Is Perplexity Safe? Privacy, Accuracy, Copyright and Security

Guides
by David Porter
Friday, 31 July 2026 at 22:55
thumbnail_is-perplexity-safe-privacy-acc
Perplexity is reasonably safe for ordinary low-stakes research when the user keeps the account secure, avoids unnecessary sensitive information and checks important citations. It is not safe to treat every cited answer as true or to give an AI browser or agent unrestricted access to consequential accounts.
“Is Perplexity safe?” contains at least five questions:
  1. Privacy: What data does Perplexity collect, retain and use?
  2. Security: Can an unauthorized person or malicious page gain access?
  3. Accuracy: Does the answer and citation support the conclusion?
  4. Action safety: What can Comet or Computer do wrong in a real account?
  5. Content rights: How does Perplexity access and reproduce online material?
The answers differ by product and plan. A basic public search on Free is not the same data flow as an Enterprise Project, a Health record connection, a Comet shopping action or a Computer workflow using corporate email.
This guide maps those differences. For general features and use cases, read the complete Perplexity guide.

The practical verdict

Use caseRisk levelSafe approach
Public, low-stakes questionLowCheck relevant citations
Article, report or business researchModerateVerify primary sources and preserve a source log
Personal document on a consumer planModerate to highRemove identifiers, check retention and sharing
Confidential company informationHighUse an approved Enterprise deployment and policy
Medical, legal or financial decisionHighUse only for orientation; involve a qualified professional
Comet with logged-in accountsHighLimit permissions and approve every consequential action
Computer with write accessHighSandbox, least privilege, action gates and audit
Connected health dataVery high sensitivityMinimize data, review providers and use it only for informational support

Key takeaways

  • Consumer Free, Pro and Max accounts have AI Data Retention enabled by default for model improvement, according to Perplexity. Users can opt out for data collected after the change.
  • An opt-out does not delete previously collected training data and does not stop processing needed for service operation, law or product improvement.
  • Perplexity says Enterprise data is never used for AI training and that third-party model providers are contractually prohibited from training on Perplexity data.
  • Ordinary session files are retained for 30 days; Enterprise session files for seven days. Files in Projects or repositories remain until deleted.
  • Sharing a session publicly can expose its attached file to anyone with the link.
  • Account deletion removes personal information from Perplexity’s servers within 30 days under its published help guidance, subject to legal and public-interest qualifications.
  • Citations make errors easier to find. They do not prove the adjacent statement.
  • Browser and computer agents add prompt-injection, permission and unintended-action risks that do not exist in the same form in basic search.
  • Perplexity faces unresolved copyright and access litigation. Allegations should not be described as final legal findings.

What data does Perplexity collect?

Perplexity’s help material says it collects information for:
  • providing and securing the service;
  • account creation and management;
  • payments;
  • troubleshooting and product improvement;
  • understanding device and service interaction;
  • and, when the consumer setting remains enabled, AI model training and search improvement.
The exact data can include:
  • account identifiers such as email;
  • queries and responses;
  • usage and device information;
  • uploaded content;
  • feedback;
  • payment-related records handled with payment providers;
  • connector data the user authorizes;
  • and logs used for security and operation.
Perplexity states that it does not sell user data and shares information with service providers or when legally required under its policies. “Does not sell” does not mean “never shares or processes.” Read the data categories and purposes, not only the slogan.

Does Perplexity use searches to train AI?

For individual Free, Pro and Max users, Perplexity says AI Data Retention is enabled by default.
To turn it off:
  1. open Account settings;
  2. go to Preferences;
  3. locate the AI data-retention control;
  4. switch it off.
Perplexity’s July 2026 help page adds important qualifications:
  • the opt-out applies only to data collected after the opt-out date;
  • previously collected training data cannot be removed from training through this control;
  • core features continue;
  • data may still be processed to operate and secure the service, comply with law and improve the product.
This means “I opted out” is not equivalent to “Perplexity stores nothing.”

Enterprise

Perplexity says Enterprise Pro and Enterprise Max data is never used for AI training, including during a temporary billing lapse. If an organization deliberately downgrades to a consumer plan, the consumer default can apply and the user must review the setting.

