

candy.ai
By Candy.ai
Account setup and access: Go to candy.ai on web or mobile, click Sign Up, register with email or Google/Apple/Discord, confirm you are 18+, and verify your email; this typically takes under 3–5 minutes.
First companion and basic use: Choose a pre‑made AI companion, answer a few preference questions, and start text chatting to understand tone, memory, and the free‑tier limits (about 50 messages and a couple of images/voice replies); most users are comfortable within 30–60 minutes.
Custom character and feature exploration: Create your own AI by configuring looks, personality, relationship style, and then test image generation, voice, and basic roleplay following tutorials; this tuning phase usually happens over a few hours across the first 1–3 days.
Candy.ai can be customized quite deeply at the character and interaction level, but it is explicitly positioned and licensed as a personal, non‑commercial companion app rather than a business platform.
The built‑in character builder lets you design companions from scratch: you can set age range, ethnicity, body type, hairstyle, eye color, outfits, personality traits, humor and empathy levels, flirtiness, and even voice profile, effectively creating role‑specific personas (for example, “supportive coach,” “playful girlfriend,” or “confident dom”).
Personality and behavior can be further tuned by adjusting tone, conversation style, boundaries, and preferred topics; over time, the system also adapts automatically based on your chats, so each user’s companion evolves in a different direction.
You can maintain multiple characters in one account, each with distinct looks, traits, and emotional styles, and switch between them or run separate “relationships” in parallel.
Visual customization tools and NSFW imaging let you control clothing, poses, and scenarios for each character, which some creators repurpose informally for storyboarding, concept art, or content‑ideation workflows.
From a technical‑stack perspective, there are “Candy AI clone” and white‑label solutions (for example, Scrile AI, Candy AI Script, Candy AI Clone) that mimic Candy’s architecture—LLM chat, memory, voice, video, payments, and APIs—allowing businesses to launch their own branded companion platforms with deeper integration and commercial rights.
Candy.ai mainly offers self‑serve tutorials, basic customer support, and community feedback rather than formal training programs. New users can rely on third‑party “ultimate tutorials” and full walkthroughs on YouTube and specialist blogs that cover account creation, subscription, character building, image generation, and roleplay tips in a step‑by‑step format designed for beginners. These guides show how to create companions, tune personality and appearance, use the image generator, and manage tokens, effectively functioning as informal onboarding and ongoing “training” for new users.
For direct help, Candy.ai provides a support email ([email protected] or support@candy‑ai.com, depending on property) and a contact form/help center where users can open tickets about billing, account access, and technical issues, with complaint‑policy language committing to prompt, confidential handling of concerns. A separate Candy AI Network support page mentions email, live chat during business hours, and a ticket system with an expected 24‑hour response window, plus community forums and social channels (Twitter, YouTube) where users can ask questions, watch tips, and follow product updates. Public review sites like Trustpilot show mixed satisfaction with support speed and refunds, but they confirm that human customer service is available rather than the product being purely self‑serve.
Candy.ai positions itself as a “private, safe” AI companion and implements multiple technical security measures around user data, though analysts still recommend caution with very sensitive information. The privacy notice and independent tests state that all traffic between users and Candy’s servers is protected with HTTPS/TLS 1.3, and that data at rest is encrypted using industry‑standard AES‑256 with secure key management, meaning chats, images, and account details are encrypted both in transit and on disk to reduce the risk from interception or data‑center breaches. External encryption reviews report an A+ TLS rating and confirm that payments (card, PayPal, crypto) go through PCI‑compliant processors with discrete billing descriptors, so bank statements do not reveal the nature of the service.
Access to stored data is restricted with role‑based access controls, so only specific staff can view limited subsets of information, and the platform claims to run continuous security monitoring plus regular security updates to detect and block suspicious activity. The privacy notice lays out retention windows—roughly 3 years for account data after last activity, up to 7–10 years for financial records due to tax rules, and shorter periods or revocation‑based retention for marketing data—and grants GDPR‑style rights to access, delete, or object to processing, with third‑party services such as YourDigitalRights.org usable to file deletion and data‑export requests. Candy.ai’s marketing site further asserts that chats are encrypted, “never shared,” and not used to train public models, and some deep‑dive reviews say they found no evidence of data breaches or obvious misuse so far.
Candy.ai treats you as the owner of your personal data but takes a very broad license over anything you input or generate, and it offers GDPR‑style rights (including portability) rather than business‑grade data‑ownership guarantees.
Personal data (email, profile info, prompts that identify you, etc.) is treated as your personal information under data‑protection law, with the service acting as controller for processing.
All “Content” (your inputs and the AI outputs) remains yours in the sense that you must have rights to upload it, but the Terms say that when you use the service you grant Candy.ai a non‑exclusive, royalty‑free, fully paid‑up, transferable, sublicensable, worldwide, perpetual license to use, modify, copy, display, commercialize, and create derivative works from that content for any purpose, as long as this is consistent with the Privacy Notice.
This means Candy.ai can reuse chats, images, and other generated media internally (e.g., improving models, moderation) and potentially in commercial ways, while you do not receive exclusivity or revenue share.
The license explicitly covers using, distributing, modifying, uploading, translating, exploiting, aggregating, and commercializing your content and its derivatives, which is much broader than a narrow “hosting only” license.
