“Private” needs an object.
A discovery setting answers who can find or use a character. A conversation setting can govern sharing a particular exchange. A policy describes the provider’s processing and exceptions. Check each separately before placing real information in a backstory, memory field or message.
Publishing and processing are different decisions.
Making a character private does not answer whether its messages reach a hosted model, support workflow or another service. An unlisted link can also be forwarded. Write down which audience you are controlling and which service still receives the content.
A local interface needs a data route.
List the interface, model, image engine, voice engine and extensions you use. A locally installed editor can connect to a cloud model. Check the selected services instead of inferring an offline conversation from the editor’s address. SillyTavern’s interface documentation separates the frontend from inference.
Deletion and a download both create follow-up questions.
Keep a distinction between removing one message, deleting a character and closing an account. Ask which copies remain and for what purpose. When you download a backup or account archive, decide where that new copy belongs and who can open it.
The full notes for each platform.
Expand a platform to read all six questions, including gaps. Source labels distinguish a policy from a help article, product wiki or technical documentation. The order is editorial, without a privacy score.
Character.AISix questions · read 4 Oct 2026
- Who can discover the character?
- Documented statement
Public characters are discoverable; unlisted characters require a link; private characters are available only to their creator.
Character.AI visibility options - Who can access conversation data?
- Read the conditions
The creator-access FAQ says other character creators cannot read your conversations. That statement does not establish staff access or provider processing.
Open question: Provider-access conditions were not established from the help articles in this review.
Character.AI creator access to chats - Can conversations improve the AI?
- Read the conditions
The training FAQ describes using content for model improvement. Its EEA/UK opt-out excludes new content from generative-model training; other improvement uses can continue.
Open question: The newer July summary refers more broadly to opt-out. Availability outside EEA/UK and treatment of earlier content need checking in the full policy and account.
Character.AI model-training settingsCharacter.AI July privacy update summary - How long is data kept?
- Not established in this review
A retention timetable was not established from the reviewed help articles.
Open question: The full policy did not return readable text in the research tool. No retention duration is inferred from Delete Account.
- What does deletion cover?
- Read the conditions
The help article documents permanent account deletion through account-data settings.
Open question: Removal from backups, previously shared content and training datasets was not established by this article.
Character.AI account deletion - What can I export or request?
- Read the conditions
Account settings document Export data on web and mobile.
Open question: The delivered archive and its contents were not inspected; account export is not proof of a portable character card.
Character.AI account-data export
KindroidSix questions · read 4 Oct 2026
- Who can discover the character?
- Not established in this review
Character-sharing and discovery controls are outside this policy review.
Open question: Inspect the sharing control separately from conversation processing.
- Who can access conversation data?
- Read the conditions
The policy says chats are encrypted at rest and in transit, but not end-to-end. Servers and automated safety systems process content; authorized human review has stated exceptions.
Open question: Atlas has not audited access controls. The policy lists requested review and legal or terms-enforcement conditions.
Kindroid privacy policy and legal page - Can conversations improve the AI?
- Not established in this review
A clear conversation-training commitment or opt-out was not established in the reviewed policy.
Open question: General service-improvement language and adapting replies in a chat do not establish whether conversations train shared models.
Kindroid privacy policy and legal page - How long is data kept?
- Read the conditions
The policy retains chats and generated media until the AI or account is deleted, with broader legal, dispute and anonymous-data exceptions.
Open question: A complete timetable for every copy and exception was not established.
Kindroid privacy policy and legal page - What does deletion cover?
- Read the conditions
The FAQ schedules the final Kin for 24-hour deletion and retains logistical data. Individual message deletion is currently unavailable in that FAQ.
Open question: Deleting a Kin is not the same action as removing one message or ending every billing relationship.
Kindroid deletion and message FAQ - What can I export or request?
- Documented statement
The policy documents a self-serve personal-data export every 30 days under Profile → Preferences.
