AI app trust & transparency index

How much do AI apps tell you about your data?

We read the privacy policy and terms of the most-used AI apps and graded what they disclose about data governance: training, deletion, retention, sharing, transparency, and security.

53 apps gradedavg score 66/100Methodology

Grade distribution

85–10070–8455–6940–540–39

Tap a bar to filter the list.

Leonardo.Ai icon

Leonardo.Ai

Leonardo Interactive (a Canva brand)

A

Strong data rights and opt-out controls for training and ads, with named transfer safeguards; the gap is no synthetic-image marking.

Image & video93/100· High confidence
Details
Notion icon

Notion

Notion Labs

A

A no-train-by-default commitment with named encryption, certifications, deletion timelines and SCCs; the cleanest policy in the set.

Productivity89/100· High confidence
Details
Photoroom icon

Photoroom

Image & video

A

A named training opt-out, an explicit no-sell commitment, full rights and detailed retention periods; light on named security controls.

Image & video86/100· High confidence
Details
Mistral Le Chat icon

Mistral Le Chat

Mistral AI

B

A detailed GDPR policy with strong rights, an account-level training opt-out, named retention windows, and a clear statement that it does not sell or run targeted advertising.

Assistant84/100· High confidence
Details
Claude icon

Claude

Anthropic

B

The strongest policy in the set, though consumer chats train by default, which caps it below A.

Assistant83/100· High confidence
Details
Cursor icon

Cursor

Anysphere

B

Does not train on your code by default, with narrow named exceptions; a strong privacy posture for a coding tool.

Productivity83/100· High confidence
Details
NotebookLM icon

NotebookLM

Google

B

Keeps user content out of foundational model training by default (only used if you send thumbs up or down feedback), lets you own generated content, and names a three-year feedback retention window.

Productivity81/100· High confidence
Details
Lovable icon

Lovable

Productivity

B

Does not sell data, names SCCs for transfers, and only uses anonymized data for model improvement with permission.

Productivity81/100· High confidence
Details
Grammarly icon

Grammarly

Productivity

B

An opt-out of AI training, a full rights suite and strong transfer safeguards; missing breach notice and a concrete deletion timeline.

Productivity80/100· Medium confidence
Details
Freepik icon

Freepik

Freepik Company (Magnific)

B

A detailed GDPR policy (Freepik now trades as Magnific) that deletes uploaded images right after generation and caps model-provider retention at 30 days.

Image & video80/100· High confidence
Details
PolyBuzz icon

PolyBuzz

Companion

B

A companion app that states it does not sell user information and gates access at 18, with clear rights.

Companion78/100· High confidence
Details
ChatGPT icon

ChatGPT

OpenAI

B

Full rights suite and a 30-day deletion window; trains by default with a clear opt-out.

Assistant76/100· High confidence
Details
Suno icon

Suno

Audio

B

Does not sell data and grants deletion rights, but trains its music models on user submissions without a clear opt-out.

Audio76/100· Medium confidence
Details
Perplexity icon

Perplexity

Perplexity AI

B

A concise policy that still grants real rights, and it scores on substance rather than length.

Assistant74/100· High confidence
Details
Kling AI icon

Kling AI

Kuaishou

B

Solid regional protections for children and transfers, but the global policy stays silent on training use and synthetic-output marking.

Image & video74/100· Medium confidence
Details
VEED icon

VEED

Image & video

B

A detailed UK GDPR policy that limits AI training to free-tier uploads with a named opt-out, grants the full rights suite, and does not sell personal data, held back by vague retention and generic security.

Image & video74/100· High confidence
Details
Canva icon

Canva

Productivity

B

Named AI-training opt-out and mature rights; sharing data with ad partners is the drag.

Productivity73/100· High confidence
Details
Remini icon

Remini

Bending Spoons

B

A GDPR-grounded policy that trains on user images only with explicit opt-in, names standard contractual clauses, and gives a full rights flow, though its own retention figures contradict each other (1, 14, and 15 days).

