Skip to content
An independent field guide to AI character platformsResearch edition · October 2026
charactersFind your fit
PRIVACY FIELD GUIDE · 4 Oct 2026

AI character privacy.Follow the conversation data.

Before you choose a home for a character, separate who can find it from what happens to its conversations. Compare 8 platforms’ published statements about access, learning, stored copies and the controls you can use.

Read the scope, not just the word “private”. 7 hosted services and one interface; 21 linked public documents read 4 Oct 2026. This is a documentation review, not a security audit. Account controls, delivered exports and deletion outcomes were not tested.

01

Audience

Can another person discover this character, use a shared link or read a deliberately shared conversation?

02

Processing

Which service receives the definition and messages to produce a reply? Which other services handle images, voice, search or translation?

03

Reuse

Can the content improve a shared model? What does a setting exclude, which region does it cover and when does it take effect?

04

Copies

What stays after deleting a message, character or account? Ask separately about backups, support tickets, shared files and records kept for other purposes.

ONE QUESTION AT A TIME

Compare the documented conditions.

Keep a decision checklist

These are published statements and review gaps, not verified security outcomes. Open-question view keeps unknown fields and stated qualifications; an empty result means no question was recorded for this selection.

8 of 8 reviewed platforms shown

Who can access conversation data?

“Private” needs an object.

A discovery setting answers who can find or use a character. A conversation setting can govern sharing a particular exchange. A policy describes the provider’s processing and exceptions. Check each separately before placing real information in a backstory, memory field or message.

Publishing and processing are different decisions.

Making a character private does not answer whether its messages reach a hosted model, support workflow or another service. An unlisted link can also be forwarded. Write down which audience you are controlling and which service still receives the content.

A local interface needs a data route.

List the interface, model, image engine, voice engine and extensions you use. A locally installed editor can connect to a cloud model. Check the selected services instead of inferring an offline conversation from the editor’s address. SillyTavern’s interface documentation separates the frontend from inference.

Deletion and a download both create follow-up questions.

Keep a distinction between removing one message, deleting a character and closing an account. Ask which copies remain and for what purpose. When you download a backup or account archive, decide where that new copy belongs and who can open it.

The full notes for each platform.

Expand a platform to read all six questions, including gaps. Source labels distinguish a policy from a help article, product wiki or technical documentation. The order is editorial, without a privacy score.

Character.AISix questions · read 4 Oct 2026
Who can discover the character?
Documented statement

Public characters are discoverable; unlisted characters require a link; private characters are available only to their creator.

Character.AI visibility options
Who can access conversation data?
Read the conditions

The creator-access FAQ says other character creators cannot read your conversations. That statement does not establish staff access or provider processing.

Open question: Provider-access conditions were not established from the help articles in this review.

Character.AI creator access to chats
Can conversations improve the AI?
Read the conditions

The training FAQ describes using content for model improvement. Its EEA/UK opt-out excludes new content from generative-model training; other improvement uses can continue.

Open question: The newer July summary refers more broadly to opt-out. Availability outside EEA/UK and treatment of earlier content need checking in the full policy and account.

Character.AI model-training settingsCharacter.AI July privacy update summary
How long is data kept?
Not established in this review

A retention timetable was not established from the reviewed help articles.

Open question: The full policy did not return readable text in the research tool. No retention duration is inferred from Delete Account.

What does deletion cover?
Read the conditions

The help article documents permanent account deletion through account-data settings.

Open question: Removal from backups, previously shared content and training datasets was not established by this article.

Character.AI account deletion
What can I export or request?
Read the conditions

Account settings document Export data on web and mobile.

Open question: The delivered archive and its contents were not inspected; account export is not proof of a portable character card.

Character.AI account-data export
Read the platform passport
KindroidSix questions · read 4 Oct 2026
Who can discover the character?
Not established in this review

Character-sharing and discovery controls are outside this policy review.

Open question: Inspect the sharing control separately from conversation processing.

Who can access conversation data?
Read the conditions

The policy says chats are encrypted at rest and in transit, but not end-to-end. Servers and automated safety systems process content; authorized human review has stated exceptions.

Open question: Atlas has not audited access controls. The policy lists requested review and legal or terms-enforcement conditions.

