Perplexity Comet Browser: Features, Privacy, Security and How to Use It

Guides
by David Porter
Thursday, 30 July 2026 at 19:56
thumbnail_perplexity-comet-browser-featu
Comet is Perplexity’s Chromium-based browser with an integrated AI assistant. It can browse ordinary websites, import familiar browser data, summarize and compare pages, use context from open tabs and perform supported actions on a user’s behalf.
It is available free on macOS, Windows, iOS and Android.
Comet’s main advantage is not an answer box beside a webpage. It is shared context: the assistant can understand what the user is viewing without a constant copy-and-paste loop. The same advantage explains its main risk. A browser sees accounts, forms, downloads, messages and potentially sensitive pages. Giving an AI assistant access to that context creates more consequence than asking a standalone search question.
The right way to evaluate Comet is therefore two-part:
  1. Does browser context save meaningful time?
  2. Can permissions and confirmations keep that context and action within an acceptable boundary?
This guide covers both. For Perplexity Search, Research, Projects and the wider product family, use the Perplexity cornerstone.

Comet at a glance

TableCopy Table Raw
DeveloperPerplexity
Product typeChromium-based web browser with AI assistance and agentic actions
PlatformsmacOS, Windows, iOS and Android
PriceFree browser; some assistant capabilities depend on the Perplexity plan
Browser compatibilityBuilt on Chromium, with familiar extension and website compatibility
Core assistant usesPage summaries, tab comparison, contextual questions, extraction and supported actions
Local password storageOperating-system vault: Keychain on macOS, Credential Manager on Windows
Enterprise versionYes, with administrative policies and controls
Main benefitAI can work in the browsing context
Main riskPage content and broad permissions can influence an agent with access to accounts
Official pageperplexity.ai/comet

What makes Comet different from adding a chatbot extension?

A typical browser extension operates inside another company’s browser and receives only the permissions declared by the extension. Comet is the browser. Perplexity can design navigation, search, side-panel assistance, history, tab context and agent actions as one product.
That integration can reduce friction:
  • ask a question about the current page;
  • compare several tabs without copying their contents;
  • find the relevant paragraph in a long document;
  • turn a browsing session into a summary;
  • fill or navigate supported forms;
  • draft a message from material on screen;
  • and continue Perplexity research without leaving the browser.
It also expands the trust boundary. The browser processes credentials, cookies, signed-in sessions and everything rendered by a page. A responsible user should not give its AI component universal access merely because the browser itself needs broad technical access.

How to install and set up Comet

1. Download from the official source

Use Perplexity’s Comet page or the official Apple or Google store listing. Avoid third-party download pages and sponsored lookalikes.

2. Import only what you need

Comet can import browser material such as:
  • bookmarks;
  • browsing history;
  • saved passwords;
  • autofill information;
  • and extensions, where supported.
A full import is convenient but not mandatory. A cautious first test can begin with bookmarks only, leaving passwords and payment autofill in the existing browser.

3. Understand the keychain request

On installation, Comet may request access to the operating system’s secure credential storage. Perplexity says this is used for data such as website credentials, payment autofill, authentication tokens and encrypted information used by intelligence features.
On macOS, passwords are kept in Keychain. On Windows, Comet uses Credential Manager. The operating system can require local verification before autofill.

4. Review sync

Most ordinary browsing information is stored locally unless the user explicitly enables synchronization with a Perplexity account. Decide which device settings, bookmarks or browsing data should sync before turning it on.

5. Set assistant permissions

Do not approve every capability during onboarding. Start with page reading and low-risk navigation. Add access to sites or accounts only when a repeatable task needs it.

6. Keep a fallback browser

During evaluation, retain a familiar browser for banking, administration, password changes and other sensitive tasks. This makes gradual adoption easy and reduces pressure to grant Comet every permission immediately.

What Comet stores on the device

Perplexity’s local storage documentation says most browsing data remains on the device, including:
  • browsing and search history;
  • cookies and site data;
  • cached files;
  • autofill form data;
  • and the download-history list.
Saved passwords are encrypted in the operating system’s vault. Downloaded files remain on disk even after browsing data is cleared. Synced settings live separately in the Perplexity account.
This creates an important deletion rule:
Clearing local Comet browsing data does not necessarily delete synced Perplexity settings, account history, downloaded files or content stored in another connected service.
Deletion needs to follow the data to each location.

