The AI Sexting Question: What You Need to Know in 2026
What AI sexting is, where the chats actually go, which apps train on them, what the 2026 laws say about age checks and real people, and the safety rules I follow on every platform I test.
Sexting with an AI is a text conversation with a chatbot that plays a partner, and by the numbers it is one of the most common things people do with companion apps. That is not a moral claim; it is what the search data, the app store reviews and the community threads all say. I have tested adult AI apps since 2022, and every platform on this site is measured on the same script, which includes an adult scene precisely because that is what most subscribers pay for. So this page is not about whether you should. It is about what happens to the messages after you hit send.
The short answer is that the messages do not stay on your phone. They sit on a server run by a company you have probably never looked up, in a country you may not have checked, under a privacy policy that in most cases does not say how long they are kept or whether they feed the next version of the model. In September 2024 that abstraction became concrete when the Muah.AI breach put 1.9 million email addresses and their image prompts into circulation. Nothing about that breach was exotic; the site was, in the hacker's words as reported by 404 Media, a handful of open-source projects duct-taped together.
Below is what I have learned from reading twenty-odd privacy policies and terms in full, from the platform safety comparison I keep updated, and from watching the law catch up in real time through 2025 and 2026. I use plain category words throughout: adult, NSFW, explicit. There are no scene descriptions here and no screenshots, because the point of the page is the plumbing, not the content.
AI sexting is legal for adults in the US and UK, common, and less private than almost anyone assumes. Of the ten platforms on my privacy scorecard, none earned an A, four (CrushOn, Secrets, Candy, Kalon) state or imply that chats are used to train models, and none offers an opt-out. Only Kindroid and Nastia tie chat retention to your own delete button. Since July 25, 2025 UK users face mandatory age checks on any service that generates adult material, since January 1, 2026 California requires companion chatbots to block sexual content for known minors, and the federal TAKE IT DOWN Act makes non-consensual intimate deepfakes of real people a crime. If you do it: separate email, virtual card, invented name, no real faces, and pick from the three apps in the last section.
What AI sexting actually is (and isn’t)
AI sexting is adult text roleplay with a chatbot that stays in character as a partner, and on every platform I test it is the same product as ordinary companion chat with the content filter set to allow it. There is no separate app category, no different model architecture and no special server. The messages travel the same route as a conversation about your day: your phone or browser sends the text to the company’s API, the company sends it to a language model (its own or a rented one), the reply comes back, and both halves are written to a database attached to your account.
That last part is what most people get wrong. The mental model is a private chat, like an encrypted message to a person, and the reality is closer to a customer-support ticket: logged, searchable, attached to an email address, and in most policies available to staff for moderation. An adult session is not a conversation with a machine that forgets; it is a conversation with a company that keeps records. Whether the app calls it “uncensored”, “NSFW mode” or “romantic partner” changes nothing about where the text lands.
It is also worth separating three things the phrase gets used for, because the risk profile is different for each. The first is text only: you and a character, no images. The second is text plus generated images of that character, which adds an image prompt to the log and, on most platforms, a token or credit purchase that shows up on a card. The third is anything involving a real person, whether you upload a photo, describe a colleague, or ask for a “digital forgery” of an ex. The first two are legal for adults and are what this guide is about. The third crosses into territory that the federal TAKE IT DOWN Act and every platform’s terms now treat as a crime, and I cover that below so nobody wanders into it by accident.
What AI sexting is not: it is not private by default, it is not free on any platform that does it well (the real monthly cost guide has the actual numbers), and it is not a feature that a company can promise to keep. The Replika precedent is the one everyone in this niche remembers: in February 2023 the Italian data protection authority ordered the company to stop processing Italian users’ data, citing risks to vulnerable people and the exposure of unscreened minors to sexual conversation, and within days Replika removed erotic roleplay for everyone, worldwide. Users pointed out at the time that Replika had used sexually suggestive advertising to draw them in. Both things were true, and the feature stayed gone for months.