Kindroid privacy policy and legal page
NomiSix questions · read 4 Oct 2026
- Who can discover the character?
- Not established in this review
Public character-discovery and sharing controls were not examined in this review.
Open question: A conversation-privacy statement does not establish all character-sharing settings.
- Who can access conversation data?
- Read the conditions
The policy collects chat and customization content and permits sharing for described business, service and legal purposes.
Open question: The review does not establish every staff-access condition or encryption architecture.
Nomi privacy policy - Can conversations improve the AI?
- Read the conditions
Nomipedia describes aggregate learning from conversations and feedback after removing identifying information.
Open question: This is a product-wiki explanation. A specific opt-out and treatment of all earlier content were not established.
Nomipedia conversation privacy explanation - How long is data kept?
- Read the conditions
The policy describes personal-data deletion about 28 days after confirmation, with exceptions including support correspondence archives.
Open question: No universal immediate-deletion promise is inferred.
Nomi privacy policy - What does deletion cover?
- Read the conditions
Account Settings is the described deletion route; the policy preserves stated archival and legal exceptions.
Open question: Archive exceptions and copied content require separate consideration.
Nomi privacy policy - What can I export or request?
- Read the conditions
The policy makes access and transfer rights depend on applicable law.
Open question: A self-serve conversation export or its file contents were not established.
Nomi privacy policy
Candy AISix questions · read 4 Oct 2026
- Who can discover the character?
- Not established in this review
A private-character publishing scope was not established from the privacy notice.
Open question: Inspect character-sharing controls separately; this review covers data processing.
- Who can access conversation data?
- Read the conditions
The notice permits moderation review and says third-party model providers or hosters may receive chat content.
Open question: The particular providers and account-level handling were not inspected.
Candy AI privacy notice - Can conversations improve the AI?
- Documented statement
The notice describes AI and moderation-model training, including possible human review of de-identified or anonymized interactions.
Candy AI privacy notice - How long is data kept?
- Read the conditions
Account data is generally kept three years after last activity, with a stated possible shorter period; deletion requests and financial records have separate treatment.
Open question: This is not a three-year rule for every data category.
Candy AI privacy notice - What does deletion cover?
- Read the conditions
The notice describes account-data deletion requests; legal obligations and claims can limit erasure.
Open question: Closing an account alone is not described as immediate erasure of every record.
Candy AI privacy notice - What can I export or request?
- Read the conditions
Its GDPR section describes conditional machine-readable portability through a data request.
Open question: No self-serve chat archive or universally available export format was established.
Candy AI privacy notice
SillyTavernSix questions · read 4 Oct 2026
- Who can discover the character?
- Depends on the setup
The multi-user setup separates user data, but filesystem access can reveal it. A user password is not a hosted-platform privacy guarantee.
Open question: Check who administers the instance and who can access its files.
SillyTavern multi-user data and backups - Who can access conversation data?
- Depends on the setup
Documentation says server data, including chats, is stored in plain text. The interface can connect to local or cloud models.
Open question: A cloud model, media engine or extension adds its own data handling. Local interface installation alone does not keep inference local.
SillyTavern multi-user data and backupsSillyTavern interface and model backends - Can conversations improve the AI?
- Depends on the setup
Model-training use depends on the connected backend and other services.
Open question: Review the actual model provider; the interface documentation does not establish a cloud backend’s opt-out.
SillyTavern interface and model backends - How long is data kept?
- Depends on the setup
The instance keeps user files; the reviewed docs do not provide a universal expiry policy.
Open question: Check instance backups and each connected service’s retention independently.
SillyTavern multi-user data and backups - What does deletion cover?
- Depends on the setup
A character-delete control is documented.
Open question: Erasure of chat files, backups, shared cards and connected-provider data must be considered separately.
SillyTavern character management - What can I export or request?
- Documented statement
Character export and a user-data folder backup archive are documented as separate controls.
