All apps

Is Candy.AI safe with your data?

C
Candy.AI icon

Candy.AI

53/100

Partial disclosure · high confidence

Candy.AI earns a C (53/100) because it discloses its data practices only in part.

Dealbreaker flag

  • D1.1: train and develop our AI models and moderation technologies; prepare datasets for further training
  • D1.4: you grant to us a non-exclusive, royalty-free, fully paid-up, transferable, sub-licensable, worldwide, perpetual license

#89

of 211 apps ranked

53

score · Companion avg 35

+18

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Candy.AI trains its AI models on user conversations with no opt-out and takes a perpetual sub-licensable licence over user input, while offering a standard set of GDPR rights, a named three-year account retention period and a named DPO.

What Candy.AI's privacy policy and terms of service say about your data

Training with no opt-out

The purposes table commits to "train and develop our AI models and moderation technologies" and to "prepare datasets for further training". No opt-out or opt-in mechanism appears anywhere in either document.

Perpetual sub-licensable content licence

Terms section 4 grants EverAI a "sub-licensable, worldwide, perpetual license" to "commercialize, and otherwise use" user input. That sits alongside a statement that users retain ownership, which the licence effectively overrides.

Deletion timing has no fixed deadline

The deletion-after-closure clause says only that data is removed "without undue delay". No timeline or number is given.

No labelling of AI-generated output

"Some content in our Services is AI-generated and created on demand" appears as an accuracy disclaimer in the no-guarantee section. Neither document describes any watermark, label or marking for synthetic output.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: your ownership of generated outputs

Candy.AI privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inAdverse
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsAdverse
Data-subject rights4 of 5 disclosed
Grants a right to access your dataDisclosed
Grants a right to delete your dataPartial
Offers data portability in a usable formatDisclosed
Grants a right to correct your dataDisclosed
Grants a way to object to or opt out of processingDisclosed
Retention and deletion1 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestPartial
Sets a shorter retention for AI conversation logsDisclosed
Commits to collecting only the data it needsPartial
Third-party sharing1 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementSilent
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersPartial
States a standard for government and law-enforcement accessPartial
Transparency3 of 5 disclosed
Discloses that you are interacting with AIDisclosed
Marks AI-generated or synthetic outputSilent
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesDisclosed
Is versioned and dated, with change noticePartial
Sensitive data and children1 of 2 disclosed
Discloses automated decisions and a human-review pathNot applicable
Limits the use of special-category dataPartial
Governs biometric data specificallyNot applicable
States protections for children's dataDisclosed
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Companion
Modalities
text, image
Processes biometrics
No
Policy last updated
2026-07-30
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Candy.AI safe with your data? Grade C | AI App Trust & Transparency Index