The checklist
Run these in order. The first failure is usually enough information.
- Find the privacy policy and confirm it says what happens to conversation data
- Find the account deletion path before you sign up, not after
- Check whether generated media is private by default or public by default
- Check the billing descriptor if a statement line matters to you
- Confirm cancellation is self-service rather than an email request
- Look for age screening at signup and an RTA label in the page source
- Find the prohibited-content policy: a platform without one has not decided anything
- Use a unique password and an email address you control, never a work one
What good answers look like
Private by default, deletion in the settings rather than in a support queue, a published policy listing what is not allowed, and age assurance that exists before the first message rather than at checkout.
For reference, that is what HoneyPot does: chats and generated media private to your account, publishing opt-in, deletion available at any time, age screening at signup, RTA labelling, and a published prohibited-content policy enforced by moderation.
One habit that solves most of it
Do not tell a companion anything you would not be comfortable seeing in a data breach. Not because a specific platform is careless, but because that is the correct threat model for every online service and it costs you nothing to adopt.