
Is Janitor AI safe? Yes, with caveats. Janitor AI is a legitimate platform run by JanitorAI Inc. at janitorai.com, it is 18+ by its own terms, and its privacy policy says it does not sell your personal data. The caveats: it collects and stores your chats, the model you pick decides who else processes your messages, and a proxy you found in a comment section can see everything you send through it.
Cherrypop.ai publishes this, and we make a competing AI companion app. Based on each vendor’s pricing and help pages and published user reports, as of September 2026.
Is Janitor AI safe? The short answers
| Question | Answer (as of September 2026) |
|---|---|
| Is it legit? | Yes. Operated by JanitorAI Inc.; payments may be handled by an affiliate, Dulova Investments Limited (Cyprus) |
| Does it store chats? | Yes. Its privacy policy lists chat conversations and messages as collected data |
| Can other users see my chats? | Only a chat you choose to publish |
| Who else sees messages? | Depends on the model: JLLM, a third-party model via Router, or whoever runs your proxy |
| Price | Free tier; janitor+ is $12.99/month plus tax |
| Refunds | Generally none, including partial months; Router credits are final sale |
| Age rule | 18+ only; ID or face-estimate check in some countries |
| Known breach | No entry in Have I Been Pwned as of September 27, 2026 |
What Janitor AI collects and stores
Janitor’s privacy policy (updated September 17, 2026) lists your account details and “User Content: Characters you create, chat conversations, messages, and other content you generate or upload.” It also collects usage data, search queries, IP address, device identifiers and approximate location, and uses cookies and pixels.
Per its privacy policy, it may use information for recommendations, content moderation and “research and development to improve our AI systems.” It does not say whether your chats specifically train models, either way. It says it does not sell personal data under the CCPA/CPRA definition, but it shares data with service providers (hosting, analytics, payments, support, marketing) and may disclose it for legal requests or in a sale of the company.
Janitor’s safety page puts it this way: “We never sell your personal data or share private conversations with third parties for advertising or commercial purposes.” That fits the policy, which still allows service providers and legal disclosures. Neither document says whether staff can view private chats.
Deleting your account
Go to Settings > Security > Delete Account. The account is deactivated first, with a grace period to restore it. After deletion, per the policy, some records, including your email address, may be kept for purposes such as receipts, security, fraud prevention or legal obligations. You can email [email protected] to ask for retained data to be deleted. Per the terms, deleting also cancels unused Router credits without refund.
JLLM vs Router vs a proxy: who sees your messages
The model behind a chat can be one of three things, and each changes who processes what you type. Per Janitor’s token guide, the model receives more than your latest message: the character’s personality, scenario, your persona and chat memory go along too.
- JLLM (JanitorLLM): Janitor’s own model and the free default. Your messages are handled by Janitor under its privacy policy.
- janitor+ Router: launched July 30, 2026 for janitor+ subscribers on the web. It runs third-party models without you handling an API key, billed per token from an in-app wallet. Janitor’s Router help page does not say how those outside providers handle your messages.
- Your own proxy: you paste an API URL, a model name and an API key into API Settings. Janitor’s help center calls the proxy “the middleman between your chat and the model provider.” Every message in that chat goes to the proxy and the model provider behind it, each under its own privacy terms, on top of Janitor’s.
The real risk: shared reverse proxies and leaked keys
A known router (the help center’s quickstart uses OpenRouter) publishes its policies, but it passes each request to a model provider, and its docs say each provider has its own logging, retention and training policies. Check both, and use its settings to exclude providers that may train on prompts. A shared reverse proxy run by a stranger is different: whoever operates it sits in the middle of every request, can log your chats, and can use any key you hand over on your bill.
- Treat your API key like a password, which is how Janitor’s own quickstart guide describes it.
- Paste it only into janitorai.com or the provider’s own dashboard, and set a spending limit.
- If a key may have leaked, revoke it on the provider’s dashboard and make a new one. Deleting your Janitor account does not revoke it.