The Privacy Notice states that data may be shared with service providers (hosting, analytics, payments, moderation) and legal authorities where required, but it also says Candy.ai does not sell personal data to third parties in the sense used by CCPA/GDPR.
Moderation and safety sections note that user content may be subject to human review if flagged, so some staff can see specific conversations or media when necessary for policy enforcement.
Under section 9.5 (or equivalent) of the Privacy Notice, Candy.ai gives you a right to data portability: you can ask for the personal data you provided to be supplied in a “structured, commonly used, machine‑readable format,” or to have it transferred directly to another controller.
This right applies where processing is based on consent or performance of a contract and is carried out by automated means, aligning with GDPR portability rules.
Practically, this means you can request an export of your account and personal data; public guidance suggests this typically covers profile data, some logs, and possibly chat history, though implementation details (format, fields) are not exhaustively specified.
You can request access, rectification, erasure, restriction, objection to certain processing, and withdrawal of consent, plus lodge complaints with supervisory authorities.
Deletion/erasure requests do not automatically revoke the broad IP license already granted for past use, but the privacy policy says processing must remain consistent with data‑protection law and retention limits (e.g., keeping billing data for legal reasons).
Cookies and tracking notices repeat that you can request portability and deletion for personal data collected via tracking technologies, again within the limits of legal bases and technical feasibility.
A separate Content Removal Policy allows you (or third parties) to ask Candy.ai to remove content that may unintentionally resemble real individuals, which is more about likeness/IP/safety than raw data control but can affect what they retain or display.
Candy.ai uses auto‑renewing subscriptions with very tight, token‑based refund rules, and cancellation only stops future renewals rather than ending access immediately.
Subscriptions (monthly/annual) renew automatically at the end of each billing period at the price and duration shown at checkout.
The renewal charge is processed automatically on the first day of the new period using the stored payment method.
There is no pro‑rated or partial‑period refund just because a subscription renewed; renewal is considered acceptance of a new full period.
Auto‑renewal can be turned off at any time in the account/subscription settings; users can also cancel by contacting support or opening a Discord ticket.
When you cancel, you keep full paid access until the end of the current billing period, then the account reverts to the free tier.
At the end of that period, all remaining tokens attached to that subscription expire, cannot be carried over, and are not refunded.
For subscriptions and non‑token purchases, you can request a refund only within 24 hours of payment, and only if you have used 20 tokens or fewer; beyond either limit, the refund is denied.
For token‑only purchases, you can request a refund only within 24 hours and only if no tokens have been used; once any tokens are consumed, no refund is available.
Refunds are only processed for card payments; other payment methods (e.g., some local methods) are typically ineligible.
Technical issues on the user’s side (device, connection, configuration) are explicitly excluded from refund eligibility.
Users in the EU or UK have a statutory right to withdraw from the contract within 14 days of the initial purchase without stating a reason.
In that case, Candy.ai will reimburse all payments minus a pro‑rated amount reflecting services already used between purchase and withdrawal; the refund should be issued within 14 days, using the same payment method unless agreed otherwise, with no extra fees.
After cancellation takes effect at period‑end, your account remains, but you lose access to premium chats, media, and other paid features, and expired tokens cannot be reactivated later.
You can resubscribe at any time, but each new subscription starts with its own token allotment; unused tokens from past, canceled periods never carry over.
Candy.ai frames its compliance primarily around major data‑protection and online‑safety laws (not enterprise certifications), with a focus on GDPR/CCPA‑style obligations, age/underage rules, and content/IP regulations.
The privacy notice states that user data is handled under “Applicable Data Protection Law,” explicitly listing GDPR, the Swiss FADP, the CCPA as amended by CPRA, and the Virginia Consumer Data Protection Act, among others.
Processing activities (account creation, provision of the service, analytics, moderation, legal compliance) are all mapped to legal bases such as consent, performance of a contract, legal obligation, and legitimate interest, in line with GDPR‑style frameworks.
The policy grants GDPR‑like rights: access, rectification, erasure, restriction, portability, objection to certain processing, and the right to lodge complaints with supervisory authorities, plus CCPA‑style rights around disclosure, deletion, and non‑sale/non‑sharing of personal information.
It also references compliance with lawful requests and court orders, indicating processes for handling government or law‑enforcement data demands consistent with these data‑protection laws.
Community Guidelines and Underage Policy impose a zero‑tolerance stance on underage content, require users to comply with local laws, and explicitly ban any content that exploits or depicts minors, with commitments to report such behavior to authorities where required.
Moderation and complaint policies describe rapid removal of illegal content and escalation pathways, aligning with emerging platform‑safety expectations (e.g., EU and US guidance on handling CSAM and harmful material), even if they are not branded under a specific standard.
A dedicated DMCA Policy confirms alignment with the U.S. Digital Millennium Copyright Act, laying out notice‑and‑takedown procedures for alleged copyright infringement.
Legal information pages highlight respect for intellectual‑property rights and reference standard copyright laws as part of the service’s terms.
A related “Candy AI Network” legal‑compliance page (for a separate but similarly named tool) claims compliance with GDPR and CCPA, and asserts that it does not collect, share, or sell personal data, plus adherence to general software‑distribution and security guidelines.