Why so many people search for AI sexting
The honest answer is that the demand was always there and the apps finally got good enough to meet it, and the only figures I trust on how widespread this is come from the teen side of the data, where researchers actually asked. Common Sense Media’s national survey, published July 16, 2025, found that 72 percent of US teens aged 13 to 17 had used an AI companion at least once and that over half use one at least a few times a month. That study is about companions in general, not adult use, and its authors recommended that no one under 18 use them at all. I quote it here for one reason: if that many people met a companion app before they could legally use the adult version, the adult market a few years later is not a niche.
The second figure is the Muah.AI breach count. Have I Been Pwned lists 1.9 million email addresses from a single “AI girlfriend” site that most people in the industry had never heard of, alongside the image prompts those accounts had submitted. That is one mid-tier platform in September 2024. I do not have a sourced total for the market and I am not going to invent one; but the one hard number we have for a single small site is seven figures.
The third is what the search itself tells you. People type “AI sexting” and “sexting AI” into Google for four reasons that show up over and over in the best NSFW AI chat apps comments and on Reddit: they want to know whether it is allowed, whether it is safe, which app does it without the filter breaking the scene, and whether anyone will find out. This guide answers the second and fourth questions. The uncensored AI list and the free NSFW AI chat ranking answer the third, and the does Character.AI allow NSFW page exists because the first question is usually asked about the biggest app, where the answer is no.
There is a reason the demand is not going away, and it is the one nobody in the marketing copy says out loud: the bar for a good scene partner is low, and a model that remembers your preferences and never gets tired clears it. I am 34, married twelve years, and my wife reads these drafts; the appeal is not mysterious to either of us. What surprised me when I started testing was how little attention the same users pay to the part that can actually hurt them, which is the next section.
The AI sexting privacy problem nobody talks about
The privacy problem with AI sexting is not that the company can read your chats; it is that the chats are stored indefinitely on most platforms, feed model training on several, and are tied to an email address and a payment record that survive any breach intact. Those are four separate failure modes, and each one needs its own defence.
Where the chats are stored
Every one of the ten policies on my privacy scorecard confirms that conversations are stored server-side, and only two tie the retention period to something you control. Kindroid’s policy says chats and generated media are kept “until you delete a specific AI or delete your account,” and adds that chats are encrypted at rest and in transit so the company cannot view them in normal operation. Nastia’s policy says you can delete chats, images and videos at any time and that backups are overwritten on a regular cycle. Those are the good answers. The rest range from Nomi’s “within 28 or so days” of account deletion, to Candy’s three years after last activity, to Swipey’s flat statement that personal information is stored “for a period of 6 (six) years after you cease being a User.” Five of the ten do not state a period at all; the phrase is “as long as necessary,” which means the company decides.
Jurisdiction matters as much as the policy. Nastia is in France, Candy in Malta, CrushOn, Swipey and Uncensy in Cyprus, all of which are bound by GDPR erasure rights whether or not the policy is generous. Kindroid, Nomi, Kalon and Secrets are US entities under state law; SpicyChat is in Quebec; Joyland is in Singapore. A deletion request to a GDPR company citing Article 17 gets answered on a legal clock. A deletion request to a Singapore company gets answered when it feels like it.
Training on your messages
Four platforms state or clearly imply that adult chats train the model, and none of the ten offers a switch to stop it. CrushOn is the plainest: its privacy policy, quoted in full on the scorecard, says chat contents are used “for training our models” and that user content from character chats may train AI models. Secrets lists “train and improve our AI models” among its uses. Kalon’s privacy policy leads with a promise not to use private chats or NSFW content to train “third-party or general-purpose AI models,” and its terms then say Input and Output “may be used to train, improve, and develop our models”; both are true, and only the second one binds. Candy’s terms licence covers model training and its notice warns that third-party LLM providers may receive the content of your messages. Nomi’s policy refers to “training archives” that survive deletion, de-linked from your name. The remaining platforms simply do not say, which the scorecard treats as a no-credit answer, because silence is a reserved right.
This is the irreversible part. A retention period ends and a deletion request gets processed, but a model that has learned from your AI sexting sessions does not un-learn them. It is why the scorecard weights training at 25 of 100 points, more than any other question.
