Use this page to avoid entering another person's messages, identity, images or private details without permission. The goal is not to label a person or certify a product. It is to notice an observable signal, verify the current account or policy, and choose a proportionate action before more money or sensitive information is involved.
What the available evidence can tell you
The sources below define a practical boundary for this question. They help distinguish an observable warning sign from a feeling or assumption. They cannot guarantee what every conversation, account or support request will do.
This guide is anchored to OWASP guidance on sensitive information disclosure, Candy AI privacy policy, Candy AI content removal policy. Those materials support the question and the recommended check; they do not prove that every account behaves identically.
The narrow question here is to avoid entering another person's messages, identity, images or private details without permission. Keeping that single question in view prevents a general warning from becoming an unsupported claim about an entire service.
Vendor pages are used for current product and policy statements. Government, nonprofit and security guidance is used for risk framing. Neither kind of source replaces what the live account shows today.
A warning sign should lead to a practical response: pause, verify, reduce exposure, document what happened, use a report or deletion route, or leave. It should not be turned into a diagnosis or legal conclusion.
A repeatable check you can run
Use a low-risk fictional example and keep the result dated. Do not provoke dangerous content or disclose something sensitive just to test whether a system will mishandle it.
- Write the exact behavior or wording connected to this question: avoid entering another person's messages, identity, images or private details without permission.
- Check the current product surface and the cited policy instead of relying on a screenshot or old review.
- Use a harmless fictional example; do not expose real credentials, private third-party information or intimate identifying details.
- State one clear boundary or decision rule, then observe whether the next step respects it without pressure.
- Record the date, the relevant setting or page, and the action you took so the decision can be reviewed later.
Turn the signal into a decision
Name the signal
Describe only what can be observed in the interface, wording or policy. For this page, that means you are trying to avoid entering another person's messages, identity, images or private details without permission. Avoid guessing at motives or turning one response into a sweeping conclusion.
Check the context
A signal matters in context: what happened before it, whether you had already stated a preference, and whether the product offered a correction or exit. Use fictional details, minimize uploads, and never enter credentials, financial information, health records, precise location or another person’s private material.
Choose a proportionate response
Start with the least risky useful action—pause, inspect a setting, remove information, decline a purchase or leave. A private-feeling conversation is not proof of confidentiality. The practical test is whether collection, retention, deletion and third-party handling are explained well enough for the information you might share.
Keep the decision reversible
Do not spend more, upload more or deepen an intimate conversation while a serious question remains unresolved. A reversible choice gives you time to compare sources and seek qualified human help when needed.
Stop conditions
Stop the test and protect the user when any of these conditions appears. You do not need a complete investigation before declining a purchase, ending a chat or seeking qualified human help.
- The service requests information it does not need.
- Retention or secondary use is unexplained.
- Real-person material is encouraged without consent checks.
- Account, chat or media deletion routes remain unclear.
A private-feeling conversation is not proof of confidentiality. The practical test is whether collection, retention, deletion and third-party handling are explained well enough for the information you might share.
Keep a short record of the source, date, setting and action. That makes the decision reviewable without pretending that a static guide can certify a changing service.
Sources checked
Official product and policy pages are labeled as vendor statements. Public-interest and security sources provide context. Recheck changing prices, settings and policies in the live service before relying on them.
- OWASP guidance on sensitive information disclosuregenai.owasp.org
- Candy AI privacy policycandy.ai
- Candy AI content removal policycandy.ai