Candy AI Safety Rating Index

Safety Score 25 / 100
Score last updated: May 16, 2026 Last reviewed: July 8, 2026 v7 How we rate

Score Breakdown

  • Data Privacy 22/100
  • Emotional Safety 41/100
  • Age Appropriateness 12/100
  • Content Safety 31/100
  • Transparency 22/100
  • User Control 41/100

Key Safety Findings

Candy AI earned a D/25/Red rating across our 23-dimension analysis, completed in March 2026. Five sub-dimensions scored 5 out of 100. Together, they describe a platform handling adult content at scale without the safety infrastructure that role requires.

The most significant concern for everyday users is data collection. Candy AI’s privacy policy (revised March 9, 2026) states that conversation content may be “aggregated, anonymized, and/or de-identified” for AI training and explicitly documents “human review of de-identified and/or anonymized interactions” during dataset preparation. On a platform whose primary product is adult content, that means intimate conversations may pass before human reviewers, even in nominally anonymized form. Users who understand that fact can make an informed choice. Users who don’t know about it can’t.

Third-party data sharing scored equally low. The same policy states that third-party LLM providers and hosters “may receive the content of your messages exchanged with our chatbot.” EverAI does not name which providers receive this data, nor what controls apply on the receiving end.

Automated web tracker analysis reinforces these data privacy concerns. Blacklight detected Hotjar session recording on candy.ai, which captures mouse movement, clicks, and scrolls as video replays. On a platform built around adult conversations, session recording means every interaction with intimate content can be replayed by third-party analytics staff. The site also runs a TikTok Pixel with “advanced matching” that sends visitor data to TikTok even when users block cookies, Google Analytics with remarketing audiences that follow users across the internet with targeted ads, 8 ad trackers (above the Blacklight 7-site average), and 7 third-party cookies from companies including ByteDance and Tapad. No known data breaches appear in the Have I Been Pwned database, but the tracking footprint itself is heavy for a platform handling this type of content.

Age verification scored 1 because the only entry gate is a self-reported checkbox affirming users are 18 or older. See our teen mental health guide for family-specific advice. The Underage Policy (revised October 2025) says the platform “may implement further measures” to verify adult users. “May implement” is not “has implemented.” For a service built specifically around adult content, a checkbox is a structural gap, not a verification system.

Crisis response scored 5/100. There’s no automated distress detection and no crisis helpline integration. When a user expresses emotional distress, the platform delivers a generic disclaimer to “reach out to a qualified professional.” A documented Trustpilot review describes a user’s AI companion announcing a fabricated stage-4 cancer diagnosis mid-conversation. That incident is a direct consequence of what a 5/100 crisis response infrastructure looks like in practice.

Safety reporting scored 5/100. No public transparency report exists. EverAI has not published a statement explaining the August 2025 ban or what specifically changed before the platform’s return to operation.

Two sub-dimensions reach near the top of the framework. Therapeutic claims avoidance scored 100/100: the Terms of Service explicitly state the service is “for entertainment purposes only” and is not intended as emotional support. AI nature transparency scored 76/100: Community Guidelines state that all conversations are “entirely fictional” and AI companions “do not possess genuine emotions.” Both of these represent the strongest version of what responsible disclosure looks like at the policy level.

Data privacy practices vary significantly across companion apps. For a detailed analysis of how another major platform handles user data, see our Character AI privacy policy explained page. Candy AI also offers voice features. See how it compares in our best AI companion apps with voice ranking.

How We Scored This

Our safety analysis of Candy AI drew on 15 primary evidence sources, first gathered in March 2026 and re-verified in May 2026, analyzed against our 23-dimension framework under Score Engine v7.

Tier 1 sources (primary regulatory documents and official platform materials): Privacy Policy (rev. March 9, 2026), Terms of Service (rev. March 6, 2026), Community Guidelines (rev. March 6, 2026), Underage Policy (rev. October 2025), and the Australian eSafety Commissioner Age-Restricted Material Codes (in force March 9, 2026).

