Trust score methodology
Every trust score on this site is the output of a fixed arithmetic rubric over verified policy facts. We never LLM-guess a score.
The rubric at a glance
A platform can earn up to 100 points across the 10 factors below. The published score is that total divided by 10, shown out of 10 (e.g. 72/100points → 7.2/10). The weights are fixed and public; two platforms with identical facts always get identical scores, and a score can be recomputed by hand from the evidence shown on the listing's trust panel.
| Factor | Weight | What earns the points | How it's determined |
|---|---|---|---|
| Does not train AI on your chats | 15 | The platform's policies state that conversation content is not used to train models, or offer a default-off opt-in. | Privacy policy / ToS extraction with a verbatim quote. |
| No human review of conversations | 10 | Policies state that staff or contractors do not read user conversations (narrow abuse/safety review carve-outs are noted on the panel). | Privacy policy / ToS extraction with a verbatim quote. |
| You can delete your chats | 10 | A user-facing control or documented process deletes conversation history. | Policy or help-page extraction with a verbatim quote. |
| You can delete your account | 5 | A self-service account-deletion control or documented deletion request process exists. | Policy or help-page extraction with a verbatim quote. |
| Does not sell or share personal data | 15 | Policies state personal data is not sold or shared for cross-context advertising. | Privacy policy extraction with a verbatim quote. |
| States a data-retention period | 5 | Policies commit to a concrete retention period or deletion timeline rather than “as long as necessary” boilerplate alone. | Privacy policy extraction with a verbatim quote. |
| Two-factor authentication | 10 | 2FA/MFA is available on user accounts. | Security/help-page extraction with a verbatim quote, or direct observation of the account settings flow. |
| Age verification | 10 | The platform gates adult content behind an age check stronger than nothing at all, as documented or observed at signup. | Policy extraction or direct observation of the signup flow. |
| No known data breach | 10 | No breach involving the platform appears in Have I Been Pwned or in our human-curated incident file. | Have I Been Pwned lookup plus a human-maintained evidence file. Breach claims are never auto-published by a scraper or a model — a human reviews every one. |
| Policies are reachable | 10 | The privacy policy and terms of service exist, load, and are readable — not 404s, redirects to nowhere, or blank stubs. | Deterministic fetch checks; no extraction involved. |
| Total | 100 | Published as points ÷ 10, out of 10. | |
Three-state facts: pass, fail, unknown
Every factor is in one of three states. Passearns the factor's full weight; fail earns zero; unknownalso earns zero — no credit without evidence — but is displayed as “unknown” on the trust panel, never disguised as a “no”. We treat “the policy doesn't say” and “the policy says they do it” as different facts, because they are.
When we refuse to publish a score
A score is published only when at least 6 of the 10 factors are determined (pass or fail, not unknown) andthe platform's privacy policy was fetched cleanly. Below that bar the listing shows “not enough verifiable information” instead of a number. A score built mostly on unknowns would be noise dressed up as data, so we don't ship one.
Every determined fact carries a quote
Each pass or fail is backed by a verbatim quote from the platform's own documents (or a deterministic check, for reachability and breach lookups). Quotes are mechanically verified to be exact substrings of the fetched page — if a quote can't be matched back to the source, the fact reverts to unknown. The trust panel on every listing shows each factor's state, its quote, a link to the source document, and the date we checked it.
We never LLM-guess a score
Language models help us locate candidate statements inside long policy documents — that's all. A model's output only becomes a fact after its supporting quote passes the substring check against the real page, and the score itself is plain arithmetic over those facts using the fixed weights above. No step of scoring asks a model for its opinion, a rating, or a summary judgment. Breach claims go further: they are never auto-published at all, and appear only after human review of the evidence.
Limitations
The score measures what platforms say and verifiably do about privacy — it cannot see inside their infrastructure, and a policy can change the day after we fetch it. Check dates are shown on every panel, listings are re-verified on a schedule, and corrections are welcome at contact@allaicompanionsites.com. For how the rest of a listing is researched, see about the directory.