An app that let you write anything in March can start refusing in October, with no announcement, no changelog entry, and no change to the word "uncensored" on its front page. Nobody lied to you. The word was always describing one layer of something with three.
That is the whole problem with ranking these apps by how permissive they are, and it is worth understanding before you pick one, because it determines which of the promises on a landing page are worth anything.
The three layers
The model. Somewhere underneath is a language model, either licensed from a provider or run in-house. Licensed models arrive with usage policies attached, and the licence is a contract the app cannot unilaterally rewrite. An app running its own weights has more room; an app renting capacity has whatever the provider allows this quarter.
The application. On top of that sit the system prompt, the classifier that watches inputs and outputs, and the rules the company writes for itself. This is the layer companies mean when they advertise being uncensored, and it is the layer they can change on a Tuesday afternoon.
The rails. Underneath everything is who processes the payments and who distributes the app. Card networks and their acquirers impose content rules on adult merchants, and mobile app stores impose their own. Those rules are not negotiated with you and are not published as a feature.
An app is only as permissive as the tightest of the three, and it advertises the loosest.
Why it moves
Layer one changes when an app swaps model, which happens for reasons of cost and quality that have nothing to do with content policy. The new model has different refusal behaviour and different prose. Users experience this as the app getting worse at exactly the thing they were paying for, which is usually the moment the reviews turn.
Layer three changes when a processor changes terms, which happens across an entire sector at once and lands with no notice on the merchant's side either.
Neither is visible to you until the behaviour changes. This is the specific reason a ranking of permissiveness is worth less than any other ranking in the category: it is not describing a stable property of the product.
What you can actually check
Read the terms rather than the tagline. Companies are more precise in their acceptable-use documents than in their marketing, because the documents are written by someone with a different job. If a service says it is uncensored and its terms then list prohibited content in detail, the terms are the accurate document — and the list tells you where the line sits far more usefully than any review can.
Look at what the interface does with the boundary. Some services refuse and say so. Some redirect the conversation without acknowledging it. Some produce a generic apology in the character's voice, which is the worst version, because it corrupts the roleplay rather than pausing it.
Note who the characters belong to. The researched entry for GirlfriendGPT describes a service where the catalogue is made by its users and the makers are ranked in a public league table. That structure means content standards are enforced against creators as well as conversations, and it means the catalogue can change composition without the company doing anything.
Note whether the company defines its own position. Candy AI describes its experience as uncensored in its own words — a self-description, which is a different thing from an established fact about behaviour, and worth reading as exactly that.
The portability question
A character you have built over months is a real investment: appearance, personality, voice, and however much conversational history the service retains. Almost none of it is portable.
If the app changes in a way you dislike, the practical cost of leaving is rebuilding from nothing somewhere else — and services on a shared character-card format are the exception, not the rule. Before you sink time into a companion, find out whether the service lets you export anything at all. The answer is usually no, and it is better to know that at the start than at the point you want to go.
Related: an account you cannot export from is an account whose data retention terms matter more than usual. Long conversations with a companion app are among the most sensitive text a person produces, and where it is stored and for how long is in the privacy policy, not the FAQ.
Picking one
Work backwards from the failure mode you would mind least.
If being refused mid-scene would ruin it, prioritise a service that is explicit about its limits over one that advertises having none — the second is more likely to surprise you, because it has told you nothing to plan around.
If you want to build rather than browse, a user-generated platform gives you range and inconsistency. If you want quality on the first try, a first-party roster gives you the opposite.
If cost predictability matters, prefer whatever publishes its numbers, and remember that the message quota and the image quota are separate meters on nearly every service in this category.
Then test it during the trial window, on the material you actually care about rather than on the demo prompt. A month's subscription is a cheap experiment; a year's is not, and the annual discount exists because of how many people find that out in month two.
The entries this directory has checked sit under AI sex chat sites. If you are after image output rather than conversation, the generator category is a different product with a different set of problems, and the companion pricing guide covers the billing side of this one.