Tier 2 sources (verified independent review data): Trustpilot aggregate (237 reviews, 100 analyzed), RAIN AI Services review analysis (February 2026), a ScribeHow controlled 21-day memory test (February 2026), an AI Companion Guides five-month independent test (February 2026), and Nudge Security supply-chain profile data.

Tier 3 sources (media coverage, used only to corroborate dated events): reporting from BitcoinWorld, MEXC News, and Intellectia.ai on the August 2025 platform ban, and coverage of Australia’s age-verification rollout alongside the eSafety Commissioner’s own March 2026 enforcement announcement.

No auto-F sub-dimensions were triggered. The D safety grade reflects weighted scoring across all 23 sub-dimensions. Five sub-dimensions scored 5 out of 100: crisis response, data collection, third-party sharing, age verification, and safety reporting. The highest-scoring sub-dimension was therapeutic claims avoidance, at 100 out of 100. The initial analysis was completed on March 17, 2026, and the rating was refreshed on May 16, 2026 after a full evidence re-verification.

For full methodology, scoring criteria, and the 23-dimension rubric, see our how we rate page.

Should You Use Candy AI?

Candy AI is an adults-only platform, and our Red safety rating reflects real gaps rather than stylistic complaints. It is a poor fit for anyone under 18, since the only age gate is a self-reported checkbox. It is also a poor fit for anyone in active emotional distress, because there is no crisis detection and no helpline routing, and for anyone uneasy about intimate conversations being used to train AI models or shared with unnamed third-party providers.

Evidence snapshot:

Public scoreD/25/Red
Worst-scoring areasCrisis response, data collection, third-party sharing, age verification, safety reporting
Primary evidence15 sources, including Candy AI policy pages and Australia’s eSafety materials
Last evidence refreshMay 16, 2026

Before creating an account, check three things:

  • Data use: whether you are comfortable with how conversation data is stored, used for AI training, and reviewed by humans. We break this down in our full Candy AI review.
  • Real cost: what the monthly price works out to once token packs are added on top of the base subscription.
  • Your local rules: whether your country or state now regulates companion chatbots, which changes the protections you can expect.

If any of those give you pause, a safer alternative is the better starting point. Our verdict: Candy AI is capable on features, but its safety infrastructure does not match the sensitivity of what the platform handles.

Candy AI’s August 2025 Ban and Australian Enforcement

Candy AI’s regulatory history is part of why its safety rating matters. In late August 2025, multiple outlets reported that the platform was pulled offline over a mix of legal, safety, and ethical concerns, with weak age verification and content moderation cited as central issues. Coverage at the time described the service being de-listed from major distribution channels. EverAI, the Malta-based company behind Candy AI, brought the platform back with substantially revised policies, reissuing its privacy policy, terms of service, and community guidelines in early 2026.

The regulatory pressure has not eased. On March 9, 2026, Australia’s eSafety Commissioner brought its Age-Restricted Material Codes into force, requiring AI chatbots capable of generating explicit content to verify user ages or face penalties of up to A$49.5 million per breach. Weeks later, the regulator published a report finding that popular AI companions were exposing children to sexually explicit material. Candy AI’s own terms already point Australian users to eSafety, which signals awareness of the rule, yet the platform’s age gate remains a self-affirmation checkbox.

This is the gap our rating keeps returning to. A platform that has already been forced offline once, and now operates under active age-verification mandates, still relies on an honesty checkbox to keep minors out. For readers weighing the category, our comparison of Candy AI and Replika and our guide to the safest AI companion apps show how that approach stacks up against competitors.

Version History

Overall (initial score) Tier 1 — Primary source
39 25

Safety rating updated after evidence refresh and editorial QA.

Overall (initial score) Tier 4 — Observation
39

Initial safety assessment based on 23-dimension analysis of privacy policy, terms of service, app store data, user reports, and regulatory filings.