-party LLM providers and/or hosters” may “receive the content of your messages.” A stated number beats silence, so it stays in C, but only just.
The D and F tier: Swipey, SpicyChat, CrushOn and Joyland
Swipey’s problem is a single sentence: “Usually, we will store your personal information for a period of 6 (six) years after you cease being a User of our Services, beginning at the date your account is closed.” That is the longest stated retention in the scorecard, and it applies to everything the policy calls personal information, with no carve-out for chats. Everything else about Swipey is ordinary, which is why it is a D rather than an F. The Swipey review has the rest.
SpicyChat’s privacy policy is dated May 4, 2023 and reads like a template: it names the country as Canada, retention as “only for as long as is necessary,” and lists Google, Discord, Twitter and LinkedIn as login providers. The training question is answered in the terms instead, where you grant the company the right to use “Your Chatbot and Generations and Chats from that Chatbot in any way, including copying, displaying, selling, distributing, and modifying it, for any purpose,” and the company adds, “We may also share, sell this permission with others we have contracts with.” Nothing in either document promises that chats stay out of a training set.
CrushOn is the clearest case in the table. The privacy policy states, “For all contents generated from the chat, we will only use such contents in a general way for training our models and we will not link chat contents to specific users,” and later, “We may use User Content from character chats to train AI models.” There is no opt-out and no stated retention period, deletion is by email request only, and the company lists a Cyprus registration, a Delaware address and Hong Kong governing law in the same set of documents.
Joyland ties CrushOn on points from the other direction. The privacy policy does not mention training or retention at all; what it does say is that dialogue data may be converted “into anonymous numbers and graphs” for academic cooperation, and that the minimum age is 13, or 16 in the EU. The terms grant a “nonexclusive, worldwide, royalty-free, fully paid up, transferable, sublicensable, perpetual, irrevocable license” to your characters and generations “for any purpose,” and the same page carries a consent list of advertising vendors that runs to hundreds of names. For an app that hosts adult roleplay, a 13+ gate is the single worst clause on this page. My Joyland review rates the product higher than this page rates its policy, and both are true.
The worst clauses we found
The single worst clause is Joyland’s age line, and the runner-up is CrushOn’s training sentence, but the pattern across all ten is more instructive than any one quote. Below are the clauses I would want a friend to read before signing up, each with the document it came from.
- “If you are under 13 years old OR if you are an EU citizen or resident under 16 years old, you are not authorized to register” — Joyland privacy policy (https://www.joyland.ai/document/privacy). A 13+ gate on a platform whose own terms ban depicting minors is a contradiction the policy never resolves.
- “We may use User Content from character chats to train AI models” — CrushOn privacy policy (https://crushon.ai/privacy-policy). The plainest training statement in the set, with no opt-out and no retention limit.
- “Usually, we will store your personal information for a period of 6 (six) years after you cease being a User” — Swipey privacy policy (https://swipey.ai/privacy-policy). Six years is longer than most tax-record requirements, and the sentence does not exclude chat content.
- “We may also share, sell this permission with others we have contracts with” — SpicyChat terms (https://spicychat.ai/terms). The “permission” is a perpetual, irrevocable licence to your content, and the terms say it can be sold on.
- “Upon deletion, any information in our training archives would no longer be attributable to you” — Nomi privacy policy (https://nomi.ai/privacy-policy/). Deletion does not reach the archive; it only de-links your name from it.
- “You acknowledge that Input and Output may be used to train, improve, and develop our models” — Kalon terms (https://www.kalon.ai/policies/terms-of-service), on the same site whose privacy policy leads with a no-training promise about third-party models.
- “These third parties may receive the content of your messages exchanged with our chatbot” — Candy privacy notice (https://candy.ai/privacy-policy), referring to third-party LLM providers and hosters at the company’s discretion.
