Yes, according to Character.AI's own pages. They retain certain data you share with them to train and improve their generative AI models, they take steps to reduce personal information in that set first, and if you are in the EEA or the UK you can turn off "Improve the Model for Everyone." That opt-out is regional. It covers new chat content used to train generative models. It does not, on their wording, stop them using your data for search, recommendations and safety classifiers, and it does not unsay the years of collection already described in their training-data documentation.
The rest of this page is what other major companion products publish about the same question, opened on 19 Sep 2026, plus how to read a privacy policy so a slogan does not stand in for a sentence. We make one of the products in the list. Factor that in. Every claim about somebody else is a quote or a close paraphrase of a first-party page, with the URL beside it. We cannot audit what any of them actually do with a chat after it is sent. We can read the contract they posted.
How to read the policy, not the homepage
- Search the privacy policy for "train", "improve our models", "machine learning", "anonymiz", and "de-identif". Homepages say "private." Policies say what "private" was allowed to mean. A sentence that only says they do not sell your information is not an answer to this question.
- Note who receives the text in order to reply. A product can refuse to train its models and still send de-identified conversation text to a third-party language-model provider so that a reply can be generated. Those are different sentences. Both matter.
- Note whether an opt-out is global. Character.AI's model-training page gives click-path steps for the EEA and the UK. If you are not in those regions, that page does not give you those steps.
- Note what survives deletion. Several policies keep a "training archive" or de-identified pool after an account is gone, and say it is no longer attributable to you. That is not the same as "deleted."
- If the product is a local app talking to a hosted model, read both halves. SillyTavern's own FAQ is explicit: a paid web model logs everything on that company's server; a model you run on your PC stays on the PC.
Do not treat a help-centre paraphrase, a Reddit AMA, or a review blog as the policy. The pages below are the operator's.
What the operators publish
Checked 19 Sep 2026. Policy dates are theirs.
Character.AI. About our Model Training says they retain certain data you share to help train and improve their AI models, and that they reduce personal information before using data to train generative models. The EEA/UK opt-out is "Improve the Model for Everyone," under Data & Privacy on the app and under Account → Manage Account & Data → Model Improvement on the web. After you opt out, "new content will not be used to train our generative AI models." They still "may use your data to improve other aspects of our services like search, recommendations, and safety classifiers." Their Training Data Documentation (updated 11 Mar 2026) says generative systems use, among other sources, "text content and interaction data from users," and that they started collecting and using data for model development in 2021.
Replika. Privacy policy (last updated 27 May 2026). Two separate claims, and they should stay separate. Small portions of messages and content, plus feedback, are "immediately anonymiz[ed]" to "train our proprietary safety algorithms, enhance chatbot performance, prevent inappropriate outputs, and ensure compliance with safety standards." That anonymized data "is used only internally and is not used to train third-party large language models." Separately, conversation data is sent to third-party AI language-model providers "solely to generate conversational responses," after de-identification and data minimization, and those providers are contractually required not to use the data to train their own models. Conversation content is not used for marketing or advertising. "Allowing your AI companion to learn from your interactions to improve your conversations" is listed as core functionality — that is personalization of your companion, not the same sentence as the safety-algorithm line. Do not flatten them.
Nomi. Privacy policy (last updated 27 Apr 2026). They encourage you not to put personally identifiable information into chats or customisation. Account deletion removes personal information "within 28 or so days," except "information that is in our training or communications archives or necessary to a legal proceeding or order." "Upon deletion, any information in our training archives would no longer be attributable to you." Their own wiki, Are Nomi conversations private?, says Nomis in aggregate use information from chats to learn, with names removed: thumbs-up and thumbs-down style learning, described as "A Nomi said X to a human" rather than a named pair. That is Nomi describing Nomi. It is not a lab test of ours.
Kindroid. Legal (terms last updated 3 Mar 2026; privacy policy effective 28 Jun 2024). We did not find a first-party sentence that says identifiable chats train their models, and we did not find a training-specific opt-out. What the terms do say, under Private User Content: they may "de-identify and/or aggregate your Private User Content … and freely use such de-identified and/or aggregated content for any purpose." The privacy policy says they may create aggregated, de-identified or anonymized data from personal data they collect and use it "to analyze, build and improve the Services," without disclosing it in a way that could identify you. "Any purpose" and "improve the Services" are broad. They are not the same as Character.AI's "train our generative AI models." Do not upgrade them.
SillyTavern. Not a hosted companion. Their FAQ splits the privacy question by which model you pointed the app at. Paid web services: "Everything is logged on their server. Privacy concerns." Self-hosted models on your PC: "Total privacy. Everything you write stays on your own PC." The app stores chats and API keys in a local data directory. If you use SillyTavern as a window onto someone else's API, their policy is the one that applies to the text.
YanMate. Our privacy policy: "We never train models on your conversations." We also do not build a profile of you from conversations for recommendations. Every model that reads your messages or writes a reply runs on Cloudflare Workers AI; there is no call to OpenAI, Anthropic or Google with your conversation in it. The one exception is speech: when a reply is spoken aloud, the text of that reply goes to Fish Audio to become audio. Fish receives the words being spoken and nothing about your account, and its terms of use let it use text it receives to develop and train its own models, so a reply that is spoken aloud may end up in Fish's training data. Your own messages and your voice never go to Fish. Export and deletion are self-serve from account settings. Ads, if they ever load on the free tier, are not allowed inside a conversation, a call or the memory ledger.
What goes wrong when you only read the slogan
"We don't sell your data" as a training answer. Nomi, Replika and Character.AI all have some version of not selling personal information. Character.AI still trains. The sale sentence and the training sentence are neighbours, not synonyms.
Treating a regional opt-out as a global off switch. Character.AI's click path is written for the EEA and the UK. If the page you are reading does not give a path for your region, do not invent one.
Treating "anonymized" as "not used." Replika anonymizes portions in order to train safety algorithms. Nomi's training archives survive deletion in de-identified form. Kindroid's de-identified private content may be used for any purpose. Anonymization is a processing step. It is not a refusal.
Treating a local UI as a local model. SillyTavern is the clean example, and they wrote it down themselves. The frontend can be on your machine while every prompt is logged at the API you configured.
Treating our "never" as a claim about other people. It is a claim about this product, checkable against the privacy page. It is not evidence that a competitor does the same.
Honest limits
We opened the pages above on 19 Sep 2026. Policies move. If a URL here 404s or a sentence has been rewritten, believe the live page.
We did not open Talkie, PolyBuzz, Chai or Janitor AI for this article. Those products have comparison pages on this site for other axes — catalogues, bans, API keys — not for training. Filling them in from memory would be the failure this page is supposed to prevent.
We cannot see inside anyone's training set. A policy that says "we take steps to reduce personal information" does not tell you which steps, or whether a name you typed survived them. The practical advice is the one Nomi and Kindroid both give in different words: do not put in a chat anything you cannot stand being processed.
A thumbs-up on Character.AI is, on their model-training page, still something they may use after you opt out of generative training. Feedback is often carved out. Read that carve-out.
Our own page used to describe analytics as "self-hosted or EU-hosted" when it was neither. That is now written into the privacy policy as a correction rather than a quiet reword, because a page that only ever described its best state would not be worth checking. Hold every other operator to the same standard, including us the next time this guide is due a refresh.
If you are leaving Character.AI more than asking this question, take your characters with you first — scroll the chats, then export. A wider product table, not a training table, is the Character.AI alternatives comparison. The wound-specific pages are Replika, Nomi and Kindroid. The FAQ is our short answer for YanMate. This page is the sourced one.