Kindroid privacy policy and legal page
Can conversations improve the AI?
Not established in this review

A clear conversation-training commitment or opt-out was not established in the reviewed policy.

Open question: General service-improvement language and adapting replies in a chat do not establish whether conversations train shared models.

Kindroid privacy policy and legal page
How long is data kept?
Read the conditions

The policy retains chats and generated media until the AI or account is deleted, with broader legal, dispute and anonymous-data exceptions.

Open question: A complete timetable for every copy and exception was not established.

Kindroid privacy policy and legal page
What does deletion cover?
Read the conditions

The FAQ schedules the final Kin for 24-hour deletion and retains logistical data. Individual message deletion is currently unavailable in that FAQ.

Open question: Deleting a Kin is not the same action as removing one message or ending every billing relationship.

Kindroid deletion and message FAQ
What can I export or request?
Documented statement

The policy documents a self-serve personal-data export every 30 days under Profile → Preferences.

Kindroid privacy policy and legal page
Read the platform passport
NomiSix questions · read 4 Oct 2026
Who can discover the character?
Not established in this review

Public character-discovery and sharing controls were not examined in this review.

Open question: A conversation-privacy statement does not establish all character-sharing settings.

Who can access conversation data?
Read the conditions

The policy collects chat and customization content and permits sharing for described business, service and legal purposes.

Open question: The review does not establish every staff-access condition or encryption architecture.

Nomi privacy policy
Can conversations improve the AI?
Read the conditions

Nomipedia describes aggregate learning from conversations and feedback after removing identifying information.

Open question: This is a product-wiki explanation. A specific opt-out and treatment of all earlier content were not established.

Nomipedia conversation privacy explanation
How long is data kept?
Read the conditions

The policy describes personal-data deletion about 28 days after confirmation, with exceptions including support correspondence archives.

Open question: No universal immediate-deletion promise is inferred.

Nomi privacy policy
What does deletion cover?
Read the conditions

Account Settings is the described deletion route; the policy preserves stated archival and legal exceptions.

Open question: Archive exceptions and copied content require separate consideration.

Nomi privacy policy
What can I export or request?
Read the conditions

The policy makes access and transfer rights depend on applicable law.

Open question: A self-serve conversation export or its file contents were not established.

Nomi privacy policy
Read the platform passport
Candy AISix questions · read 4 Oct 2026
Who can discover the character?
Not established in this review

A private-character publishing scope was not established from the privacy notice.

Open question: Inspect character-sharing controls separately; this review covers data processing.

Who can access conversation data?
Read the conditions

The notice permits moderation review and says third-party model providers or hosters may receive chat content.

Open question: The particular providers and account-level handling were not inspected.

Candy AI privacy notice
Can conversations improve the AI?
Documented statement

The notice describes AI and moderation-model training, including possible human review of de-identified or anonymized interactions.

Candy AI privacy notice
How long is data kept?
Read the conditions

Account data is generally kept three years after last activity, with a stated possible shorter period; deletion requests and financial records have separate treatment.

Open question: This is not a three-year rule for every data category.

Candy AI privacy notice
What does deletion cover?
Read the conditions

The notice describes account-data deletion requests; legal obligations and claims can limit erasure.

Open question: Closing an account alone is not described as immediate erasure of every record.

Candy AI privacy notice
What can I export or request?
Read the conditions

Its GDPR section describes conditional machine-readable portability through a data request.

Open question: No self-serve chat archive or universally available export format was established.

Candy AI privacy notice
Read the platform passport
SillyTavernSix questions · read 4 Oct 2026
Who can discover the character?
Depends on the setup

The multi-user setup separates user data, but filesystem access can reveal it. A user password is not a hosted-platform privacy guarantee.

Open question: Check who administers the instance and who can access its files.

SillyTavern multi-user data and backups
Who can access conversation data?
Depends on the setup

Documentation says server data, including chats, is stored in plain text. The interface can connect to local or cloud models.

Open question: A cloud model, media engine or extension adds its own data handling. Local interface installation alone does not keep inference local.

SillyTavern multi-user data and backupsSillyTavern interface and model backends
Can conversations improve the AI?
Depends on the setup

Model-training use depends on the connected backend and other services.

