Updated: August 15, 2026 · Based on Candy.ai official Terms of Service and Privacy Notice (revision July 30, 2026) plus practical account hygiene. Adults 18+ only.
Disclosure: This site may earn a commission via sponsored links. Safety guidance below is still the checklist you should run yourself.
Safe path: evaluate Candy only through official channels after the checks on this page.
Short answer
Candy AI can be used more safely when you stick to the official site, are 18+, control your email/payment method, read EverAI’s policies, and avoid third-party APKs or account marketplaces. It is not “safe” in the absolute sense if you expect zero data processing, irreversible anonymity, or a product that never enforces content rules.
| Claim people want | Reality check |
|---|---|
| “Totally private forever” | A commercial AI service processes account and usage data under a published Privacy Notice |
| “Uncensored means no rules” | Terms and Trust & Safety still apply; violations can cost access |
| “APK mirror is fine” | High malware and credential-theft risk |
| “I can ignore checkout details” | Billing surprise is a safety/financial risk too |
Who operates Candy AI?
According to the official Terms of Service and Privacy Notice (Date of Revision: July 30, 2026), the services are operated by EverAI Limited (Malta Business Registry C107181). Knowing the named operator is step one of basic buyer diligence.
Age, content and account enforcement
- Services are intended for adults (18+ or higher age of majority where applicable).
- You are responsible for activity under your credentials.
- Policy violations can lead to restriction or termination; do not assume refunds when moderation acts on violations.
- Keep illegal content and non-consensual intimate material out — full stop.
| Risk | Mitigation |
|---|---|
| Underage access | Do not use the service if under 18; do not help others bypass age gates |
| Account takeover | Unique password; protect email; never share OTP/password |
| Malicious APK | Official web / first-party install only — see download guide |
| Oversharing | Avoid real full names, addresses, workplace secrets in chats |
| Billing shock | Screenshot plan period; find cancel path pre-pay — pricing guide |
Privacy checklist (practical)
- Read the Privacy Notice on candy.ai (revision July 30, 2026).
- Use an email you control long-term.
- Prefer a payment method you monitor weekly.
- Check whether creations can appear in discover/community contexts before posting publicly.
- Assume chats are not a permanent legal archive.
- If you stop using the product, follow official account/subscription management paths.
Continue on official Candy after checks →
Payment and data processors
The Privacy Notice describes payment processing for subscriptions, tokens and refunds via payment service providers. That is normal for paid consumer apps — and it means “card never touches any third party” is usually the wrong expectation. Monitor statements and keep screenshots of what you bought.
When to walk away
- Any site asks you to install a random APK to “unlock premium.”
- Someone offers shared/sold accounts.
- You cannot find cancel/manage controls before paying.
- The product pushes you past the adult gate without clear 18+ framing.
Related guides
- Candy AI review hub (full purchase-risk verdict)
- Free trial protocol
- Safe download / web access
- Pricing and credits reading
- OurDream alternative review
Threat model for adult AI companion apps
Before asking “is Candy AI safe,” define safe from what:
| Threat | Relevant? | Primary controls |
|---|---|---|
| Malware from fake apps | High if you sideload | Official web / first-party only |
| Account credential theft | High with reused passwords | Unique password + email security |
| Billing surprise | High for impulsive upgrades | Checkout screenshots + cancel path |
| Unwanted content exposure | Medium if you publish | Default private; understand sharing |
| Social embarrassment | Medium | Device lock, notifications hygiene |
| Legal/content policy issues | High if you ignore rules | Read Terms; no illegal content |
| Absolute anonymity from operator | Usually unrealistic | Minimize personal data you type |
Candy, like other commercial companions, is not a self-hosted air-gapped model. If your threat model requires that no company can process prompts, you need a different architecture entirely — not a different marketing page.
Operational security basics (non-paranoid edition)
- Use a strong unique password manager entry for candy.ai.
- Lock your phone/laptop; companion apps are not a reason to disable screen locks.
- Be careful with screenshots that include email, payment last four, or chat content you would not show a roommate.
- If you share a computer, use a separate browser profile or always log out.
- Do not connect accounts you cannot afford to lose recovery on.
| Hygiene item | Good | Risky |
|---|---|---|
| You control long-term | Shared/family inbox you do not own | |
| Install source | Official site flows | spammy “mod APK” blogs |
| Payment | Method you review monthly | Someone else’s card |
| Chat content | Fiction + clear boundaries | Other people’s intimate images without consent |
| Support contact | In-product / official help | Random Discord “admins” |
What official policies imply for safety decisions
Without turning this page into a legal memo, EverAI’s public Terms and Privacy Notice (revision July 30, 2026) are enough to set expectations:
- There is a named company entity behind the service.