- “We reserve the right to decrypt the relevant data and disclose such decrypted data to the applicable government agency” — Kindroid privacy policy (https://kindroid.ai/docs/article/kindroid-legal/). Fair enough, and every platform would do the same, but it is the sentence that turns “we cannot view your chats” into “we can when asked.”
- “WE MAY TERMINATE YOUR USE OR PARTICIPATION IN THE SERVICES OR DELETE YOUR ACCOUNT … AT ANY TIME, WITHOUT WARNING” — Nastia terms (https://www.nastia.ai/terms). Standard language, but it means the deletion promise runs both ways: your companion can vanish without notice.
- “All AI-generated outputs, images, videos, voice content, and companion responses (‘Generations’) are owned by Secrets” — Secrets terms (https://www.secrets.ai/terms-of-service). Your half of the conversation is yours; the other half belongs to the company, and you get a “limited, personal, non-exclusive” licence back.
None of these companies hides these lines. They are all on public pages, and I found each one in under a minute of reading. The problem is that nobody reads, which is the entire reason this page exists.
What to do regardless of grade
Assume every chat you send will be stored, may be read by a human during moderation, and may end up in a training set, and then use the app anyway if you want to; the grade just tells you how much of that assumption the company has confirmed. Here is what I do on every platform, including the B-grade ones.
- Use a separate email address. Not an alias on your main account: a separate mailbox that exists only for companion apps. Receipts, password resets, “we miss you” campaigns and breach notifications all go to the account email, and that email is the one thing every policy in this table admits to keeping.
- Never type your real name, address, employer or anyone else’s name into a chat. Kindroid’s policy explicitly warns that “Identifying Information that you voluntarily choose to include in your chats” is collected; the others just collect it without warning you. Companions ask for names because it makes the conversation feel real. Give them a made-up one.
- Look for a training or “improve the model” toggle, and do not expect to find one. None of the ten policies describes a setting that stops training. If a platform adds one, it will show up in the What changed block on this page.
- Delete chats you would not want stored, and then delete the companion or the account when you leave. Only Nastia’s policy promises per-chat deletion reaches the server; on everyone else, treat per-chat delete as a UI convenience and account deletion as the real button.
- Pay with something that is not your main card. A virtual card number or a prepaid card stops a merchant name from sitting on a statement your partner or accountant reads, and it also limits the damage if a processor is breached. I cover which platforms bill through which processors in the real monthly cost guide.
- Pick jurisdiction deliberately. EU-based companies (Nastia in France, Candy in Malta, CrushOn and Swipey in Cyprus) are bound by GDPR erasure rights whether or not the policy is generous. US companies give you state-law rights only in the states that have them. A polite email citing GDPR Article 17 gets a faster answer than a support ticket.
The best NSFW AI chat apps ranking uses this scorecard as one input among four; a platform can rank well there and poorly here if the product is good and the policy is not. That is deliberate, and the editorial policy explains why the scores are kept separate.
How billing descriptors and account emails leak
The two ways a companion subscription becomes visible to someone else are the line on a card statement and the inbox that receives the receipts, and only one of the ten platforms documents what it does about the first. Secrets’ privacy policy states, “Charges will appear on your statement as S LABS INC.” That is a discreet descriptor: it names the parent company’s abbreviation rather than the brand, so a statement reader sees a lab, not an AI girlfriend. It is the only descriptor promise I found in any of the twenty documents I read for this page.
The other nine do not state their descriptor in the policy, which does not mean it is indiscreet, just that you will not know until the first charge posts. Candy’s notice names five payment processors (Emerchantpay, TrustPay, Volt, Coingate and UpGate), and the descriptor on your statement depends on which one handled the transaction. Kalon and Nastia route through processors they do not name. SpicyChat’s terms say tax may be added mid-subscription if the service becomes taxable in your jurisdiction, which changes the amount on the statement without changing the name. Before you rely on any descriptor, run one charge on a card you can check the next day.
