How we test Privacy
We use a paid test account and review the platform’s privacy policy, terms, help pages, and account settings.
First, we look for clear answers about AI training, human review, third-party sharing, advertising, and how long different types of data are stored.
We then use the test account to try deleting chats, deleting the account, removing personal data, opting out of training, and exporting our information.
For security, we check which types of encryption the company clearly confirms, try to enable two-factor authentication, and check whether the billing name is shown before payment.
We also search for confirmed security incidents from the previous five years. We only count incidents supported by the company, a regulator, a court filing, or a reliable security report.
Finally, we contact support with a real question and rate how easy it is to reach them, how quickly they reply, and whether the answer actually helps.
Important limitations
We cannot look inside a company’s private systems. We can only test the controls available to users and check what the company clearly says in its policies and help pages.
When a company does not explain something, we record it as Unknown. Unknown does not automatically mean the app is unsafe, but it also does not give us proof that your data is protected.
Privacy policies can change at any time. Our results show what the platform said and offered on the date we tested it.
Not finding a past security incident does not guarantee that a platform will never have one. It only means we did not find a confirmed incident within the period we checked.
Support is tested using one real request. Your experience may be different depending on the question, time of day, or support agent.