Breaches, and what Muah.AI proved
Muah.AI was breached in September 2024, the data was added to Have I Been Pwned on October 8, 2024, and 1.9 million email addresses went into circulation together with the image prompts each address had submitted and the sexual-preference settings on each account. 404 Media broke the story; Malwarebytes reported that the site’s administrator blamed competitors in the uncensored AI industry and that extortion attempts using the data followed. The part that should worry every reader of this page is the structure of the leak, not its size. Prompts were tied to verified email addresses, and a large share of those addresses were real names. Anyone who signed up with a work or personal mailbox handed an extortionist the two things they needed: the fantasy and the identity.
Two further details from the breach coverage matter for 2026. First, the breach exposed a substantial number of prompts describing child sexual abuse, which turned a privacy story into a criminal one for the people who wrote them; Linklaters noted that in the UK possession of such pseudo-images is a serious criminal offence. Second, the extortion pattern was not just “pay or we tell your wife.” Reports described threat actors contacting IT employees found in the data and demanding access to their employers’ systems. Your roleplay log became somebody’s corporate attack surface because you used the same email address for both.
Billing descriptors and the account email
The two ways a subscription becomes visible to someone else are the line on a card statement and the inbox that receives receipts, and only one of the ten platforms on the scorecard documents what appears on the statement. Secrets’ privacy policy states that charges appear as S LABS INC., the parent company’s abbreviation; I could not re-render that page today, so I am relying on the scorecard’s reading of it. Candy’s notice names five payment processors (Emerchantpay, TrustPay, Volt, Coingate and UpGate), so the descriptor depends on which one handled your charge. Chub AI users report card charges appearing as “Postcron.com,” which is not documented anywhere official. Every other platform leaves you to find out on the first charge.
The account email is the bigger leak and no descriptor fixes it. Every platform sends receipts to the registered address, most send marketing by default, and Nomi’s policy states that personal information in any communication with the company “cannot be changed or deleted as it is part of our archives.” If your phone shows sender names on the lock screen, a receipt notification undoes a discreet descriptor in one glance. The scorecard’s descriptor section goes into each platform; the fix is the same one I give below.
AI sexting platform safety comparison
Kindroid and Nastia are the safest places for AI sexting on paper, CrushOn is the worst, and the gap between them is retention and training rather than encryption or age gates. The grades below are the September 2026 privacy scorecard grades, and every cell comes from the privacy policy or terms linked there; “not stated” means I searched the document and found nothing, not that the feature is absent from the app.
| Platform | Privacy grade | Chat retention | Training opt-out | Card descriptor | Adult chat |
|---|---|---|---|---|---|
| Kindroid | B (73) | Until you delete the companion or the account; encrypted at rest and in transit | None; content may be de-identified “for any purpose” | Not stated in policy | Limited (filter tightens on some scenes) |
| Nastia | B (72) | While account is open; per-chat deletion promised; backups overwritten on a cycle | None; chats improve “the quality of companion replies” | Not stated in policy | Yes, uncensored |
| Secrets AI | C (68) | Chat history deleted immediately on account deletion; voice audio deleted after transcription; transactions 7 years | None; trains “and improve our AI models” | Documented: S LABS INC. | Yes |
| Nomi | C (67) | Deleted “within 28 or so days,” except “training archives” | None; archives survive, de-linked | Not stated in policy | Limited |
| Kalon | C (57) | “As long as reasonably necessary”; voice input not stored | None; terms say Input and Output may train its models | Not stated in policy | Yes |
| Candy AI | C (56) | 3 years after last activity; financial data 10 years | None; messages may reach third-party LLM providers | Depends on one of 5 named processors | Yes |
| SpicyChat | D (43) | “Only for as long as is necessary”; not stated | None; terms grant a perpetual, irrevocable licence “for any purpose” | Not stated in policy | Yes |
| CrushOn | F (34) | Not stated; deletion by email only | None; chats used “for training our models” | Not stated in policy | Yes |
Two notes on the table. Uncensy is not on the scorecard yet because it launched on August 18, 2026, but its privacy policy, which I opened today, states that on account deletion personal information is deleted within 30 days, conversation history is permanently erased and backups are removed within 90 days, with no training statement either way; it will be graded at the next scorecard pass. Joyland and Swipey are graded F and D respectively on the scorecard and are left out here because Joyland’s policy sets the minimum age at 13, which disqualifies it from any adult-chat recommendation regardless of the rest, and Swipey’s six-year retention makes it the wrong choice for the specific question this page asks. The Swipey review and Joyland review cover them as products.