SillyTavern character managementSillyTavern multi-user data and backups
Joi AISix questions · read 4 Oct 2026
- Who can discover the character?
- Not established in this review
Character-discovery and private-sharing controls were not established from this notice.
Open question: Check character visibility separately from the policy’s conversation-processing statements.
- Who can access conversation data?
- Read the conditions
The notice allows access by operational staff and service providers, alongside stated legal and business exceptions.
Open question: Its non-sharing statement has exceptions; it is not a promise that only the user can access messages.
Joi website privacy policy - Can conversations improve the AI?
- Read the conditions
The notice lists text and voice messages as used to improve replies and develop AI.
Open question: The exact shared-model training scope and a conversation-training opt-out were not established.
Joi website privacy policy - How long is data kept?
- Read the conditions
Data is retained as needed for the service, with legal and legitimate-interest exceptions.
Open question: A fixed expiry period for all conversations and backups was not established.
Joi website privacy policy - What does deletion cover?
- Read the conditions
Profile deletion or a support request can remove data, subject to retention exceptions. Previously disclosed data and caches may remain.
Open question: No immediate erasure of every copy or completed deletion was verified.
Joi website privacy policy - What can I export or request?
- Read the conditions
The EU section describes conditional machine-readable personal-data portability through support and identity verification.
Open question: This does not establish a self-serve chat archive, character-card export or availability for every user.
Joi website privacy policy
LovescapeSix questions · read 4 Oct 2026
- Who can discover the character?
- Read the conditions
The profile guide ties shared character links to public visibility. The policy separately describes public account profiles and submissions.
Open question: A character, an account profile and a conversation have different audiences; the complete private-character access scope was not established.
Lovescape character profiles and sharingLovescape privacy policy - Who can access conversation data?
- Read the conditions
The policy collects chats and uploads, allows authorized business access and shares data with service providers and stated other recipients.
Open question: Encryption in transit is not an end-to-end encryption commitment.
Lovescape privacy policy - Can conversations improve the AI?
- Not established in this review
A specific conversation-training commitment or opt-out was not established in the policy.
Open question: General service-improvement language does not establish whether chats train shared models.
Lovescape privacy policy - How long is data kept?
- Read the conditions
Data is kept as needed for stated purposes, including legal, accounting and reporting requirements.
Open question: No fixed conversation or backup expiry was established; policy date labels also need clarification.
Lovescape privacy policy - What does deletion cover?
- Read the conditions
The help guide separates Clear Chat from Delete Character. The policy describes account deletion and conditional erasure requests.
Open question: Removing a visible chat or character does not establish removal of all retained provider records.
Lovescape character profiles and sharingLovescape privacy policy - What can I export or request?
- Read the conditions
The policy describes personal-data access and portability rights that depend on applicable law.
Open question: A self-serve conversation archive or portable character-card export was not established.
Lovescape privacy policy
SpicyChatSix questions · read 4 Oct 2026
- Who can discover the character?
- Read the conditions
Technical docs describe public, link-accessible unlisted and creator-only private characters. Definition visibility is separate; hidden characters remain visible to moderators.
Open question: The help article lists only private and public options. Current unlisted availability needs checking in the creator.
SpicyChat visibility and definition visibilitySpicyChat creating a character - Who can access conversation data?
- Read the conditions
The policy permits sharing with service providers and other stated recipients. Visibility docs address characters, not staff access to conversations.
Open question: Detailed chat-access conditions and encryption architecture were not established.
SpicyChat privacy policySpicyChat visibility and definition visibility - Can conversations improve the AI?
- Not established in this review
A specific conversation-training commitment or opt-out was not established in the reviewed policy.
Open question: Service-improvement language and character memory do not answer the shared-model training question.
SpicyChat privacy policy - How long is data kept?
- Read the conditions
The policy retains personal data as needed for its purposes, legal obligations, disputes and enforcement.
Open question: No fixed chat or backup timetable was established.
SpicyChat privacy policy - What does deletion cover?