Image & video73/100· High confidence
Details
Gemini icon

Gemini

Google

B

A 'Keep Activity' toggle stops training; long default retention and human review weigh it down.

Assistant72/100· High confidence
Details
FaceApp icon

FaceApp

Image & video

B

Photos are not used for training and auto-delete within 48 hours, but a perpetual licence to user feedback trips a dealbreaker flag.

Image & video72/100· High confidence
Details
Genspark icon

Genspark

Assistant

B

States it does not train AI on user data beyond the requested service, does not sell, and deletes within 30 days.

Assistant72/100· High confidence
Details
ElevenLabs icon

ElevenLabs

Audio

B

Treats voiceprints as biometric data with a named retention limit; trains on voice data.

Audio71/100· High confidence
Details
Microsoft Copilot icon

Microsoft Copilot

Microsoft

C

The shared Microsoft policy allows training but is thin on Copilot-specific retention, deletion timelines and output ownership.

Assistant69/100· Low confidence
Details
QuillBot icon

QuillBot

Learneo

C

A detailed multi-service policy that uses your inputs to improve its AI models, paired with a full rights suite and named transfer safeguards.

Productivity69/100· Medium confidence
Details
Facemoji icon

Facemoji

Image & video

C

Discloses strong rights and concrete retention numbers, but it sells personal information for advertising (with an opt-out) and collects biometric face scans with no governance regime.

Image & video69/100· High confidence
Details
Picsart icon

Picsart

Image & video

C

A thorough rights-and-retention policy with standard contractual clauses named, but it predates the AI features and never addresses model training.

Image & video68/100· Medium confidence
Details
Candy.AI icon

Candy.AI

EverAI Limited

C

A detailed GDPR notice with a full rights suite and named retention windows, but it trains its models on companion chats by default with only a general objection right and stays silent on marking AI-generated media.

Companion68/100· High confidence
Details
Kimi icon

Kimi

Moonshot AI

C

Grants a full set of GDPR-style rights and says it does not sell data. It also trains on your content by default with no opt-out, and retention is vague.

Assistant67/100· High confidence
Details
CapCut icon

CapCut

ByteDance

C

Trains its models on user content and is light on a no-sell commitment, though it says face and body data is not used to identify you.

Image & video67/100· High confidence
Details
Higgsfield icon

Higgsfield

Image & video

C

Openly says it trains its algorithms on your prompts and uploads with no opt-out, but balances that with named deletion windows and a full rights suite.

Image & video66/100· Medium confidence
Details
PixVerse icon

PixVerse

PixVerse (AISphere)

C

Names a no-sale commitment, standard contractual clauses, and one-shot facial-data deletion, but it trains on your content by default and reserves a free, worldwide, perpetual and sublicensable licence to it.

Image & video66/100· High confidence
Details
Meta AI icon

Meta AI

Meta

C

Graded on the shared Meta privacy policy: your AI interactions help develop Meta's AI and AI for third parties, with no training opt-out named.

Assistant64/100· Medium confidence
Details
Hypic icon

Hypic

Image & video

C

Names strong rights, transfer safeguards, and careful face-data handling, but it trains its models on your content by default with no opt-out and keeps retention vague.

Image & video64/100· High confidence
Details
Ideogram icon

Ideogram

Image & video

C

Trains the models behind its service on your data as a legitimate interest with no opt-out, but commits clearly to never selling or sharing personal information.

Image & video63/100· Medium confidence
Details
Midjourney icon

Midjourney

Image & video

C

Users own their images but grant Midjourney a perpetual licence to reuse them, and prompts and outputs train the model unless declined.

Image & video62/100· High confidence
Details
Manus icon

Manus

Assistant

C

A recent agentic-assistant policy with solid transfer and advertising controls, but it never says whether your tasks and prompts train any model.

Assistant62/100· Medium confidence
Details
Brainly icon

Brainly

Brainly sp. z o.o.

C

Explicitly promises not to train models on personal data, grants a full rights suite, and names standard contractual clauses, held back by no security, breach, or retention detail.

