Q16 Frontier Watch

Ratings Methodology

How we rate the privacy of consumer AI apps — traced all the way through the model behind them.

What we measure

We rate how privacy-protective a consumer AI product is on a 0–10 scale (higher is more private). This is not a measure of legal compliance; it is a judgment of how well a product protects the data you put into it.

Three layers, traced end to end

Most AI apps don’t run their own model — they send your data to a third party. So we don’t stop at the app’s promise. We trace each product through the chain it actually runs on:

App  →  Host (how it connects)  →  Provider (whose model)

Each app carries two scores, both on the same 0 (worst) to 10 (best) scale:

(Earlier versions of this page called these the Stated and Effective scores, with the difference published as the Gap. Same math, clearer names: App, Model, and the overall weakest-link rating.)

A layer is dropped from the weakest-link calculation only when it is a confirmed zero-retention path — a signed zero-data-retention agreement, or a verified self-host where content never leaves the operator. A model maker that never receives your data (for example, a model run inside a cloud host that contractually walls it off) is not the weak link.

The six dimensions

Every layer is scored on the same six dimensions, combined by the weights below. Score each 0–10 against the anchors, interpolating.

DimensionWeight10 — best0 — worst
D1 · Training use of user data0.25Never trains on user data, contractually guaranteedTrains on all user data, no opt-out
D2 · Data retention0.20Zero-retention or user-controlled immediate deletionIndefinite retention, no deletion path
D3 · Jurisdiction & government-access exposure0.20Strong privacy law + narrow, warranted access; or self-hostBroad state-access mandate, compelled handover
D4 · Third-party sharing & sub-processors0.15No sharing, no sale, no sub-processors touch contentSells or broadly shares user data
D5 · User control0.10Full delete/export/opt-out + zero-retention tierNo user control
D6 · Transparency & policy specificity0.10Specific, versioned, dated policy; changes loggedVague, absent, or contradictory

Training use leads because it is the defining privacy question for AI. Retention and jurisdiction follow because they set the ceiling on everything else. Where a policy is silent on a protection, it scores low — we rate what a product commits to, not what it might do.

Confidence: how we label each score

Every score carries a confidence label. It never changes the number — only how sure we are of it.

Minors and parental controls

Some of these apps are used by teenagers, and a few (companion and roleplay apps in particular) carry real risk for them. Protecting minors is a different question from protecting privacy, so we score it separately. Each app gets a Minors score from 0 to 10, reported alongside the privacy rating and never folded into it. The privacy number measures what happens to your data; the Minors number measures how well the app keeps under-18 users safe.

An app can earn a strong Minors score two ways:

A bare age disclaimer with no verification, or silence on parental controls and minors’ data, scores low. As with privacy, the score carries a confidence label, and “Verified” requires independent evidence that the controls actually work, not just that the policy claims them.

How we publish, and how to dispute

Independence is the point: we publish independently, and no company pre-approves, previews, or vetoes a rating. Every rating is built from the company’s own published policies and binding terms, and every score shows its basis.

Scope

The first cohort is 12 application-tier products selected for category coverage (routers, coding, productivity, notetakers, companions), each running on a third-party frontier model or its own, and the frontier model providers behind them. Ratings are refreshed as policies change, on a set cadence per layer.

Q16 Frontier Watch is an independent project of Q16 PBC.