Our Janitor AI prompts guide covers token budgets and proxy prompts.
Payments, billing and refunds
janitor+, Janitor’s first subscription, launched June 24, 2026. As of September 2026 it costs $12.99 USD per month plus tax, renews automatically, and “usage limits apply.” Over the free tier’s roughly 9k-token context it adds 5x more context, priority routing, monthly enhanced swipes, an included Router balance and profile cosmetics. For what stays free, see is Janitor AI free.
- Who charges you: JanitorAI Inc. and affiliates including Dulova Investments Limited (Cyprus), plus third-party processors. Per the policy, card details are not stored on Janitor’s servers.
- Cancelling: Settings > Billing > Manage subscription, or email [email protected]. You keep access until the end of the paid period.
- Refunds: generally none, and no partial refunds, except where the law requires them, for a defective paid service, or if Janitor ends your plan early for reasons other than enforcement.
- Router credits: need an active janitor+ plan, are final sale, and per the terms Janitor reserves the right to expire unused ones 365 days after purchase.
- App store purchases: cancel and request refunds through Apple or Google, under their rules.
janitor+ is only a few months old, so there is little public billing history yet. Janitor’s Trustpilot reviews from before its launch are mostly about errors and reply quality.
Age rules and verification
Janitor’s terms make the platform 18+ only and let it terminate accounts it reasonably believes belong to someone under 18. In most countries that is a self-declaration. Per its safety page, users connecting from Brazil and Australia must pass an age check through k-ID (on-device face estimate, ID scan or a reusable AgeKey), Janitor’s June 2026 announcement also named the UK, though its safety page currently lists only Brazil and Australia. Janitor says it only receives a yes or no.
Moderation, as Janitor describes it
Per its safety page, automated systems “trained on our Content Policy” screen every piece of content before it is published, and full-time human moderators review reports. There is a Report button on characters and comments.
Its terms prohibit content involving anyone under 18, sexual violence, gore, doxxing and more, and bar explicit nudity in avatars. The policy lists moderation among its uses of your data but does not describe how private chats are screened.
Public chats
Since March 31, 2026 you can publish a chat. It goes live as a snapshot others can read, comment on and fork. Janitor says published chats go through moderation, and you can unpublish in one click. Strip out anything that identifies you first.
Copycat sites and fake apps
The official site is janitorai.com. Copycats use the Janitor name: in February 2026 Janitor warned about fake apps on the app stores. Its official app has been on the App Store and Google Play since February 2026.
- Use a bookmark, not an ad, and get the app through janitorai.com.
- Keep real names, addresses and workplaces out of chats and personas on any site.
- If you logged in on a copycat site or app, change your Janitor password and revoke any API key you entered there.
Alternatives if Janitor isn’t for you
If the proxy setup is more than you want to manage, our Janitor AI alternatives list compares other options.
Cherrypop.ai is one of them: uncensored AI chat and roleplay with a large catalog of ready-made characters (female, male and trans, realistic and anime), a create-your-own wizard, and AI images of your character, including NSFW. It’s free to start, with limits, and paid plans unlock more messages, images and features (see pricing on the site). It works in mobile browsers with no app to install, and like Janitor it’s 18+ only, with age checks where the law requires them.
FAQ
Can you trust Janitor AI?
It is a named company with a published privacy policy, terms and an 18+ rule. That tells you what it promises, not how securely it runs. It stores your chats and may use data to improve its AI, so keep your real identity out of them.
Does Janitor AI collect your data?
Yes: account details, your characters and chats, usage data, IP address, device identifiers and approximate location, per its privacy policy.
Has Janitor AI ever been hacked?
There is no Janitor AI entry in Have I Been Pwned’s breach list, and no breach notice among Janitor’s newsroom announcements, as of September 27, 2026. That only means none has been reported there. The policy itself says no storage method is completely secure.
Can people see what I do on Janitor AI?
Other users can see a chat only if you publish it. Janitor itself stores your chats, and if you use Router or a proxy, the model provider or proxy operator receives your messages too.