Third-party model providers

Perplexity lets eligible users access models from other companies. Perplexity says contractual protections prevent providers such as OpenAI and Anthropic from using Perplexity data to train their models.
That is a provider commitment. A company still needs to review the applicable contract, subprocessors and exact product.

How long does Perplexity keep searches and account data?

Perplexity says personal information is retained while the account remains active. After a full account deletion request, it says personal information is removed from its servers within 30 days.
The help page also notes that removal requests can be balanced against public-interest and other rights, giving examples involving scams, professional malpractice, criminal convictions and public official conduct. That appears to address removal of information available through Perplexity, not a blanket promise about every legal record.
Search history, a session, an uploaded file and an account are different objects. Deleting one does not automatically prove that every related object has been removed.

File retention and deletion

Perplexity’s file rules are unusually important because they vary by location.
File locationPublished standard retention
Consumer session attachment30 days
Enterprise session attachment7 days
ProjectUntil deleted
Personal repositoryUntil deleted
Organization repositoryUntil deleted
After a session file expires, its raw contents are no longer available for new follow-ups, but earlier questions and answers can preserve contextual information derived from it.

Deleting a file from a session

Removing the file from the input context can stop it from being used in a new follow-up, while earlier generated responses retain what they already included. Perplexity’s web interface has more granular controls than some mobile and desktop surfaces.
For complete removal of an attachment and its use in the conversation, deleting the relevant session is the clearer action. Perplexity also provides a support form for immediate deletion requests.

Public session sharing

If a user makes a session public, anyone with the link can see and download the attached material according to Perplexity’s documentation.
Before sharing:
  • remove attachments;
  • export a sanitized PDF if appropriate;
  • inspect generated text for confidential excerpts;
  • and confirm that the session is not exposing connected-source information.
Do not use an unguessable link as if it were access control.

Are Perplexity answers accurate?

Perplexity improves one aspect of reliability: the reader can usually see sources immediately.
It can still fail in several ways:
  • retrieve the wrong page;
  • cite a page that supports only part of a sentence;
  • choose a copied or syndicated version;
  • miss a source that contradicts the answer;
  • confuse publication date and event date;
  • synthesize incompatible figures;
  • perform a calculation incorrectly;
  • or invent a claim around otherwise real citations.
A 2025 Tow Center study tested eight AI search products on identifying news articles from excerpts. Across that specific test, Perplexity answered 37% of the queries incorrectly, and the authors found confident errors and attribution problems across the wider category.
That is not a universal Perplexity accuracy score. It is evidence against the claim that visible citations eliminate retrieval errors.

How to check a Perplexity citation

For every decision-relevant claim:
  1. Open the citation directly beside it.
  2. Confirm that the page names the same entity, product and jurisdiction.
  3. Find the passage that supports the claim.
  4. Separate the page’s publication date from the underlying event or effective date.
  5. Prefer the original document over a summary.
  6. Check whether the source is reporting, marketing, opinion or research.
  7. Look for corrections and later updates.
  8. Search for credible disagreement.
If one sentence contains a price, limit and privacy claim beside one citation, split it and validate each fact.

Source hierarchy by task

ClaimPreferred evidence
Product price or limitCurrent official pricing/help page
Law or regulationOfficial legal text and regulator
Company financial resultFiling or audited report; reliable reporting for private estimates
Medical efficacySystematic review, guideline and relevant primary research
Security certificationTrust center, audit scope and contract
Breaking eventDirect announcement plus independent reporting
Scientific consensusMultiple high-quality reviews and expert body
An official source is authoritative for what its owner claims. It is not independent evidence of its own superiority.

Security of the account

Basic account safety still matters:
  • use a unique password;
  • use a password manager;
  • enable the strongest available multi-factor or passkey protection;
  • secure the email identity tied to the account;
  • review signed-in devices and connected services;
  • remove stale sessions and Projects;
  • do not share credentials;
  • and treat unexpected login or connector prompts as suspicious.
If a work account is provisioned through SSO, offboarding should disable access centrally and remove active sessions under company procedure.

Connector risks

A connector can expose a broad source through one authorization.
Before connecting:
  • define the question the connector solves;
  • grant the narrowest scope;
  • clean source-system permissions;
  • exclude sensitive folders or channels;
  • test retrieval as several user roles;
  • plan for deletion and permission changes;
  • disconnect it when the workflow ends.
The source provider’s permission model can prevent unauthorized file retrieval. It cannot guarantee that an authorized user will not generate an inappropriate summary or share it.

