Blog

What Models AI Girlfriend Apps Actually Run

What AI models power AI girlfriend apps? Platforms with public data run rented open-weight models; most of the rest never name their chat model.

Most AI girlfriend apps won’t tell you what AI powers them. Where the numbers are public, the answer is rented open models: on OpenRouter’s rankings, the most-used chat model behind Janitor AI, the busiest companion platform in those rankings, was DeepSeek V3.2 at 281 billion tokens in the 30 days to July 18, 2026.

The market splits three ways: the platforms you can see into rent open models, the polished apps hide the name, and a few genuinely build. Adult AI Guide examined the public pages of twenty AI girlfriend and adult AI apps between April and July 2026: of the fifteen that offer chat, only two named the real model behind it.

Most AI girlfriend apps are wrappers around rented models

Most AI girlfriend apps are interface and billing wrapped around a character system, and the intelligence is rented: your chat runs on a language model, the companion’s pictures come from an image model, her voice from a speech model, and the app bills you for all of it. A few, led by Character.AI, genuinely train their own.

Most of those models are open-weight, meaning the trained model itself can be downloaded and run on hardware the operator picks, which moves content decisions from the model maker to the app. That one fact shapes this whole market, and it’s why the biggest AI names barely appear in the traffic you can measure.

AppWhat it disclosesWhat that means
Janitor AI, Chub AIRoute through OpenRouter (public)DeepSeek-led open-weight mix, visible in the data
Candy AI (EverAI)Unnamed “third-party” providersAdmits outside model work, names none
Backyard AI“Most common base model… is LLaMa”Names the open base outright
Character.AITrains its own (“Kaiju”)Genuinely proprietary
Nomi.aiReported “in-house” modelBase unverified

You can watch the renting happen on OpenRouter, a marketplace that routes apps’ AI requests to hundreds of models and publishes which apps use which. Janitor AI sent requests to 323 different models there in the 30 days ending July 18, 2026; Chub AI, a more explicitly adult platform, used 311. In the marketplace’s own app rankings for the month to mid-July 2026, Janitor AI was the ninth-busiest app of any kind. No other companion platform ranked above it. No app builds 300 models. They’re rented off a menu, and on these two platforms users often pick which one.

Those two are the see-through end of the market, and the polished consumer apps are the other end, one branded companion with the machinery hidden. That split shapes everything below. The receipts come from the see-through platforms, while the hidden apps offer nothing but their policies.

The platforms you can see into run DeepSeek

On the two adult platforms whose model traffic is public, Janitor AI and Chub AI, the busiest chat models are open-weight, and DeepSeek, an open line from a Chinese lab, leads both. Six of Janitor AI’s ten busiest models in the 30 days to July 18, 2026 were DeepSeek versions.

Here are Janitor AI’s top three by token count (a token is a few characters of text):

RankModelMakerTokens (30 days)
1DeepSeek V3.2DeepSeek281B
2DeepSeek V4 FlashDeepSeek94.5B
3DeepSeek V4 ProDeepSeek74.4B

The seven below them were more DeepSeek builds, open models from Nvidia, Google, and Tencent, and one unlabeled stealth model. The only established closed model in either platform’s top ten was Anthropic’s Claude Sonnet 4.5 on Chub AI, at a comparatively thin 8.3 billion tokens, a sliver consistent with a maker that bars erotic use. And the pattern runs wider than companion apps: in mid-July 2026, seven of the ten busiest models on OpenRouter’s overall weekly leaderboard were open-weight. It adds up to one fact. The chat these platforms sell runs on models anyone can rent.

The big-name AIs are missing because of policy, then price

ChatGPT, Claude, and Gemini barely appear in the companion traffic you can measure, and that is a policy fact before it is a technical one. A closed model is reachable only through its maker’s servers, so the maker’s content rules bind every app built on it. For explicit chat, those rules mostly say no.

Anthropic’s usage policy files “erotic chats” under a section headed “Do Not Generate Sexually Explicit Content.” Not a gray area. Google’s generative AI rules ban content “created for the purpose of pornography or sexual gratification.” Both bans are in force as of July 2026. OpenAI’s written usage policy stops short of a blanket ban, but the age-gated adult mode it announced has been indefinitely paused since March 2026. The one exception runs the other way: xAI’s acceptable use policy doesn’t prohibit fictional adult content, and Grok sells its own companion characters. Policy mostly clears the closed flagships out, and what’s left rents cheap. The disclosure side agrees. None of the fifteen chat-offering apps in Adult AI Guide’s review names OpenAI, Anthropic, or Google as its provider. The going rates in July 2026, with the one established closed model from those top tens for scale:

ModelPer 1M tokens (in / out)
DeepSeek API$0.14 / $0.28
DeepSeek, hosted on DeepInfra$0.26 / $0.38
Claude Sonnet 4.5$3 / $15

DeepSeek V3.2’s weights are MIT-licensed and free to run commercially, so an app can rent them from any host or run them on its own machines. But the order of causes stays put. The ban does the excluding; cheap open rates only explain why the survivors get rented.

What the apps that won’t say still admit

Candy AI, which sells chat, pictures, voice, and video as one branded companion, names no model behind any of them. Its privacy notice, revised May 2026, still admits the outsourcing, saying messages may go to unnamed “third-party LLM providers and/or hosters.” The notice spells out what that means for your side of the chat:

“Please note that these third parties may receive the content of your messages exchanged with our chatbot.”