Incognito mode: what it does and does not do

When an Incognito window closes, Comet says it does not retain that window’s browsing history, cookies, form fills or passwords locally.
Incognito does not make activity invisible to:
  • the websites visited;
  • an employer or school network;
  • the internet service provider;
  • downloaded files;
  • bookmarks created;
  • or permissions changed.
If the user invokes Comet AI in Incognito, the query and context required to answer it are still sent to Perplexity’s servers. Perplexity says those AI interactions are not saved to account history when AI Data Retention is off, while security and abuse-prevention logs can still exist.
Incognito is a local-history control, not anonymity and not a no-processing mode.

What can the Comet Assistant do?

Capabilities vary by platform, plan, site and rollout. Common categories include:

Understand a page

Ask for:
  • the central argument;
  • a definition in context;
  • a list of dates or people;
  • the difference between two sections;
  • or an explanation for a specific audience.
For consequential claims, open the source passage instead of relying on the summary.

Work across tabs

Comet can compare products, policies, itineraries or other material across several open pages. Give explicit dimensions:
Compare the four open plan pages on monthly price, annual price, data treatment, seat minimum and cancellation. Use only text visible in those pages. Mark missing information instead of inferring it.

Navigate and extract

The assistant can help locate a control, follow a series of pages or turn unstructured material into a table. This is useful for discovery; validate extracted numbers.

Perform actions

With suitable permission, an agent can interact with sites and logged-in services. Examples can include drafting or sending a message, filling a form, organizing information or assisting with shopping.
Action is where human confirmation becomes essential.

A safe permission model

Use three tiers.

Tier 1: read-only and public

Good starting tasks:
  • summarize public pages;
  • compare open documentation;
  • extract a public table;
  • navigate an unfamiliar website;
  • draft text without sending it.

Tier 2: private but reversible

Require inspection:
  • read selected email or calendar information;
  • prepare a draft in a signed-in service;
  • organize a non-sensitive workspace;
  • add items to a cart without ordering;
  • fill a form without submission.

Tier 3: consequential or hard to reverse

Keep a human at the final step:
  • sending messages;
  • making purchases;
  • publishing;
  • deleting data;
  • changing account permissions;
  • accepting legal terms;
  • handling banking;
  • resetting passwords;
  • disclosing health, employment or identity information.
An agent’s ability to click a button is not a reason to remove approval.

Prompt injection in an AI browser

Prompt injection occurs when untrusted page content contains instructions intended to manipulate the assistant. The malicious text can be visible, hidden or embedded in content the agent reads.
An attack might try to persuade an assistant to:
  • ignore the user’s instruction;
  • reveal information from another tab;
  • send data to an attacker;
  • download or execute something;
  • or approve a transaction.
Traditional browsers render hostile content but do not usually treat it as an instruction. An AI browser must distinguish webpage data from authorized user commands.

Reduce prompt-injection risk

  • Keep the agent on the minimum number of tabs.
  • Close sensitive pages before exploring an untrusted site.
  • Deny a page access to unrelated account context.
  • Require confirmation for external communication and transactions.
  • Read the proposed action, recipient, amount and destination.
  • Do not allow a page to redefine the task.
  • Stop when the agent requests an unexpected permission.
  • Use an isolated browser profile for higher-risk research.

Independent security findings

Security research is useful only when the status of a finding is clear.

Guardio’s Scamlexity tests

Guardio Labs tested agentic browsers against scam and malicious-page scenarios in 2025. The work illustrated a category-level problem: an agent can interact with deceptive content more actively than a passive browser.
The tests do not prove that every current Comet session will fail. They support the need for constrained permissions and transaction approval.

Zenity’s PleaseFix and PerplexedAgent research

Zenity Labs disclosed a chain that could expose local data through the browser agent. The researchers say they responsibly disclosed it in October 2025. Perplexity implemented a stronger trust boundary, and Zenity confirmed on February 13, 2026 that the reported attack no longer worked.
It should be described as a fixed historical vulnerability, not a known unpatched flaw.
The episode still teaches an architectural lesson: browser agents need explicit separation between untrusted web instructions and trusted local resources.

Comet and the Amazon dispute

Amazon sued Perplexity over an agent that could access Amazon customer accounts and place orders. Amazon alleged unauthorized automated access and disguising agent traffic as human browsing. Perplexity disputed the case and framed it as a question of user choice.
A federal judge issued a preliminary restriction in March 2026; an appeals court temporarily paused that order, and the Ninth Circuit heard arguments in June. At the time of review, the dispute was ongoing.
The case is not proof that every Comet use is unlawful. It exposes a new question: when an agent uses a signed-in account, who is technically and legally accessing the service, and which site rules apply?
Users should not assume that authorizing an agent overrides a website’s terms or technical restrictions.

