SpicyChat AI Safety Rating Index

Safety Score 20 / 100
Score last updated: March 30, 2026 Last reviewed: March 30, 2026 v2 How we rate

Score Breakdown

  • Data Privacy 12/100
  • Emotional Safety 31/100
  • Age Appropriateness 14/100
  • Content Safety 31/100
  • Transparency 31/100
  • User Control 12/100

Key Safety Findings

SpicyChat AI is an NSFW-focused AI companion and roleplay chatbot platform operated by NextDay AI USA Inc. (Montreal) and NextDay AI EU Ltd. (Cyprus). The platform attracts roughly 32.4 million monthly visits and uses more than 10 different AI models across subscription tiers ranging from free to $24.95 per month.

The platform operates entirely outside both major app stores. Apple removed the SpicyChat iOS app in August 2025 for guideline non-compliance, and no confirmed official Google Play listing from NextDay AI exists. This eliminates all app store code review, billing oversight, and data handling scrutiny that other companion apps are subject to.

Privacy practices raise serious concerns. The privacy policy is hosted as a JavaScript single-page application that does not render for scrapers or accessibility tools, making it structurally harder to audit than competitors with static policy pages. Conversations are stored on servers without end-to-end encryption. Data is shared with unnamed “business partners” and routed through an undisclosed number of AI model providers. The platform uses Segment (a customer data platform that routes user data to multiple downstream services), Google Analytics, Beamer, and Tapfiliate trackers. Users have reported cross-chat data leakage where information shared in one private conversation appeared in a separate chat session.

A March 2024 security incident saw a hacker change approximately 1,600 usernames across roughly 15,000 bots. SpicyChat staff stated chat data was not compromised, but questions about email exposure went unanswered. A Trustpilot reviewer separately reported receiving support contact via an email address they never provided to the platform.

Age verification varies by region. Self-declaration (18+ affirmation) is required for all users. Third-party video selfie and ID verification is mandatory in 26 jurisdictions (France, UK, and 24 US states). However, VPN bypass of this verification is widely documented, with published guides specifically teaching circumvention. No verification exists in regions without mandates. No parental controls, no documented CSAM detection systems, and no NCMEC reporting mechanisms were found.

The platform has no crisis detection, suicide prevention, mental health resource referrals, break reminders, session limits, or digital wellbeing features of any kind. Community guidelines explicitly ban underage content, non-consensual activities, and hate speech, but private chats are largely unmoderated and SFW-labeled bots can still produce NSFW content.

How We Scored This

We scored SpicyChat AI using 28 evidence sources collected on March 30, 2026:

  • Privacy policy and terms of service from spicychat.ai. Both are hosted as JavaScript single-page applications that do not render for scrapers, so we relied on third-party extractions and cached descriptions (Tier 1)
  • Community guidelines, FAQ, age verification documentation, and iOS app notice from docs.spicychat.ai (Tier 1)
  • Corporate records: LinkedIn company profile, CB Insights profile, and Cyprus company registry for NextDay AI EU Ltd (Tier 1-2)
  • App store data: Pre-removal iOS App Store reviews (app removed August 2025 for guideline non-compliance) and Trustpilot reviews (Tier 2)
  • Independent safety analyses from AIGirlfriend.WTF, AICompanionGuides, AI Tipsters, Spiced AI, and an independent consent analysis (Tier 2-3)
  • Community reports: Six Reddit threads from r/SpicyChatAI covering the March 2024 security incident, data privacy concerns, cross-chat data leakage, and age verification bypass (Tier 4)

We scored all 23 sub-dimensions on a 1-to-5 scale using a weighted formula across six categories. Three sub-dimensions hit the floor score of 1 with 3x weight each: crisis response (no mental health safety infrastructure despite facilitating intimate AI interactions at scale), minor-specific safeguards (no parental controls, platform operates entirely outside app stores), and minor content moderation (private chats largely unmoderated, no documented CSAM detection). Any one of these alone caps the maximum grade at B-. The base weighted average of 1.76 already yields an F grade and Red tier, so the caps do not lower the grade further.

Data privacy drove the lowest dimension score at 1.3/5. No end-to-end encryption, conversations stored in readable format, a March 2024 security incident with incomplete disclosure, and data shared with unnamed “business partners” through an undisclosed number of AI model providers.

This is version 1 of the SpicyChat AI safety score, published March 30, 2026. For the full methodology, including how we weight each dimension and when override rules apply, see How We Rate.