You can establish what an NSFW AI platform does with your data in about ten minutes, and it will tell you more than any review. The method is five steps, and the answer is usually in what the policy declines to say.
The five steps
| Step | Look for | Fail signal |
|---|---|---|
| 1. Find retention | A stated period | "As long as necessary" |
| 2. Find training | An explicit no, or a working opt-out | No mention at all |
| 3. Test deletion | Delete something, then look for it | Still reachable by direct link |
| 4. Read the processor list | Named third parties | "Trusted partners" |
| 5. Check the descriptor | Buy the smallest pack, read the statement | Anything recognisable |
Step 3 is the one people skip
Policies describe intent; deletion tests behaviour. Delete an image, then try its direct URL. If the file is still served from the CDN, "deleted" meant removed from your gallery view, not removed. This takes two minutes and is the single most informative thing you can do.
Step 5 costs a few dollars and is worth it
Buy the smallest possible pack before any subscription and read the card statement. The descriptor is frequently a neutral holding company, but not always, and finding out on the smallest possible transaction is better than finding out on an annual plan. See what shows up on your card statement.
What the answers mean
See are AI girlfriend chats private for how to read what you find. Part of the full NSFW AI safety checklist.
FAQ
What if there is no privacy policy at all?
That is your answer. Do not use it.
How long should this take?
Ten minutes, plus a few dollars for the descriptor check. Less time than you will spend choosing a character.
Does an opt-out actually work?
Unverifiable from outside. An explicit "we do not train on user content" is stronger than an opt-out you cannot audit.