- Adults-only framing is explicit.
- Accounts can be restricted; entitlements are not a moral right if you break rules.
- Payment processing can involve specialized processors for subscriptions and tokens.
- Privacy documentation exists — your job is to read it, not assume “AI girlfriend” means “no data.”
If a review site refuses to link official legal pages and only pushes aggressive signup claims, treat that as a quality smell in the review — including ours if we ever slip. This page links the official sources on purpose.
Social engineering and fake “Candy” properties
Safety failures often happen around the real product:
- Lookalike domains with extra hyphens or weird TLDs.
- Ads promising free premium unlocks via downloads.
- Phishing pages harvesting passwords under “login fix” pretenses.
- Marketplace sellers offering aged accounts (often stolen or against Terms).
Countermeasure: manually navigate to candy.ai, then use in-product navigation. For install questions, stay on our download safety guide and the official site — not random comment sections.
Emotional and usage safety
Product security is only half the story. Companion apps can become compulsive time sinks. Practical guardrails:
- Set a session timer when you are testing, not only when you already feel hooked.
- Do not make high-cost billing decisions late at night on impulse.
- If chat is substituting for crisis support, stop and contact real-world help resources appropriate to your country — an AI companion is not emergency care.
- Keep fantasy content clearly separated from real people who did not consent to be included.
| Situation | Safer response |
|---|---|
| You feel pressure to upgrade immediately | Close checkout; revisit tomorrow with notes |
| A character encourages harmful real-world acts | End session; report via official tools if available |
| You are unsure about a content boundary | Read Trust & Safety / Terms before pushing |
| Partner/household privacy matters | Notifications off; device lock; separate profile |
Safety checklist before first payment
- Official domain confirmed.
- 18+ confirmed.
- Email recovery confirmed.
- Password unique.
- Trial notes complete (chat + media + checkout).
- Cancel/manage path found.
- Budget rule written.
- No APK sideload involved.
If any item fails, do not pay yet. Return to the Candy AI review hub for the broader purchase-risk framework, or compare OurDream only after the same checklist.
Proceed only on official Candy →
You might also like: Candy AI Cost
Extended FAQ
Does HTTPS make Candy fully safe? HTTPS protects transport to the real site. It does not fix bad passwords, fake apps, or reckless billing.
Can I use a privacy card / virtual card? Often a reasonable billing-hygiene choice if your issuer supports it — still monitor statements.
Are my generations used to train models? Read the current Privacy Notice and related disclosures on the official site the day you care; training/use statements can be updated. Do not rely on a third-party summary alone.
What if I already installed a shady APK? Uninstall it, run mobile security basics, change passwords that may have been typed into the fake app, and only then consider the official product.
Is Candy safer than smaller unknown sites? Named operator + public policies is a positive signal versus anonymous mirrors, but you still execute the checklist. Brand familiarity is not a substitute for hygiene.
Device, browser and notification hygiene
Small settings prevent large awkward moments:
- Disable lock-screen previews for browser/app notifications if previews can show chat snippets.
- Prefer a separate browser profile for adult accounts if you share a machine.
- Clear or protect download folders if you save images locally.
- On shared iCloud/Google photo backup, know whether saved media will sync to family devices.
| Surface | Setting to review | Why |
|---|---|---|
| Phone notifications | Hide sensitive previews | Lock screen leakage |
| Cloud photos | Backup exclusions | Unintended sync |
| Browser | Separate profile / site permissions | Shared-device privacy |
| Marketing vs transactional filters | Reduce noisy prompts to re-open and re-spend |
None of these settings replace reading official policies — they reduce everyday exposure while you evaluate whether Candy deserves a place in your routine.