Open question: Review the actual model provider; the interface documentation does not establish a cloud backend’s opt-out.

SillyTavern interface and model backends
How long is data kept?
Depends on the setup

The instance keeps user files; the reviewed docs do not provide a universal expiry policy.

Open question: Check instance backups and each connected service’s retention independently.

SillyTavern multi-user data and backups
What does deletion cover?
Depends on the setup

A character-delete control is documented.

Open question: Erasure of chat files, backups, shared cards and connected-provider data must be considered separately.

SillyTavern character management
What can I export or request?
Documented statement

Character export and a user-data folder backup archive are documented as separate controls.

SillyTavern character managementSillyTavern multi-user data and backups
Read the platform passport
Joi AISix questions · read 4 Oct 2026
Who can discover the character?
Not established in this review

Character-discovery and private-sharing controls were not established from this notice.

Open question: Check character visibility separately from the policy’s conversation-processing statements.

Who can access conversation data?
Read the conditions

The notice allows access by operational staff and service providers, alongside stated legal and business exceptions.

Open question: Its non-sharing statement has exceptions; it is not a promise that only the user can access messages.

Joi website privacy policy
Can conversations improve the AI?
Read the conditions

The notice lists text and voice messages as used to improve replies and develop AI.

Open question: The exact shared-model training scope and a conversation-training opt-out were not established.

Joi website privacy policy
How long is data kept?
Read the conditions

Data is retained as needed for the service, with legal and legitimate-interest exceptions.

Open question: A fixed expiry period for all conversations and backups was not established.

Joi website privacy policy
What does deletion cover?
Read the conditions

Profile deletion or a support request can remove data, subject to retention exceptions. Previously disclosed data and caches may remain.

Open question: No immediate erasure of every copy or completed deletion was verified.

Joi website privacy policy
What can I export or request?
Read the conditions

The EU section describes conditional machine-readable personal-data portability through support and identity verification.

Open question: This does not establish a self-serve chat archive, character-card export or availability for every user.

Joi website privacy policy
Read the platform passport
LovescapeSix questions · read 4 Oct 2026
Who can discover the character?
Read the conditions

The profile guide ties shared character links to public visibility. The policy separately describes public account profiles and submissions.

Open question: A character, an account profile and a conversation have different audiences; the complete private-character access scope was not established.

Lovescape character profiles and sharingLovescape privacy policy
Who can access conversation data?
Read the conditions

The policy collects chats and uploads, allows authorized business access and shares data with service providers and stated other recipients.

Open question: Encryption in transit is not an end-to-end encryption commitment.

Lovescape privacy policy
Can conversations improve the AI?
Not established in this review

A specific conversation-training commitment or opt-out was not established in the policy.

Open question: General service-improvement language does not establish whether chats train shared models.

Lovescape privacy policy
How long is data kept?
Read the conditions

Data is kept as needed for stated purposes, including legal, accounting and reporting requirements.

Open question: No fixed conversation or backup expiry was established; policy date labels also need clarification.

Lovescape privacy policy
What does deletion cover?
Read the conditions

The help guide separates Clear Chat from Delete Character. The policy describes account deletion and conditional erasure requests.

Open question: Removing a visible chat or character does not establish removal of all retained provider records.

Lovescape character profiles and sharingLovescape privacy policy
What can I export or request?
Read the conditions

The policy describes personal-data access and portability rights that depend on applicable law.

Open question: A self-serve conversation archive or portable character-card export was not established.

Lovescape privacy policy
Read the platform passport
SpicyChatSix questions · read 4 Oct 2026
Who can discover the character?
Read the conditions

Technical docs describe public, link-accessible unlisted and creator-only private characters. Definition visibility is separate; hidden characters remain visible to moderators.

Open question: The help article lists only private and public options. Current unlisted availability needs checking in the creator.

SpicyChat visibility and definition visibilitySpicyChat creating a character
Who can access conversation data?
Read the conditions

The policy permits sharing with service providers and other stated recipients. Visibility docs address characters, not staff access to conversations.

Open question: Detailed chat-access conditions and encryption architecture were not established.

SpicyChat privacy policySpicyChat visibility and definition visibility
Can conversations improve the AI?
Not established in this review

A specific conversation-training commitment or opt-out was not established in the reviewed policy.