- Read the conditions
The help article describes permanent removal of chats, characters, personas and memories. The policy preserves stated legal-retention exceptions.
Open question: The help article says website subscriptions cancel with the account; externally managed subscriptions require separate cancellation. Erasure outcomes were not tested.
SpicyChat deleting your accountSpicyChat privacy policy - What can I export or request?
- Read the conditions
The policy offers a support route for personal-data access and removal requests.
Open question: A machine-readable delivery format or self-serve chat archive was not established.
SpicyChat privacy policy
Character.AI’s help articles were readable, but the full privacy-policy page did not return readable text in the research tool. Retention and provider-access gaps remain explicit. Older FAQ dates and the newer July summary remain separate.
A checklist before you start a longer conversation.
Use this to make a decision, rather than to calculate a safety score. A missing answer is a reason to investigate the particular condition.
- Choose what you plan to enter. Start with a fictional premise. Keep real names, private correspondence and other people’s details out of the first test.
- Inspect sharing and discovery separately. Check character visibility, shared links and any conversation-posting controls.
- Identify the services receiving content. Include the model, media engines, extensions and support submissions.
- Find the training statement and setting. Record the date, region, whether it covers new content and what other uses continue.
- Read the retention and deletion exceptions. Look separately at chats, backups, support correspondence and transactional records.
- Check the export route before relying on it. Distinguish a personal-data request, chat archive, card and full instance backup. A documented button is not an inspected file.
- Keep your decision and its date. Note the source and any unanswered question. Revisit the relevant condition if your setup or the policy changes.
Begin with a definition you can inspect.
Write a fictional character brief before putting it into a platform. Read the backstory, creator notes and example dialogue for details you did not intend to share. Keep a text copy you can adapt when comparing different editors.
Prepare a fictional definitionOur manual builder formats fields in the browser and saves a device draft only when you press Save. A shared browser profile can access that saved copy. Uploading the result elsewhere introduces the destination’s own handling; this guide does not inspect your files or contact a platform on your behalf.
Read the card and archive guide for what a file carries, or compare free-access scopes before choosing a service. A free tier does not establish its privacy conditions.
Common privacy questions.
Can a character creator see my conversations?
Check the platform-specific statement. Character.AI’s creator-access FAQ excludes other creators from reading chats; that is narrower than a statement about provider access. Sharing an exchange yourself is a separate action.
Does opting out remove earlier training data?
Read what the control explicitly covers. An instruction about new content does not establish removal of earlier content or reversal of its use. The comparison keeps those unknowns visible rather than inferring them from a setting’s name.
Does deleting an account cancel a subscription?
Check billing and data actions separately, including a subscription managed through an app store. This guide documents data handling; it does not verify a cancellation or refund. Read the platform’s recorded billing conditions as a separate decision.
SpicyChat’s account-deletion article says website subscriptions cancel with the account. Subscriptions managed through Google Play, SubscribeStar or Boosty require cancellation with that provider. Its privacy policy still describes retention exceptions; cancellation and complete erasure are different outcomes.
Which platform is safest?
The reviewed documents do not establish a universal winner. Compare the condition that matters for your use, keep unanswered questions visible and inspect your actual setup. Encryption architecture, policy wording and fulfilled data requests are different evidence.
Primary documents, with their dates and scope.
Read 4 Oct 2026. Publisher dates are printed separately; a missing date was not replaced with the reading date. No accounts, private conversations, data requests or deletion actions were used. This is a reading of published terms, not a determination of your legal rights or the platforms’ compliance.
- Help articleCharacter.AI visibility options
Read 4 Oct 2026 · publisher update 17 Jun 2026
Character discovery and access: public, unlisted and private. Does not establish provider processing.
- Help articleCharacter.AI creator access to chats
Read 4 Oct 2026 · publisher update 17 Oct 2024
Other character creators cannot read conversations. Provider access is a separate question.
