test log // 2026-10-07 cycle
AI Story App Privacy, Compared: What Each Platform Does With Your Stories
Answer first: privacy in AI story apps reduces to four questions, and every platform answers them in its terms, not its marketing. One: is your content used to train models? Two: who can read your sessions (human review, moderation pipelines)? Three: where does the data live and how does deletion work? Four: is there a local option where the answer to all three is "nobody"? The current answers: NovelAI states it does not train on user content. SillyTavern over local models keeps everything on your hardware, the only architecturally private option. Character.AI and the hosted chat class reserve review rights for moderation and safety. The authored tier (curated story platforms) is a conventional web service: standard account data, reading history, and the privacy upside that no generation logs exist because nothing is generated. Terms were checked this month; they change, and the checker re-runs monthly.
The comparison
| Platform | Training on your content | Human review | Local option | Deletion story |
|---|---|---|---|---|
| NovelAI | No, per its stated policy | Support-scale only | No | Account deletion path |
| AI Dungeon | Per policy and tier | Moderation for policy | No | Account deletion path |
| Character.AI | Policy reserves rights for improvement and safety | Review rights documented | No | Account and chat deletion, with quirks |
| Chai / Talkie class | Per policy | Moderation | No | Standard account deletion |
| JanitorAI | Depends on the model endpoint you use | Platform + model operator | No (hosted) | Per-operator |
| SillyTavern + local models | No: nothing leaves your machine | Nobody | Yes, by definition | Delete the files |
| Ouba (ouba.art) | Not applicable (authored) | Standard service staff | No | Standard account controls |
The four questions, applied
Training use. The highest-emotion question and the one with the clearest answers: NovelAI's positioning (no training on user stories) is long-standing and product-defining. The hosted chat class reserve broad rights to use content for service improvement and safety, which is the industry's standard language and covers more than most readers assume. The local stack ends the question: if the model runs on your hardware, there is nothing to send. The authored tier sits outside the question (no generation occurs), which is worth knowing when the requirement is "my stories are nobody's data."
Human review. Hosted platforms document rights to review content for moderation, safety, and abuse; the practical exposure is low-frequency and the policy exposure is broad. Readers who treat sessions as private journals should weight this row heavily; the local stack is the only answer with zero review surface, and NovelAI's support-scale exposure is the closest hosted approximation.
Data residence and deletion. Standard cloud answers across the hosted field: encrypted transit, stored sessions, account deletion paths with varying completeness (the chat platforms' documented quirk: deleting a chat and deleting an account are different operations with different residue). The local stack's answer is a file system. The authored tier's answer is conventional: account controls and support, with the same expectations as any reading app.
The local option. The only architectural answer, worth pricing honestly: SillyTavern (or any local UI) over a self-hosted model means prompts, stories, and state never leave the machine. The costs are hardware (a GPU that serves modern models), setup literacy, and maintenance. For readers whose threat model includes any of the above rows, the price is the product.
Practical hygiene, platform-independent
Six practices that dominate the marginal decisions. One: read the current terms at subscribe time; policy pages are the ground truth and reviews are archaeology. Two: separate identities: a story account's email needs no connection to your legal name or primary inboxes. Three: assume anything typed into a hosted platform could be read by a person; the terms say so, and the habit follows. Four: use the deletion tools you expect to rely on once, early, and verify. Five: keep private projects local from the start; retrofitting privacy is harder than starting with it. Six: payment metadata is identity; privacy coins and gift cards exist, and this site does not editorialize about your choices, only notes that the account email is not the only trace.
The honest framing
Three caveats keep this page honest. Policies change without notice, and this page is re-verified monthly for exactly that reason. Privacy is a spectrum, not a binary: NovelAI's posture and Character.AI's posture are both "cloud service" answers that differ in degree, while the local stack differs in kind. And the threat model matters: a reader protecting private journals and a reader avoiding training-data inclusion have different best answers, and this page's tables serve both without pretending they are the same reader.
One closing observation from the test desk: the privacy question keeps routing readers to the authored tier (curated story platforms included), not because those platforms are privacy products, but because readers discover that what they wanted was stories that are objects (saved, deletable, nobody's training corpus) rather than sessions in someone's model infrastructure. Verified October 2026.
Jonah Petrov is a former machine learning engineer who reads terms of service as part of platform testing and documents the privacy questions alongside the performance probes.