Comet browser safety

Comet’s assistant can see and act in browser context. That creates three special risks.

Prompt injection

A malicious webpage may include instructions designed for the agent rather than the reader.

Cross-context exposure

An assistant with access to several tabs may combine public hostile content with a sensitive signed-in page.

Unintended action

The agent can misunderstand a form, recipient, product, amount or permission.
Use Comet read-only on public pages first. Close sensitive tabs. Require explicit approval before sending, buying, deleting, publishing or changing access.
Independent research found serious agent-browser weaknesses in 2025. Zenity later confirmed that Perplexity fixed its disclosed local-file attack by February 2026. That finding should not be misrepresented as a currently unpatched issue. It does demonstrate why isolation must be continuously tested.
The Comet browser guide covers the security model in detail.

Perplexity Computer safety

Computer can connect to email, collaboration, code, CRM and data systems, create files and run scheduled work.
Risks include:
  • overbroad authorization;
  • harmful tool chaining;
  • prompt injection through retrieved content;
  • action based on an incorrect conclusion;
  • silent changes;
  • recurring errors;
  • and uncontrolled credit spend.
A safe Computer task states:
  • allowed inputs;
  • permitted actions;
  • actions requiring approval;
  • output destination;
  • verification;
  • budget;
  • and a stop condition.
Use a sandbox or test workspace before production. Give read access before write access. Keep legal, financial, identity, employment and destructive decisions human.

Perplexity Health

Perplexity Health is available to eligible US Pro and Max users and can connect medical records, Apple Health and supported wearable or wellness providers.
Perplexity says:
  • Health is for informational use and does not diagnose or replace medical care;
  • health chats, connector data, files and memories are not used to train AI models;
  • raw health data is queried on demand and not permanently stored on Perplexity servers;
  • uploaded health files are kept in a separate encrypted repository;
  • health memories may be generated for personalization;
  • connections can involve providers such as b.well and Terra API.
These are strong safeguards, but the data is exceptionally sensitive. “HIPAA-aligned” consumer safeguards do not necessarily make Perplexity the user’s healthcare provider or convert every consumer interaction into a HIPAA-covered service.
Use Health to organize questions and trends. Confirm lab interpretation, diagnosis, treatment, nutrition therapy and emergencies with a qualified professional. Share the minimum categories needed and disconnect sources that no longer serve a purpose.

Shopping and financial action

Perplexity can support shopping and eligible Instant Buy experiences. Comet and Computer can also act across web services.
Before a purchase:
  • verify the merchant;
  • product variant;
  • total including tax and shipping;
  • delivery address;
  • return and cancellation terms;
  • recurring subscription language;
  • and payment method.
Keep final confirmation manual. Do not let an AI agent interpret a financial agreement or investment risk as personalized professional advice.

Copyright and publisher disputes

Perplexity’s answer engine depends on access to online material. Publishers and platforms dispute how some of that material is accessed and reproduced.

Lawsuits

The New York Times sued Perplexity in December 2025, alleging unlawful copying. CNN filed another suit in May 2026, alleging that Perplexity copied and distributed protected stories, video and images. Other litigation has involved Dow Jones, Reddit and additional parties.
Perplexity has disputed claims and argued, among other points, that facts are not protected by copyright. The cases were unresolved at review. A complaint contains allegations, not adjudicated facts.

Crawler controls

Cloudflare reported in 2025 that traffic associated with Perplexity used undeclared crawling behavior after sites tried to block its named crawlers. Perplexity disputed the characterization.
Robots preferences, contractual access, copyright and technical circumvention are related but legally distinct questions.

Publisher partnerships

Perplexity has also signed licensing, content and revenue-sharing arrangements with publishers. A partnership with some publishers does not resolve claims from others.

What users should do

  • Cite the original source, not the Perplexity answer.
  • Do not reproduce long protected passages.
  • Check licenses for images, video, data and premium sources.
  • Treat generated summaries as drafts.
  • Follow the publication’s attribution and AI policies.
  • Get legal review for commercial reuse with material rights uncertainty.

Is Perplexity safe for children and students?