Comet for Enterprise

Perplexity offers an enterprise version with administrator controls and deployable browser policies.
Published controls include areas such as:
  • sign-in restrictions;
  • synchronization;
  • extension management;
  • password and autofill behavior;
  • site permissions;
  • security settings;
  • and other Chromium-derived policies.
Administrators should treat Comet as both a browser deployment and an AI deployment. The rollout needs:
  • managed versions and updates;
  • allowed extensions;
  • identity and device policy;
  • AI data settings;
  • approved use cases;
  • sensitive-site rules;
  • incident handling;
  • and agent-action controls.
The Perplexity Enterprise guide covers the larger organizational system.

Ten useful Comet workflows

1. Compare current documentation

Open only the relevant official pages. Ask for a matrix of named fields, with “not stated” for missing data.

2. Summarize a long page

Ask for claims, evidence, exceptions and dates rather than a generic summary.

3. Inspect a terms change

Open old and new versions where available. Ask Comet to identify changed clauses, then verify line by line.

4. Research before writing an email

Let the assistant create a draft from selected public tabs. Review it before granting access to the mail account.

5. Build a reading list

Ask for the original sources cited by several secondary pages, remove duplicates and open the most authoritative items.

6. Extract event details

From the event page, extract location, time zone, price, cancellation terms and accessibility information. Confirm before booking.

7. Compare shopping options

Ask for total price, shipping, return policy and vendor. Add to cart if useful, but place the order manually.

8. Navigate a complex government site

Use the assistant to locate the form or guidance. Verify the domain and complete submission yourself.

9. Review open support tickets

In an approved work profile, summarize themes without sending replies. Remove unnecessary customer identifiers from the output.

10. Turn tabs into a research note

Ask for a sourced note containing only the open pages, then move the verified result into the approved knowledge system.

When not to use the Comet Assistant

Keep the assistant out of:
  • a password manager’s master interface;
  • online banking;
  • tax filing;
  • administrative identity controls;
  • confidential legal or medical systems without explicit approval;
  • destructive production controls;
  • or any page where the data class exceeds the account and company policy.
Ordinary manual browsing in Comet can still be possible. The issue is granting AI access to page context and actions.

Comet versus Chrome, Edge and Safari

Comet’s differentiator is integrated Perplexity assistance. Chrome, Edge and Safari have larger platform ecosystems, long-established enterprise deployment and their own evolving AI features.
Choose Comet when contextual AI creates a clear advantage and its policies meet the use case. Stay with the incumbent browser when compatibility, enterprise management, existing security tooling or a lower AI trust surface matters more.
Using two browsers is a valid arrangement: Comet for public research, a managed incumbent for sensitive accounts.

Frequently asked questions

Is Comet browser free?

Yes. Perplexity offers the browser free, while some assistant capacity and premium Perplexity features depend on the subscription.

Is Comet based on Chrome?

It is based on Chromium, the open-source browser project that also underpins Chrome and several other browsers. It is not Google Chrome.

Can Comet use Chrome extensions?

Chromium compatibility supports many familiar extensions, subject to platform and extension behavior. Review every extension’s permissions.

Where does Comet store passwords?

Perplexity says saved passwords are encrypted in the operating system’s secure vault: Keychain on macOS and Credential Manager on Windows.

Does Comet upload all browsing history?

Perplexity says most browsing information stays locally unless the user enables synchronization. Invoking AI features sends the query and necessary context to Perplexity for processing.

Is Incognito private from Perplexity?

Incognito prevents several local records from persisting after the window closes. AI requests still require server processing, and security logs can remain.

Is Comet safe?

It can be used safely for many tasks when kept updated and given limited permissions. Agentic browsing adds risks such as prompt injection and unintended action, so sensitive steps need human control.

Was the Zenity vulnerability fixed?

Zenity says Perplexity implemented a fix and the disclosed attack no longer worked when retested in February 2026.

Can Comet buy things for me?

Supported agents can assist with shopping in some contexts. Review the product, seller, price, address and terms, and keep final purchase confirmation manual.

Can a company manage Comet?

Yes. Comet for Enterprise supports administrative policies. Organizations still need use-case governance and incident procedures.

The bottom line

Comet makes AI assistance feel native to browsing. For public research, page comparison and navigation, that can be substantially more efficient than moving material into a separate chat window.
The browser is also where an AI assistant can encounter hostile content and sensitive accounts at the same time. The solution is not to treat every agent feature as unsafe or every prompt as trusted. Start read-only, isolate sensitive work, grant permissions narrowly and confirm every consequential action.
Comet is most useful when it reduces browser friction without removing the user’s control of the browser.
loading

Loading