Skip to content
Messaging Agents

Do AI assistants train on your messages? Most will not say

26 of the 62 AI assistants you can text give no answer on training. 16 of those published a privacy policy and left the question out of it.

Of the 62 AI assistants catalogued here, 26 give no answer to the most basic question you can ask one: does it train on your conversations. Sixteen of those wrote a privacy policy and left the question out of it.

That is not a gap in the research. Every policy in the table below was fetched, read and dated, and the 10 products with nothing to read are counted separately.

What the policies actually say

What each listing’s privacy policy says about training on your conversations
AgentWhat its policy saysRead
States it trains on your conversations 4In its own words.
Boba“Developing, training, and fine-tuning models, algorithms, and artificial intelligence technologies”2026-09-06
Kachi“training and improving our own models on conversations and outcomes”2026-09-06
Sidekicks“Collected data may be used to: Operate and enhance the Service ... Train and refine AI systems”2026-09-09
Wajo“Developing, training, and fine-tuning models, algorithms, and artificial intelligence ("AI") technologies, including personalizing the AI Agent”2026-09-06
Trains unless you turn it off 3On by default, with a switch somewhere.
Arlo“A new adult account created from a server-verified U.S. location starts prospective participation by default”2026-09-09
Muse“If you do not want your data to be used in model training at all, you can opt-out via a simple switch in Muse settings.”2026-09-08
Poke“Improve and customize our products and services...including to train our artificial intelligence models. Data from users who select Maximum Privacy will not be used for model training”2026-09-06
Answers a narrower question 8True as written, and not the question a person asked.
222“improving the machine learning model we leverage to improve its ability to match you”2026-09-06
Bloome“We do not use your personal data to train general-purpose AI models”2026-09-09
Catch“AI vendors process data solely to handle requests and are contractually prohibited from retaining or training on it”2026-09-06
Flip“under contractual terms that prohibit using it to train their models”2026-09-09
Martin“our app does not use any google user data for developing, improving, or training ai and/or ml models”2026-09-06
Notis“Where feasible, we instruct providers not to use your data to train their models.”2026-09-06
Ollie“Message content may be reviewed or used in aggregate to improve Ollie's systems, with safeguards in place to protect user privacy.”2026-09-09
Tomo“We do not use your health data...to train or improve generalized...AI/ML models”2026-09-06
Trains a model that is only yours 1A distinct claim, made by one product.
Orchid“We don't train shared models on your data. We train your model on your data.”2026-09-06

20 state they do not train on your conversations: alfred_, allora, Beside, Bo, Caddy, folk, Iris, Juke, Lindy, Lucas, Matcha, Navi, Ori, Pally, Predicts, remi, Served, textmyagent, TryOpenClaw, Vellum.

16 publish a privacy policy that never mentions it: Alfi, Boardy, Ditto, Duckbill, Homer, Howie, Jarvie, Manoa, Maxi, Mochi, Nudge, OpenClaw, Shuffle, Super, Zeme, Zo Computer.

10 publish no policy we could find: brobot, Dunnit, DUO, Ember, Hermes, iChatWithGPT, Instinct, OpenInstinct, Series, Town.

Every row is read off the product’s own published policy on the date shown and quoted rather than characterised. A blank is not an accusation: it means we read the policy and it does not address the question.

Twenty state plainly that they do not. That is the good half of this and it is worth saying before anything else.

The rows worth reading are the 4 that say they do, the 3 that do it unless you find the switch, and the 8 that answer a narrower question than the one asked. Those last are the ones to slow down on, because each is true as written.

Bloome writes that it does not use personal data to train general-purpose AI models, which leaves its own models unaddressed. Flip explains that it sends your balances, transactions and messages to OpenAI and Anthropic under terms that prohibit those providers from training on it, and says nothing about Flip. Both sentences are accurate. Neither is an answer.

The ones that wrote a policy and skipped the question

This is the finding, and it took reading 52 documents to see it.

A company with no privacy policy has told you nothing, and you know where you stand. A company that publishes a policy has sat down with counsel, worked through what it collects, named its processors, set out your rights under GDPR and four American state statutes, and then not mentioned whether the conversations are training data. Sixteen listings did that.

Zo Computer is the clearest case. It runs a computer for you, holding your files. Its policy lists the categories of personal data it collects: an email address, trackers, usage data. The files are not in the list. Neither is training.

Some of this is a template. The state-by-state sections in several of these are the same boilerplate with the product name changed, and a template written for a shopping site does not have a paragraph about model training in it because a shopping site does not have this problem. That explains the omission. It does not answer it.

The one that decides by where you signed up

Arlo publishes the most detailed answer in the set, and it is not the one anybody would guess.

Its policy states that a new adult account created from a server-verified United States location starts participating by default, while an account created in the EEA, the UK or Switzerland has to opt in from settings. Same product, same price, and consent that turns on where your signup resolved.

What it participates in is unusual too. Arlo does not train on raw messages, and says so at length. It builds deidentified structural records instead, and its policy says it may license approved datasets of them to outside AI developers, who use them for their own model training as independent recipients rather than as Arlo's subprocessors. It is the only clause of its kind recorded here.

Read the whole clause before deciding what you think of it. It is also the most carefully written thing on this subject in the set, and a company that says this much has thought about it. The 16 have published nothing that shows they have.

Nobody is selling the opposite

Here is the part that makes this a market story rather than a compliance one.

Reading all 62 taglines on 9 September 2026, one product makes a data-privacy claim in the sentence it uses to describe itself: Bo, which says its AI provider is held to zero retention. One, out of 62. Every other product leads with what it can do.

Twelve publish a security contact, which is the cheapest possible signal that somebody is responsible for this, and it costs a line in a text file.

Meanwhile 20 of them state they do not train on you, and almost none says so anywhere a buyer would see it. The position is empty because twenty companies are standing on it without saying a word.

One of the four that state they do train is Kachi, which writes that it trains and improves its own models on conversations and outcomes. It is quoted on its listing like every other, and of the four it is the plainest, which is worth something on its own.

What is still not known

The training question is the one people ask. Two others matter more and are answered less.

Nine of the 52 readable policies address people who never signed up: the friend in the group thread, the colleague on the calendar invite, the person on the other end of the email your agent answered. Every one of these products processes those people's messages, and nine of them have written down what happens to them.

Retention is thinner still. Fifteen listings state what happens to your data when you cancel. The rest leave it to a general sentence about keeping data as long as necessary, which is a legal formula rather than an answer.

What to watch

Three things, and each is checkable rather than a prediction.

The first is whether any of the 16 adds a sentence. It costs nothing, it is the highest-value line any of them could publish, and the board that ranks disclosure will move the day one does.

The second is whether anybody starts selling this. The first product in this category to put a training answer in its own headline takes a position the rest of this directory has left empty, and it will be visible from the homepage rather than from a policy page.

Last is whether consent by geography spreads. One product decides your default by where your signup resolved. If a second does it, a norm is forming, and it will have formed without anybody discussing it.