Account email is the bigger leak, and no descriptor fixes it. Every platform in the table sends receipts to the registered email. Most also send marketing: Secrets, Kalon and Swipey all describe opt-out routes for promotional email, which means they send it by default. Kalon’s policy adds that it may “email or otherwise communicate reminders about this policy.” Nomi’s policy states that “any personal information contained in any communication with us cannot be changed or deleted as it is part of our archives,” so a support email you send from your main address is archived permanently. If your email client shows sender names on a lock screen, a “Your Secrets receipt” notification undoes the discreet descriptor in one glance.
The fix is the same one I gave above: a dedicated mailbox, a virtual card, and a browser profile that is not signed into your main Google or Apple account, because six of the ten policies describe pulling profile information from third-party logins.
How to delete your data step by step
Account deletion is self-serve on Kindroid, Nastia, Secrets, Nomi and Joyland, by email on CrushOn, Candy, Kalon and Swipey, and by either route on SpicyChat; per-chat deletion is documented only by Nastia and, at the companion level, by Kindroid. Here is the route each policy describes. Where a platform’s app has a delete button that the policy does not mention, I say so, because a button without a policy behind it is a request, not a guarantee.
Kindroid. Delete individual companions from inside the app; the policy says chats and media are retained “until you delete a specific AI or delete your account.” For a full export first, use Profile, then Preferences, where the self-serve export is available every 30 days. Then delete the account from the same profile area. The terms warn that anything you shared publicly “may remain fully available to other users.”
Nastia. Delete chats, images and videos from the chat interface “at any time,” then delete the account from settings. The policy says this “deletes your account and the content in it.” Backups are “overwritten on a regular cycle,” so allow one cycle before assuming a clean slate. For a GDPR erasure request beyond that, email the address given in the policy.
Secrets. Use Delete Account in profile settings; the interface text quoted in the policy reads “Permanently delete your account and all personal data” and warns the action “cannot be undone.” Chat history is “deleted immediately”; transaction records stay seven years in pseudonymised form. For a formal request, email support@secrets.ai; the policy commits to a 30-day response for EEA and UK users and 45 days for California.
Nomi. Delete the account from Account Settings or ask support@nomi.ai. Expect the 28-day window the policy describes. Anything in the “training archives” stays, de-linked from you.
Candy. There is no self-serve route in the policy. Email support@candymail.ai, the address named in the privacy notice, and ask for deletion of account data; the policy promises deletion “without undue delay.” Financial data will be kept ten years regardless.
Kalon. Request deletion by email to privacy@kalon.ai, the address the policy gives for privacy rights; the policy says deletion is “subject to certain exception under applicable law.” Voice chat input is “processed transiently and not stored,” so there is nothing to delete there unless you saved a voice journal.
Swipey. Email Admin@invai.tech to withdraw consent; the policy says the company will then “take reasonable steps … to delete your user account in a timely manner.” Then expect the six-year retention to apply to whatever the company classifies as personal information. If you are in the EU, cite GDPR erasure explicitly, because the Cyprus entity is bound by it.
SpicyChat. The policy says you may “delete Your information at any time by signing in to Your Account” and visiting account settings, or by contacting support@spicychat.ai. The licence you granted in the terms is “perpetual” and “irrevocable,” so deletion removes your account, not the company’s right to content it already has.
CrushOn. The privacy policy names no self-serve route; all rights requests go to support@crushon.ai and must be verified. Nothing in the policy says what happens to chat content already used for training.
Joyland. The terms say, “If you want to delete your account, you can use the delete account function on the Setting page.” For a formal deletion request, the privacy policy directs you to support@joyland.ai and warns you may need to verify your identity first.
On every platform, cancel the subscription before deleting the account. Several terms, Kalon’s among them, say purchased credits “will expire if your account is terminated or deleted,” and none of them refunds the remainder of a billing period on deletion.
