Does Janitor AI read your chats?
Nothing on Janitor AI is end-to-end encrypted, so chats sit on its servers in a form staff can technically access. Janitor's policy says it doesn't read private chats or sell them, and moderation targets published bots and posts. If you use a proxy, your text also reaches that model provider.
Why — the first-principles explanation
Two different questions get mashed together here, and separating them is the whole answer. "Can they read my chats?" is a technical question with a definite answer. "Do they read my chats?" is a policy question with no verifiable answer from outside. Almost everything written about this online blurs the two.
Start with "can." There's a term for the property that would make reading impossible: end-to-end encryption. It means the server only ever holds scrambled ciphertext and doesn't have the key, so operators literally cannot read your messages — not as a promise, as math. Signal works this way. Janitor does not offer it, and you can prove that from the outside without any technical access: close the tab, come back on your phone, and your chat is right there. That only works if a server is storing your conversation in a form it can hand back readable. So the technical answer to "can" is yes. What's left protecting you is company policy and internal access controls — real things, but promises rather than guarantees.
Now the part most people miss: you may have added a second reader yourself. If you use Janitor's default model, JLLM, your text stays on Janitor's infrastructure. But if you set up a proxy, you pasted in an API URL and an API key, and from then on your messages leave Janitor entirely and travel to whoever runs that endpoint — OpenRouter, OpenAI, Anthropic, DeepSeek, or someone else. That provider has its own retention rules, its own logging, its own abuse review, and its own policy about training on your data. And free tiers are typically where the loosest data terms live — a good rule of thumb is that free inference is often paid for with data. So "does Janitor read my chats" is frequently the wrong question. Janitor might be the more private half of your setup.
On moderation, the distinction that matters is published versus private. Automated classifiers and human moderators exist to police content that goes out to other users — character cards, avatars, posts, anything reportable. Janitor's own rules operate here, prohibiting NSFW images on bot cards, for example. A classifier scanning text is also not the same thing as a person reading your roleplay for entertainment; it's a program producing a score. But on any centralized platform, an employee with database access can pull records, and legal demands, abuse investigations, and security incidents are all handled by humans. Breaches happen to companies that never intended anyone to read anything.
So the practical rule isn't "trust" or "don't trust." It's this: treat anything you type into any cloud chat as something a human could read someday. Not likely — possible. Which means keep your legal name, address, employer, school, face, and anything you'd be genuinely harmed by out of it, and use a throwaway email. Janitor lets you delete your account permanently, which removes your posts, characters, personas, and profile data. What that does to old chat logs and backups isn't spelled out in the public documentation, and "it's not spelled out" is exactly the honest answer rather than a reassuring one. Janitor's policy pages are at janitorai.com/policy — the wording changes, and it's worth reading the current version yourself rather than trusting any summary, including this one.
An example that makes it click
It's a hotel room safe. You punch in your own code, the little light goes green, and your passport is locked away. Feels private.
But the front desk has a master code. It has to — guests forget their codes every single day. The hotel's policy says staff don't open safes without a reason, and almost always that's true. Still, the box was built so they can. That's Janitor AI: your chats are behind a login, the company says it doesn't read them, and mostly nothing happens — but the design allows it.
End-to-end encryption would be a safe with no master code, where losing your code means the box gets cut open with a saw. Janitor isn't that. And using a proxy? That's the hotel storing your passport in a partner hotel across the street. Now two front desks have a master code, and you only ever read one of their policies.
How to do it
- Check which brain you're using: default JLLM keeps text on Janitor's infrastructure; a proxy sends every message to a third-party provider instead.
- If you use a proxy, go read that provider's data policy — OpenRouter, OpenAI, Anthropic, or DeepSeek — specifically the retention period and whether the tier you're on trains on your inputs. Free tiers usually have the loosest terms.
- Read Janitor's current privacy policy at janitorai.com/policy yourself rather than trusting a summary. The wording changes over time.
- Keep identifying details out of chats entirely: legal name, address, employer, school, phone number, photos of yourself, anything that could be used against you if it leaked.
- Register with an email that isn't tied to your real identity, and don't reuse a password from another account.
- Remember that anything you publish — character cards, avatars, forum posts — is reviewed content by design and is a different privacy category from your private chats.
- If you want out, delete the account through Settings > Security > Delete account. It's permanent, removes your posts, characters, personas, and profile data, and cannot be undone.
Key facts
- Janitor AI does not offer end-to-end encryption, and chats persist across sessions and devices — which requires server-side storage the operator is able to read (as of 2026-07).
- Using a proxy means supplying an API URL and your own API key, which routes your chat text to a third-party model provider such as OpenRouter, OpenAI, Anthropic, or DeepSeek, each governed by its own retention and training policy.
- Janitor's official proxy guide documents free-tier limits of 50 messages/day via OpenRouter, rising to 1,000/day after adding $10 in credits (as of 2026-07) — free inference tiers commonly carry the least restrictive data terms.
- Janitor's content rules apply to published material: character cards and avatars must follow image guidelines and NSFW bot images are prohibited, a review category distinct from private chats.
- Account deletion is permanent: per Janitor's help center, "All your data including posts, characters, personas, and profile information will be permanently removed and cannot be recovered."
- Janitor's public help documentation does not specify the retention period or backup handling of private chat logs after account deletion.
▶ The 60-second explainer (script)
Does Janitor AI read your chats? Two questions are hiding inside that one, and separating them gives you the real answer. Question one: can they? That's technical, and it has a definite answer. There's a property called end-to-end encryption — it means the server only holds scrambled text and doesn't have the key, so the company literally cannot read your messages. Not a promise. Math. Signal works that way. Janitor doesn't, and you can prove it yourself in five seconds: close the tab, open the site on your phone, and your chat is right there waiting. That only works if a server stored your conversation in readable form. So — can they? Yes. What protects you is company policy and internal access controls. Janitor's policy says it doesn't read private chats and doesn't sell your data. That's a promise, and promises are worth something, but they're not the same as being unable to. Now here's the part almost nobody mentions. If you set up a proxy, you added a second reader yourself. Your messages leave Janitor entirely and go to OpenRouter, OpenAI, Anthropic, or DeepSeek — whoever owns that API key you pasted in. They have their own retention rules and their own policy on training. And free tiers usually carry the loosest data terms. Free inference tends to get paid for with data. So Janitor might be the more private half of your setup. The practical rule isn't trust or don't trust. It's this: treat anything you type into any cloud chat as something a human could read someday. Not likely. Possible. So keep your real name, address, employer and face out of it — and read the current policy yourself at janitorai dot com slash policy.
What authoritative sources say
People also ask
Are Janitor AI chats encrypted?
They're protected in transit by HTTPS like any website, but they are not end-to-end encrypted. The server stores them in a form it can read — which is why your chats follow you across devices.
Does Janitor AI train its model on my chats?
Janitor's policy pages are the authoritative source and the wording changes, so check janitorai.com/policy directly. If you use a proxy, the separate question is whether that provider trains on inputs — free tiers commonly reserve that right.
Can Janitor staff see my private roleplay?
Technically yes — there's no encryption preventing it, and employees with database access exist at every centralized platform. Janitor's policy says it doesn't read private chats. That's a policy commitment, not a technical barrier.
Is using a proxy more private than JLLM?
Usually less private, not more. A proxy sends your text off Janitor's servers to a third party with its own logging and retention rules, so you end up with two companies holding your conversations instead of one.
Does deleting my account erase my chat logs?
Deletion is permanent and removes posts, characters, personas, and profile data per Janitor's official help article. What happens to old chat logs and backups isn't spelled out in the public documentation.