The category is harder to shop than most
AI companion apps sit in adult-adjacent subscription territory that has historically had thin regulation, high fraud rates, and payment processors that sometimes pull the plug without warning. When a payment processor drops an AI companion app, users on that app lose subscription access overnight — and the pattern has burned enough users that the whole category now has to prove itself to every new buyer.
Candy AI and Sloane both clear the bar. Both name their operating entity, both use standard payment infrastructure, both have self-serve cancellation. Where they and every other product in the category differ is in the specific subscription-behavior choices each has made — and those choices are what you can actually evaluate before committing.
The subscription-safety framework
Five things worth checking on any AI companion subscription before you type a card number. If a product answers all five cleanly, it's subscription-safe. If it can't answer one or two, that's where the friction will live.
1. Is the operating entity named? Company name on the About page or footer. If you can't figure out who runs the product, you have no counterparty when something goes wrong.
2. Is the checkout a recognizable processor? Stripe Checkout, PayPal, Apple Pay, Google Pay. If the checkout redirects you somewhere with unfamiliar branding or asks for card details in a non-standard interface, step back.
3. What descriptor appears on your card statement? Most legitimate AI companion apps use a neutral statement descriptor. Check the FAQ before signing up, or sign up for the cheapest tier and verify on the first charge before committing longer.
4. What does the cancel flow look like? The green-flag pattern is self-serve, one-click, in-app or via a standard billing portal. Yellow flags are cancellation via emailing support or clicking through retention pop-ups. Red flags are cancellation requiring a phone call or mailed letter.
5. What's the refund policy? "No prorated refunds, cancel anytime, access to end of cycle" is standard and fine for the category. What's not fine is opaque or hidden refund terms combined with long minimum commitments.
Where Sloane sits on each of the five
The best way to explain the framework is to walk through it with a specific product. Here's how Sloane answers each of the five checks — you can run the same test on Candy AI, or on any other product you're considering.
1. Operating entity. Named in the footer and on the About/contact page — not hidden behind a shell.
2. Checkout processor. Sloane uses Stripe Checkout for all subscription payments. Recognizable Stripe UI, standard card entry, Apple Pay and Google Pay accepted. Card details go to Stripe, not stored on Sloane's servers.
3. Statement descriptor. Standard Stripe descriptor on the card statement — neutral, not the product name spelled out. If your first charge shows a descriptor you find surprising, contact support before committing to longer subscriptions.
4. Cancel flow. Sloane's cancel button opens the Stripe Billing Portal — the same self-serve cancellation surface that runs thousands of legitimate subscription products. One click to cancel, no phone call, no retention pop-up, no "please tell us why you're leaving" survey. Access continues to the end of the current billing cycle.
5. Refund policy. No prorated refunds (standard for the category) but no auto-charge after cancel either. If you cancel on day 5 of a monthly cycle, you keep access to day 30 and your account reverts to Free at renewal.
Any product that answers all five cleanly is subscription-safe. Start with Kaya on the free tier if you want to see what all of this looks like in practice — no card at signup, real conversation with real memory, cancel via the Stripe portal whenever you're done.
What the red flags actually look like
To make the framework concrete, here's what to specifically avoid — without naming the offenders, because the category churns and today's red-flag app might be gone by year-end.
Hard-to-cancel patterns. Cancellation locked behind emailing support, cancellation locked behind a phone call, retention pop-ups with three "are you sure" screens before the button appears, "we'll process your cancellation in 30 days" delays. Any of these turn a $10/month test into a months-long extraction.
Coin/token escalators. Base subscription looks reasonable at $5-10/month, then the actually-useful features (images, voice, extended chat) consume tokens you have to buy separately. Real monthly spend can hit 3-5x the sticker for active users. Not fraud — you consent to each purchase — but pricing surface architected to create purchase moments. Ask before signing up whether a coin economy exists.
Missing operator information. No company name anywhere on the site, no founder, no working support address. If you can't figure out who runs the product, you have no one to escalate to if a charge goes wrong.
"All sales final" on annual-only pricing. No-refund is fine on monthly. No-refund plus annual-only plus aggressive upsell is the combination that traps buyers who thought they were signing up for a trial.
Non-standard payment flows. Crypto-only checkout, wire transfer required, "we'll email you a code to activate" — these are outside the normal SaaS payment envelope and outside the safety net that comes with using standard processors.
Candy AI and Sloane both sit far from this pattern — the framework above is how you verify that yourself rather than taking anyone's word for it. Newer apps that appear overnight sometimes do match some of these red flags; the framework is what lets you tell the difference.
The privacy caveat that applies everywhere
One caveat worth naming that applies to any AI companion product, not just any specific one: the "how private are my conversations" question doesn't have a fully clean answer anywhere in the category yet.
Every AI companion app you can name today has some flavor of the same underlying issue: conversations become model inputs, some abstract form of them may end up in training pipelines, and "delete my data" and "delete the version of my data that already got baked into model weights" are two very different operations that no consumer AI product has cleanly solved.
The behavioral mitigation is the same everywhere: don't share personally identifying information (real name, address, workplace, financial details, specific medical details) in AI companion conversations you wouldn't want stored somewhere. This isn't paranoia — it's the same hygiene you'd apply to any new online service handling sensitive content. Sloane's specific privacy commitments (no selling conversations, no third-party sharing, no training models for enterprise licensing) are in the privacy page; comparable products document their own commitments in their equivalent pages, and reading those before you sign up is worth the ten minutes.