When we re-check
Every policy in this scorecard is re-read on the 22nd of each month, and a grade moves only when the document changes, not when the app does. The check is simple: I open each URL under Sources, compare the “last updated” date and the six graded sections to the copy saved at the previous check, and log any difference in the What changed block above the FAQ. If a platform adds a training opt-out, a stated retention period or a per-chat deletion promise, it gains points the same month. If a policy disappears behind a login wall or a broken link, the platform drops one band until it is public again, because a policy you cannot read is a policy that does not bind anyone.
Four of the ten documents changed in the six months before this check by their own dating: Nastia (September 16, 2026), Candy (July 30, 2026), Nomi (April 27, 2026) and Secrets (April 10, 2026). SpicyChat’s privacy policy has not been updated since May 4, 2023, which is its own kind of signal. Joyland’s privacy policy carries no date at all.
If you spot a change before I do, the contact page is the fastest route; I check submissions before the monthly pass and credit the first person who flags a change. The about page explains who I am and why I read these things for a living.
One email a month when a policy in this scorecard changes, a grade moves or a platform starts training on chats.
Frequently asked questions
Which AI companion app is the most private?
Kindroid, by a small margin, followed by Nastia. Kindroid's policy says chats are encrypted at rest and in transit and are retained only until you delete the companion or the account. Nastia lets you delete individual chats and images and names a seven-year limit for violation records. Neither earned an A because neither offers a training opt-out or names its vendors.
Do AI companion apps use my chats to train their models?
Several state that they do. CrushOn says chat contents are used for training its models, Secrets lists training among its uses, Candy's terms grant a licence covering model training, and Kalon's terms say Input and Output may be used to train its models. Kindroid, Nomi, Nastia, Joyland, SpicyChat and Swipey do not state a clear yes, which is not the same as a no.
Can I opt out of training on my conversations?
Not on any of the ten platforms in this scorecard, as of September 2026. None of the privacy policies or terms I read describes a setting or a request route that stops your chats being used to improve or train the model. The only opt-outs offered are for marketing email, cookies and, on some, targeted advertising.
How long do AI companion apps keep my messages after I delete my account?
It ranges from immediately to six years. Secrets says chat history is deleted immediately on account deletion, Kindroid retains chats until you delete the companion or the account, Nomi says about 28 days, Candy says account data is kept up to three years after your last activity, and Swipey says six years after your account closes. Five platforms do not state a period at all.
Is a discreet billing descriptor enough to keep an AI girlfriend app private?
No. A descriptor such as Secrets' documented "S LABS INC." hides the brand on a card statement, but the account email still receives receipts and marketing, and the payment processor still holds your name and billing address. Use a separate email address and, where possible, a virtual card, and treat the descriptor as one layer rather than the whole plan.
Why did Joyland get an F when it is free and does not sell data?
Because the grade measures the paperwork, not the price. Joyland's privacy policy sets the minimum age at 13, does not state a retention period, and its terms grant a perpetual, irrevocable licence to your characters and generations for any purpose. The "we do not sell" line is worth something, but it does not offset the rest.
Related
Sources (19)
- SpicyChat privacy policy, last updated May 4, 2023
- SpicyChat terms and conditions
- CrushOn privacy policy, last modified March 6, 2025
- CrushOn terms of use, last modified July 22, 2025
- Kindroid terms of use, effective November 1, 2024, and privacy policy, effective June 28, 2024
- Candy AI / EverAI privacy notice, revised July 30, 2026
- Candy AI terms of service
- Nomi privacy policy, last updated April 27, 2026
- Nomi terms of service, January 16, 2026
- Joyland privacy policy, undated
- Joyland terms of service, last updated May 14, 2025
- Nastia privacy policy, last updated September 16, 2026
- Nastia terms and conditions, last updated September 16, 2026
- Kalon privacy policy, last updated February 4, 2026
- Kalon terms of service, last modified February 4, 2026
- Secrets AI privacy policy, last updated April 10, 2026
- Secrets AI terms of service, last updated April 10, 2026
- Swipey / INVAI privacy policy, undated
- Swipey terms of service, version 3.0, August 1, 2026