- Help articleCharacter.AI model-training settings
Read 4 Oct 2026 · publisher update 30 Oct 2025
EEA/UK instructions, new-content opt-out and other improvement uses; no account setting inspected.
- Help articleCharacter.AI July privacy update summary
Read 4 Oct 2026 · publisher update 1 Jul 2026 · policy effective 1 Jul 2026
Summary refers to training opt-out and regional disclosures. It is not the full binding policy.
- Help articleCharacter.AI account deletion
Read 4 Oct 2026 · publisher update 3 Oct 2024
Documented account-deletion control; no retention timetable established by this article.
- Help articleCharacter.AI account-data export
Read 4 Oct 2026 · publisher update 10 Jul 2025
Account-data export control. Archive contents, delivery and character-card compatibility were not tested.
- PolicyKindroid privacy policy and legal page
Read 4 Oct 2026 · legal-page update 30 Sept 2026 · policy effective 28 Jun 2024
Encryption, permitted review, retention and self-serve data portability. The privacy section retains its own earlier effective date.
- Help articleKindroid deletion and message FAQ
Read 4 Oct 2026 · publisher update 26 Sept 2026
Deleting a Kin or account is different from deleting individual messages; logistical data remains.
- PolicyNomi privacy policy
Read 4 Oct 2026 · publisher update 27 Apr 2026
Collection, business-purpose sharing, account deletion, archives and law-dependent data rights.
- Product wikiNomipedia conversation privacy explanation
Read 4 Oct 2026 · wiki edit 24 Aug 2026
Aggregate learning from conversations after removing identifying information. Product explanation, not the privacy policy or a security audit.
- PolicyCandy AI privacy notice
Read 4 Oct 2026 · revision 30 Jul 2026
Training, review, service providers, account-data retention, erasure and conditional GDPR portability.
- Technical documentationSillyTavern interface and model backends
Read 4 Oct 2026 · publisher date not established
Locally installed interface; inference may use a local or cloud backend. Extensions add separate services.
- Technical documentationSillyTavern multi-user data and backups
Read 4 Oct 2026 · publisher date not established
Plain-text server data, user separation and a user-data backup archive; not a promise about a connected backend.
- Technical documentationSillyTavern character management
Read 4 Oct 2026 · publisher date not established
Character export and deletion controls; deleting a character does not establish erasure of every copy.
- PolicyJoi website privacy policy
Read 4 Oct 2026 · publisher update 4 Jun 2026
The main website notice describes messages, permitted access, deletion exceptions and conditional data rights. Regional sections are not a universal export entitlement.
- PolicyLovescape privacy policy
Read 4 Oct 2026 · last-modified label 4 Jun 2024
Collection, authorized access, retention and data requests. The page also displays an effective date of 4 October 2026; its relationship to the older last-modified label was not established. No new policy release is inferred.
- Help articleLovescape character profiles and sharing
Read 4 Oct 2026 · publisher update 8 Jun 2026
Public character links, Clear Chat and Delete Character. These interface actions do not establish erasure from provider backups or every retained record.
- PolicySpicyChat privacy policy
Read 4 Oct 2026 · publisher update 4 May 2023
General collection, sharing, retention and data requests. A specific conversation-training commitment or opt-out was not established; the older publisher date is preserved.
- Technical documentationSpicyChat visibility and definition visibility
Read 4 Oct 2026 · publisher date not established
Describes public, unlisted and private characters, separate definition visibility and moderator access to hidden characters. A publisher date was not established.
- Help articleSpicyChat creating a character
Read 4 Oct 2026 · publisher date not established
Lists private and public visibility, while the technical guide also lists unlisted. The displayed update is Mon, Sep 21 without a year; a full publisher date was not established.
- Help articleSpicyChat deleting your account
Read 4 Oct 2026 · publisher date not established
Describes removal of account content and separates website subscriptions from externally managed billing. The displayed update is Tue, Sep 29 without a year; a full publisher date was not established. No deletion was performed.