Students can use Perplexity to discover sources, explain concepts and build research maps. Risks include inaccurate answers, exposure to unsuitable content, academic misconduct and sharing personal information.
Schools should define:
  • allowed assignments;
  • disclosure and citation rules;
  • age and account requirements;
  • data that may be entered;
  • source-verification expectations;
  • and when teacher review is mandatory.
The student should read the source and produce original reasoning. A citation generated by Perplexity is not evidence that the paper was read.

Is Perplexity safe for work?

For public research, a consumer account may be acceptable under company policy. For internal, confidential or regulated material, use the approved enterprise workspace and connectors.
Never upload through an unapproved personal account:
  • unreleased financial results;
  • customer secrets;
  • authentication credentials;
  • privileged legal advice;
  • employee medical or identity data;
  • source code or vulnerability details classified as confidential;
  • export-controlled or contract-restricted information.
The Enterprise deployment guide explains the organizational controls.

A privacy and safety checklist

Before using Perplexity:
  •  Identify whether the data is public, internal, confidential or regulated.
  •  Use the approved account and plan.
  •  Turn off consumer AI Data Retention if model-improvement use is unwanted.
  •  Remove identifiers and irrelevant content.
  •  Check file location and retention.
  •  Review session sharing.
  •  Inspect connector scopes.
  •  Open the citations that determine the decision.
  •  Keep high-stakes judgment with a qualified person.
  •  Require approval for external or irreversible action.
  •  Set Computer credit limits.
  •  Delete sessions, files, Projects and connectors when they are no longer needed.

Common safety myths

“Perplexity cites sources, so it cannot hallucinate”

It can cite incorrectly, omit evidence or add unsupported inference.

“Turning off AI Data Retention deletes my history”

The control changes future model-improvement use; it is not the same as deletion.

“Files disappear after 30 days”

Session files do. Project and repository files remain until deleted.

“Incognito means Perplexity cannot process the page”

AI assistance still sends needed context to the service.

“Enterprise means every use is compliant”

Compliance depends on scope, configuration, contract, data and workflow.

“A fixed vulnerability means the product is permanently safe”

Security is continuous. Updates, new features and new attacks change the assessment.

“A lawsuit proves infringement”

Only a final decision or settlement resolves particular legal claims. Report allegations as allegations.

Frequently asked questions

Is Perplexity safe to use?

Yes for many ordinary research tasks with normal account security and source checking. Sensitive data, high-stakes advice and agent actions need stronger controls.

Does Perplexity sell my data?

Perplexity says it does not sell user data. Its policies still allow processing and sharing with service providers or when required by law.

Does Perplexity train on my searches?

Consumer AI Data Retention is enabled by default according to Perplexity and can be turned off for future data. Enterprise data is not used for training.

Does opting out delete old training data?

No. Perplexity says previously collected training data cannot be removed through the opt-out.

How long are uploaded files stored?

Consumer session files: 30 days. Enterprise session files: seven days. Project and repository files: until deleted.

Are public Perplexity links private?

No. Anyone with a public session link can view the session, and Perplexity warns that attached files remain visible.

Are Perplexity citations reliable?

They are useful routes to evidence, not guarantees. Verify the exact source passage.

Is Perplexity safe for medical questions?

Use it for general education and organizing questions, not diagnosis, treatment or emergencies. Perplexity Health has special data safeguards but does not replace care.

Is the Comet browser safe?

It can be used safely with updates, limited permissions and manual approval. AI browsers have added prompt-injection and action risks.

Is Perplexity safe for confidential business data?

Only in an approved Enterprise configuration and policy appropriate to the data. Do not assume personal Pro has enterprise treatment.

Is Perplexity legal?

The service is legally available, while specific crawling, content and agent practices are being contested in ongoing cases. Users must still comply with copyright, site terms and professional duties.

The bottom line

Perplexity’s visible citations and current search make it easier to audit than an opaque answer, but the user must actually perform the audit.
Privacy requires more than one toggle. Trace where searches, session files, Projects, connectors and health data go. Security requires more than a secure login. Limit what Comet and Computer can see and do. Legal safety requires using and crediting original sources responsibly while active disputes are resolved.
Use Perplexity to shorten the path to evidence. Do not let it shorten the path past judgment.
loading

Loading