The legal side of AI sexting in 2026
For an adult chatting with a fictional adult character, AI sexting is legal in the US and the UK in 2026; the law has moved on three fronts around it, and each one changes what the apps must do rather than what you may type. Age checks, minors, and real people are the three lines. Here is where each stands, with the source for every date.
Age rules
The UK crossed the line first. Under the Online Safety Act, Ofcom’s deadline for “highly effective” age assurance on services that make pornographic content available to UK users was July 25, 2025. Self-declaration and payment methods that do not confirm age are explicitly rejected; accepted methods include facial age estimation, ID checks, mobile-operator checks and email-based cross-referencing. Penalties run to £18 million or 10 percent of global turnover, plus business-disruption orders that can force UK ISPs to block a site. Ofcom’s own guidance, summarised by Winston Taylor, says age-assurance duties apply to chatbots that generate pornographic material, and that services letting users create chatbots mimicking real or fictional people count as user-to-user services under the Act. The gap, and Ofcom admits it, is the standalone chatbot that shares nothing between users; the Crime and Policing Act finalised in May 2026 gives the government powers to close that gap, with a progress report due by December 31, 2026.
The US has no federal age law for this, so the states filled in. California’s SB 243, signed October 13, 2025 and effective January 1, 2026, is the model most others copied: operators of companion chatbots must disclose that the user is talking to AI, publish suicide and self-harm protocols, and, when they know a user is a minor, send break reminders at least every three hours and take “reasonable measures” to prevent the chatbot from producing sexually explicit material or encouraging the minor toward it. It carries a private right of action at the greater of actual damages or $1,000 per violation. New York’s law took effect earlier, on November 5, 2025, with a three-hour AI reminder for all users and penalties up to $15,000 a day. By the September 16, 2026 Privacy World midyear update, Colorado, Connecticut, Georgia, Hawaii, Idaho, Iowa, Nebraska, Oregon and Washington had enacted their own versions, most effective in 2027; Georgia and Washington include age-verification provisions and Connecticut requires reasonable measures to prevent explicit content for minors. MultiState’s count in June 2026 was twelve states; the Transparency Coalition’s in July was fourteen.
What this means for you as an adult: expect more apps to ask for ID, a selfie or a card check, especially if you are in the UK or California, and expect the ones that do not to be the ones with the least to lose. Character.AI removed open-ended chat for under-18s in the US on November 25, 2025 after the Setzer lawsuit and two Texas cases; the platforms that serve adult content will not get to wait for a lawsuit.
Consent and the fiction line
Every serious platform draws the same line in its content rules, and it is the line the criminal law draws: fictional adults, yes; minors, never; real people, no. JanitorAI’s help centre puts it plainly: its services are “exclusively intended for an audience above the age of 18,” the creation or roleplay of an underage persona “is strictly prohibited under all circumstances,” and permanent bans follow a reasonable suspicion of an under-18 user. The same page bans content celebrating real-world violence and harassment targeting real individuals. Nastia, Kalon, Secrets and Nomi all state an 18-plus minimum in the privacy policy itself; Kindroid says 18 in the terms and 16 in the privacy policy, an inconsistency I flagged on the scorecard.
The Muah.AI breach is the case study for why these rules are not decoration. A significant share of the exposed prompts described child abuse scenarios, and the people who wrote them were exposed by email address. In the UK, and under US federal law, AI-generated material of that kind is prosecuted as the real thing. “It’s just a chatbot” is not a defence anyone has won.