Productivity62/100· High confidence
Details
Character.AI icon

Character.AI

Character Technologies

C

Better rights disclosure than most companion apps, but data is shared for advertising.

Companion60/100· Medium confidence
Details
Photomath icon

Photomath

Google

C

Photomath spells out a full set of GDPR-style data-subject rights and a clear no-sale commitment. On a legitimate-interest basis with no opt-out, it also uses captured images and feedback to improve its service and affiliate machine vision technologies. Retention periods are not specified, and there is no breach-notification clause.

Productivity60/100· High confidence
Details
Talkie icon

Talkie

Talkie AI

C

Grants full data rights and maps each purpose to a legal basis, but never says whether conversations train its models and keeps retention vague while sharing browsing data with advertisers.

Companion59/100· High confidence
Details
Cutout.Pro icon

Cutout.Pro

Image & video

C

States plainly that it does not train on uploads and does not share data, and gives short numbered retention windows. It says nothing about portability, breach notice, certifications, or versioning.

Image & video59/100· Medium confidence
Details
DeepSeek icon

DeepSeek

Hangzhou DeepSeek AI

C

Solid rights, but data is stored in China with only vague transfer safeguards.

Assistant57/100· High confidence
Details
Gamma icon

Gamma

Gamma Tech, Inc.

C

Grants a full slate of European data rights and names standard-form contracts for transfers, but it trains its AI models on your data with no opt-out and names no retention period or specific security controls.

Productivity57/100· High confidence
Details
Qwen icon

Qwen

Alibaba

C

Scored on Alibaba Cloud's generic policy, which grants core rights and names transfer safeguards but omits any AI-specific disclosure.

Assistant57/100· Medium confidence
Details
Grok icon

Grok

xAI

D

Trains by default with no general opt-out, and no 'we don't sell' statement.

Assistant54/100· High confidence
Details
Hugging Face icon

Hugging Face

Productivity

D

This dated, GDPR-aware policy names a full subprocessor list and grants access and deletion rights. It says nothing about AI training inputs, output ownership, retention periods, or portability, which places it in the D band. No adverse reservations are present, so no dealbreaker flags apply.

Productivity49/100· High confidence
Details
Janitor AI icon

Janitor AI

JanitorAI Inc.

D

Grants real rights and doesn't sell, but stays silent on training, retention, and breaches.

Companion47/100· Medium confidence
Details
Civitai icon

Civitai

Image & video

D

A short 2024 policy that explains what it collects and shares but stays silent on AI training, retention periods, formal data rights, and labelling of generated images.

Image & video46/100· Medium confidence
Details
Pixelcut icon

Pixelcut

Image & video

D

A generic compliance policy with a full set of data rights, but it never mentions AI at all: nothing on whether your images train models or whether outputs are marked.

Image & video45/100· Medium confidence
Details
SeaArt icon

SeaArt

Image & video

D

A 2023 policy that spells out a full set of data rights but stays silent on whether prompts and generated images train its models, with only vague retention and security.

Image & video44/100· Medium confidence
Details
Poe icon

Poe

Quora

D

Poe lets third-party developers train on user chats and shares data with ad platforms, with no user control over either.

Assistant42/100· Medium confidence
Details
CrushOn AI icon

CrushOn AI

CrushOn

F

A thin template policy: deletion rights are stated, but training use, retention, output ownership and security are all absent.

Companion32/100· Low confidence
Details
SpicyChat icon

SpicyChat

Companion

F

A thin policy that grants deletion and an 18-plus gate but is silent on training, retention, sharing and security.

Companion21/100· High confidence
Details

How we grade

Every app is scored across seven data-governance domains on a transparent 10-point scale, with each grade anchored to a quoted clause. Scoring is automated and reproducible: a fixed prompt at temperature 0, rubric version 1.2.

Read the full methodology

Assessed 2026-06-20. Scores reflect each policy as captured on that date; policies change.

AI app data privacy ratings: ChatGPT, Claude, Gemini & more | VerifyWise