Open question: Service-improvement language and character memory do not answer the shared-model training question.

SpicyChat privacy policy
How long is data kept?
Read the conditions

The policy retains personal data as needed for its purposes, legal obligations, disputes and enforcement.

Open question: No fixed chat or backup timetable was established.

SpicyChat privacy policy
What does deletion cover?
Read the conditions

The help article describes permanent removal of chats, characters, personas and memories. The policy preserves stated legal-retention exceptions.

Open question: The help article says website subscriptions cancel with the account; externally managed subscriptions require separate cancellation. Erasure outcomes were not tested.

SpicyChat deleting your accountSpicyChat privacy policy
What can I export or request?
Read the conditions

The policy offers a support route for personal-data access and removal requests.

Open question: A machine-readable delivery format or self-serve chat archive was not established.

SpicyChat privacy policy
Read the platform passport

Character.AI’s help articles were readable, but the full privacy-policy page did not return readable text in the research tool. Retention and provider-access gaps remain explicit. Older FAQ dates and the newer July summary remain separate.

A checklist before you start a longer conversation.

Use this to make a decision, rather than to calculate a safety score. A missing answer is a reason to investigate the particular condition.

  1. Choose what you plan to enter. Start with a fictional premise. Keep real names, private correspondence and other people’s details out of the first test.
  2. Inspect sharing and discovery separately. Check character visibility, shared links and any conversation-posting controls.
  3. Identify the services receiving content. Include the model, media engines, extensions and support submissions.
  4. Find the training statement and setting. Record the date, region, whether it covers new content and what other uses continue.
  5. Read the retention and deletion exceptions. Look separately at chats, backups, support correspondence and transactional records.
  6. Check the export route before relying on it. Distinguish a personal-data request, chat archive, card and full instance backup. A documented button is not an inspected file.
  7. Keep your decision and its date. Note the source and any unanswered question. Revisit the relevant condition if your setup or the policy changes.

Begin with a definition you can inspect.

Write a fictional character brief before putting it into a platform. Read the backstory, creator notes and example dialogue for details you did not intend to share. Keep a text copy you can adapt when comparing different editors.

Prepare a fictional definition

Our manual builder formats fields in the browser and saves a device draft only when you press Save. A shared browser profile can access that saved copy. Uploading the result elsewhere introduces the destination’s own handling; this guide does not inspect your files or contact a platform on your behalf.

Read the card and archive guide for what a file carries, or compare free-access scopes before choosing a service. A free tier does not establish its privacy conditions.

Common privacy questions.

Can a character creator see my conversations?

Check the platform-specific statement. Character.AI’s creator-access FAQ excludes other creators from reading chats; that is narrower than a statement about provider access. Sharing an exchange yourself is a separate action.

Does opting out remove earlier training data?

Read what the control explicitly covers. An instruction about new content does not establish removal of earlier content or reversal of its use. The comparison keeps those unknowns visible rather than inferring them from a setting’s name.

Does deleting an account cancel a subscription?

Check billing and data actions separately, including a subscription managed through an app store. This guide documents data handling; it does not verify a cancellation or refund. Read the platform’s recorded billing conditions as a separate decision.

SpicyChat’s account-deletion article says website subscriptions cancel with the account. Subscriptions managed through Google Play, SubscribeStar or Boosty require cancellation with that provider. Its privacy policy still describes retention exceptions; cancellation and complete erasure are different outcomes.

Which platform is safest?

The reviewed documents do not establish a universal winner. Compare the condition that matters for your use, keep unanswered questions visible and inspect your actual setup. Encryption architecture, policy wording and fulfilled data requests are different evidence.

Primary documents, with their dates and scope.

Read 4 Oct 2026. Publisher dates are printed separately; a missing date was not replaced with the reading date. No accounts, private conversations, data requests or deletion actions were used. This is a reading of published terms, not a determination of your legal rights or the platforms’ compliance.

  • Help articleCharacter.AI visibility options

    Read 4 Oct 2026 · publisher update 17 Jun 2026

    Character discovery and access: public, unlisted and private. Does not establish provider processing.