Real people and the TAKE IT DOWN Act
The federal TAKE IT DOWN Act was signed on May 19, 2025. It makes it a crime to knowingly publish non-consensual intimate images of an adult, including AI-generated “digital forgeries,” with penalties of up to two years’ imprisonment for sharing and eighteen months for threatening to share; the figures rise to three years and thirty months where the person depicted is a minor. It also requires covered platforms to run a notice-and-removal process that takes down reported material within 48 hours, with a compliance deadline of May 19, 2026 and enforcement by the FTC under its unfair-practices authority. The practical effect for AI sexting is simple: a character based on a fictional adult is fine; uploading your ex’s photo to a “make her say this” bot is not, and the platform now has a legal duty to remove it fast.
The enforcement climate matches. On September 11, 2025 the FTC issued 6(b) orders to Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI demanding records on how their companion chatbots handle children, monetise engagement and process the personal information in conversations. In January 2026 Ofcom opened a formal Online Safety Act investigation into X after Grok’s image tool was used to “undress” photos of real women and, reportedly, minors; Malaysia and Indonesia blocked the platform outright. None of those companies is an adult-companion app, which is the point: regulators started with the biggest names, and the smaller apps on this site are downstream of every rule that comes out of it.
Safety rules I actually follow
Assume every AI sexting message will be stored, may be read by a human during moderation, and may end up in a training set, and then decide what you are comfortable sending under that assumption; everything below is about making the storage less dangerous, not about pretending it is not there. These are the rules I use on every platform I test, including the two graded B.
- A separate mailbox, not an alias. Muah.AI’s leak was dangerous because prompts sat next to real email addresses. Use an address that exists only for companion apps, receives nothing else, and is not linked to your name. Password resets, receipts, “we miss you” emails and breach notifications all go there, and that mailbox is the one thing every policy admits to keeping.
- A card that is not your main card. A virtual card number or a prepaid card stops the merchant name from sitting on a statement your partner or accountant reads, and it limits the damage if a processor is breached. Only Secrets documents its descriptor; for the rest you find out on the first charge. Run one charge and check it the next day before committing to a year.
- An invented name, and nobody else’s. Kindroid’s policy warns that identifying information you type into chats is collected; the others collect it without warning you. Companions ask for names because it makes the scene feel real. Give a made-up one, and never type a real colleague, ex or partner into a scene.
- No real faces, ever. No uploads of anyone’s photo, no descriptions that identify a real person. This is the TAKE IT DOWN Act line, and the platform’s own terms line, and the one that turns a privacy problem into a criminal one.
- A browser profile that is not signed into your main Google or Apple account. Six of the ten scorecard policies describe pulling profile data from third-party logins. Sign up with email and a password manager, not “Continue with Google.”
- Read the training clause before the first message, not after. Search the privacy policy and terms for “train,” “improve” and “licence.” If the answer is yes with no opt-out, decide whether you are fine with that now, because you cannot undo it later.
- Delete as you go, and delete the account when you leave. Only Nastia’s policy promises per-chat deletion reaches the server; on everyone else, treat the chat-delete button as a UI convenience and account deletion as the real button. Cancel the subscription first, because several terms say credits expire on deletion and none refunds the remainder.
- Check your email against Have I Been Pwned. The Muah entry is flagged sensitive and only searchable by verified address, which is exactly why you should verify the companion-app address and subscribe to notifications for it.
That list is longer than most people will follow, so if you take two items, take the first two. A separate email and a virtual card cover the two leaks that have actually hurt people in this niche. The are AI companion apps safe guide covers the non-sexual side of the same question, and the how we test page explains why the privacy policy read is part of every review score.
Red flags that mean run
A minimum age below 18 in the privacy policy is the single red flag that ends the conversation, and there are seven more that should make you close the tab before typing a first message. Each one below is drawn from a real clause or a real incident, not a hypothetical.
- A minimum age below 18 anywhere in the paperwork. Joyland’s privacy policy says 13 (16 in the EU) on a platform whose own terms ban depicting minors. An adult roleplay app with a 13-plus gate will be the first target of every regulator in the section above, and its user base is not who you want in the room.