The same notice says Candy AI trains its models on de-identified chats, in a process that “may include human review.” Assume your side of the chat leaves the app: what the policy describes is transfer to outside providers and training use, with possible human review. Silence about the model is the norm across the polished apps that imply something proprietary. Thirteen of the fifteen chat-offering apps in Adult AI Guide’s review never name the real model behind it. Only three of the fifteen say anywhere public that outside AI providers process your messages: Candy AI in its privacy policy, OurDream in its account privacy summary, and SecretDesires on a security page.

Some dress the rented engine in a house name. Kindroid’s “Ember” is a house name that reveals nothing about the base model underneath. Treat engine names as labels, not information. “Proprietary” usually means fine-tuned at most (a rented base model given extra training), because building a model from scratch costs far more than any companion app earns. It costs an app nothing to name its stack, except the mystique, and the mystique is what the silence protects.

Pictures, voice, and video follow the same pattern

The image, voice, and video features are rented from a small pool of mostly open models too, and the app almost never says which. Of twenty apps in Adult AI Guide’s 2026 review, only three name a real image model; of the eighteen offering video, only one names its model. Candy AI names none.

  • Pictures: the public pool is small: Stable Diffusion XL with fine-tunes such as Pony Diffusion, plus the newer FLUX family. The licenses carry a quiet catch: FLUX’s popular “dev” variant and Pony Diffusion both bar paid image generation under their public terms, so a paid app on those weights would need a separately bought commercial license. None says whether it has one. The three apps in our review that do name an image model draw from this same pool: SecretDesires AI (Stable Diffusion XL and FLUX), PornWorks (Stable Diffusion, SDXL, FLUX, and Pony), and CelebMakerAI (an SDXL fine-tune).
  • Voice: the supplier’s name, when known, comes from the vendor’s side, not the app’s. ElevenLabs’ own case study says “Kindroid uses ElevenLabs to power their voices.” Wherever the supplier is known at all, the voice is a bought-in vendor service.
  • Video: the thinnest layer. Open bases exist, such as Alibaba’s Wan, and just one app in our review, CelebMakerAI, names what powers its clips (Kling and Wan). The other apps that offer video name nothing.

So below the chat layer the honest answer is a shrug with a shortlist: a small and mostly open pool, and almost nothing named.

The few that genuinely build their own

Character.AI is the clearest counterexample. It describes itself as “a full-stack AI company… training our own language models from scratch,” and it ships an in-house family called Kaiju in 13B, 34B, and 110B sizes, meaning small to large. That is a genuine proprietary model.

The line blurs from there. Replika’s help center describes a mix: it “combines our own and third party Large Language Models and scripted dialogue.” TechCrunch reported in September 2024 that Nomi “built its LLM in-house,” though it named no base model to check. And in its 2025 Kaiju post, Character.AI itself wrote that the team “shifts towards building on top of Open-Source models.” Even the builders drift toward the open pool, and the visible market leans rented, with from scratch the exception.

How to check what your app actually runs

You can check a companion app’s stack yourself, from public pages, in a few minutes, and you don’t need an account for any of it. For an app like Candy AI or Kindroid, the privacy policy and the public traffic data answer faster than any marketing page. Four checks, in rough order of reliability:

  1. Search OpenRouter’s app rankings for the app’s name. If it routes there, its page lists the exact models with usage counts. That is the closest thing to a receipt.
  2. Read the privacy policy before the homepage. Search it for “third party,” “providers,” “LLM” (the industry term for a chat model), or “model.” Wording like Candy AI’s “third-party LLM providers” means the model work happens outside the app, whatever the marketing implies.
  3. Discount branded engine names. An in-app “V2 engine” or a named persona model is a label; the base model behind it stays unknown.
  4. See whether the app lets you choose a model. The ones that expose a model picker, like Backyard AI, usually name the open bases behind it, which tells you what the default is drawn from too.

For the apps that will not name it, the stack is unnamed because naming it would show how little of what you’re paying for the app actually built.

Frequently asked questions

What LLM does Janitor AI use?

Janitor AI doesn't run one model; it routes across hundreds. In OpenRouter's public rankings for mid-July 2026, its most-used model was DeepSeek V3.2, and six of its ten busiest models were DeepSeek versions. The rest were mostly open models from Nvidia, Google, and Tencent, plus one unlabeled stealth model.

What AI model does Candy AI use?

Candy AI does not say. Its privacy notice, revised May 2026, discloses that messages may be sent to unnamed 'third-party LLM providers and/or hosters,' but names no specific model.

Do AI girlfriend apps use ChatGPT?

Not visibly. OpenAI's written policy doesn't ban adult text for consenting adults outright; it bans non-consensual content and anything involving minors, and the age-gated adult mode OpenAI announced has been indefinitely paused since March 2026. The companion traffic you can measure runs on open models like DeepSeek, and an app calling OpenAI directly wouldn't show in that data.

Why do so many AI girlfriend apps run DeepSeek?

Policy first, then price. Anthropic bars 'erotic chats' and Google bans content made for sexual gratification, so explicit chat has to run on models whose operator sets the content rules. Among those, DeepSeek publishes its weights under the MIT License and rents for a fraction of flagship prices.

Are AI girlfriend chats private?

It depends on the app, so read its privacy policy and terms before assuming anything. Candy AI's notice, for example, says de-identified interactions may train its AI models, that preparing the data 'may include human review,' and that third-party providers may receive message content. The app's own pages are your best public window into who can store and read your messages, and in Adult AI Guide's review most disclosed nothing at all.