NovelAI
Anime image generation and long-form AI writing in one subscription, with stories encrypted at rest.
- $10/mo
- No card
- Subscription
Roleplay is the one category here where the tooling matters more than the model. Anyone can put a character card in front of a language model. What separates these products is how much of the machinery they hand you: whether world detail is injected when a trigger word appears, whether you can set sampling behaviour yourself, how much context the plan buys, and whether the thing you wrote last week is still in scope this week.
So this hub compares control rather than personality. Context window, whether lorebooks and author's notes exist, whether the model runs on your hardware, and what the vendor states it does with the text you produce. That last one matters more in roleplay than anywhere else on this site, because the input is long, personal and written rather than clicked.
One finding is worth stating up front: the best-documented training position in this whole directory belongs to a roleplay tool, and the deepest authoring controls belong to a product whose reputation for privacy is out of date.
Ordered by editorial review. Click rankings for this category begin once enough listings clear our publishing thresholds. How we rank.
Never listedClothing removal from photographs of real people, sexual imagery of real people, and anything involving minors. Refused permanently, and refused by the schema rather than by a promise. What we will not list
Anime image generation and long-form AI writing in one subscription, with stories encrypted at rest.
Unfiltered character chat with a real free tier. The local desktop app it was known for is deprecated.
Unfiltered roleplay and story generation under Swiss law, with training off by default rather than opt-out.
Free open-source roleplay front-end you install yourself. No hosted service, no model, no account.
Unfiltered character chat with a genuine free tier, and one of the few rules here that names aged-up characters.
Roleplay, characters and image generation running on the phone itself, with most modes fully offline.
Nothing matches those filters. to see all 6.
The facts that decide whether to trust a tool rather than whether to try it. Every value is taken from the vendor's own published pages on the date shown on each listing. A blank is never a guess: where a vendor publishes nothing, the cell says so.
| Tool | From | Age check | Trains on your content | Deletion | Filtering | Minors policy | Jurisdiction |
|---|---|---|---|---|---|---|---|
| NovelAI | $10/mo | Self-declared at signup | Not documented | By request | Light filtering | Not published | Delaware, United States |
| Backyard AI | $12/mo | Self-declared at signup | Not documented | By request | No documented output filter | Published | California, United States |
| DreamGen | $7.83/mo | Self-declared at signup | No | In account | No documented output filter | Published | Switzerland |
| SillyTavern | Free | None stated | No | Your own files | No documented output filter | Not applicable | Not applicable, open-source project |
| CrushOn.AI | $4.9/mo | Self-declared at signup | Yes | By request | No documented output filter | Published | Hong Kong, by governing law |
| Layla | Not published | None stated | No | Your own files | No documented output filter | Not applicable | Not stated on the site |
The comparison that matters is not the same in every category. These are the questions that separate a good choice from a bad one here specifically, and why each one earns its place.
This is what separates a roleplay tool from a chat window with a costume on. A lorebook injects world detail when a trigger word appears, so setting survives a long session without being restated. An author's note steers tone without becoming dialogue. Most products in this category offer neither and are competing on model access instead.
Context is the closest published proxy for memory, and unlike memory it is checkable without an account. It decides how much of the session the model can still see. Vendors here sell plans by it, so it is one of the few specifications in this directory you can compare as a number rather than as a claim.
Roleplay input is long, personal and written rather than clicked, which makes it the worst thing on this site to hand to a third party. A local tool has no retention policy because nothing leaves the machine. That trade costs setup effort and compute and it is the only complete answer to the privacy question.
Opt-out and opt-in are not the same commitment, and a vendor that says nothing has not said no. The strongest position in this directory is training off by default with opt-in only, stated alongside the honest caveat that withdrawing consent cannot un-train a model.
A free tier that drops the context window to a fraction of the paid one is a demo rather than a trial, because the thing you are evaluating is exactly the thing it removed. A free tier at the same context as the entry plan is a fair test, and the listings record which is on offer.
Findings from assessing every candidate in this category against the same checklist, including the ones that are not listed. A gap that every vendor shares is a fact about the category rather than a complaint about one product.
For authoring control, Backyard AI: lorebooks, author's notes, grammars and exposed sampling parameters, which most competitors do not offer at all. For privacy, a local runner such as LM Studio, because models run on your own hardware and nothing leaves it. For a written guarantee about training, DreamGen. ClickTug publishes no ranking, because the quality of the writing is the thing people mean and it cannot be measured for someone else.
Yes, and they differ a lot. Backyard AI gives 300 messages a week at the same context window as its paid entry plan, which makes it a fair test. SillyTavern is free outright because it is open source and runs on your own machine. Several others advertise a free tier and publish no allowance for it, which each listing records.
This is the question ClickTug cannot answer honestly for most of them, and our listings say so. Memory behaviour needs an account to test, and we hold none, so it is marked not tested rather than guessed at. What is checkable is context window, which is published: DreamGen sells plans by it, and Backyard AI goes up to 100,000 tokens on its top tier.
Yes, and it is the strongest privacy position available. SillyTavern is a free open-source front-end you install yourself, and it needs a model behind it, which the local model runners on our Uncensored AI Chat hub provide. Layla runs models on the phone itself. Nothing you write leaves your hardware in either case.
Who wrote the character. On this hub you author or select the cast and the product is the machinery around it. On AI Girlfriend and AI Friend the vendor ships one persona and the relationship with it is the product. Some tools blur the line, so each listing states which side it was filed on and why.
Every directory in this category claims a standard. Ours is written as the four things we refuse, rather than as a promise to be careful, because a standard nobody can check is the same as no standard at all.
These refusals are permanent. They apply regardless of how much traffic the category would send, and each one is enforced by the software that stores these listings rather than by anybody remembering it.
The field that records this on a listing has exactly one legal value: not offered. There is no value that means yes, so a tool with that capability cannot be described by our schema, cannot be saved, and cannot be published. It is a shape in the data model, not a rule anybody has to remember to apply.
Including public figures, and including any product that builds a character from an uploaded photograph of somebody. A tool that puts a real person's face into adult material is refused on the same grounds, whatever the vendor calls the feature. Invented characters from a text prompt are what this directory covers, and that distinction is the whole line.
In any context whatsoever. A second word list fails this build on every page, including the pages written to state the refusals, which is why those pages describe this without using the vocabulary such products market themselves with. Credible reporting that a product generated this material excludes the vendor no matter what its own terms claim, because a policy page is a statement and a product is evidence.
Services that distribute that material are refused, and so is anything sold around it. If a listed service has been used against you, the removal request page is linked from every page on this site, is never hidden behind a menu, and is acknowledged by a person within 48 hours.
Refusals are enforced at the domain level as well as the word level, because a service can rename itself out of a word list overnight and keep the same infrastructure. Every vendor we assessed and turned down is named on assessed but not listed, with the reason and the date, including the ones refused on something they published themselves.
We do not chase the excluded keywords either, and they carry more search volume than everything ClickTug does cover. That is the trade: a smaller market, and a directory that is still here in five years. ClickTug also hosts no explicit images or video at all. Listings use vendor logos, interface screenshots and dashboards, and the build rejects any image loaded from a host other than our own.