- No named legal entity, address or governing law. If you cannot find who runs the site, you cannot send them a deletion request, and neither can a regulator. Chub’s terms and privacy pages could not be rendered when I checked them for the platforms file, and its operator is not named on any page I could reach; that alone kept it off the recommendation list.
- “We do not store your chats” on the marketing page and nothing in the policy. A blog post or a Discord answer from staff does not bind the company. Kalon’s privacy policy leads with a no-training promise that its own terms then narrow; the marketing version is always the first sentence, the licence is always the second.
- A perpetual, irrevocable licence “for any purpose.” SpicyChat’s terms grant one and add that the company may share or sell that permission to others. Deletion removes your account, not the right they already hold.
- A stated retention period longer than a tax audit. Swipey’s six years after account closure with no carve-out for chats is the longest in the scorecard. Nobody needs your roleplay log in 2032.
- Age gates that are a checkbox. Under the UK rules self-declaration is explicitly insufficient, and any adult platform still using one in 2026 is either not serving the UK or not complying. Either way it tells you how seriously it takes the rest of its obligations.
- Sudden, unannounced limits on paid accounts. Chai froze chats for paying users with unannounced token limits in February 2026; it is a product complaint, but a company that changes paid terms without notice is not one I trust with a deletion request.
- Any tolerance for real-person or minor content in the community. Muah.AI’s administrator told 404 Media the site had moderation staff; the breach showed what that moderation had allowed. If the character library shows real names, celebrities or anyone described as a student, leave, because that library is what a regulator will screenshot.
If a platform passes all eight, it is probably somewhere on the scorecard already. If it is not, the contact page is the fastest way to get it graded; I read submissions before each monthly pass.
Which apps handle it best
Nastia is my first recommendation for AI sexting, Kindroid is the pick if you value privacy over an uncensored filter, and Secrets is the pick if a documented billing descriptor and immediate deletion matter more to you than the training clause; all three are ranked, with prices, in the best NSFW AI chat apps list.
Nastia (B, 72 on the scorecard) is the only platform of the ten whose policy promises per-chat deletion reaches the server, it is uncensored by design, and it is a French company bound by GDPR, which means a deletion request has a legal clock behind it. It is also the only policy that admits backups exist and are overwritten on a cycle, which is more honest than the silence elsewhere. It loses points for not naming a single vendor and for listing advertising providers among recipients, and its plans have been renamed often enough that the checkout is the only reliable price source (from $6.69 a month on the annual plan and $15.99 monthly for Unlimited, as of September 2026 per the pricing page). The Nastia review covers how the app behaves in a scene; this page only cares that the paperwork is the best in the category.
Kindroid (B, 73) is the most private on paper: chats retained only until you delete the companion or the account, encryption at rest and in transit stated in the policy, a self-serve data export every 30 days, and an 18-plus terms page. The catch for this specific use is the filter. Kindroid’s adult mode is marked “Limited” in my platform data because it tightens on some scenes that the uncensored apps allow, and users report that consistently. If your priority order is privacy first and content second, it is the answer; if you want the filter out of the way, it will frustrate you. Standard is $13.99 a month on the web ($139.99 a year) as of September 2026, per the pricing page, with a three-day trial that auto-converts.
Secrets AI (C, 68) gets the third slot for two things nobody else documents. Its policy says chat history is “deleted immediately upon account deletion” and that voice-call audio is deleted permanently after transcription, and it is the only platform whose policy states the card descriptor, S LABS INC. The reason it is third and not first is the training clause: the same policy lists training and improving its models as a use of your information with no opt-out, and its terms assign ownership of all generations to the company. Premium is $19.99 a month or $109.99 a year as of September 2026; the Secrets review has the rest. If the descriptor matters to you more than the training clause, swap it to first.
Two honourable mentions with caveats. Kalon (C, 57) has the best-sounding privacy sentence in the niche and voice input that is not stored, but its terms grant training rights its policy seems to deny; the Kalon review explains the product. Uncensy launched on August 18, 2026 with a policy that promises 30-day deletion and 90-day backup purge, which would score well, but it is five weeks old and I do not recommend five-week-old platforms for this; the Uncensy review will say when that changes.