Billing, statement label, cancel and deletion FAQ
Quick answer (official pages reviewed 2026-08-15): Candy’s paid subscriptions auto-renew for the same price and term until you cancel in-account. The public subscriptions UI states charges can appear as EverAI on bank statements; homepage marketing FAQ language also describes a neutral merchant string without Candy branding. Cancel via Settings → Unsubscribe (Terms). Remaining tokens generally expire at the end of the current billing period after cancel and do not carry into a later resubscribe. Account/data retention and payment processors are described in the Privacy Notice (revision July 30, 2026). None of this is legal advice — re-read live Terms/Privacy the day you pay or delete.
| Buyer question | What public sources said on 2026-08-15 | Practical move |
|---|---|---|
| What appears on my bank/card statement? | Subscriptions UI: charge shown as EverAI. Homepage FAQ marketing copy: neutral merchant name without a direct “Candy AI” label. | Make a minimal charge first if the descriptor matters; keep the receipt email. |
| Who operates the product? | EverAI Limited, Nr. C107181 (address block on subscriptions UI / legal pages). | Match the entity on Terms before a large prepay. |
| How do I cancel? | Terms §10.1: account Settings / Unsubscribe. UI also: cancel any time in settings; auto-renews same price/term until then. | Find the control on day one; set a calendar reminder before renewal. |
| Do I keep tokens after cancel? | Terms: remaining tokens expire at end of the current billing period; no carry-over or refund after the period; a later resubscribe does not restore old unused tokens. | Use or consciously forfeit tokens before period end. |
| Refund window? | Baseline Terms: request within 24 hours; subscription refunds denied if you used more than 20 tokens; token-pack refunds denied if tokens were used; card path described. EU/UK consumers have a separate withdrawal section — email [email protected]. | Do not assume cancel equals refund; screenshot usage before opening a ticket. |
| Who processes payments? | Privacy Notice names processors/orchestrators including Emerchant Pay, TrustPay, Volt, Coingate, UpGate for subscriptions/tokens/refunds. | Expect third-party processor fields on statements/receipts. |
| How long is account data kept? | Privacy Notice: commonly three years after last account activity, with operational cases that may shorten retention (e.g. toward one year after last activity or after paid sub ends, as written). | Deletion/access requests go through official channels; DPO published as [email protected]. |
Visible Q&A (billing & account safety)
How will Candy AI appear on my bank statement?
On the public subscriptions UI reviewed 2026-08-15, Candy states the charge can show as EverAI. Marketing FAQ copy on the homepage also describes a neutral merchant label without naming “Candy AI”. Always verify on your own first receipt — processors and descriptors can vary.
How do I cancel a Candy subscription?
Per Terms of Service: open your account Settings and use Unsubscribe. Auto-renew stops for future periods; you keep paid access until the current period ends unless a refund/chargeback path revokes it earlier under the refund rules.
What happens to my tokens if I cancel?
Terms: remaining tokens expire and become unusable at the end of the current billing period. They are not refunded and do not carry into a later new subscription.
Can I get a refund easily?
Baseline Terms describe a short 24-hour request window and deny many cases after meaningful token use (more than 20 tokens on subscription refunds; any use on token-pack refunds), with card-purchase limitations. EU/UK users should read the dedicated withdrawal section and contact [email protected]. Cancel ≠ automatic refund.
Is payment data shared with third parties?
Yes for processing. The Privacy Notice (revision July 30, 2026) lists payment providers/orchestrators such as Emerchant Pay, TrustPay, Volt, Coingate and UpGate for subscriptions, tokens and refunds.
How long does Candy keep my account data?
Privacy Notice: typically up to about three years after last account activity for many account records, with possible shorter operational windows described in the Notice. Re-read the live Notice before relying on a retention number.
Who do I contact for privacy rights?
Privacy Notice publishes a Data Protection Officer contact: [email protected]. Product support email referenced in Terms refund language: [email protected].
Open the official Candy account path to verify cancel and billing controls →
Continue with the Candy AI review hub · pricing guide · trial checklist.
FAQ
Is Candy AI a scam? A named operator with public legal pages is not the same as a random mirror site — but you still must verify billing and avoid unofficial downloads.
Is my chat secret? Treat it as private-ish commercial processing under a privacy policy, not attorney-client secrecy.
Can I use a fake age? No. Adult-only rules exist for a reason.
What if I only care about NSFW? Still read Trust & Safety / Terms. “Adult” is not “no rules.”
"I was skeptical at first, but Candy.ai genuinely surprised me. The conversations feel incredibly natural."
Ready to Meet Your AI Companion?
Join 2,000,000+ users already on Candy.ai. Start chatting in under 30 seconds.
Start Chatting Now — It's Free →Create Your Perfect AI Girlfriend on Candy.ai
Chat, voice call, and generate images with the most realistic AI companion available. No credit card required.
Create Your AI Girlfriend Free →✓ Free forever plan ✓ No signup required ✓ NSFW enabled