  • Help articleCharacter.AI creator access to chats

    Read 4 Oct 2026 · publisher update 17 Oct 2024

    Other character creators cannot read conversations. Provider access is a separate question.

  • Help articleCharacter.AI model-training settings

    Read 4 Oct 2026 · publisher update 30 Oct 2025

    EEA/UK instructions, new-content opt-out and other improvement uses; no account setting inspected.

  • Help articleCharacter.AI July privacy update summary

    Read 4 Oct 2026 · publisher update 1 Jul 2026 · policy effective 1 Jul 2026

    Summary refers to training opt-out and regional disclosures. It is not the full binding policy.

  • Help articleCharacter.AI account deletion

    Read 4 Oct 2026 · publisher update 3 Oct 2024

    Documented account-deletion control; no retention timetable established by this article.

  • Help articleCharacter.AI account-data export

    Read 4 Oct 2026 · publisher update 10 Jul 2025

    Account-data export control. Archive contents, delivery and character-card compatibility were not tested.

  • PolicyKindroid privacy policy and legal page

    Read 4 Oct 2026 · legal-page update 30 Sept 2026 · policy effective 28 Jun 2024

    Encryption, permitted review, retention and self-serve data portability. The privacy section retains its own earlier effective date.

  • Help articleKindroid deletion and message FAQ

    Read 4 Oct 2026 · publisher update 26 Sept 2026

    Deleting a Kin or account is different from deleting individual messages; logistical data remains.

  • PolicyNomi privacy policy

    Read 4 Oct 2026 · publisher update 27 Apr 2026

    Collection, business-purpose sharing, account deletion, archives and law-dependent data rights.

  • Product wikiNomipedia conversation privacy explanation

    Read 4 Oct 2026 · wiki edit 24 Aug 2026

    Aggregate learning from conversations after removing identifying information. Product explanation, not the privacy policy or a security audit.

  • PolicyCandy AI privacy notice

    Read 4 Oct 2026 · revision 30 Jul 2026

    Training, review, service providers, account-data retention, erasure and conditional GDPR portability.

  • Technical documentationSillyTavern interface and model backends

    Read 4 Oct 2026 · publisher date not established

    Locally installed interface; inference may use a local or cloud backend. Extensions add separate services.

  • Technical documentationSillyTavern multi-user data and backups

    Read 4 Oct 2026 · publisher date not established

    Plain-text server data, user separation and a user-data backup archive; not a promise about a connected backend.

  • Technical documentationSillyTavern character management

    Read 4 Oct 2026 · publisher date not established

    Character export and deletion controls; deleting a character does not establish erasure of every copy.

  • PolicyJoi website privacy policy

    Read 4 Oct 2026 · publisher update 4 Jun 2026

    The main website notice describes messages, permitted access, deletion exceptions and conditional data rights. Regional sections are not a universal export entitlement.

  • PolicyLovescape privacy policy

    Read 4 Oct 2026 · last-modified label 4 Jun 2024

    Collection, authorized access, retention and data requests. The page also displays an effective date of 4 October 2026; its relationship to the older last-modified label was not established. No new policy release is inferred.

  • Help articleLovescape character profiles and sharing

    Read 4 Oct 2026 · publisher update 8 Jun 2026

    Public character links, Clear Chat and Delete Character. These interface actions do not establish erasure from provider backups or every retained record.

  • PolicySpicyChat privacy policy

    Read 4 Oct 2026 · publisher update 4 May 2023

    General collection, sharing, retention and data requests. A specific conversation-training commitment or opt-out was not established; the older publisher date is preserved.

  • Technical documentationSpicyChat visibility and definition visibility

    Read 4 Oct 2026 · publisher date not established

    Describes public, unlisted and private characters, separate definition visibility and moderator access to hidden characters. A publisher date was not established.

  • Help articleSpicyChat creating a character

    Read 4 Oct 2026 · publisher date not established

    Lists private and public visibility, while the technical guide also lists unlisted. The displayed update is Mon, Sep 21 without a year; a full publisher date was not established.

  • Help articleSpicyChat deleting your account

    Read 4 Oct 2026 · publisher date not established

    Describes removal of account content and separates website subscriptions from externally managed billing. The displayed update is Tue, Sep 29 without a year; a full publisher date was not established. No deletion was performed.