And one platform I will not recommend for this regardless of product quality: CrushOn, graded F, because its policy says in plain words that chat contents train its models with no opt-out and no stated retention. It ranks well on the best NSFW AI chat apps list because the product is good and the ranking uses four inputs; this page uses one, and on that one it is last. The editorial policy explains why those two scores are kept apart, and the affiliate disclosure explains which of the platforms above pay a commission; none of them changed the order here, which you can check against the grades.
One email a month when a platform in this guide changes its retention, starts training on chats, gets breached or adds an age check.
Frequently asked questions
Is AI sexting illegal?
Not for adults, in the US or the UK, when the character is fictional and adult. What is illegal is content involving minors, including fictional or AI-generated depictions, and, since the TAKE IT DOWN Act was signed on May 19, 2025, publishing non-consensual intimate images or digital forgeries of a real person. Every platform I test bans both in its terms, and the good ones enforce it.
Can the app see my messages?
Yes. Every policy I have read stores chats on the company's servers, and most allow human review for moderation. Kindroid's policy says chats are encrypted at rest and in transit so staff cannot read them in normal operation, but the same policy reserves the right to decrypt on a government request. Treat every message as readable by someone other than you.
Which AI sexting app is the most private?
Kindroid and Nastia, both graded B on my scorecard. Kindroid keeps chats only until you delete the companion or the account and documents encryption; Nastia is the only policy that promises per-chat deletion reaches the server and is bound by GDPR in France. Neither offers a training opt-out, which is why neither earned an A.
Do AI sexting apps use my chats to train their models?
Several say so in writing. CrushOn's policy states chat contents are used for training its models, Secrets lists training among its uses, Kalon's terms say Input and Output may be used to train its models, and Candy's terms licence covers model training. None of the ten platforms on my scorecard offers an opt-out setting, as of September 2026.
Will the subscription show on my bank statement?
Yes, under whatever descriptor the payment processor uses. Secrets is the only platform whose policy documents its descriptor, S LABS INC. Candy names five different processors, so the line depends on which one handled the charge. A virtual or prepaid card and a separate email address are the only reliable fixes; the descriptor alone is not a privacy plan.
Do I need to verify my age for adult AI chat in 2026?
In the UK, yes: since July 25, 2025 the Online Safety Act requires highly effective age assurance on services that generate adult material, and self-declaration does not count. In the US it depends on the state; California's SB 243 requires companion chatbots to block sexual content for known minors, and Georgia and Washington enacted age-verification provisions in 2026 that take effect in 2027.
Related
Sources (15)
- Have I Been Pwned, Muah.AI breach entry (breach September 2024, added October 8, 2024)
- Malwarebytes, AI girlfriend site breached, user fantasies stolen (October 2024)
- Gunderson Dettmer, California SB 243 compliance requirements for companion chatbot operators
- Troutman Pepper Locke, Analyzing the new AI companion chatbot laws (New York and California), January 2026
- MultiState, State AI companion chatbot laws, twelve states, June 26, 2026
- Privacy World, US AI law 2026 midyear state update, September 16, 2026
- FTC press release, FTC launches inquiry into AI chatbots acting as companions, September 11, 2025
- Skadden, TAKE IT DOWN Act requires platforms to remove unauthorized intimate images and deepfakes, June 2025
- National Law Review, Online Safety Act age assurance deadline, July 25, 2025
- Winston Taylor, Chatbots and the UK Online Safety Act, to what extent are they in scope
- The Register, Ofcom officially investigating X as Grok's nudify button stays switched on, January 12, 2026
- Wikipedia, Character.ai (under-18 open-ended chat removed November 25, 2025; lawsuits)
- Common Sense Media, Nearly 3 in 4 teens have used AI companions, July 16, 2025
- JanitorAI help centre, content guidelines
- Uncensy privacy policy (AVERIQ LTD, Cyprus)