What these agents do with your data
These products read your messages, and several read your email. We went looking for a published privacy policy for all 33 agents in this directory and found one we could read for 25. Of those, 7 state plainly that they do not train on your conversations, 3 state that they do, 5 give a qualified answer that turns out to be narrower than it first reads, 1 trains by default unless you opt out, one trains a model for you but not a shared one, and 8 do not address it at all.
How to read this
Every quote is verbatim from the linked policy, with the date we read it. We report what the document says and link it so you can check. We do not interpret its legal effect, we are not lawyers, and policies change without notice. A blank row means the policy is silent on that question, not that we know the answer.
Policy by policy
| Agent | Trains on your data | Mentions non-users | Model providers named | Policy last updated |
|---|---|---|---|---|
| 222 | Qualified statement“improving the machine learning model we leverage to improve its ability to match you” | Addressed | None named | 2026-06-22 |
| Arlo | Not stated | Not stated | None named | Not stated |
| Boardy | Not stated | Addressed | None named | Not stated |
| Boba | States it does“Developing, training, and fine-tuning models, algorithms, and artificial intelligence technologies” | Addressed | None named | 2026-08-28 |
| Caddy | States it does not“Caddy does not use Customer Data to train AI models.” | Not stated | None named | Not stated |
| Catch | Qualified statement“AI vendors process data solely to handle requests and are contractually prohibited from retaining or training on it” | Not addressed | None named | Not stated |
| Ditto | Not stated | Not addressed | Anthropic, OpenAI, Google | 2026-07-28 |
| Duckbill | Not stated | Not addressed | None named | 2024-12-04 |
| folk | States it does not“we never use your data to train AI models” | Not stated | None named | Not stated |
| Homer | Not stated | Not stated | Anthropic, Google, Perplexity | Not stated |
| Jarvie | Not stated | Addressed | None named | 2026-06-24 |
| Kachi | States it does“training and improving our own models on conversations and outcomes” | Addressed | None named | Not stated |
| Lucas | States it does not“We do not use your messages or other User Content to train AI or machine learning models.” | Addressed | OpenAI, Anthropic, Google | 2026-05-23 |
| Martin | Qualified statement“our app does not use any google user data for developing, improving, or training ai and/or ml models” | Not addressed | OpenAI | 2024-09-09 |
| Notis | Qualified statement“Where feasible, we instruct providers not to use your data to train their models.” | Not addressed | OpenAI | 2026-01-04 |
| OpenClaw | States it does not“We do not monitor, read, analyze, or use your conversations for any purpose, including training AI models.” | Not stated | None named | Not stated |
| Orchid | Your model only“We don't train shared models on your data. We train your model on your data.” | Not addressed | Google Vertex AI, OpenAI, Anthropic, OpenRouter | 2026-05-21 |
| Ori | States it does not“We do not use the content of a message you send through the corporate Site to train consumer-facing AI models unless we first provide a separate notice and obtain any consent required by law.” | Not addressed | None named | 2026-07-27 |
| Pally | States it does not“we configure these services so your messages and other content are not used to train AI models” | Not addressed | None named | 2026-09-04 |
| Poke | Yes, with opt-out“Improve and customize our products and services...including to train our artificial intelligence models. Data from users who select Maximum Privacy will not be used for model training” | Addressed | None named | 2026-06-23 |
| Shuffle | Not stated | Not addressed | None named | 2026-01-29 |
| Sidekicks | Not stated | Not stated | None named | Not stated |
| Tomo | Qualified statement“We do not use your health data...to train or improve generalized...AI/ML models” | Not addressed | None named | 2026-06-23 |
| Vellum | States it does not“but do not use it to train AI models” | Not stated | Anthropic, OpenAI, Google, ElevenLabs | Not stated |
| Wajo | States it does“Developing, training, and fine-tuning models, algorithms, and artificial intelligence ("AI") technologies, including personalizing the AI Agent” | Addressed | None named | 2026-08-24 |
What we found
Most of this market has no policy you can find. We could locate a readable privacy policy for 25 of 33 products. The rest either publish nothing at a conventional address, block automated access, or have no site at all. For a category whose products read your inbox and your group chats, that is the headline finding, and it is not close.
The training question has four answers, not two. 7 policies state plainly that they do not train on user content. 3 state that they do. Orchid draws a distinction nobody else does: it trains a model on your data for you, but not a shared model anyone else uses.
And 5 give a qualified answer worth reading twice. Notis says “where feasible, we instruct providers not to use your data to train their models”, which is a request to third parties rather than a commitment about itself, conditioned on feasibility. Martin says its app does not use “google user data” for training, which is a statement about one integration rather than about your conversations. Catch says its AI vendors are contractually prohibited from training on your data, while also saying Catch uses your data to improve the experience. None of these are the same as “we do not train on your conversations”, and all three read like it at a glance.
Two policies are near-identical. Boba and Wajo describe their use of personal information in nearly the same words, including the same phrasing about developing and fine-tuning models and the same sentence about users providing information about others. That pattern suggests a shared template rather than two documents written to describe two products, which is worth knowing before treating either as a considered statement of what the product actually does.
Some policies predate the products they govern. Martin’s says it was last updated on 9 September 2024 and Duckbill’s on 4 December 2024. A further 10 of 25 state no date at all, so there is no way to tell whether what you are reading describes the product you are about to use.
One product makes it a setting. Poke says it uses data to “train our artificial intelligence models” and that “data from users who select Maximum Privacy will not be used for model training”. It is the only policy here that makes training a choice rather than a policy, which is more honest than silence and worth knowing is off by default.
The people who never signed up. This is the question the category is built to avoid. A group agent reads the messages of everyone in the thread, and an agent that texts your friends processes the data of people who never saw any terms. 8 of 25 policies acknowledge this at all. Jarvie is unusually direct about it: “In a group, Jarvie processes the thread’s messages to respond, and its replies are visible to everyone.” Most simply do not mention that anyone other than the account holder exists.
Almost nobody names who processes your messages. Only 7 of 25 policies name the model providers your conversations are sent to. Vellum lists fifteen. Orchid names four. Lucas names three. The rest refer to “third-party AI providers” without saying which, which means you cannot check those companies’ terms even if you want to.
Method
We looked for a privacy policy on each product’s own domain, at conventional addresses and then by searching, and read what we found on 6 September 2026. Where a policy could not be reached, the listing records that we have not reviewed it rather than that the product is silent, because those are different claims and only one of them is ours to make.
Three separate outcomes are collapsed in the 8 we could not read, and the distinction matters. Some products have no site we could find at all. Some publish nothing at any address we tried. And some, including Town and Sidekicks, publish a policy that returns an error to automated requests, so it is readable by a person and not by a machine. Only the first two are the product’s silence; the third is a technical choice, and we have not counted it against them.
If we have misread your policy, or it has changed, tell us and we will correct it and date the change. Submit a correction. The same applies if you would like your policy read and added.